Privacy Policy

Gde Grinch · GG RPG (gdegrinch.com, Telegram bot @GG_RPG_BOT and its Mini App). Last updated: 29 September 2026.

GG RPG is a personal real-life game project run by the person who plays the character GRINCH ("we", "the owner"). This policy describes what the project actually collects and how it is used. Contact: grinch32ru@gmail.com (also Telegram @dmt_grinch).

1. Google Health data (the owner's own wristband)

Only the owner connects a Google account, and only his own. Viewers never connect Google accounts, and we never access any viewer's Google data.

The owner authorizes read-only access through Google OAuth to the Google Health API with these scopes: activity and fitness, health metrics and measurements, and sleep. From them the project reads only:

Why: these values are the character's live game stats in the app (steps, pulse, energy, sleep today, "sleeping now"), and step totals count toward the progress of step-based quests.

What is public: viewers see only the current numbers: steps and calories for today, a heart rate no older than two hours, sleep minutes for today and whether GRINCH is sleeping right now. Sample times, device details and technical diagnostics are never shown to viewers.

Storage: the OAuth refresh token is kept only on the project server, in a file readable by the server alone. It is not in the database, not in the app sent to users and not in logs. Access tokens exist only in server memory. Health readings are kept as a small current snapshot on the server (today's values, sleep sessions of the last 48 hours and short technical diagnostics) that is overwritten as new data arrives. They are not kept as a long-term health history. Step totals can be saved as the progress of a step quest.

No other use: Google Health data is not sold, not shared with third parties, not used for advertising, not sent to AI models and not used to train them. It is used only to show the game stats described above. Our use of data received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.

Revoking: the owner can revoke access at any time in the Google Account (myaccount.google.com/permissions). The server then stops receiving data, and the health tiles show that data is unavailable.

2. Telegram sign-in (viewers)

When you open the Mini App, Telegram passes us your Telegram user ID, username, display name and interface language. We use them to sign you in, to show your display name next to things you post, to apply limits and moderation, and to pick the interface language. Your Telegram user ID is never shown to other viewers. We also keep when you were last seen and simple counters of app openings, used for the "watching now" audience counter.

3. What you post

Quest proposals, comments, votes, likes and map markers are public inside the app and shown with your display name. A map marker is a point that you choose yourself, so do not post private addresses. The owner can hide or archive content. Hidden content is removed from public view but may remain in the database and in server backups.

4. The owner's location

GRINCH's exact location is private by default. It becomes visible only when the owner deliberately publishes an approximate area or a time-limited point. The project is built so that a private or live location does not become public by accident. Places attached to public events (for example, a hotel) are points the owner chose to publish.

5. Support and payments

Telegram Stars payments are processed by Telegram. We keep the payment record (amount, Telegram payment ID and your account in the app) to credit your support. Bank and crypto details are shown only to signed-in users. Manual transfers are recorded by the owner.

6. AI processing

The owner's own food photos and descriptions may be sent to Google Gemini to estimate calories. When translation features are enabled and used, text (for example, a quest title or a comment) may be sent to Google Gemini for translation, and the translation may be stored so the same text is not sent again. Health and activity data are not sent to Gemini for translation or for any other purpose.

7. Retention and your requests

Your account record and your posts stay while the project runs. To have your posts hidden or your account data removed, contact grinch32ru@gmail.com or Telegram @dmt_grinch. Copies may remain in server backups until they expire. This website itself sets no cookies and uses no analytics or trackers.

8. Security

All traffic uses HTTPS. Secrets and tokens stay on the server, and permissions are checked on the server for every request.

9. Changes

If this policy changes, the updated version will be published on this page with a new date.


Политика конфиденциальности (кратко по-русски)

GG RPG — личный проект человека, играющего персонажа ГРИНЧ. Связь: grinch32ru@gmail.com, также Telegram @dmt_grinch.