Privacy policy

What we collect, what we use it for, and who else ever sees it.

Last updated:

  1. Who we are

    MOSINT (mosint.org) monitors the Mongolian-language social and news web with AI and sends approved users the content that matches the topics they chose, over Telegram.

    This policy covers the mosint.org website, the @MOSINTERXBOT Telegram bot and the dashboard (mosint.org/app and bot.mosint.org/app).

    The service is operated by the MOSINT team. Contact: batunasan.u@gmail.com

  2. What we collect

    We collect only what running the service requires.

    • From Telegram — your Telegram ID, name, username and language setting. Telegram passes these automatically when you start the bot. We do NOT get your phone number, your contacts, or any of your other chats.
    • From you — the topics you create, their keywords, and your alert settings.
    • Technical logs — operational records (errors, timings, request counts) needed to diagnose faults and keep the service secure.
  3. Content from public sources

    MOSINT reads public sources only: posts from open Facebook pages, public posts on X/Twitter, and articles from Mongolian news sites.

    • Private profiles, closed or secret groups and private messages are NEVER processed.
    • On Facebook, only publicly visible posts are analysed.
    • Comments on posts are not used in the analysis.
    • If you own a public page and want it excluded from monitoring, write to the address below.
  4. Why we process it

    We do not use your information for advertising and do not pass it to third parties for marketing.

    • To perform the contract — delivering the alerts, daily reports and dashboard you subscribed to.
    • Legitimate interest — keeping the service secure, preventing abuse, and improving quality.
  5. AI processing

    • To analyse content, the text of public posts and the topic descriptions you write are sent to the OpenAI API.
    • Data sent through the OpenAI API is not used to train their models (per OpenAI’s API data policy).
    • A numeric representation of the text’s meaning (an embedding) is stored in our database, so topics can be compared and searched.
    • AI output — sentiment, summaries, relevance decisions — is not perfect. Check the original source before acting on anything important.
  6. Who else sees it

    We do NOT sell your personal information. These processors are involved because the service cannot run without them:

    • OpenAI — text analysis and embeddings.
    • Telegram — the channel alerts are delivered over.
    • Contabo GmbH — server hosting. Our database sits inside the European Union (France).
    • We may also be required to disclose information on a lawful request from a competent authority under Mongolian law.
  7. How long we keep it

    • Account information — for as long as your account is active.
    • Topics and alert history — for as long as your account is active. Delete a topic and its alerts go with it.
    • Public content — this is not your personal data and stays in our archive for as long as it remains published at its source.
    • A deletion request is carried out within 30 days. Removal from backups may take up to another 30.
  8. Cookies and tracking

    • The mosint.org marketing site sets no cookies. There is no Google Analytics, no Facebook Pixel, no analytics or advertising tracker of any kind, and no third-party script is loaded.
    • The dashboard (mosint.org/app and bot.mosint.org/app) authenticates two ways: Telegram’s sign-in data (initData), or a one-time code issued by the bot. Either way the session key is held in your browser’s local storage — not a cookie — and none of it serves advertising.
    • When you sign in with a code we record the session’s lifetime and a coarse device description (for example “Chrome · Windows”). You can see it on the bot’s sessions screen and end it whenever you like.
    • We do not track you across other sites.
  9. Your rights

    You have the right to:

    • See what we hold about you.
    • Correct anything wrong or incomplete.
    • Delete your account and the data attached to it.
    • Receive a copy of your data in a readable format.
    • Object to processing, or withdraw a consent you gave.
  10. Security and changes to this policy

    • The database is not exposed to the public internet — it is reachable only from the server itself and over an encrypted private network. All web traffic is HTTPS.
    • Access is limited to what the work requires, and credentials are not kept in the repository.
    • We may update this policy from time to time. Material changes are announced through the bot in advance, and the date at the top of this page always shows the current version.

Questions and complaints

If you have a question about this policy, a suggestion, or reason to believe your rights have been infringed, contact us directly. We answer within 30 days.