Anyone selling into a business that runs on Telegram meets the same five questions, usually in the same order, usually from the most senior person in the room. They are good questions. Most software in this category answers them with reassurance rather than with mechanics, which is why they keep getting asked.
Here they are with the mechanics.
"Do you store our conversations?"
No. There is no message content in the platform at all. No message table, no attachments, no voice notes, no searchable archive of what anyone said. What exists is the contact, when the conversation was last active, and a link into the real chat in Telegram.
That is a decision rather than an omission, and it cost features. There is no way to grep five years of chat history inside the web application, and there is no setting that turns storage on. The full reasoning is in never storing conversations.
What it buys is the answer to every question that follows. There is nothing to leak, nothing to hand over in a dispute, and nothing that changes hands if the company is ever sold.
"Then how does your assistant know what we discussed?"
It reads the conversation in Telegram at the moment it writes a reply, and does not retain it afterwards. What persists is the outcome: a stage change, a tag, a note somebody wrote, a task, or a claimed purchase.
This is the part that surprises technical buyers, because they expect context to require a memory. It does not. The chat already exists in the messenger, in the account you control, and reading it at write time is a smaller privilege than copying it into a second database and keeping it there indefinitely.
"Can my staff read my clients' chats inside the software?"
There is nothing there to read. A colleague sees the contact record according to the permissions you gave them, and they can open the real Telegram chat only if they have access to that Telegram account themselves.
The permission model is worth explaining to a client rather than summarising. Access is granted per area, with read, add, write and delete separated, so a media buyer can be given the reporting without the ability to delete contacts, and one person can confirm deposit submissions without also being able to change the rules that govern every page. The setup is in teams and permissions.
When a client asks who can see what, do not answer with a role name. Answer with the four rights and the areas they apply to, and show them the workspace. Vagueness at this point is what loses the deal.
"What happens to the keys we give you?"
Secrets are write-only after the first save. A token can be replaced and cannot be read back out of the interface, by you or by anyone you invite into the workspace. That applies to every connection, and every connection lives in one place on the Integrations page while every other screen only selects from it.
Two things never reach the platform at all. Card details stay with the processor that took the payment, and only the completed sale comes back. And conversation text, connected integration or not, which no integration can quietly reverse. The design argument for the single page is in one page where everything connects.
"What is actually on a record, then?"
Worth being able to list it without hedging: the contact's display name, username and the internal Telegram identifier that survives a username change; when the conversation was last active; the stage and tags you set; notes and tasks your team wrote; the campaign values captured at the click that brought them in; and purchases synced from a connected checkout or confirmed through a broker connection, with their amounts.
That is a marketing and sales record. It is not a communications archive, and the distinction is the entire privacy posture. A client who understands it stops asking about encryption, because encryption is a question about protecting data you hold and the more useful answer is about data you never took.
One follow-up usually arrives here: what about the bridge landing pages sitting on your own domain, and the tracking links? Those hold click context and whatever a person deliberately submitted on a form, such as an email or a deposit amount. Personal data is hashed before it goes to an advertising platform, so a match improves without the address itself leaving in readable form. That is a separate body of data from the conversation, collected with the person in front of a form rather than lifted out of a chat, and it is worth describing to a client as exactly that rather than folding it into one answer.
The questions you should raise before they do
Two things are your responsibility rather than the software's, and saying so early tends to build more confidence than waiting to be asked.
First, your own legal basis for holding contact records and for messaging people, which varies by jurisdiction and is not something a tool decides for you. The general shape of that for firms in this sector is covered in privacy obligations for trading firms.
Second, what your assistant is allowed to say. Flirting, romantic framing and promises the business cannot keep are blocked on every reply by the engine, whatever the persona says. In a trading-adjacent business that floor matters, because the reputational damage from an assistant improvising a promise about returns arrives months later with a screenshot attached. Signals, copied trades and any tooling around them are information rather than advice, no result is promised, and trading carries a high risk of loss.
SINGUARD builds software. It is not a broker, a bank or an adviser, and every firm running on this stack carries its own licensing, compliance and client obligations. Being clear about that line in the first meeting saves a difficult conversation in the fourth.
"Encryption is an answer about data you are holding. The stronger answer is that you never took the data in the first place."
— Roman Onta, Executive Director, SINGUARD
Key Takeaways
- No message content exists in the platform: only contacts, recency and a link to the real chat.
- The assistant reads a conversation at the moment it replies and retains nothing afterwards.
- Secrets are write-only after the first save and cannot be read back by anyone in the workspace.
- Per-area read, add, write and delete rights are the honest answer to who can see what.
Frequently Asked Questions
Does the AI assistant keep a copy of what it read?
No. It reads the conversation in Telegram when it is writing a reply and does not retain it. Only the outcome persists, such as a stage change, a tag, a task or a claimed purchase.
Can I export my clients' conversations from Scalegram?
No, because they were never copied there. Exporting chat history is something you do inside Telegram itself, from the account that holds the conversations.
Who at SINGUARD can see our data?
SINGUARD supplies software and does not operate your business, hold client funds or act as a broker or adviser. Access to a workspace is governed by the accounts you invite and the per-area rights you grant them, and connection secrets cannot be read back out of the interface by anyone.
About the Author
Roman Onta is an Executive Director at SINGUARD. He builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals side by side with his brother Alex Onta, and he helped on the design of eTrader, the division Alex built and leads. His ground is worldwide payment processing, AML compliance and the corporate structures brokers are built on, work the two of them carry together, shaped by executive roles in the UAE and international corporates. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.