Privacy Policy
This policy covers every AstraCRM service: the web application, the iOS and Android apps, the Telegram bot, and the astracrm.pro website. Mobile specifics are described in the separate iOS and Android policies.
Last updated: July 2026
1. Introduction
This document explains how AstraCRM collects, uses, and protects the data you trust us with. It applies to every part of the platform:
• Web application: the workspace for owners, managers, and dispatchers
• iOS and Android apps: the tools field technicians use
• Telegram bot: quick actions and notifications
• astracrm.pro: public product information
By using any of these services you accept the handling of data described here.
Who is the controller for what:
• Data about your staff as AstraCRM users (account, contacts, billing) is processed by us, and we are the controller for it.
• Data about your clients, counterparties, and employees that you enter into the system belongs to you. Your organization is the controller for it, and AstraCRM processes it on your instructions solely to make the service work.
So the legal grounds for processing your clients' data are your responsibility: obtaining consent where it is required, and letting people know that you hold their data.
2. What We Collect
We collect the following types of data:
• Account data: name, email, phone, company name and registration details, job title, role, and permissions
• Sign-in data: session tokens, two-factor settings, passkey credentials
• Work data: clients, orders, services, inventory, schedule, amounts, and everything else you enter into the system
• Device data: device type, operating system, browser, mobile app identifier
• Usage data: which sections you open, which features you use, how fast the system responds
• Communications: messages in channels and the Telegram bot, call logs and call recordings when telephony is connected, notifications, support correspondence
• Files: photos, documents, and attachments you add to orders and client records
• Technical data: IP address, API requests, application errors, and performance metrics
3. Why We Use It
The data is there to run the service, and nothing beyond that:
• Running the platform: orders, client base, scheduling, inventory, reports, coordinating field staff
• Sign-in and security: verifying users, protecting accounts, enforcing permissions, investigating suspicious logins
• Notifications: order changes, reminders, maintenance windows, important announcements
• Support: reproducing and fixing the problems you report
• Product work: understanding which features people use and which get in the way. We look at aggregated statistics, not at the contents of your orders
• Legal obligations: accounting and tax records, responding to lawful requests from government bodies
• Product emails: news about new capabilities. One click unsubscribes you, and it changes nothing about how the service works
4. Who We Share Data With
We do not sell your data, rent it out, or hand it to advertisers, data brokers, or anyone else for their own purposes. We do not publish your data in public directories and we do not include it in any transaction.
Data leaves the AstraCRM perimeter in three cases only.
Inside your organization. Your staff see data according to the roles and permissions you configure.
Contractors the service cannot run without. Each one receives only the minimum its function needs:
• Selectel: servers, databases, and object storage for files. The data centers are in Russia
• Timeweb Cloud: the content delivery network that serves images and attachments through temporary signed links
• Yandex Cloud: the language model that parses inbound messages, email notification delivery, and the gateway for telecom integrations
• Yandex Maps (Tiles API): maps, address display, and routing
• Yandex.Metrika: visit statistics for the astracrm.pro website. It sees no CRM work data
• OpenRouter: summaries of call transcripts. Direct identifiers are stripped before sending, so only de-identified text goes out
• DaData: address and company-details suggestions and validation
• Expo and Firebase: push notification delivery to the mobile apps
• Telegram: running the Telegram bot and the messages inside it
• T-Bank: payment acquiring
• Telephony partners: connecting your PBX
Two things we keep in-house rather than hand to a contractor. Speech recognition for call transcription runs on our own servers. Error monitoring runs on our own self-hosted Sentry inside the same infrastructure.
When the law requires it. If a court, an investigator, or another government body requests data within its authority. We check such requests for validity and hand over only what they explicitly cover.
5. How We Protect Data
The measures that are actually in place:
• Transport encryption: all traffic runs over TLS
• Sign-in: session tokens, two-factor authentication via app, SMS, or email, and passkey login
• Permissions: roles and rights are configured per organization, so a person sees only what you opened for them
• Tenant isolation: each company's data lives in its own database schema, so organizations cannot see each other
• Files: private storage with no public bucket access. Attachment links are temporary and signed
• Backups: regular, encrypted, and restore-tested
• Monitoring: our own Sentry for errors and metrics, plus API access logs
• Updates: security patches and dependency updates on a regular cadence
No system is perfectly secure, and promising otherwise would be dishonest. If a breach affects your data, we will tell you what happened.
6. Your Rights
Regarding your own data you can:
• Get access: find out what we hold about you and how it is processed
• Correct it: fix inaccurate data in your account settings or through support
• Delete it: request removal of your account and the data attached to it. Some records we are legally required to keep, accounting documents for example
• Take it with you: export orders, clients, and reports in a machine-readable format
• Restrict or object to processing
• Withdraw consent where consent is the legal basis
• Tune notifications: email, push, and SMS are switched on and off separately
Write to privacy@astracrm.pro or use the settings in the web application. We reply within 30 days, usually sooner.
7. Platform Specifics
Different parts of the service have their own details:
• Web application: sessions, reports, file uploads
• Mobile apps: camera access for photo reports on orders, push notifications, and access to already-downloaded data on a weak connection
• Telegram bot: messages pass through Telegram's servers and are covered by Telegram's own privacy policy
• Telephony: call logs and call recordings when recording is enabled. Warning the other party about recording is your organization's responsibility
• Call transcription: speech recognition runs on our own servers, so the audio never leaves them
• AI call summaries: direct identifiers are stripped from the transcript before it goes to OpenRouter, so only de-identified text is sent
• Inbound message parsing: requests from channels are parsed by a Yandex Cloud language model, and here personal data can appear in the text, because it is the content of your client's message
• File storage: private object storage, delivered through the CDN via temporary links
• Over-the-air mobile updates (Expo OTA): the app can pull new code and assets on its own. No extra data is collected during that
• API: token-based access for your integrations
8. Third-Party Services
The full list of external services involved in running the platform:
• Infrastructure, databases, and file storage: Selectel
• Content delivery network: Timeweb Cloud
• Language model for inbound message parsing, email notifications, and the telecom gateway: Yandex Cloud
• Maps and routing: Yandex Maps (Tiles API)
• astracrm.pro website statistics: Yandex.Metrika
• Call transcript summaries: OpenRouter, on de-identified data
• Addresses and company details: DaData
• Payments: T-Bank
• Push notifications: Expo and Firebase
• Telegram bot: Telegram
Each of them has its own privacy policy, which is worth reading. We pass along only the data a given feature cannot work without.
Two things are not outsourced: speech recognition for call transcription and error monitoring. Both run on our own servers.
9. How Long We Keep Data
Retention depends on the type of data:
• Account: while the account is active, and up to 7 years after closure where accounting or tax rules require it
• Work data: orders, clients, and documents are kept while you use the service and removed on your request
• Support correspondence: up to 3 years
• Technical logs and error reports: up to 1 year
• Payment records: 7 years, a period set by law
• Backups: up to 90 days, then overwritten
After deletion, data disappears from live systems immediately and from backups as those copies rotate, so within 90 days at the latest. We keep things longer only where the law obliges us to.
10. Where Data Is Stored
The database and files sit in Selectel data centers on Russian territory. That satisfies the Federal Law 152-FZ requirement to localize the personal data of Russian citizens.
Some data does cross the border, and here are those cases in full:
• OpenRouter: de-identified transcript text for AI summaries, with direct identifiers stripped before sending
• Telegram: the messages you and your clients write in the Telegram bot
• Expo and Firebase: device tokens for push delivery, without any order content
Nothing else leaves Russia. By using those features you consent to that transfer. If it does not suit you, those features can be left switched off.
11. Children
AstraCRM is built for companies and is not intended for anyone under 16.
We do not market to children and do not knowingly collect their data. If you are a parent or guardian and believe your child's data reached us, write to privacy@astracrm.pro and we will delete it.
12. Changes to This Policy
The policy needs updating from time to time: laws change, new features appear, the set of contractors shifts.
We announce material changes in advance:
• We publish the new version on the website and in the apps
• We email registered users
• We show a notice inside the service
• We update the date at the top of this document
You get at least 30 days to read the changes before they take effect. Continuing to use the service after that date means the new version works for you. If it does not, you can stop using the service and take your data with you.
13. Contact Us
For questions about your data or this policy:
• Privacy email: privacy@astracrm.pro
• Support: support@astracrm.pro
• Website: https://astracrm.pro/contact
• Postal address: 164500, Severodvinsk, Karla Marksa St., 46, office 12
We answer these within 5 business days. If it is urgent, put "URGENT: Privacy" in the subject line. We reply in Russian and English.
Platform-specific questions:
• iOS: see the iOS privacy policy or contact us through the App Store
• Android: see the Android privacy policy or contact us through Google Play
• Telegram bot: the /help command, or the email above
This policy covers every AstraCRM service: the web application, the iOS and Android apps, the Telegram bot, and the astracrm.pro website. Mobile specifics are described in the separate iOS and Android policies.