Effective date: 2026-05-16
This Privacy Policy describes how Mykhailo Samiliak, operating as a sole proprietor under the trade name "KNICE TECH" ("we", "us", "our"), collects, uses, and shares information when you use the website at https://knice.test.minice.ai and our digital subscription service (the "Service"). Use of the Service is also governed by our Terms of Service.
1. Information We Collect
We collect only what we need to run the Service:
- From Telegram OAuth (sign-in): your Telegram user ID, first name, last name, and username. We use Telegram's standard login widget; the cryptographic hash returned by Telegram is verified server-side and not stored.
- From you, at checkout: your email address (used for billing receipts and account notifications). Email is optional on Stripe checkout but required for any tax receipt.
- From Stripe (our payment processor): the transaction ID, payment status, and (if you opt in to auto-renewal at checkout) a tokenised payment-method reference. We do not see or store your full card number, CVC, or banking details — Stripe handles those directly.
- Operational: short-lived session tokens for keeping you signed in, and aggregate logs (IP address, timestamps) used for security and abuse prevention.
We do not run third-party advertising or analytics SDKs on this site.
2. How We Use the Information
- to create and authenticate your account;
- to provide, maintain, and improve the Service;
- to process payments and renewals through Stripe;
- to send transactional messages (receipts, renewal reminders, security notices);
- to comply with applicable law and tax obligations;
- to detect, prevent, or investigate fraud and abuse.
3. Legal Bases for Processing
We process information on the basis of (a) performance of the contract under which we provide the Service to you, (b) our legitimate interest in operating and securing the Service, and (c) your consent — for example, when you opt in to auto-renewal.
4. Sharing & Disclosure
We do not sell your personal information. We share it only with:
- Stripe, Inc. (Delaware, USA) — to process payments and manage subscriptions. Stripe's privacy practices are at stripe.com/privacy.
- Telegram — only insofar as you sign in via Telegram's login widget. We do not push any data back to Telegram other than messages sent through our official bot account.
- Legal authorities — when required by valid legal process, or to protect the rights, safety, or property of us, our users, or the public.
5. Cookies & Similar Technologies
We use a single first-party, HTTP-only session cookie ("session_token") to keep you signed in for up to two hours after you authenticate. We do not use third-party tracking or advertising cookies.
6. Data Storage & International Transfers
Our primary database is operated by us and physically hosted on a server located in the Russian Federation. By using the Service, you understand that information described in §1 will be transferred to, stored in, and processed on that server. Connections to the database are encrypted in transit.
Payment-method tokens and transaction records held by Stripe are stored according to Stripe's infrastructure (primarily United States). If you do not consent to this cross-border arrangement, please do not use the Service.
7. Data Retention
- Account and profile data are retained for as long as your account is active.
- Expired session tokens are automatically deleted by a scheduled job (typically within 24 hours of expiry).
- Payment records may be retained for up to seven (7) years to meet tax-recordkeeping obligations.
- You may request deletion of your account at any time — see §8.
8. Your Rights
Subject to applicable law, you have the right to:
- request a copy of the personal information we hold about you;
- request correction of inaccurate information;
- request deletion of your account and associated personal data;
- opt out of non-essential communications (transactional messages required for billing are excepted);
- withdraw consent where processing is based on consent.
To exercise any of these rights, email mishasamil32@gmail.com from the email address associated with your account, or include your Telegram ID. We respond within 30 days.
9. Security
We use industry-standard safeguards: TLS for all traffic in transit, hashed and salted credentials, HTTP-only session cookies, restricted database access from the application server only, and webhook signature verification for Stripe events. No system is perfectly secure; if you suspect a security issue, email us immediately.
10. California Residents (CCPA / CPRA)
- In the past 12 months we have collected the categories of information described in §1: identifiers, commercial information (subscription/payment history), and internet activity (session cookies, logs).
- We do not sell or share personal information for cross-context behavioral advertising.
- California residents may exercise the rights in §8 free of charge and without being denied service for doing so.
11. Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, please contact us and we will delete it.
12. Changes to this Policy
We may update this Privacy Policy from time to time. The "Effective date" above reflects the latest revision. Material changes affecting your rights will be communicated by email or in-app notice at least 14 days before they take effect.