Privacy Policy
Last updated: April 24, 2026
Who we are
Gnomik is a small software service that helps solo professionals organise their schedule, reminders and simple bookkeeping. Gnomik is operated by the Gnomik Team: Alina Riaby, Pavel Riaby, Andrey Andrianov, and Nick McLarnan. You can contact us at [email protected].
What Gnomik does
Gnomik connects your existing tools — Telegram and Google Calendar — to help you manage appointments and payment reminders. Gnomik itself is intentionally built on a principle of minimal data storage: it doesn't keep its own copy of your data and uses your Google account as the primary data store.
Roles under data-protection law
- If you use Gnomik in your own practice, you are the data controller for information about your clients.
- For that data, Gnomik acts as your data processor: we process it only on your instructions and only to provide the service.
- Gnomik is a data controller for data about you as a user (billing, account management, support).
Data we process
Depending on how you use the service, we may process:
- Account data: display name (a name you choose to present to your clients — this need not be your legal name), Telegram user ID, Google account ID, language, time zone.
- Scheduling data: appointment date, time and duration, a display name provided by your client when booking (which may not be their legal name), internal client identifiers, basic appointment metadata read from your Google Calendar. When a client books via Gnomik, their Telegram username or display name is added to the corresponding event in your Google Calendar so you can identify and contact them; this data is written to your own Google account and governed by Google's privacy policy.
- Payment configuration data: if you use Gnomik's invoicing feature, we store the payment details you explicitly provide so Gnomik can include them in invoices sent to your clients. Depending on your chosen payment method this may include a payment link URL, a phone number for bank transfers (e.g. SBP), bank account holder name, IBAN, SWIFT/BIC, routing number, or a cryptocurrency wallet address. This data is stored only at your explicit request and is treated as your business configuration. It is never logged or shared with third parties beyond delivering invoices to your clients.
- Messaging data: technical details of Telegram messages sent to and from the Gnomik bot (chat IDs, timestamps, message IDs). We do not store copies of message contents in our database; they remain in Telegram.
- Technical data: server logs with anonymised identifiers: request IDs, error codes, IP address in security logs. On the public landing website, we also use Umami Cloud to collect anonymised pageview analytics such as page URL, referrer URL, browser, operating system, device type and country of origin. The Umami tracker does not use cookies and is configured to respect Do Not Track. When you click a landing CTA, Gnomik uses a first-party attribution bridge to remember the landing page, campaign parameters, referrer, landing language, browser language, time zone hint, coarse device/browser/screen class, and Do Not Track state before opening Telegram. The bridge does not store IP address or raw user agent. If Do Not Track is enabled, Gnomik keeps the first-party CTA and campaign facts but does not keep a durable Umami join key or durable device/browser/screen analytics fields.
Google API data and Limited Use
Gnomik accesses your Google account through OAuth 2.0 authorisation that you explicitly grant. The specific data accessed includes:
- Calendar list — to let you select which calendar Gnomik should use for your appointments.
- Calendar events (read and write) — to display your schedule, create booking events, set reminder metadata, and remove cancelled appointments.
- Free/busy information — to identify available time slots for client bookings.
This data is used exclusively to provide the scheduling, booking, and reminder features visible in the service. In particular:
- We do not use any Google user data to serve you advertisements or for any advertising-related purpose.
- We do not allow any human to read your Google account data, except where required by applicable law, where strictly necessary for security or fraud-prevention (and only to the minimum extent required), or where you have given explicit written consent.
- We do not sell, transfer, or disclose Google user data for any purpose other than those explicitly described in this Privacy Policy.
- We do not use Google user data for any purpose unrelated to providing and improving Gnomik's user-facing features.
- We do not use your data — including any data obtained via Google APIs — to develop, improve, or train generalised AI or machine-learning models.
Gnomik's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Where your data lives
- Google Calendar: most long-term data about your clients and appointments lives in your own Google account and is governed by Google's privacy policy.
- Telegram: messages between you, your clients and the Gnomik bot live in Telegram and are governed by Telegram’s privacy policy.
- Gnomik infrastructure: we operate servers on reputable hosting providers, where we store only what is needed to run the service: OAuth tokens, internal identifiers and technical logs.
Security
We take the protection of your data seriously and use appropriate technical and organisational measures to safeguard it. All data transmitted between you, Gnomik, and our integration partners (Google, Telegram) is encrypted in transit using TLS. Access to systems that hold your data is restricted to authorised members of the Gnomik team. No method of transmission or storage is 100% secure, but we work to protect your information using industry-standard practices.
Why we process your data
We use your data to:
- provide and maintain the service (legal basis: performance of a contract);
- secure and troubleshoot the service (legal basis: our legitimate interest in keeping the service reliable and secure);
- understand anonymous usage of the public landing website (legal basis: our legitimate interest in improving the website);
- communicate with you about your subscription, updates and changes (legal basis: performance of a contract / legitimate interest);
- comply with legal obligations (for example, accounting and tax rules).
How long we keep data
Account-level data is kept for as long as your account is active and for a reasonable period afterwards where required by law (e.g. invoicing records).
Technical logs are kept for short, fixed periods (90 days maximum) for security and debugging, then permanently deleted.
We do not keep our own copy of any of your and your clients' records; those remain under your control in your Google and Telegram accounts.
Sharing and subprocessors
We do not sell your data. We do not transfer or disclose your information to third parties for purposes other than the ones provided in this policy. We use the following service providers to operate Gnomik. Where required by law we sign data-processing agreements with them.
| Provider | Country | Purpose |
|---|---|---|
| Hetzner Online GmbH | Germany | Cloud infrastructure — the servers and in-memory database (Valkey) that store your account data, OAuth tokens, and operational state |
| Sentry (Functional Software, Inc.) | United States | Error monitoring — anonymised crash reports and stack traces used to diagnose bugs. May include technical identifiers (e.g. Telegram user ID, request path) attached to error events |
| Umami Software, Inc. | United States | Privacy-focused analytics for the public landing website — anonymised pageviews, referrers, browser/OS/device type and country of origin, without cookies |
| Google LLC (Gemini API) | United States | AI-assisted schedule import — used only when you photograph a paper schedule and ask Gnomik to extract appointments from it. Only the photo is sent; no calendar data or personal details are included |
| OpenAI, L. L.C. | United States | AI-assisted schedule import (fallback) — same feature; used only if Google Gemini is unavailable |
Google LLC is also our primary integration partner for Google Calendar; that relationship is described under Where your data lives and Google API data and Limited Use above.
International transfers
Our infrastructure may be hosted outside the region where you are located. We take reasonable steps to ensure your data is handled with appropriate care during any such transfers, and we intend to implement formal transfer safeguards (such as Standard Contractual Clauses) as the service matures.
Your rights
You have the right to:
- access, correct or delete your personal data;
- restrict or object to certain processing;
- receive a copy of your data in a portable format;
- complain to your local data-protection authority.
For most requests about your clients’ data (for example, a client who wants their Google Calendar entry removed), you remain the controller and handle those requests yourself through your own Google and Telegram accounts. We will support you where reasonably possible.
Contact
For privacy questions or requests, email us at [email protected]
Update History
- April 24, 2026: Added the public landing website analytics disclosure for Umami Cloud, including the no-cookie tracker configuration, Do Not Track handling, analytics legal basis, and subprocessor entry.
- April 28, 2026: Added the first-party landing-to-Telegram attribution bridge disclosure.