Skip to main content

Security

Your data travels over HTTPS and sits on an encrypted disk. The bot only posts to channels where you made it an admin, and it cannot read your private chats.

  • HTTPS and encrypted storage
  • Admin-scoped bot access
  • Bot cannot read private chats

Encrypted in transit and at rest

Every connection to Autogram runs over HTTPS, and the database holding your channel data and content sits on an encrypted disk.

Admin-scoped bot access

The bot can only post where you added it as a channel admin. It cannot read your private conversations. If you remove its admin rights, it can no longer publish there, and Autogram tells you why the channel paused.

Built to retry, not fail

A transient error talking to Telegram — a dropped connection, a rate limit — is retried automatically, so a scheduled post does not silently disappear.

How your data is protected

Traffic between your browser, Autogram and Telegram runs over HTTPS, and the disk that holds the database is encrypted. The bot only has the Telegram permissions you grant it as a channel admin, and it cannot read your private conversations. If you remove its admin rights, publishing to that channel fails on the next attempt and Autogram pauses the channel after repeated failed deliveries. A transient error talking to Telegram, such as a dropped connection, is retried automatically instead of silently failing your post.

How access is checked, step by step

  1. 1

    Sign in

    You sign in with an email and a password, with Google, or with Telegram. An email account must confirm the address first, and the link works for 24 hours. Passwords are stored as hashes, not as text. Sign-in and sign-up give the same answer whether or not an account exists, and each has a limit on attempts from one address.

  2. 2

    Prove you run the channel

    You link your Telegram account by opening a one-time link in the Autogram bot. The link works for 20 minutes, and a new link replaces the old one. When you connect a channel, Autogram asks Telegram for the channel administrators and connects it only if your linked account is on that list. A channel belongs to one Autogram account.

  3. 3

    Grant the bot only what it needs

    The setup link asks Telegram for three administrator rights: post messages, edit messages and delete messages. Autogram checks that the bot can post before it accepts the channel. You can untick rights in Telegram, and you can remove the bot at any time.

  4. 4

    Keep the session short

    An access token lasts 30 minutes and a refresh token lasts 7 days from sign-in. Each refresh issues a new token, and using an old one again after a short grace period signs that account out everywhere. Signing out and changing your password also end your other sessions.

Transport, storage and what is kept

Encrypted in transit and on disk

Autogram is served over HTTPS, plain HTTP is redirected to HTTPS, and browsers are told to use HTTPS for a year. The disk that holds the database is encrypted. The storage for backups and uploaded media is encrypted too, and media is served through short-lived links. Individual fields in the database are not encrypted separately.

What Autogram keeps

Autogram keeps your email, your name, your Telegram ID, your channels, and the text and images of your posts. It does not keep a Telegram login session, and it does not hold your card number: card payments run on the payment provider’s page, and Autogram keeps only the identifiers of the customer and the subscription. When you generate text or images, your prompt goes to the AI provider that runs the model. To delete or export your data, write to us and we answer within 30 days.

What this page does not promise

Two-factor sign-in is not available. Autogram has no security certificate such as SOC 2 or ISO 27001, and we do not claim end-to-end encryption, because we must read your posts to publish them. Data you put into a custom API integration is stored with your automation, so do not store a secret there that you cannot replace.

Security questions

No. A Telegram bot cannot read your conversations with other people. Autogram only receives messages that people send to the bot itself, such as the link code, and posts in channels where you made the bot an administrator.

Publishing to that channel stops, because Telegram refuses the bot. Autogram pauses an automation channel after two failed deliveries in a row and shows the reason. Add the bot again and turn the channel back on to continue.

No. Autogram asks Telegram for the channel administrators and connects the channel only if your linked Telegram account is one of them. It checks again every day, and it pauses the channel if you are no longer an administrator.

No. Card payments run on the payment provider’s page. Autogram keeps identifiers such as the Stripe customer and subscription IDs, and the status of each payment.
AES-256encrypted
OAuth 2.0verified

Ready to get started?

Start automating your Telegram channels today. No credit card required.

Get started free