Privacy Policy
Last updated: 2026-09-10
What supernuggets is
supernuggets is a private, personal bucket. You send content to the Telegram bot (@supernuggetss_bot) — text, images, videos, voice notes, or URLs — and it's processed, tagged, and saved for you at a personal link. Nothing you save is public or visible to other users. There is no feed, no sharing, no discovery of other people's content.
What we store
- The content you send (text, transcripts, image/video metadata, and thumbnails)
- Your Telegram user ID, used to keep your bucket separate from everyone else's
- Your timezone, if you set it with /timezone in the bot. Telegram sends us your location once so we can look up the timezone name from it — only the timezone name (e.g. Europe/Berlin) is stored, never the coordinates. It is used only to time the digests the bot sends you in Telegram. supernuggets does not send email.
- Basic usage data (when entries were saved) used for digest summaries and monthly limits
How it's processed
What you send is passed to AI providers (Anthropic, and OpenAI for voice/video transcription) to generate a summary, tags, and fact-checks. This processing happens automatically on save — it is not reviewed by a person, and the output is stored alongside your original content in your bucket.
Who can see it
Only you — by default. Your bucket is reachable only via a private, unguessable link tied to your account; there is no username/password login. Every query the app runs is scoped to the account that link belongs to, so one link can never load another person's content. The database is separately closed to anonymous access, so the app is the only way in — nobody can read it directly from the outside.
Editing or deleting an entry requires an extra step: confirming you're the account owner by logging in through the Telegram bot (a separate sn_session cookie, see below). Viewing your bucket only needs the link.
This means the link itself isthe access control: anyone you send it to can open your entire bucket, no separate login required. Treat it like a password — don't post it publicly or forward it to anyone you don't want seeing your saved content.
Cookies
One cookie, sn_session. It is set only if you confirm a login through the Telegram bot, and it exists so the site knows the browser editing a bucket is the account that owns it. It is httpOnly (unreadable by scripts), sent only over HTTPS, and lasts 90 days from your last visit. Clearing it, or using the log-out button, ends the session immediately. There are no advertising or tracking cookies, and nothing is shared with ad networks.
Analytics
The public pages of this site use Vercel Web Analytics to count page views. It is cookie-less and does not build a profile of you across sites. It is deliberately switched off on bucket pages (/u/…) — the pages holding your saved content are not measured at all.
How long it's kept
- Saved content, tags, and summaries: kept until you delete them, or until the account is deleted. There is no automatic expiry.
- Your Telegram user ID, bucket link, and timezone: kept for as long as the account exists.
- Login sessions: 90 days from last use; login codes expire in minutes.
- Usage records (one row per save, used for the monthly limit): kept indefinitely.
Deleting your data
You can delete any individual entry directly from the bot or the web app at any time. To delete your entire account and all stored content, message the bot owner directly — full deletion is completed within 30 days of the request.
Telegram platform data
Telegram itself also processes data whenever you use the bot, covered separately by Telegram's own Privacy Policy for Bots and Mini Apps.
Questions
Reach out via Telegram.