Privacy Policy
This Privacy Policy describes how SumKit (Telegram bot @sumkit_bot, settings mini-app at oauth.bottovod.ru/sumkit/) processes data when you connect Google, Zoom and related services.
1. Who we are
Operator: Bottovod / SumKit. Contact: kir.skryl@gmail.com.
2. What we access
Depending on the features you enable, SumKit may access:
- Your Telegram user id and chat messages you send to the bot;
- Google account identity (email) via OAuth;
- Google Drive / Docs / Sheets — only to create or update files and indexes that you requested (transcripts, knowledge base, course indexes);
- Zoom account identity and cloud recordings (transcript/video) of the account that authorized SumKit, to transcribe and summarize meetings you asked to process;
- Optional integrations you connect (e.g. Notion, Yandex.Disk) under the same principle: only for the job you started.
3. How we use data
We use this data solely to:
- download, transcribe, summarize and store materials you asked to process;
- write results to destinations you chose (Yandex.Disk, Google, Telegram, server);
- maintain job status, cost estimates and operational logs needed to run the service.
We do not sell personal data. We do not use Google or Zoom user data for advertising, and we do not use it to train AI/ML models.
4. Storage and retention
OAuth tokens are stored on our servers (in a database restricted to the application, not reachable from the public network) so the bot can act on your behalf until you disconnect. Temporary media files are deleted after successful delivery unless you asked to keep them on the server destination. You can revoke access at any time in Google Account → Third-party access, in Zoom App Marketplace → Manage → Added Apps, and/or via bot commands such as /disconnect. When access is revoked, we delete the corresponding stored tokens and integration record.
5. Sharing
Processing providers used to fulfil your request may include speech-to-text and LLM APIs (e.g. AssemblyAI, DeepSeek). Content is sent to them only as needed for transcription/summarization of the files you submitted.
6. Google API Services User Data Policy
SumKit’s use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Your rights
Regardless of where you are located, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten") — disconnecting an integration (/disconnect, or removing the app in Google/Zoom) deletes the corresponding stored tokens and data; you can also request full account deletion directly;
- Restrict or object to certain processing of your data;
- Data portability — request an export of the data we hold about you in a structured, machine-readable format;
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
- Lodge a complaint with your local data protection supervisory authority if you believe your rights have been violated.
To exercise any of these rights, contact us at kir.skryl@gmail.com. We respond to verified requests within a reasonable time and no later than one month, as required by applicable law (e.g. GDPR Art. 12).
8. Contact
Questions: kir.skryl@gmail.com · Home: https://oauth.bottovod.ru/sumkit/ · Terms: https://oauth.bottovod.ru/terms