Ask most software companies what they store and you get a paragraph about security posture. The answer that helps you is a field list. Here is what a Telegram operation running on Scalegram holds, where each item came from, where it can go, and which parts of it your team can touch.
The contact record
A contact carries who the person is as Telegram exposes them: their numeric identifier and username, and whatever name they show. On top of that sit the things you and your systems added. The stage they occupy in your pipeline. The tags your team applied. Your own notes, which are yours and are free text, so treat them the way you would treat anything you might one day have to show the person. Custom fields. Tasks with due dates. Purchases and deposits that arrived from a checkout or an integration rather than from a guess. And the campaign that produced them.
Then two timestamps that do more work than everything else combined: when they last spoke to you, and when you last spoke to them. Nearly every question a Telegram business asks is a recency question. Who went quiet after saying they were interested. Who has not been touched in ten days. Who paid this morning and should be left alone tonight. None of those need the words of the conversation. They need a timestamp and a stage.
What is deliberately absent
No message content. None. Not the text, not the attachments, not the voice notes, not the photos a client sent. The assistant reads the conversation inside Telegram at the moment it writes a reply and retains nothing afterwards. Every contact row instead carries a link that opens the real chat in your real Telegram app, so the conversation is read where it always lived, under Telegram's own encryption and retention.
The full reasoning, including what this costs in features, is in why there is no message table. The consequence for control is worth naming: the largest and most sensitive category of data in a DM business is not held by the vendor at all, which means it is not yours to lose through the vendor either.
Absence is not privacy on its own. Your teammates can still see a contact's name, stage, notes and purchase history, a client can still screenshot you, and Telegram still holds the chat. What changes is the size of the thing a breach would expose: a contact list, not a conversation archive.
What leaves the system
Data flowing outward is where control is actually exercised, and it happens in three places. Conversion events go to the advertising pixels you connected: a click, a join, a registration and a purchase with its value, with the UTM parameters carried through so the ad platform can attribute them. What fires and when is set out in conversion events. A Meta Ads sync pulls campaign structure and results inward rather than pushing client records outward. And the integrations you connect, a checkout, a broker, a subscription platform, write confirmed facts onto the contact.
Every one of those connections is made in one place. Connecting a bot, a Telegram account, a pixel or a domain happens on the Integrations page and nowhere else. Every other screen in the product only selects from what is already connected there, which is described in the Integrations page. That is a control decision as much as a design one: there is a single screen where you can see, and revoke, everything that talks to an outside service.
Who on your team can read it
Team members get permissions per area, split four ways into read, add, write and delete. A setter can be given the ability to read the client list and add contacts without the ability to edit purchases or delete anything. An analyst can read without touching. The mechanics are in teams and permissions.
The right way to use this is uncomfortable and worth doing anyway: assume every account you create is one leaked password away from being someone else's account, and grant accordingly. Delete rights and export rights belong to the smallest possible number of people. Most operations discover this after the fact.
Data held on your own domain
One part of the funnel sits outside the CRM entirely. Bridge pages are landing pages hosted for you on your own domain, so the visitor never sees a vendor URL and the traffic belongs to your brand. The page collects the click, carries the campaign parameters and hands the visitor to Telegram. Because it runs on your domain, the analytics and pixel context are yours in the way any other page on your site is.
What the bots will not do with it
Control over data includes control over what is said with it. Bots are hard blocked from flirting, from romantic framing, and from promising anything the business cannot deliver, and they answer in the language the client wrote in. Those are enforced rules rather than tone suggestions in a prompt, which matters because the failure mode of a persuasive assistant with a client's full purchase history in front of it is a promise you then have to honour. The detail is in no flirting and no fake promises.
The test to run before you commit
Ask any vendor, us included, for three things. A field list of what a contact record holds. The list of outbound destinations client data can reach. And a demonstration of a full deletion, showing what remains afterwards. If a vendor answers the first with adjectives and the third with a support process, you have learned what you needed to know. Scalegram is at scalegram.io, and SINGUARD sells the software only: the operation on top of it, and the obligations that come with it, are yours.
"If a vendor cannot hand you a field list, they are not describing their storage, they are describing their marketing."
— Roman Onta, Executive Director, SINGUARD
Key Takeaways
- A contact record holds identity, stage, tags, notes, custom fields, tasks, confirmed purchases, the campaign that produced them, and two recency timestamps.
- No message content is written anywhere, so the conversation stays in Telegram and each contact row deep links to it instead of mirroring it.
- Outbound data is limited to conversion events with their UTM parameters and the integrations you connected, all of which are managed on one Integrations page.
- Per area permissions with separate read, add, write and delete rights keep export and deletion in the hands of the fewest possible people.
Frequently Asked Questions
Can I export my client data?
Yes, the contact records are yours. The point worth remembering is that every export becomes a copy you are then responsible for, which is why export and delete rights are worth restricting to a small number of team members.
What client data reaches Meta or the other ad platforms?
Conversion events for a click, a join, a registration and a purchase with its value, with the campaign parameters carried through so the platform can attribute them. Nothing from your conversations goes anywhere, because none of it is stored.
If I stop using Scalegram, what happens to the data?
You take your contact records with you and the account is closed. There is no conversation archive to hand back or to leave behind, because the product never wrote one.
About the Author
Roman Onta is an Executive Director at SINGUARD. He builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals side by side with his brother Alex Onta, and he helped on the design of eTrader, the division Alex built and leads. His ground is worldwide payment processing, AML compliance and the corporate structures brokers are built on, work the two of them carry together, shaped by executive roles in the UAE and international corporates. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.