Privacy policy
Last updated 26 September 2026. This policy explains what Hilsen processes, why, and the choices you have.
Who we are
Hilsen provides software that helps teams run Telegram outreach and manage relationships in a CRM. For data your team imports or collects through Hilsen, your organisation is the controller and Hilsen acts as processor.
What we process
- Account data: your name, email address and workspace membership.
- Telegram sender accounts you connect: phone number, public profile details and an encrypted session. Two-step verification passwords are never stored.
- Contacts your team gathers: public Telegram profile information (display name, username, ID, bio, admin status in a community), plus notes, tags and messages exchanged through Hilsen.
- Optional phone-number lists your team uploads for matching, stored only as a one-way hash and the last four digits.
- Usage data needed to operate the service, such as audit logs of sensitive actions.
How it is protected
- Telegram sessions and integration credentials are encrypted at rest (AES-256-GCM).
- Workspaces are isolated at the database level with row-level security.
- API keys are stored as hashes and scoped; AI agents can draft but never send messages.
Your team's responsibilities
Teams must have a lawful basis for contacting people, respect opt-outs, and follow Telegram's terms. Hilsen enforces user-set sending limits and never tries to evade platform anti-spam systems. Phone matching may only be used for your own customers who consented to be contacted.
Rights and deletion
Admins can export all workspace data, export everything about a single person, and permanently forget a person, which deletes their record and conversations and prevents them from being re-imported. Removing a Telegram account deletes its session.
Sub-processors
- Supabase (database, authentication).
- Your hosting provider for the web app and engine.
- Anthropic (optional, only when AI features are enabled with an API key).
- Integrations you connect yourself (Notion, Google Sheets, Airtable, HubSpot, Slack, webhooks).
Contact
Questions about privacy, or a request to access, correct or delete personal data: send a privacy request. If you have an account, you can also use Contact support in the app.