Filexa Privacy and Personal Data Processing Policy

Version dated 28 August 2026

Russian original. This English text is a translation for convenience. If the texts differ, the Russian original prevails to the extent permitted by mandatory law.

This Policy explains what data Filexa processes, why it is needed, who may receive it and how a User may exercise their rights. This Policy is not consent by itself. Where consent is required, the User gives it through a separate affirmative action after receiving access to the applicable text. The Operator records the version, date, method and technical evidence of that action.

1. Controller

The controller is Nikita Andreevich Andrianov, Russian taxpayer identification number 773001849734, an individual applying the Russian Professional Income Tax regime. Privacy and legally significant electronic requests: thismailnotbad@gmail.com. Official page: tnick.cc.

2. Scope

This Policy applies to @FilexaAIBot, related Filexa interfaces, server and shared Billing account data, support, security and payment-status processing. Telegram, banks, payment services and AI/API providers may also act independently under their own rules.

3. Data processed

Filexa may process:

After product-profile deletion, shared Billing may retain financial history and a minimal irreversible anti-abuse marker needed to prevent repeat bonuses and fraud.

Filexa does not obtain Telegram conversations outside the Bot and does not store a full card number, CVC/CVV or payment password. Users should not send passports, payment credentials, health data or other sensitive data unless specifically and lawfully required for a support case.

4. Purposes and legal grounds

Data is used to perform User requests and the contract, manage plans and Lex, take and refund payments, issue required tax receipts, provide support, protect users and the Service, prevent abuse, resolve disputes and comply with law. Depending on the operation, the ground is contract performance, a legal obligation, consent, or a legitimate interest that does not override the User's rights.

The Operator does not sell personal data, create advertising profiles from prompt content, or track Users across unrelated services for behavioural advertising.

5. AI processing and recipients

5.1. To perform a selected function, Filexa may transmit the prompt, attachment and required technical parameters to an external AI model, API or routing provider. A provider may process them under its own privacy and technical-use rules. Users must assess whether confidential or third-party material may lawfully be transmitted.

5.2. The providers may include CometAPI (terms, privacy), ProxyAPI (terms, privacy), and models made available through them or directly by OpenAI (terms, privacy) and Google Gemini (terms, privacy information). A named provider does not participate in every operation.

5.3. Other recipients or processors may include Telegram, Apple/Google and RevenueCat for enabled mobile purchases, security and network providers, logging and backup systems, banks, payment services, the Russian Federal Tax Service through My Tax, communications and support providers. Russian infrastructure is hosted by JSC IOT through FirstVDS. Rouble payments are processed through Robokassa (privacy); Telegram Stars are governed by the Telegram terms for virtual goods. RevenueCat is a technical purchase-synchronisation intermediary; the relevant store controls the actual purchase, cancellation and refund.

5.4. Filexa sends each recipient only what is reasonably necessary and does not send AI providers payment-card data or a Telegram password.

5.5. Filexa may replace fragments that resemble personal data with synthetic substitutes before external transmission. This reduces exposure but cannot guarantee removal of every identifier and does not replace the User's duty to avoid prohibited data.

5.6. Local connector. If the User voluntarily attaches a third-party master host, its owner can technically receive prompts, links, files, references and results. The interface shows a separate warning before attachment. That owner acts independently from the Operator, so the User should attach only a trusted host and must not transmit data for which that host lacks a lawful processing basis.

6. Third-party data and shared chats

If a User supplies another person's data, image, voice, correspondence or work, the User must have a lawful basis and any required permission for the transfer and AI processing. Passport, medical and biometric data of third parties must not be submitted without a lawful basis and required consent. In a group or public chat, the request and result may be visible to its participants.

7. Retention and deletion

7.1. Account data is retained while the account is used. After the purpose ends or consent is withdrawn, data lacking another legal basis is deleted within the period required by Article 21 of Russian Federal Law 152-FZ, normally no later than 30 days.

7.2. User files and results are transient and retained only for processing and delivery unless a function expressly says otherwise. Filexa is not permanent storage.

7.3. Completed operational records and ordinary logs without User files are kept up to 90 days; complaints, decisions and consent evidence up to 3 years after closure, relationship end or withdrawal; payment, tax and primary accounting records for at least 5 years and afterwards only while a separate lawful purpose remains, subject to annual necessity review; destruction acts and system-journal extracts for 3 years. Incident, claim or court records remain restricted until the procedure and applicable rights-protection period end. A minimal anti-abuse marker is reviewed at least every 3 years and deleted when no longer needed.

Backups rotate within 30 days. Deleted live data may remain isolated until scheduled replacement and is not used for ordinary processing; a disaster-recovery restore reapplies deletion actions.

7.4. External providers delete data under their rules and technical capabilities. The Operator sends binding deletion requests where the contract and law permit.

8. Russian localisation and international transfers

8.1. When collecting personal data of Russian citizens, the initial recording, systematisation, accumulation, storage, updating and retrieval occur in databases in Russia. Filexa uses Russian FirstVDS sites identified in the provider's official location statement.

8.2. After initial recording in Russia, Telegram and AI/API providers may receive the minimum necessary data abroad. This later transfer does not replace localisation and remains separately subject to cross-border-transfer procedure, recipient assessment and minimisation under Article 12 of Russian Federal Law 152-FZ as applicable on the transfer date. Separate consent is obtained where required.

9. Linked accounts

Voluntary linking with AI360 or another product sends shared Billing the confirmed technical account identifiers, product code, plan, wallets and operations. Billing automatically selects one active financial profile; linking does not transfer or add funds. Accounts are not linked merely because an email, username or name matches. Unlinking stops future interface access but does not erase lawfully retained financial history or the minimal de-identified anti-abuse marker.

10. Security and incidents

The Operator applies access controls, minimum privileges, protected transmission, logging, backups and incident procedures proportionate to the risks and scale of processing. No internet system is risk-free. If an incident creates a legal notification duty, the Operator notifies the competent authority and affected persons in the required scope and time.

11. User rights

The User may request access, clarification, restriction, objection where applicable, withdrawal of consent, and deletion or blocking of unlawfully processed data. Withdrawal does not invalidate prior lawful processing and may make a necessary function unavailable. The Operator may request proportionate identity confirmation.

Requests go to thismailnotbad@gmail.com. The User may also complain to the competent supervisory authority or court.

If and only if their territorial and material scope applies, Users in the EEA may have rights under the EU GDPR, UK Users under UK data-protection law, and California residents under the CCPA/CPRA framework. Filexa does not sell or share personal information for cross-context behavioural advertising and does not make decisions producing legal or similarly significant effects solely by automated processing. For restricted international transfers, an applicable mechanism such as the EU Standard Contractual Clauses is used where required and available.

12. Account deletion

The User may use Delete account in Filexa settings or email the Operator. Data is deleted or de-identified after verification except records retained for settlements, taxes, fraud prevention and disputes. Deleting an account does not automatically cancel a subscription; cancellation must be completed through its purchase channel.

13. Changes and contact

The current version is published through the Service. Material changes affecting the User are communicated by an available method. Questions and requests: thismailnotbad@gmail.com.