Privacy Policy

Last updated: August 7, 2026

1. Who we are

Jel is a social media scheduling and chat automation service operated by IP BYOMAR (individual entrepreneur, registration number 000603501247), Raiymbek Avenue 590/15, office 113, Almaty, Kazakhstan. Jel is the data controller for account data and the data processor for the content and contacts you bring into the service.

Contact for any privacy question, including access and deletion requests: support@jel.digital.

2. Data we collect

  • Account data — e-mail address, display name, password hash (we never store passwords in readable form), interface language, and, if you sign in with Google or Apple, the identifier those providers return.
  • Connected account data — access and refresh tokens for the social accounts you connect, plus the public identifier and display name of each account, so the service knows where a post is going.
  • Content you create — post text, images and videos you upload, scheduled times, and the result each platform returned.
  • Conversation data — messages exchanged through the chat automations you build, and the contacts who wrote to your bots.
  • Operational records — request logs, error reports and billing history.

We do not collect precise location, biometric data, health data, or any special category of personal data, and we do not buy personal data from third parties.

3. Data we receive from TikTok

When you connect a TikTok account through Login Kit, TikTok gives us an access token, a refresh token, your account identifier (open_id) and your display name. We use them for three things only: to show which account you are posting to, to publish the content you scheduled, and to keep the connection alive by refreshing the token. We do not read your followers, your private messages, your analytics, or anyone else's content.

Content flows in the other direction as well: the videos, photos and captions you upload to Jel are sent to TikTok through the Content Posting API at the moment you asked us to publish them. Nothing is sent without your instruction.

You can disconnect at any time inside Jel, or revoke access from TikTok itself under Settings and privacy → Security and permissions → Manage app permissions. Disconnecting deletes the stored tokens immediately.

4. Data we receive from other platforms

The same principle applies to every channel: Telegram (bot token and the messages your bot receives), Meta platforms — Instagram and WhatsApp (page and account identifiers, message webhooks, published content), YouTube (channel identifier and the videos you upload), and e-mail (your subscriber list and delivery results). We request the narrowest permission that makes the feature work, and we store only what the feature needs.

5. Why we process data

  • To provide the service you signed up for: publish, schedule and automate replies.
  • To keep the service secure, detect abuse and prevent unauthorised access.
  • To bill subscriptions and keep accounting records required by law.
  • To answer support requests.

Where the law requires a legal basis, we rely on performance of a contract with you, our legitimate interest in running and protecting the service, and legal obligations.

6. We do not sell or share data for advertising

We do not sell personal data, we do not rent it, and we do not share it with advertising networks or data brokers. We do not use your content or your subscribers' messages to train machine learning models of our own.

7. Service providers

Jel runs on infrastructure operated by Railway (application hosting and PostgreSQL database). Outgoing e-mail is delivered through Resend or Amazon SES. When you switch on an AI reply feature, the text of that specific conversation is sent to the AI provider that powers it (Anthropic or OpenAI) so a reply can be generated; those providers act on our instructions and do not use the text to train their models. Each provider processes data only to deliver its part of the service.

8. International transfers

Our infrastructure and the platforms you connect operate outside Kazakhstan, so your data is processed abroad. We only use providers that commit to appropriate safeguards and confidentiality.

9. Retention

  • Account data: kept while the account exists.
  • Platform tokens: kept until you disconnect the account, then deleted.
  • Posts and uploaded media: kept until you delete them or delete the account.
  • Conversation data: kept while the automation is in use.
  • Billing records: kept for the period accounting law requires.

10. Your rights

You can access, correct, export or delete your data. Inside the app you can disconnect any account, delete individual posts, and change your profile. To delete your account and everything in it, write to support@jel.digital or use the data deletion page; we complete the deletion within 30 days and confirm by e-mail. You may also object to processing or ask us to restrict it.

11. Security

Traffic runs over HTTPS, passwords are stored as salted hashes, platform tokens are held in the application database and are never exposed to the browser, and uploaded media is served through signed URLs that cannot be guessed. Access to production data is limited to the operator of the service.

12. Children

Jel is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 18.

13. Changes

If this policy changes we update the date at the top of the page, and for material changes we notify account holders by e-mail before the change takes effect.

14. Contact

IP BYOMAR, Raiymbek Avenue 590/15, office 113, Almaty, Kazakhstan.
support@jel.digital