You are letting software speak in someone else's room.
Your members did not sign up for Vestry. You installed it. That asymmetry is the whole reason this page exists, and the reason the product behaves the way it does.
This page is written for you, the operator. The version your members should be able to read without asking you anything is on its own page.
What Telegram sends is not ours to limit.
Telegram's privacy mode restricts an ordinary bot to commands, mentions and replies. Promoting a bot to administrator overrides that: the platform states plainly that bot administrators always receive all messages. Most useful group behaviour needs admin rights, so this is the normal case, not an edge one.
No vendor can switch that off on your behalf, and any product that implies otherwise is describing a setting the platform does not have.
- ReceivesTelegram decides
- Everything sent in a group where the bot is an administrator, from the moment it joined. Detected and displayed, never claimed.
- RetainsWe decide, you set it
- A bounded window, 14 to 90 days depending on plan. At the end of it the message, its search index entry, anything derived from it and its use as a citation are all deleted together.
- SpeaksYou decide, per chat
- Silent, on mention, or proactive. Turning it down takes effect immediately and any Telegram admin can do it from inside the group.
What is stored, why, and what bounds it.
Messages from chats you connected
The grounding an answer stands on. Without it there is no product.
Only what Telegram delivered, and only inside your retention window. Nothing sent before the bot joined can be received at all.
Who said what
So an answer can name the member it came from.
Telegram user id and display name. No phone numbers, no email addresses of your members.
Answers you seeded by hand
The only grounding that exists on day one, and the fastest way to make the assistant useful.
Written by an admin, editable and deletable by an admin, attributed to them.
Your bot token
It is how Vestry acts as your bot.
Encrypted at rest with an externally held key. Never returned by any API, never written to a log, never shown back to you.
Replies it generated, and the sources they used
The audit log, and the basis for your usage.
Kept with the workspace and deleted with it.
Token counts and cost per reply
So your usage page and our margin are the same number.
Counts and cost only. Not the content of the exchange.
What never happens.
- Message content in any log, at any level, in any environment.
- Anything sent to a chat before the bot was added. The platform does not deliver it, so it cannot exist here.
- Your members' phone numbers or contact lists. The Bot API does not expose them and we do not ask for them.
- Your community's content used to train a model, ours or anyone else's.
- Direct messages pooled into a group's knowledge. A DM stays scoped to that person.
- A commercial link, an upgrade prompt or a payment request inside Telegram.
Your community is a tenant, enforced twice
Every row belonging to your workspace carries its workspace id, and the database itself refuses to return rows from another one. That second check exists because the first one is written by hand, and a single forgotten condition in a query is what a cross-tenant leak actually looks like.
Caches are keyed per workspace. Background jobs run under the same restriction as a web request. There is no admin path that reads across workspaces.
Member messages are data, never instructions
Anything a member writes is untrusted, including a pasted document and including a message that says it is a system notice. It is placed in a clearly delimited data region with a standing rule that instructions found inside it are reported rather than followed.
Vestry posts as itself, under the bot's own name. It cannot be made to speak as you or as a moderator, which keeps the worst case at “the bot said something wrong” rather than “the owner appeared to say it”.
Retention is a window, not a promise to be tidy
Nothing is kept indefinitely on any plan. When a message reaches the end of your window, its search index entry, anything derived from it and its use as a citation go at the same time. That is a property of how the data is related, not a cleanup job that might quietly fail.
The deletion lands in your audit log with a count, so the window is something you can watch happening. You can also purge a single chat, export the whole workspace, or delete it outright, on any plan.
Where the model sits
Answers are generated by a third-party model provider. The prompt contains the retrieved messages and the question, and nothing from any other workspace. We do not permit your content to be used for training.
The provider in use is named in the workspace settings rather than buried in a subprocessor list you have to hunt for. If it changes, you are told before it changes.
Spending stops rather than accumulating
The hard cap is on by default on every plan, and on the free plan it cannot be turned off. At the limit, generation stops and you are told in Telegram. Reading and search keep working, so nothing about your community breaks.
Going over the included allowance is opt-in and has a ceiling you set. Underneath the workspace allowance sit per-chat hourly and daily budgets, so one busy group cannot consume the plan.
Authority is checked where it lives
Being an administrator of a Vestry workspace does not let you configure a chat. Vestry asks Telegram whether you are currently an administrator of that specific group, and refuses until the answer is yes.
The reverse is deliberately easier. Any Telegram admin of the group can silence the bot from inside the chat, with no dashboard and no login, and that asymmetry is a safety property rather than an oversight.
What your members can find out, without asking you.
Anyone in the group can send /vestry about and get a plain answer: what the bot is delivered, what is kept and for how long, who administers it, and how to reach them. When it is added, and whenever its permissions change, it says so in the chat rather than quietly.