Privacy Policy
1. The short version: we do not ask who you are
The Service does not need your real name, your company, an identity
document, an address, or banking or business details. We do not request
them in any form and expressly ask you not to send them — neither your
own nor anyone else's. There is one exception, and it is in plain sight: the
request form asks “what you do” — a free-text line such as “construction,
owner”. We need it to decide whom to let in; a job title, an employer and a
company name are neither required nor verified. Call yourself whatever suits
you; the company may be left out or made up. The quality of the analysis does
not suffer: the panel works with the substance of the decision, not with your
passport. There is also a mode in which a hearing leaves no trace at all — the
/privacy command in the bot.
2. What we process, and on what basis
The one thing the Service needs in order to work is your Telegram account identifier (the numeric ID and, if you have one, the username). The access code, the status messages and the report itself are delivered there. Under the GDPR an online identifier of this kind is personal data (Art. 4(1)), and we treat it as such — we do not argue otherwise.
- Purpose: granting access to the Service and delivering the result of your hearing.
- Legal basis: performance of a contract with you (Art. 6(1)(b)) for the delivery itself, and your consent (Art. 6(1)(a)) for the request form on the website, which you give by ticking the box before submitting.
- Data minimization by design (Art. 5(1)(c)): we deliberately collect nothing that would let us identify the person behind the account. The name you give may be freely chosen; it is never verified. The one exception we name plainly is the email address used for card payments — purpose, basis and retention for it are listed in section 2.
- Your rights: access, rectification, erasure, restriction, objection and portability. Write to the Service’s Telegram bot, which keeps a record of your request, or email opponentura@gmail.com if you do not use Telegram. We answer within 30 days.
- Retention: you choose it yourself with the
/privacycommand; in the no-trace mode nothing is kept beyond the report number, the verdict and the file hash, which exist so that a document already in someone else's hands can still be verified. - Transfers: the content of your request goes to the AI providers listed below, whose servers are outside the EU; payment data is handled by the payment platform under its own rules and never reaches us.
If you nonetheless include personal data — yours or a third party's — inside the description of your matter, it is processed under the retention mode you chose. We recommend redacting materials with labels before sending: the less you have told us about yourself, the less there is to lose.
3. Data about other people inside your matter
A review is rarely about you alone: the description and the attachments bring in a counterparty, a partner, a spouse, an employee. The Service cannot avoid processing that — it is the substance of the work — so the terms are stated separately.
- You set the scope. What you send is what gets processed. The Service works with it only for your hearing and within it. By sending materials you confirm you are entitled to pass them on (section 3 of the Terms).
- What we never do with it. We do not train models on it, do not sell it, do not enrich it against outside databases, do not look people up by name and do not build dossiers on them. Open-source research happens only with your consent and only about the subject of the case.
- How long it lives. Exactly as long as the case materials: 30 days by default, one hour in the “one hour” mode, not stored at all in the no-trace mode. The Service keeps no store organized by person.
- If that person contacts us. Write to opponentura@gmail.com. The limits up front: cases are de-identified and we have no search by name, so a name alone is not enough — we need circumstances (roughly when, what kind of document). Anything found is deleted and you are told the outcome; we answer within 30 days. After the retention period there is usually nothing left to delete.
4. Web-server logs and how attendance is counted
There are no counters on the pages: no Google Analytics, no Yandex Metrica, no pixels — and there never will be. But the web server, like every web server in the world, writes an access log, and saying so plainly is more honest than hiding behind “we do not count you”.
- What is recorded. The IP address, the browser string (User-Agent), the page requested, the response code, the time and the page you came from. No name and no account appear in those lines: the site does not identify you and never asks you to log in.
- Why. Availability and protection — scanners and address guessing are visible in the log — and counting attendance: how many people came and what they read. It is the only way to count visitors without putting someone else's script on the page.
- Retention. The log rotates: no more than 30 days and no more than five 10 MB files, whichever comes first.
- What we actually see. In reports the address is reduced to its network (the last part is zeroed) and a “unique visitor” is an irreversible hash of that network and the browser string with a secret key. No address ever reaches a report.
- Who else gets it. Nobody: the log stays on our servers.
5. If you are checking someone else's report
The person who opens the verification page is usually not the customer but someone who was shown the document: a partner, a lawyer, a board. The terms for you are different, and they are short.
- The file never reaches us. The SHA-256 digest is computed in your own browser; only that digest and the report number are sent. We neither see nor can reconstruct the contents.
- The answer is “matches” or “does not”, plus the issue date. No subject, no verdict, no customer name: the report belongs to them, not to us.
- What stays with us. The digest you sent and the report number in a request log, so that brute-force attempts are visible. No name, no contact, no account — you never give us any. Plus the ordinary web-server log line described in section 4.
6. What data we process
- The content of your requests and attached materials — what you send to the bot / on the website for analysis.
- Telegram technical data — your ID and username (for access and the case ledger). This is personal data and we say so.
- Your email address — only if you pay by card or by bank transfer: the payment provider needs it for the invoice and the receipt, and the Service needs it to match the incoming payment to you and to process a refund (the provider's notification carries no identifier of ours). Only the address: card details are seen by the provider alone and never reach us. If you pay with Telegram Stars, no email is requested at all.
- The request form on the website — the name you asked us to use (it need not be real), your field of work, a one-sentence description of the decision, how you heard about us and your Telegram contact. Kept while the request is being handled and deleted on your request; access already granted stays.
- Your ledger of cases — case names, verdicts, report (they belong to you).
- Voice messages, if you use them: the recording goes to a speech-recognition provider (Groq or OpenAI), only the transcript reaches the case, and we do not keep the audio.
- Service ledger — the fact and cost of model calls (no content), so we can control spending and limits.
7. How we use it
- Only to produce the analysis (the session) and to store your cases so you can return to them.
- Data is NOT used to train models — neither ours nor the AI providers’ (terms of the Anthropic, OpenAI, Google and Groq APIs on paid tiers).
8. What leaves us, and to whom (important, honest)
To generate a response, your requests are transmitted to third-party providers’ servers and processed under their privacy policies. We do NOT promise that “data never leaves our server” — with frontier-model APIs this is impossible. It is a common property of any service built on such models, and here is the full list. It has been incomplete twice: on 4 August it named two recipients out of six, and until 6 August it listed neither Telegram — through which the entire dialogue and every file passes — nor the platform the data actually rests on. Both omissions are of one kind: transport and hosting do not feel like “disclosure to third parties”, though that is exactly what they are.
The table scrolls sideways →
| Recipient | What goes there | Why | Processed in |
|---|---|---|---|
| Telegram | the entire dialogue, attachments and voice messages | the messenger itself: the bot runs on it | under Telegram's terms |
| Anthropic | case materials and the course of the hearing | the panel's reasoning and the panel's dialogue with you | USA |
| OpenAI | case materials; the text being spoken aloud; your voice message | the second-vendor critic, speech synthesis and recognition | USA |
| Google (Gemini) | the text of the reply | speech synthesis, if that voice is selected | USA |
| Groq | your voice message | speech recognition | USA |
| Tavily | a search query about the subject of the case — only with your consent, and never about you personally; the address of a page you ask us to read | fact-checking, background on the subject and reading pages you name | USA |
| lava.top | your email address and the invoice amount | card and bank-transfer payments; only the platform sees the card | under the platform's terms |
| Hetzner | case materials as they are stored with us | the server the Service runs on and where files are kept | Germany |
If you decline open-source research and do not use voice, the only thing that leaves us is the case material itself — to Anthropic and OpenAI (and, as always, the dialogue itself travels through Telegram).
Where the data sits. The Service runs on a server in Germany (Hetzner); case materials and reports are stored there. The Russian domain opponentura.ru is served by a separate server in Russia, but it holds only the website pages: cases, the database and documents never reach it — requests are passed through to the main server.
9. Your control over data
- Redaction. The Service proactively offers to replace names/companies/figures with labels (Person A, Company B) before anything reaches a model.
- “No-trace” mode (ephemeral session). Neither the case materials nor its title are saved to the ledger, and attachments are deleted as soon as the report is issued; only the verdict and the report’ seal hash remain.
- Deletion. You may request deletion of your cases and data.
- Retention. Exact terms are in the table below.
9.1. What is stored, where and for how long
The customer chooses the term. In the Telegram bot the
/privacy command switches the retention mode: standard —
the terms in the table below; within an hour — attachments and report
files are deleted an hour after the report is issued; anonymous —
every hearing runs without storing materials, and the case title does not enter
the event journal. The mode applies from the moment it is switched. Regardless
of the mode, the report number, the verdict and the hashes of issued files are
retained: without them authenticity checks on the copy held by the customer and
by third parties stop working.
| Data | Where | Term | How it is deleted |
|---|---|---|---|
| Case description, answers to the examination | our database | while you use the Service | on your request; in “no-trace” mode never saved |
| Attached files and photos | our server | 30 days after the hearing (“within an hour” mode — one hour; “anonymous” — never saved); uploads never attached to a case — 24 hours | automatically, on the term you chose in /privacy |
| Issued report (PDF; those issued before 02.08.2026 also have an HTML copy) | our server | 1 year (“within an hour” mode — one hour after delivery) | automatically, on the term you chose in /privacy, or earlier on request |
| Case title and verdict | our database | while you use the Service | on your request; in “no-trace” mode the title is not saved |
| Seal hash of the report | our database | indefinitely | not deleted — it is the integrity proof of the document and contains no content |
| Voice recording | at the speech-recognition provider | not stored by us | — |
| Database backups | same server, operator access only | last 90 copies (a bit over a week) | rotated out by newer ones |
Support correspondence (your messages in /paysupport, our
replies) | our database | 3 years | on your request, except while a payment dispute is open. Stored separately from case materials and not governed by the retention mode you chose: it is the record of a conversation about money, and both sides need it if a dispute starts six months later |
| Service ledger (fact, size and cost of a call) | our server | while cost accounting runs | contains no message content |
| Event journal: what happened and when (arrived, described a case, received report, paid, was refused) — with case numbers, amounts and the case title, but no content | our database | 24 months; anonymized monthly totals — indefinitely | automatically on expiry; used for service analytics and for resolving disputes. It holds no text of the decision, no interrogation answers and no document content — this is enforced by an automated test, not by a promise. In "no-trace" mode the case title does not enter the journal either |
Swipe the table sideways →
Deletion on request is performed in the live database; data disappears from already-made backups as those rotate — rewriting the history of backups instantly is not possible, and we will not promise it.
10. What we do NOT do
- We do not sell your data to third parties.
- We do not publish your cases without your written consent (a video testimonial or case study — only by explicit consent).
- We install no counters or trackers. The site carries no web-analytics systems (Yandex.Metrica, Google Analytics and the like), no advertising pixels, no social widgets and no third-party scripts whatsoever; fonts are self-hosted rather than pulled from someone else's CDN. Your visit is not shared with third parties, and profiling in ad networks based on reading this site is not possible. This is a deliberate position, enforced technically: the Content-Security-Policy header forbids the browser to load resources from other domains — a counter would not work here even if it slipped into the markup.
- We use no cookies at all. The only thing the site stores in your browser is
the language you picked (localStorage, key
opp_lang), so that the switch offer is not repeated on every page. It is not an identifier, it is never sent to us or anyone else, and clearing site data removes it. The Telegram bot operates inside Telegram under its rules.
11. Contact
Questions about data — via the Service’s Telegram bot or by email to opponentura@gmail.com. The mailbox exists for people without Telegram: a data-subject request must not depend on a messenger.