Privacy Policy
Melnicom Ltd. ("Company", "we", "us", "our") operates the Tlyck platform at tlyck.com and robots.tlyck.com. This Privacy Policy explains what personal data we collect, how we use it, and your rights under Israeli privacy law and applicable international standards.
1. Data We Collect
| Category | Examples | Source |
|---|---|---|
| Account information | Name, email address | You provide at sign-up or via OAuth (Google, Apple) |
| Authentication data | OAuth tokens, one-time sign-in codes (not stored after use) | Authentication flow |
| Usage & telemetry | Token consumption, agent request counts, response latency | Collected automatically via OpenTelemetry as your agent runs |
| Payment data | Transaction ID, amount, purchase date | Paddle (our payment processor) — we do not store raw card details |
| Agent conversation data | Messages exchanged with your Telegram agent | Processed in-flight to produce responses; not stored by us beyond operational logs |
| Technical data | IP address, browser type, referring URL | Collected automatically on each request |
| Social media data | Instagram Business Account ID, Facebook Page ID, OAuth access tokens, post IDs, comment IDs, commenter usernames — processed to deliver comment automation features | Provided by you via Meta OAuth when you connect an Instagram Business account to your agent |
2. How We Use Your Data
- Service delivery: provisioning your agent, routing AI requests, managing your token budget.
- Billing: processing payments and maintaining transaction records.
- Communication: sending sign-in codes, purchase receipts, and service notices.
- Safety and security: detecting abuse, fraud, and unauthorized access.
- Service improvement: aggregated, anonymized analytics to improve performance and features.
We do not sell your personal data to third parties. We do not use your data for advertising or profiling.
3. Data Sharing and Third Parties
We share limited data with the following service providers solely to operate the platform:
- Telegram — to operate your bot. Telegram's privacy policy applies to messages sent through Telegram.
- Google / Apple — if you choose OAuth sign-in. Their policies govern the OAuth exchange.
- Resend — to send transactional emails (sign-in codes, receipts).
- Paddle — to process payments. Paddle is the Merchant of Record for purchases made on our platform.
- AI model providers — your agent's messages are forwarded to AI providers to generate responses. We route these through our own proxy to minimize direct data exposure.
- Hosting infrastructure — Hetzner VPS (EU data center); data is stored and processed on servers operated by us.
- Meta (Facebook / Instagram) — when you connect an Instagram Business account, we use Meta's Graph API on your behalf. We store your Page Access Token and Instagram Business Account ID solely to execute automations you configure (e.g., reading post comments, sending Private Reply DMs). We do not share this data with any other party. You can revoke access at any time from your Meta Business settings or by deleting your agent.
3c. SMS / Text Messaging
Some of our services (for example, the Tlyck Focus assistant) let you interact with us by SMS text message. Messaging is user-initiated: we only send you text messages after you have opted in by texting us first or by otherwise providing express consent.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with, or sold to, any third parties.
We use your mobile number and message content solely to provide the service you requested. Message frequency varies. Message and data rates may apply. You can opt out at any time by replying STOP, and get help by replying HELP or emailing david@melnicom.com.
3a. Instagram / Meta Platform Data
When you connect an Instagram Business account to your Tlyck agent, we access and process the following data via the Meta Graph API:
- Post comments: We read comments on your Instagram Business posts to identify users who have expressed interest in content you offer. Comment text and commenter usernames are processed in-memory and are not stored in our database.
- Private Reply DMs: We send private direct messages on your behalf to users who commented on your posts, using Meta's official Private Replies API. Message content is provided by you or your agent configuration.
- Access tokens: Your Page Access Token is stored encrypted and is used exclusively to execute the automations you configure. It is never shared with third parties.
- Deletion: If you disconnect your Instagram account or delete your agent, all associated tokens and configuration are permanently deleted within 24 hours.
We use Instagram data only to provide the features you explicitly configure. We do not use Instagram data for advertising, profiling, or any purpose beyond your stated automation goals. Our use of Meta Platform data complies with the Meta Platform Terms.
3b. Google Workspace Data
When you connect Google Workspace to your Tlyck agent, we access and process data via the Google API Services on your behalf, solely to fulfill your explicit instructions. The following Google APIs and scopes may be used:
- Gmail (
gmail.modify) — read, draft, and send email messages as you direct your agent. - Google Calendar (
calendar) — read and create calendar events as directed. - Google Drive (
drive.readonly,drive.file) — list, search, upload, and download Drive files as directed.drive.readonlyis used to find and read files you already own;drive.fileis used to create or edit files the application generates on your behalf. - Google Sheets (
spreadsheets) — read and write data in spreadsheets as directed. - Google Docs (
documents) — read and edit documents as directed.
Limited Use compliance statement: The use of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google Workspace user data is processed exclusively to respond to your explicit in-session requests and is never transferred to third-party AI model providers for training, model improvement, or any secondary purpose.
Specifically, Google Workspace user data is:
- Used only to perform the action you explicitly requested through your agent.
- Not used for advertising, profiling, or any purpose unrelated to your stated instruction.
- Not used to train, fine-tune, evaluate, or improve any AI or machine-learning model — neither ours nor any third party's.
- Shared only with the AI inference providers listed below, and only in the context of fulfilling your request. Those providers operate under API terms that prohibit using customer inputs or outputs for model training: Anthropic (Claude API), Google DeepMind (Gemini API), and DeepSeek API.
You can revoke Tlyck's access to your Google Workspace data at any time from your Google Account permissions page or by disconnecting the integration in your agent's Settings tab. Upon disconnection, all stored OAuth tokens are permanently deleted within 24 hours.
4. Data Retention
We retain account information for as long as your account is active and for up to 12 months after closure, unless a longer period is required by law. Aggregated usage statistics may be retained indefinitely in anonymous form. Operational logs are rotated within 30 days.
5. Cookies and Tracking
We use only a single session cookie (an encrypted HTTP-only cookie) to keep you signed in. We do not use advertising cookies, cross-site trackers, or analytics pixels. The session cookie is strictly necessary and does not require consent under applicable law.
6. Your Rights
Under the Israeli Privacy Protection Law 5741-1981 and related regulations, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your data (subject to legal retention requirements).
- Withdraw consent where processing is based on consent.
To exercise any of these rights, contact us at david@melnicom.com. We will respond within 30 days.
7. Data Security
We use industry-standard measures including TLS encryption in transit, encrypted storage for sensitive credentials, and access controls limited to authorized personnel. No method of transmission over the Internet is completely secure; we cannot guarantee absolute security.
8. Children's Privacy
The Service is not directed at children under 18. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
9. International Transfers
Our servers are operated in the European Union. If you access the Service from outside the EU or Israel, your data may be transferred to and processed in those jurisdictions. By using the Service, you consent to such transfer.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the platform. The "last updated" date at the top of this page reflects the most recent revision.
11. Contact Us
Melnicom Ltd. — Data Controller
Israel
Email: david@melnicom.com