Data

You are sending us your face

Asking what happens to it next is fair. No legal fog below: what happens to the clip, what is left of it, what leaves our server and how to erase it — there is no delete command in the bot yet, we erase by hand when you ask. Every point is written from what the code actually does, not from what sounds nicer.

The main thing

The clip file is not stored

What happens to the video

The bot fetches your clip from Telegram, writes it to a temporary file, analyses it and deletes that file immediately, inside the same handler. The deletion sits in a block that runs even if the analysis fails with an error. There is no second copy: we do not put videos into storage, do not keep individual frames and do not forward the file anywhere.

What stays with us

The measured numbers and the technical notes of the check-in: duration, size, hour of recording, type (circle or video), check-in number, date and the marker of where you came from. It lives in a private file on our disk, tied to your Telegram id. This is what your history, personal baseline and dynamics are built on.

Leaving the server

An external model writes the snapshot text

This is the place where data leaves our server, and it is usually the part nobody shows. We are showing it.

What exactly is sent

So that the snapshot reads like human language, the list of indicators is sent to a language model through OpenRouter. What travels is exactly a text list: indicator label, number, unit, state and confidence, plus two notes — whether the face is clearly visible and whether speech was detected. No video, no frames, no audio, no name and no Telegram id are in that request.

If the model is unavailable

The text is assembled on our server from the very same numbers. The server also re-reads the model's answer and rejects it if it drifts into report language or into judgements about emotions. The model does not decide anything: the set of indicators and their limits are fixed before it is called.

Site and app

Counters

On this site

Yandex Metrica is running (counter 111157661): visits, button clicks, scroll depth and session recording — Webvisor. It records behaviour on the website pages; there is nothing to type here, we have no forms.

In the Mini App

No third-party JavaScript at all. Only a counting pixel image with no script is left, so the screen with your check-in is not read by outside code. Check-ins and history themselves are served only against a Telegram signature: a request without one is refused.

What we do not do

Boundaries

No selling, no training

We do not sell or pass your check-ins to third parties and we do not train a model on your videos — there is nothing to train on, the video is not stored. Inside the team, disk access belongs only to the people who keep the service running.

Not medicine

Senti does not diagnose, and does not determine illnesses, hormones, mental state or “true emotions”. The snapshot is a point of observation worth comparing only with yourself, and it does not replace a doctor or a therapist.

Questions

How do I delete my data?

There is no automatic delete command yet — we will not pretend otherwise. Write to the team in Telegram and we will remove your check-in history by hand. When the command appears in the bot, we will say so here.

What about the clip inside Telegram?

It stays in your chat with the bot — that is Telegram's storage, not ours. You can delete the message right in the chat, like any other.

Why not just promise “we store nothing”?

Because it would not be true. We really do not store the video, but we do store the numbers: without them there is no history and no personal baseline — the reason Senti exists.

Who do I ask about data?

The Senti team on Telegram. People answer, not an autoresponder.

Back to noticing

If nothing is left unanswered — your first clip does not have to prove anything.

Open Senti in Telegram