Provision record
Telegram · Telegram Privacy Policy · View original document ↗

Third-Party Bot Data Access

High severity High confidence Explicit document language Common · 289 of 352 platforms
Stay ahead of the changes
Track Telegram and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

The policy states that third-party bot developers receive public account data including screen name, username, and profile picture when users interact with bots, and may also receive messages, IP addresses (via links), group membership status, and interface language. Third-party bot developers are described as independent from Telegram, and their data practices are governed by their own terms rather than Telegram's privacy policy.

This analysis describes what Telegram's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that user data transmitted to third-party bots is outside Telegram's data protection framework, and that Telegram does not govern how independent bot developers collect, store, or use that data. Users interacting with third-party bots should review those bots' separate privacy policies.

Clause Stability Stable

0
Changes
4
Months Monitored
Apr 18, 2026
First Seen
May 22, 2026
Last Seen
This clause type exists across 5149 other provisions on other platforms.

Change history

modified Jun 28, 2026

Excerpt significantly expanded to provide detailed technical specification of what data bots can access, including public account data, interactive data, and group message access modes.

View full change record →

Consumer impact (what this means for users)

The agreement states that interacting with third-party bots transmits public account data and potentially messages, IP addresses, and language settings to independent developers who are not subject to Telegram's privacy policy. The policy states bots should request user permission before accessing data, but Telegram does not enforce or guarantee third-party bot data practices.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    To revoke a connected chatbot's access to your chats, navigate to Settings > Telegram Business > Chatbots and alter or revoke the bot's permissions, including the list of chats it can access.

How other platforms handle this

Google Cloud Medium

Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.

Glassdoor Medium

We will also provide an individual opt-out choice, or opt-in for sensitive data, before we share your data with third parties other than our agents, or before we use it for a purpose other than which it was originally collected.

Square Medium

to request that your data be transferred to a third party (data portability)

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
The developers of an automated user (bot) can get your public account data (see section 3.1 above): your screen name, username and profile picture(s). Bots can also receive the following data when you interact with them... Bots added to groups can operate in two modes: with access to messages in the group or without access. If the bot has access to messages, it can see everything that happens in the group... The terms of use for certain bots are set by Telegram. No other bots or third-party bot developers are affiliated with Telegram. They are completely independent from us. They should ask you for your permission before they access your data or you make it available to them.

Excerpt from Telegram's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →

Applicable regulations

Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US
VPPA
United States Federal

Provision details

Document information
Document
Telegram Privacy Policy
Entity
Telegram
Document last updated
May 5, 2026
Tracking information
First tracked
May 20, 2026
Last verified
May 20, 2026
Record ID
CA-P-002910
Document ID
CA-D-00174
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
254e0a0f475f303b19d7bea19e3509d7cffd49f04954691cb890759d163b36a4
Analysis generated
May 20, 2026 21:51 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Telegram
Document: Telegram Privacy Policy
Record ID: CA-P-002910
Captured: 2026-05-20 21:51:16 UTC
SHA-256: 254e0a0f475f303b…
URL: https://conductatlas.com/platform/telegram/telegram-privacy-policy/provision/CA-P-002910/third-party-bot-data-access/
Accessed: Sept. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Telegram's Third-Party Bot Data Access clause do?

This provision establishes that user data transmitted to third-party bots is outside Telegram's data protection framework, and that Telegram does not govern how independent bot developers collect, store, or use that data. Users interacting with third-party bots should review those bots' separate privacy policies.

How does this clause affect you?

The agreement states that interacting with third-party bots transmits public account data and potentially messages, IP addresses, and language settings to independent developers who are not subject to Telegram's privacy policy. The policy states bots should request user permission before accessing data, but Telegram does not enforce or guarantee third-party bot data practices.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.

Is ConductAtlas affiliated with Telegram?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Telegram.