noti.vn

Chính sách quyền riêng tư

Cập nhật lần cuối: Đơn vị vận hành: mcp.nguyentatduong.com

English version ↓

Chính sách này giải thích cách hệ thống Ads MCP tại mcp.nguyentatduong.com (“Hệ thống”) thu thập, sử dụng, lưu trữ và bảo vệ dữ liệu. Hệ thống do mcp.nguyentatduong.com (“Đơn vị vận hành”, “chúng tôi”) tự cài đặt và vận hành trên máy chủ của mình, sử dụng phần mềm Ads MCP do noti.vn phát triển.

Đơn vị vận hành là bên kiểm soát dữ liệu trong Hệ thống. noti.vn chỉ là nhà phát triển phần mềm: noti.vn không vận hành Hệ thống này, không lưu trữ và không truy cập dữ liệu của Hệ thống.

1. Hệ thống dùng để làm gì

Hệ thống là công cụ làm việc nội bộ cho đội marketing của Đơn vị vận hành. Người dùng kết nối tài khoản quảng cáo Meta (Facebook/Instagram), TikTok Ads, Google Ads (gồm quảng cáo YouTube) và OpenAI Ads bằng access token, refresh token, khoá service account hoặc API key do chính họ tạo trong ứng dụng nhà phát triển của mình, rồi điều khiển quảng cáo từ trợ lý AI (Claude, ChatGPT, Gemini) qua một đường dẫn MCP riêng: xem chỉ số theo ngày, bật/tắt, sửa, sao chép, tạo mới quảng cáo và đọc bài viết, chỉ số của Trang Facebook.

Người dùng cũng có thể thêm kênh thông báo Telegram (bot Telegram do chính họ tạo) để nhận tin khi trợ lý AI thay đổi quảng cáo, khi kết nối quảng cáo sắp hết hạn hoặc bị lỗi, khi có bản cập nhật phần mềm, hoặc khi trợ lý AI được phép gửi tin.

Người dùng cũng có thể khai báo thư mục Google Drive và Google Sheet (bằng cách chia sẻ chúng cho tài khoản dịch vụ - service account - của Hệ thống) để trợ lý AI lấy ảnh, video quảng cáo tải lên tài khoản quảng cáo, đọc kế hoạch creative trong sheet và ghi trạng thái ngược vào sheet.

Không có đăng ký công khai: chỉ người được quản trị viên cấp tài khoản mới đăng nhập được. Hệ thống không dùng tính năng “Đăng nhập bằng Facebook”.

2. Dữ liệu chúng tôi xử lý

  • Tài khoản nhân sự: họ tên, email, vai trò. Mật khẩu chỉ được lưu dưới dạng băm một chiều; khoá bí mật xác thực 2 bước (2FA) và mã dự phòng được mã hoá; phiên đăng nhập kèm địa chỉ IP và thông tin trình duyệt.
  • Thông tin truy cập nền tảng quảng cáo: access token Meta (kèm App ID, App Secret nếu người dùng nhập); access token TikTok (kèm App ID, App Secret); thông tin Google Ads (OAuth client ID, client secret và refresh token, hoặc tệp khoá JSON của service account, kèm ID tài khoản quản lý nếu có); API key OpenAI Ads. Chúng được mã hoá AES-256-GCM trước khi lưu, không bao giờ hiển thị lại (giao diện chỉ hiện 4 ký tự cuối), không được ghi vào nhật ký và không bao giờ được gửi cho trợ lý AI.
  • Dữ liệu quảng cáo: danh sách tài khoản quảng cáo (tên, ID, tiền tệ, múi giờ, trạng thái) được lưu để phân quyền. Chiến dịch (kể cả chiến dịch video YouTube chạy qua Google Ads), nhóm quảng cáo, quảng cáo, từ khoá và chỉ số hiệu quả được lấy trực tiếp từ Meta Marketing API, TikTok API for Business, Google Ads API và OpenAI Ads API mỗi khi người dùng yêu cầu, không được lưu thành kho dữ liệu riêng.
  • Kênh thông báo Telegram: bot token (mã hoá AES-256-GCM như trên, giao diện chỉ hiện 4 ký tự cuối, không ghi vào nhật ký, không gửi cho trợ lý AI), chat ID, tên nhóm/kênh, ID chủ đề (nếu có), tên bot và các loại sự kiện đã đăng ký. Mỗi lần gửi tin được ghi nhật ký gửi (thời gian, nguồn, loại sự kiện, trạng thái, mã lỗi và đoạn xem trước tối đa 300 ký tự đã che thông tin bí mật).
  • Google Drive và Google Sheet: khoá JSON của service account Google và API key Google (mã hoá AES-256-GCM như trên, giao diện chỉ hiện 4 ký tự cuối, không ghi vào nhật ký, không gửi cho trợ lý AI); email của service account (không bí mật, hiển thị để mọi người chia sẻ thư mục); danh sách thư mục / sheet đã khai báo (mã và tên trên Google Drive, phạm vi công ty / riêng, người khai báo, cấu hình cột, trạng thái kiểm tra). Nội dung file ảnh / video và các ô của sheet chỉ được đọc khi người dùng hoặc trợ lý AI yêu cầu; file được chuyển thẳng từ Google Drive tới nền tảng quảng cáo, không lưu trên máy chủ. Hệ thống lưu mã file và mã media đã tải lên tài khoản quảng cáo (để dùng lại), đường dẫn tạm cho nền tảng tải video (mã bí mật, hết hạn sau 60 phút) và trạng thái các lượt tải video ở chế độ nền. Với sheet được bật ghi, Hệ thống chỉ ghi vào các cột trạng thái / kết quả đã khai báo.
  • Dữ liệu Trang Facebook (chỉ đọc): danh sách Trang mà token được cấp quyền (tên, ID, danh mục, ảnh đại diện, số người theo dõi) được lưu để phân quyền. Bài viết và chỉ số của Trang được đọc qua Graph API khi người dùng yêu cầu. Hệ thống không đăng, sửa, xoá bài viết và không đọc nội dung bình luận hay tin nhắn.
  • Nhật ký: nhật ký thao tác của nhân sự (thời gian, người thực hiện, hành động, đối tượng, địa chỉ IP, thiết bị) và nhật ký từng lệnh MCP (thời gian, ứng dụng AI, địa chỉ IP, công cụ được gọi, tham số và tóm tắt kết quả, giá trị trước và sau với thao tác ghi). Thông tin bí mật được che trước khi ghi và dung lượng mỗi bản ghi có giới hạn.
  • Dữ liệu kỹ thuật tạm thời: bộ đếm chống dò mật khẩu và giới hạn tần suất (theo email, địa chỉ IP), các thao tác đang chờ xác nhận 2 bước. Chúng tự động bị xoá khi hết hạn.

3. Mục đích sử dụng

  • Xác thực người dùng, phân quyền và bảo vệ tài khoản.
  • Thực hiện đúng yêu cầu của người dùng: xem báo cáo, bật/tắt, sửa, sao chép, tạo mới quảng cáo; đọc bài viết và chỉ số Trang.
  • Gửi thông báo tới nhóm/kênh Telegram mà người dùng đã cấu hình, đúng các sự kiện họ đã bật.
  • Lấy ảnh, video từ Google Drive để tải lên tài khoản quảng cáo và cập nhật trạng thái trong Google Sheet theo yêu cầu của người dùng.
  • Ghi nhật ký để kiểm soát thao tác, điều tra sự cố và phát hiện lạm dụng.
  • Vận hành, bảo trì và cập nhật Hệ thống.

Chúng tôi không dùng dữ liệu để quảng cáo, không lập hồ sơ người dùng cho mục đích tiếp thị và không bán hay cho thuê dữ liệu.

4. Cơ sở xử lý dữ liệu

  • Cần thiết để cung cấp công cụ mà nhân sự sử dụng trong công việc.
  • Sự đồng ý của người dùng: người dùng chủ động kết nối tài khoản quảng cáo, Trang, kênh Telegram, chia sẻ thư mục / sheet Google Drive và cấp quyền cho token; có thể rút lại bất cứ lúc nào (mục 8).
  • Lợi ích chính đáng của Đơn vị vận hành trong việc bảo vệ Hệ thống và tài sản quảng cáo (nhật ký, chống dò mật khẩu).
  • Nghĩa vụ theo quy định của pháp luật, khi có.

Đơn vị vận hành chịu trách nhiệm xử lý dữ liệu cá nhân theo quy định của pháp luật Việt Nam về bảo vệ dữ liệu cá nhân.

5. Chia sẻ dữ liệu

  • Meta Platforms, TikTok, Google và OpenAI: Hệ thống gọi API của họ bằng token, khoá hoặc API key của bạn, chỉ khi cần để thực hiện yêu cầu. Dữ liệu phía nền tảng tuân theo chính sách quyền riêng tư của Meta, TikTok, Google và OpenAI.
  • Telegram: nếu bạn thêm kênh thông báo, Hệ thống gửi tin qua Telegram Bot API bằng bot token của bạn tới nhóm/kênh bạn chọn. Tin có thể chứa tên MCP, tên và ID tài khoản quảng cáo, tên đối tượng quảng cáo, thay đổi trạng thái/ngân sách, trạng thái kết nối, thông tin phiên bản phần mềm và nội dung do trợ lý AI soạn (chỉ khi bạn cho phép). Tin không bao giờ chứa token, API key hay đường dẫn MCP. Mọi thành viên của nhóm/kênh đó đều đọc được tin; tin trên Telegram tuân theo chính sách quyền riêng tư của Telegram.
  • Google Drive và Google Sheets (Google): Hệ thống gọi Google Drive API và Google Sheets API bằng service account hoặc API key do Đơn vị vận hành (hoặc chính bạn) tạo, chỉ với thư mục / sheet đã được chia sẻ cho service account hoặc file đã chia sẻ công khai “Bất kỳ ai có đường liên kết”. Ảnh, video được chuyển tiếp tới nền tảng quảng cáo bạn chọn (Meta, TikTok, Google, OpenAI); với video, nền tảng tải qua một đường dẫn tạm có mã bí mật trên tên miền của Hệ thống. Trợ lý AI chỉ nhận mã file, tên, kích thước và thông số - không nhận khoá, API key hay đường dẫn tạm. Dữ liệu trên Google tuân theo chính sách quyền riêng tư của Google.
  • Trợ lý AI mà bạn kết nối (Claude, ChatGPT, Gemini…): khi bạn thêm đường dẫn MCP vào ứng dụng AI, trợ lý chỉ nhận dữ liệu bạn yêu cầu thông qua các công cụ MCP, trong phạm vi tài khoản, Trang và quyền đã cấp cho đường dẫn đó; trợ lý không bao giờ nhận token hay API key. Nội dung cuộc trò chuyện do nhà cung cấp AI xử lý theo điều khoản của họ.
  • Máy chủ có thể tự kiểm tra bản cập nhật phần mềm (GitHub) và tải thông báo hệ thống từ noti.vn. Các yêu cầu này không gửi kèm dữ liệu người dùng hay dữ liệu quảng cáo.
  • Cơ quan nhà nước có thẩm quyền, khi pháp luật yêu cầu.

Ngoài các trường hợp trên, chúng tôi không chia sẻ dữ liệu cho bên thứ ba.

6. Nơi lưu trữ và bảo mật

Toàn bộ dữ liệu được lưu trong cơ sở dữ liệu trên máy chủ do Đơn vị vận hành quản lý (mcp.nguyentatduong.com); truy cập qua kết nối HTTPS được mã hoá.

  • Token, API key, khoá service account, bot token Telegram và đường dẫn MCP được mã hoá AES-256-GCM; khoá mã hoá được giữ tách khỏi cơ sở dữ liệu.
  • Mật khẩu được băm một chiều; hỗ trợ xác thực 2 bước (TOTP); tạm khoá khi nhập sai nhiều lần.
  • Phân quyền theo vai trò Quản trị viên / Nhân viên; nhân viên chỉ thấy kết nối, kênh Telegram và MCP của chính mình; thư mục / sheet Google Drive riêng chỉ chủ sở hữu và quản trị viên thấy.
  • Thao tác ghi do trợ lý AI đề xuất có thể yêu cầu xác nhận 2 bước và bị giới hạn ngân sách; quảng cáo tạo mới hoặc sao chép luôn ở trạng thái tạm dừng.
  • Đường dẫn MCP sai, đã tắt hoặc hết hạn không trả về dữ liệu.

Không hệ thống nào an toàn tuyệt đối. Khi phát hiện sự cố ảnh hưởng tới dữ liệu, chúng tôi sẽ khắc phục và thông báo cho người bị ảnh hưởng theo quy định.

7. Thời gian lưu trữ

  • Nhật ký MCP: giữ 3 tháng gần nhất cộng tháng hiện tại; phần cũ hơn tự động bị xoá vĩnh viễn.
  • Nhật ký nhân sự: giữ 3 tháng gần nhất cộng tháng hiện tại; phần cũ hơn tự động bị xoá vĩnh viễn.
  • Token và API key: tới khi kết nối bị xoá hoặc được thay token; khi xoá kết nối, bản mã hoá của token bị ghi đè ngay.
  • Bot token Telegram: tới khi kênh thông báo bị xoá hoặc được thay token; khi xoá kênh, Hệ thống ngừng gửi tin và không dùng token đó nữa.
  • Nhật ký gửi tin Telegram: giữ theo thời hạn của nhật ký MCP (3 tháng), sau đó tự động bị xoá.
  • Google Drive: khoá service account và API key giữ tới khi bị xoá hoặc thay; thư mục / sheet đã khai báo giữ tới khi bị xoá; đường dẫn tạm cho video hết hạn sau 60 phút và bị xoá sau 24 giờ; lượt tải video ở chế độ nền bị xoá sau 30 ngày; mã media đã tải lên giữ để dùng lại tới khi tài khoản quảng cáo bị xoá khỏi Hệ thống. File trên Google Drive không bị Hệ thống sao chép hay lưu lại.
  • Tài khoản nhân sự: tới khi quản trị viên xoá tài khoản.
  • Phiên đăng nhập, bộ đếm bảo mật, thao tác chờ xác nhận: tự động xoá khi hết hạn.
  • Dữ liệu quảng cáo và Trang lấy từ nền tảng: không lưu lâu dài, ngoài danh sách tài khoản, Trang và phần tóm tắt trong nhật ký.

8. Quyền của bạn

  • Xem và sửa thông tin tài khoản của mình trong trang Tài khoản; yêu cầu Đơn vị vận hành cung cấp bản sao dữ liệu về bạn.
  • Yêu cầu xoá dữ liệu: làm theo Hướng dẫn xoá dữ liệu tại https://mcp.nguyentatduong.com/data-deletion.
  • Rút lại quyền truy cập: xoá kết nối trong Hệ thống, thu hồi token hoặc API key, hoặc gỡ ứng dụng khỏi tài khoản Facebook, TikTok For Business hay tài khoản Google. Sau đó Hệ thống không truy cập được dữ liệu nền tảng của bạn nữa. Với Telegram: xoá kênh thông báo trong Hệ thống và/hoặc thu hồi bot token bằng @BotFather (lệnh /revoke). Với Google Drive: bỏ chia sẻ thư mục / sheet với email service account trên Google Drive, xoá thư mục / sheet trong Hệ thống, hoặc (quản trị viên) xoá khoá service account / API key trong Google Cloud.
  • Phản đối hoặc yêu cầu hạn chế xử lý, khiếu nại theo quy định của pháp luật.

9. Trẻ em

Hệ thống là công cụ làm việc nội bộ, không dành cho người dưới 18 tuổi và không cố ý thu thập dữ liệu của trẻ em.

10. Thay đổi chính sách

Chính sách có thể được cập nhật; ngày cập nhật gần nhất ghi ở đầu trang. Với thay đổi quan trọng, Đơn vị vận hành sẽ thông báo cho người dùng trước khi áp dụng.

11. Liên hệ

Mọi câu hỏi hoặc yêu cầu về quyền riêng tư, vui lòng liên hệ mcp.nguyentatduong.com:

quản trị viên hệ thống tại mcp.nguyentatduong.com

English version

Privacy Policy

Last updated: Operator: mcp.nguyentatduong.com

This policy explains how the Ads MCP system at mcp.nguyentatduong.com (the “System”) collects, uses, stores and protects data. The System is self-hosted and operated by mcp.nguyentatduong.com (the “Operator”, “we”) on its own server, using the Ads MCP software developed by noti.vn.

The Operator is the data controller for the System. noti.vn is only the software developer: noti.vn does not operate this System and does not store or access its data.

1. What the System does

The System is an internal work tool for the Operator’s marketing team. Users connect Meta (Facebook/Instagram), TikTok Ads, Google Ads (including YouTube ads) and OpenAI Ads ad accounts with an access token, refresh token, service account key or API key they create in their own developer app, then manage ads from an AI assistant (Claude, ChatGPT, Gemini) through a private MCP link: daily metrics, pausing/activating, editing, copying and creating ads, and reading Facebook Page posts and insights.

Users can also add a Telegram notification channel (a Telegram bot they create themselves) to receive messages when an AI assistant changes ads, when an ad connection is about to expire or fails, when a software update is available, or when the AI assistant is allowed to send messages.

Users can also register Google Drive folders and Google Sheets (by sharing them with the System’s service account) so the AI assistant can take ad images and videos from them, upload them to ad accounts, read a creative plan in a sheet and write status back to that sheet.

There is no public sign-up: only people given an account by an administrator can sign in. The System does not use “Login with Facebook”.

2. Data we process

  • Staff accounts: name, email, role. Passwords are stored only as one-way hashes; two-factor (2FA) secrets and backup codes are encrypted; sign-in sessions include the IP address and browser information.
  • Ad platform credentials: Meta access tokens (plus App ID and App Secret if entered); TikTok access tokens (plus App ID and App Secret); Google Ads credentials (OAuth client ID, client secret and refresh token, or a service account JSON key file, plus the manager account ID if any); OpenAI Ads API keys. They are encrypted with AES-256-GCM before storage, never shown again (the interface only shows the last 4 characters), never written to logs and never sent to an AI assistant.
  • Advertising data: the list of ad accounts (name, ID, currency, time zone, status) is stored for access control. Campaigns (including YouTube video campaigns run through Google Ads), ad sets/ad groups, ads, keywords and performance metrics are fetched directly from the Meta Marketing API, the TikTok API for Business, the Google Ads API and the OpenAI Ads API whenever a user asks, and are not kept as a separate data store.
  • Telegram notification channels: the bot token (encrypted with AES-256-GCM as above, only the last 4 characters shown, never logged, never sent to an AI assistant), chat ID, group/channel title, topic ID (if any), bot name and the subscribed event types. Each message sent is recorded in a delivery log (time, source, event type, status, error code and a preview of at most 300 characters with secrets masked).
  • Google Drive and Google Sheets: the Google service account JSON key and the Google API key (encrypted with AES-256-GCM as above, only the last 4 characters shown, never logged, never sent to an AI assistant); the service account email (not secret, shown so people can share folders with it); the registered folders / sheets (Google Drive ID and name, company / personal scope, who registered it, column mapping, check status). Image / video files and sheet cells are only read when a user or the AI assistant asks; files are passed straight from Google Drive to the ad platform and are not stored on the server. The System stores file IDs and the media IDs already uploaded to an ad account (for reuse), temporary links the platform uses to fetch a video (secret token, expire after 60 minutes) and the status of background video uploads. For sheets with write-back enabled, the System only writes to the declared status / result columns.
  • Facebook Page data (read-only): the list of Pages the token can access (name, ID, category, profile picture, follower count) is stored for access control. Page posts and insights are read through the Graph API when a user asks. The System does not publish, edit or delete posts and does not read comment or message content.
  • Logs: staff activity logs (time, actor, action, target, IP address, device) and a log of every MCP request (time, AI app, IP address, tool called, parameters and a result summary, before/after values for write actions). Secrets are masked before logging and each record has a size limit.
  • Temporary technical data: password-guessing and rate-limit counters (by email, IP address) and actions waiting for two-step confirmation. They are deleted automatically when they expire.

3. Purposes

  • Authenticating users, enforcing permissions and protecting accounts.
  • Doing what users ask: reporting, pausing/activating, editing, copying and creating ads; reading Page posts and insights.
  • Sending notifications to the Telegram groups/channels users configured, for the events they enabled.
  • Taking images and videos from Google Drive to upload them to ad accounts, and updating status in Google Sheets, when users ask.
  • Keeping logs for accountability, incident investigation and abuse detection.
  • Operating, maintaining and updating the System.

We do not use data for advertising, do not profile users for marketing and do not sell or rent data.

4. Legal basis

  • Necessity to provide the work tool staff use in their job.
  • User consent: users choose to connect ad accounts, Pages and Telegram channels, to share Google Drive folders / sheets and to grant permissions to their token, and can withdraw at any time (section 8).
  • The Operator’s legitimate interest in protecting the System and its ad assets (logs, password-guessing protection).
  • Legal obligations, where applicable.

The Operator is responsible for processing personal data in accordance with Vietnamese personal data protection law.

5. Sharing

  • Meta Platforms, TikTok, Google and OpenAI: the System calls their APIs with your token, key or API key, only as needed to fulfil a request. Data on their side is governed by the privacy policies of Meta, TikTok, Google and OpenAI.
  • Telegram: if you add a notification channel, the System sends messages through the Telegram Bot API with your bot token to the group/channel you chose. Messages may contain the MCP name, ad account names and IDs, ad object names, status/budget changes, connection status, software version information and text written by the AI assistant (only if you allow it). Messages never contain tokens, API keys or MCP links. Every member of that group/channel can read them; messages on Telegram are governed by Telegram’s privacy policy.
  • Google Drive and Google Sheets (Google): the System calls the Google Drive API and the Google Sheets API with a service account or API key created by the Operator (or by you), only for folders / sheets shared with that service account or files shared publicly with “Anyone with the link”. Images and videos are passed on to the ad platform you choose (Meta, TikTok, Google, OpenAI); for videos, the platform fetches them through a temporary link with a secret token on the System’s domain. The AI assistant only receives file IDs, names, sizes and dimensions - never keys, API keys or temporary links. Data on Google’s side is governed by Google’s privacy policy.
  • The AI assistant you connect (Claude, ChatGPT, Gemini…): when you add your MCP link to an AI app, the assistant only receives the data you request through the MCP tools, within the accounts, Pages and permissions granted to that link; it never receives tokens or API keys. Conversation content is processed by the AI provider under its own terms.
  • The server may check for software updates (GitHub) and download system notices from noti.vn. These requests do not include user or advertising data.
  • Competent authorities, when required by law.

Apart from the above, we do not share data with third parties.

6. Storage and security

All data is stored in a database on a server managed by the Operator (mcp.nguyentatduong.com) and accessed over encrypted HTTPS connections.

  • Tokens, API keys, service account keys, Telegram bot tokens and MCP links are encrypted with AES-256-GCM; encryption keys are kept separate from the database.
  • Passwords are hashed; two-factor authentication (TOTP) is supported; repeated wrong attempts trigger a temporary lock.
  • Role-based access (Administrator / Staff); staff only see their own connections, Telegram channels and MCP servers; personal Google Drive folders / sheets are only visible to their owner and administrators.
  • Write actions proposed by an AI assistant can require two-step confirmation and are subject to budget limits; newly created or copied ads always start paused.
  • Invalid, disabled or expired MCP links return no data.

No system is perfectly secure. If we detect an incident affecting data, we will remediate it and notify affected people as required by law.

7. Retention

  • MCP logs: the last 3 months plus the current month are kept; older entries are deleted permanently and automatically.
  • Staff activity logs: the last 3 months plus the current month are kept; older entries are deleted permanently and automatically.
  • Tokens and API keys: until the connection is deleted or its token is replaced; when a connection is deleted its encrypted token is overwritten immediately.
  • Telegram bot tokens: until the notification channel is deleted or its token is replaced; once a channel is deleted the System stops sending messages and no longer uses that token.
  • Telegram delivery logs: kept for the MCP log retention period (3 months), then deleted automatically.
  • Google Drive: service account keys and API keys until deleted or replaced; registered folders / sheets until deleted; temporary video links expire after 60 minutes and are deleted after 24 hours; background video uploads are deleted after 30 days; uploaded media IDs are kept for reuse until the ad account is removed from the System. Files on Google Drive are never copied or kept by the System.
  • Staff accounts: until an administrator deletes the account.
  • Sessions, security counters and pending confirmations: deleted automatically when they expire.
  • Advertising and Page data fetched from the platforms: not stored long-term, except the account and Page lists and the summaries in logs.

8. Your rights

  • View and correct your own account information on the Account page; ask the Operator for a copy of the data about you.
  • Request deletion: follow the Data Deletion Instructions at https://mcp.nguyentatduong.com/data-deletion.
  • Withdraw access: delete the connection in the System, revoke the token or API key, or remove the app from your Facebook account, TikTok For Business or Google account. The System can then no longer access your platform data. For Telegram: delete the notification channel in the System and/or revoke the bot token with @BotFather (the /revoke command). For Google Drive: stop sharing the folder / sheet with the service account email in Google Drive, delete the folder / sheet in the System, or (administrators) delete the service account key / API key in Google Cloud.
  • Object to or request restriction of processing, and lodge complaints as provided by law.

9. Children

The System is an internal work tool, not intended for people under 18, and does not knowingly collect children’s data.

10. Changes

This policy may be updated; the last update date is shown at the top of the page. For material changes, the Operator will inform users before they take effect.

11. Contact

For any privacy question or request, please contact mcp.nguyentatduong.com:

the system administrator at mcp.nguyentatduong.com