Build with Arven/Privacy Policy
Legal
Written to be read, not scrolled past. If something here is unclear or looks wrong, write to me and I'll fix the page.
Andrea Marengo, operating as Arven, is the data controller. Contact: arven@buildwitharven.com — it reaches me directly and I answer within one working day. There is no company behind this: one person, in Italy, selling one piece of software.
Analytics run on Umami, self-hosted on a server I control at analytics.buildwitharven.com. It sets no cookies, does not follow you across other sites and does not build a profile: it counts page views, countries and which links get clicked, in aggregate. The site does keep two things in your browser's local storage — the language you picked, so you aren't asked twice, and the utm_source of your first visit, so I can tell which channel a download came from. Both stay on your device and you can clear them from your browser at any time. There is no advertising, no remarketing pixel, and nothing is sold to anyone.
Payments run through Creem, which sells as Merchant of Record. The purchase contract is with them: they take the payment, apply VAT and issue the invoice. Your card details go to Creem and never reach me — I never see them and cannot store them. What I receive is your email address, which product you bought and the order identifier. What Creem does with the rest is governed by their own privacy policy.
The licence key is generated by KeyAuth, a third-party licensing service. To stop one key being shared by a hundred people, KeyAuth ties it to an identifier of the computer it is activated on. On my own server I keep: your email address, the plan you bought, the licence key, the order identifier and the date. I keep that record because KeyAuth is somebody else's service — if it changed terms or went offline tomorrow, without my own copy I would not even know who I had sold to.
When a download finishes for the first time, the app sends me a device identifier and how many files were transferred. That is the number this whole project is judged on, and it is published on the homepage. It counts once per device: sending the event ten times does not make it ten. No name, no email and no file name travels with it — from that event I cannot tell who you are or what you downloaded.
Telegram Downloader runs on your machine. The api_id and api_hash you create on my.telegram.org, and the session that authenticates you, stay on your computer: they are never sent to me and I have no way of reading them. Files go from Telegram straight to your disk without passing through any server of mine. The app reaches only the chats your own Telegram account can already open.
Besides Creem and KeyAuth, the server and the mailbox are hosted by OVH, in Europe. Email to you is sent from the arven@buildwitharven.com mailbox. For abuse protection the server records the IP address of requests to its API and deletes it after one hour. Purchase records are kept while the licence is valid and for as long as tax rules require. Ask me to delete your data and I will, apart from what I am legally obliged to keep — and I will tell you exactly what that is.
You can ask for a copy of what I hold about you, have it corrected, have it deleted, or object to how it is used. Write to arven@buildwitharven.com and I'll do it: there is no form to fill in. The legal basis is performing the contract, for delivering and supporting a licence you bought, and legitimate interest, for the aggregate counting and abuse protection described above. If you are in the EU and think I have handled this badly, you can complain to your national data protection authority; in Italy that is the Garante per la protezione dei dati personali.