Legal
Privacy Policy
Last updated 2026-10-04. This is an honest, accurate description of what we actually do today.
What we collect
Depends on which surface you're using:
- This website (targa.dev): standard server access logs (IP, user agent, requested path) generated by our hosting/CDN provider. No advertising trackers, no third-party analytics pixels, no cookie banner because we don't set any tracking cookies.
- Dashboard account (app.targa.dev): your email address, a securely hashed password, the Telegram chat ids you connect, and your plan. A single session cookie keeps you signed in — not used for tracking.
- The Targa bot, in groups it protects: the detection engine's durable records are moderation records, not messages: a message's score, which detectors fired, the action taken, and — because moderation has to say who — the member's numeric Telegram id and display name, plus warn history, roles, and ban-list entries that admins create. Profile photos and bios are analyzed in memory only. Records age out automatically (per-message records after 90 days, member activity after 180 days). Spam examples an admin explicitly submits with /spam are kept as anonymous training text for at most 12 months. Message text is kept up to 90 days — needed for AI review, to catch edit-after-post spam, and to power /why — then scrubbed, leaving only the moderation record.
- AI review: some messages are sent to an AI model provider acting as our processor, for a verdict — on all plans, including the free one. The provider processes the message text under a data-processing agreement, only to return a verdict; it does not train on it, and we send no member or channel identifiers with it. Message text is retained up to 90 days for AI review, then scrubbed to the durable moderation record. AI review is part of the service and is managed by Targa; if you need it disabled for a group you administer, contact us.
- Payment: the free plan has no payment data. If you buy a paid plan, payment is handled entirely by our payment processor (Stripe). We never see or store your card details.
What we don't do
We don't sell personal data. We don't share dashboard account data with third parties except the providers required to run the service (hosting, email delivery, payments, sign-in, push delivery, and an AI model provider for AI review). Each is bound to use the data only to provide its service. The current list of sub-processors, with their roles and locations, is available on request and is provided to customers who sign a data-processing agreement with us; we notify those customers before adding or changing one. We don't run advertising trackers on the site or in the dashboard.
The public Spam Index
Aggregated, anonymized counts (not individual verdicts or identities) from the detection layer power the public Spam Index research pages. Nothing published there is traceable back to a specific person, group, or message.
Retention
Dashboard account data (email, password hash, sign-in identifiers, connected channels, device push tokens, launch-list entries) is kept until you delete your account, at which point it's removed immediately and your entries in the configuration audit trail are anonymized. Detection and moderation records age out automatically on fixed schedules — message text and per-message records after 90 days, member activity records after 180 days, admin-submitted spam examples after 12 months. Ban lists that admins and federations maintain are kept while they remain in force, as an anti-abuse measure.
Your controls
From the dashboard you can disconnect any channel at any time and delete your account outright, which removes your account data immediately. Group members (people in protected groups who aren't account holders): the data we hold about you is your numeric Telegram id, display name, and moderation events in that group — most of it ages out automatically, and you can contact us to have it erased sooner (ban-list entries retained as an anti-abuse measure). For anything without a self-serve control yet (a data export, a specific deletion request), contact us — see below.
Children's privacy
Targa is not directed at children and we don't knowingly collect data from anyone under 13 (or the relevant minimum age in your jurisdiction). If you believe a child has provided us data, contact us and we'll remove it.
International use
Our servers are in the European Union (Germany). Targa is used globally, so support channels and third-party providers (Cloudflare, Stripe, sign-in and push providers) may process data outside your home country. If you're in the EEA/UK and want specifics on transfer mechanisms, contact us.
Changes to this policy
We'll update the "last updated" date above when this changes. Material changes will be noted here; we don't currently have an email-notification system for policy changes (see the site gap this is part of closing).
Contact
Questions or data requests: reach us on Telegram at @targapraetorian, on X at @targapraetorian, or via the dashboard's Support page.