Legal
Privacy Policy
Last updated: 26 July 2026 · Applies to the Telegram bot @abbassakbot and to this website.
This is an English translation
The Arabic version at abbassak.pages.dev/privacy is the original and prevails if the two ever disagree. Both are updated together.
The short version
- We collect what the service needs to keep your books: your Telegram identity, and the transactions you photograph or type in.
- Receipt images are sent to outside text-reading services (listed below) — the image does leave us.
- We do not sell your data, do not use it for advertising, and do not share it with anyone not named here.
- You can ask for a copy of your data, or for it to be deleted, at any time — /support in the bot, or +249 912 816 697.
1) Who is responsible for your data
Abbas the Accountant is a product of DT+, a Sudanese agency. Any question or request about your data goes to them directly: +249 912 816 697, or from inside the bot with the /support command (the reply arrives in the same chat).
2) What we collect
From Telegram
- Your Telegram account number (the numeric id) and display name — Telegram gives us these the moment you open the bot.
- Your phone number — only if you choose to share it. Sharing is optional and the service works without it.
- The text of your messages to the bot in the “contact the team” path only, and the team's replies to them.
From your ledger
- The ledger or shop name, its kind (business / personal), its time zone, and its opening cash balance.
- Transactions: amount, type (income/expense), category, date and time, notes.
- The bank account numbers you register as your own, and the names you give to the parties you deal with.
- Team membership: who is a cashier on which ledger, and in what role.
From receipt images and account statements
- The fields read out of the image: amount, transaction (reference) number, date and time, the bank or wallet name.
- Third-party data: a transfer receipt usually carries the name and account number of the other party to the transaction. When you send the image, that data is stored in your ledger. It is your responsibility not to send an image you are not comfortable sharing; we hold it only to serve your ledger.
- Images you send to the bot are not stored on our servers — we store Telegram's reference to it (the file id) so we can show it to you again, and it remains in Telegram under their policies. We also store a fingerprint of the image so the same receipt cannot be recorded twice.
- One exception: the payment screenshot you upload yourself on the subscription page is stored by us rather than in Telegram — it is proof of a payment. Section 5 explains for how long.
From your use of the service
- Usage counters (how many images, how many AI reads, how many statement pages) so we can apply your plan's limits.
- Short technical traces of failed reads, to improve reading accuracy.
If you subscribe through this website
- The transfer's reference number and the amount you declare, plus the plan and its duration.
- The identifier you type (a phone number or the shop's name) and your contact method — so we can match the payment to your ledger and reach you if something is unclear.
- Your IP address is recorded temporarily (under two hours) to stop abuse of the form.
We do not collect your geographic location, and this site uses no tracking cookies and no analytics tools.
3) Why we collect it
- To provide the service itself: reading receipts, keeping the ledger, reports, reconciliation.
- To apply plan limits and to activate a subscription when you pay.
- To answer your questions and resolve your problems.
- To protect the service from abuse and automated misuse.
- To improve reading accuracy — we review failure patterns; we do not sell or share the contents of your ledger.
4) Who your data reaches
For the service to work we rely on technical providers. This is the complete list:
- Telegram — the conversation itself and the images. Anything you send the bot passes through Telegram and is subject to their privacy policy.
- Cloudflare — hosting for the service, the database and this site, and the “you are not a robot” check on the subscription form.
- OCR.space — reading text out of receipt images (the primary path).
- Google (Gemini API) — reading difficult images and statement pages when the ordinary read does not work.
- OpenRouter — a fallback reading provider used when the first is unavailable.
The image or statement page is sent to those providers only at the moment of reading, and without your name or your number. Their servers are generally outside Sudan. We do not sell your data to anyone, do not share it with advertisers, and do not hand it to any third party other than those named above unless compelled by a binding legal order.
5) How long it is kept
- Your ledger's transactions: for as long as your account is active — these are your books, and deleting them automatically would cost you your history.
- Usage counters: deleted automatically after 90 days.
- The notification and reminder queue: deleted a week after being sent.
- The website's anti-repeat record (IP): under two hours — swept on every new submission.
- “Contact the team” messages: kept as a support record so we can go back to your issue if it recurs.
- The admin action log: which team member did what and when — this is a protection record for you, and it is kept.
- Subscription requests: kept as a financial record while the subscription runs and afterwards for accounting.
- The payment screenshot you upload on the subscription page: stored in a separate database and kept for as long as your account is active — so there is evidence of the payment if it is ever disputed, and, if you ticked the box for it, to improve how accurately we read receipts. If you did not tick it, we use the image only to review your payment. When you ask for your ledger to be erased, this image is erased with it.
- Backups: we keep copies of the database so your ledger cannot be lost; a deletion reaches them on the next backup cycle.
6) Your rights
- A copy of your data: you can export your whole ledger as CSV from the bot's settings at any time, without asking anyone.
- Correction: you can edit or delete any transaction yourself from “transaction list”.
- Deletion: ask for your ledger and your account to be erased via /support or on the DT+ number, and we erase it.
- Withdrawing your phone number: you can ask us to delete your phone number; we delete it and the service keeps working.
7) Security
All traffic is encrypted (HTTPS), and database access is limited to the DT+ team and bound to a restricted permission list inside the bot. Even so, no service on the internet can guarantee absolute security — so do not send the bot images you are not prepared to risk sharing.
8) Children
The service is aimed at adult business owners (18 and over) and is not designed for children.
9) Changes to this policy
If we change something material — such as adding a new provider your data reaches — we update this page and announce the change inside the bot. The last-updated date is always shown above.
A note about the beta
Abbas is still a beta and we develop it daily. If you find anything in the service that does not match this page, tell us immediately at /support or +249 912 816 697 — that is a bug we fix, not a detail.