Privacy Policy
Podatky Canada · Last updated 2 August 2026
Podatky Canada (“the bot”) is operated by Vladyslava Berova, 125 Albert St, Port Moody, BC V3H 0M8, Canada. Questions about this policy or about your data: Vlada@podatkycanada.com.
This policy explains what the bot collects, why, where it is kept and how to get rid of it.
The short version
- Your books and your receipt files live in your own Google Drive, in your own account. We do not host them and we cannot delete them.
- The bot can only see the files it created for you. The rest of your Drive is invisible to it.
- Receipt images are sent to an AI provider to be read. Nothing else is shared with anyone.
- You can disconnect at any time. Your files stay with you.
What we collect
From Telegram: your Telegram user ID, and the messages you send to the bot — photos and PDFs of receipts and invoices, and the text you type in reply to its questions. The bot does not read any other chat.
About your business: the business name you give it, and the email address of the Google account you connect. The email is read from Google once, at the moment you connect, so the bot can show you which account it is writing to.
From your documents: the merchant name, date, amounts, GST/HST amount, the merchant’s GST/HST number when it is printed, the category and the description. This is the data that ends up as a row in your spreadsheet.
To keep the connection working: a Google refresh token — the key that lets the bot write to the files it created for you. It is stored on our server, separately from everything else, and never shown or sent anywhere.
Where your data lives
In your Google Drive: the folder named after your business,
the yearly spreadsheets, and every receipt file you send, under
receipts/YYYY/. You own all of it. If you stop using the bot, it
stays exactly where it is.
On our server: your Telegram ID, business name, Google account email, the identifiers of your folder and books, your subscription status, and the Google key. Also an operational log that records, for each receipt, the merchant, the amounts, the GST/HST number and your Telegram ID — we need it to work out what went wrong when something does. Logs rotate and old ones are overwritten.
What access to Google we ask for, and why
The bot asks for exactly one Google permission:
drive.file — “see, edit, create and delete only the specific Google
Drive files you use with this app”. In practice this means the bot can only
touch files it created itself: your bookkeeping folder, your
books and your receipts. Every other file in your Drive is invisible to it —
not by policy, but because Google does not give it access.
The bot uses this access only to keep your bookkeeping: to create the folder and the yearly book, to add rows, and to file your receipt images. It is not used for advertising, it is not sold, and it is not used to train any model.
Who else sees your data
- Telegram — your messages and files pass through Telegram to reach the bot. Telegram’s own privacy policy applies to that leg.
- Anthropic (the Claude API) — the receipt image or PDF is sent there to be read, and the extracted fields come back. Under Anthropic’s Commercial Terms of Service (section B, Customer Content), Anthropic may not train its models on this content.
- Google — your own account, holding your own files.
- DigitalOcean — the server the bot runs on, located in Toronto, Canada.
Nobody else. We do not sell personal information and we do not share it for advertising.
How long we keep it
Files in your Drive: for as long as you keep them. They are yours; the bot has no way to delete anything in your Drive, by design.
Your record on our server: kept while you use the service, and kept in a closed state after you disconnect, so that returning does not create a second folder and so we can answer “whose folder is this?” a year later. Ask us and we will erase it.
The Google key: deleted the moment you disconnect.
Operational logs: rotated automatically by size — five files of 5 MB, after which the oldest is overwritten. How much history that covers depends on how many receipts pass through; at our volume it is a matter of months, not years.
Disconnecting and deleting
Send /disconnect to the bot. We ask Google to drop the
permission, we delete the key, and the bot stops writing. Nothing is deleted
from your Drive — your folder, your books and your receipts stay exactly as they
are.
You can also remove the permission yourself in your Google account, under Security → Third-party apps & services.
To have your record on our server erased as well, write to Vlada@podatkycanada.com.
Your rights
Canadian privacy law (PIPEDA, and the British Columbia Personal Information Protection Act) gives you the right to know what personal information we hold about you, to get a copy, to have it corrected, and to withdraw consent. Write to Vlada@podatkycanada.com and we will answer within 30 days. If you are not satisfied, you can complain to the Office of the Privacy Commissioner of Canada.
Security
The connection to the bot, to Google and to the AI provider is encrypted. The Google key is stored with restricted file permissions, separately from everything else, and is never written to logs or shown on any screen. No system is perfect: if a breach affects you, we will tell you and the relevant authority, as the law requires.
Children
The service is for businesses and is not directed at children.
Changes
If this policy changes in a way that matters, the bot will tell you in Telegram before the change takes effect.