4builders · Website, Telegram bot & Mini App
Privacy Policy
Updated 7 October 2026
How 4builders handles information when you create a profile, join a circle, connect your accounts or use our Telegram bot.
1. Who is responsible
4builders is operated by Gabriel Naulleau, who is responsible for the service and its handling of personal data.
- Legal operator
- Gabriel Naulleau, operating 4builders
- Business address and country
- 48 rue du Montparnasse
75014 Paris
France - Contact
- gabriel.naulleau@gmail.com
2. Information we handle
- Your account: Telegram user ID, username, display name and authentication information; profile, avatar, languages, timezone, skills, availability and project details you supply.
- Community activity: circle membership and previous matches, achievements, votes, roasts, replies, reactions, reports, departure answers and moderation reasons.
- Connected accounts: provider identifiers, encrypted access credentials, selected properties or repositories, sync status and the metrics needed for the features you connect.
- Payments: Stripe customer and payment references, price reservations, authorization records, payment status, tester-code redemptions and refunds. Stripe collects payment-card details through its checkout; our application does not store your full card number or security code.
- Service operation: session information, request and security logs, delivery records and errors used to run and protect the service.
3. Why we use it
We use account and project information to provide profiles, match builders, run circles, show progress and deliver the features you request. Where applicable, this processing is necessary to perform our service agreement or take steps you request before joining.
We use payment records to manage your authorization, collect the joining fee and handle refunds; some records must also be kept to meet legal obligations. We use limited security, delivery, moderation and previous-match records for our legitimate interests in preventing abuse, keeping the service reliable, resolving disputes and avoiding repeat matches.
Optional integrations begin when you choose to connect an account. Where consent is the applicable legal basis, you may withdraw it without affecting earlier lawful processing. An OAuth permission screen grants technical access; it does not by itself determine the legal basis for every use.
4. Telegram and group activity
The bot receives Telegram updates that are made available to it, including commands, messages, sender and chat identifiers, and service events. In circles where message access is enabled, it processes ordinary messages to count activity for achievements. The activity counter stores identifiers, timestamps and counts, not the ordinary message text, captions or media files.
Information you intentionally submit for other features is different: for example, proposed names, votes, expulsion reasons and departure answers may be stored and reviewed by administrators. Reasons for an expulsion are communicated to the affected member. Do not include unnecessary sensitive information in a report.
The bot sends operational messages about onboarding, matching, payments, group changes, achievements and roast activity. Telegram must allow the bot to contact you; blocking it stops those messages but does not delete your 4builders account.
Telegram separately handles messages and account data under its Privacy Policy. Other group members can copy or forward material shared with them.
5. Connections and domain metrics
- Google Search Console: connecting Google is optional. With your authorization, 4builders requests only the read-only
webmasters.readonlypermission. We read the list of Search Console properties your account can access and their access levels, then import performance data for the property you select: clicks, impressions, click-through rate, average position, reporting dates and daily history. We do not request Gmail, Drive, contacts or permission to change your Search Console properties. - GitHub: account and repository information and commit activity support project progress, achievements and commit rankings, according to the permissions you grant and visibility settings you choose.
- Stripe / RevenueCat project connections: project revenue metrics support revenue progress, achievements and sharing. These connections are separate from paying your own 4builders joining fee. RevenueCat sign-in requests read-only access to your project list and overview revenue metrics. You select the project to connect; the backend stores encrypted access and refresh tokens to refresh its metrics. API-key connections remain supported. Disconnecting RevenueCat or archiving its 4builders project deletes stored credentials and pending authorization.
- Ahrefs: when you add a public project website, we send its domain to Ahrefs to check Domain Rating each week. We do not send the URL path, query parameters, your account identity or private credentials. Your project displays the score; rating changes appear in your circle’s pinned message only while that project is shared with the circle. Removing the website stops checks for that project.
- X: account identity and follower counts support audience statistics and growth history. Connected follower stats are shared with your circle, including its pinned Telegram message, by default. Disconnect X to stop future synchronization and sharing.
Google data powers your project dashboard and growth charts, progress comparisons, achievements and the sharing features you enable. Your Search Console connection can be set to Private or shared with your circle. Sharing can display metrics in the circle dashboard and pinned Telegram message; member leaderboards follow the relevant visibility settings. Cloudflare processes API requests and Neon stores the connection and metrics to provide these features. We do not share Google access credentials with other members or include them in Telegram messages.
We store the selected property, imported metrics, reporting history, synchronization status and an encrypted OAuth refresh token. Credentials are encrypted using AES-GCM before storage, access is limited to the backend, and project ownership is checked before data is returned or a connection is changed. HTTPS protects data in transit.
You can stop synchronization by disconnecting Search Console in the project. Disconnecting, or archiving that project, deletes its stored Google connection credentials, pending authorization and current search metrics. Disconnecting also deletes its stored daily Search Console history. You can separately revoke 4builders’ Google access at Google Account connections. Disconnecting one project does not revoke a Google grant used by another connected project. Completed achievements and copies previously shared in Telegram may remain; request deletion using the contact in section 1.
You can disconnect other supported integrations in the app and revoke access through the provider. This stops future access; it does not recall copies already shared in Telegram.
4builders’ use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google data is used for the connected user-facing features, not sold, used for advertising or used to train generalized AI models. Human access is limited to the circumstances permitted by that policy.
7. Retention and deletion
Profile, project and membership information is needed while your account and its community features remain active. Retention after closure must be limited to an identified purpose, such as handling a dispute, preventing abuse or complying with record-keeping law.
X follower history is pruned during synchronization using a 400-day cutoff; disconnecting X removes its connection and follower history. Other integrations, activity records, moderation records, backups and logs have different storage needs. Disconnecting an integration does not necessarily remove previously earned achievements or content shared with other members.
Search Console credentials and imported metrics are retained while the project remains connected so we can refresh and display its performance. You can delete that connection and its daily history using Disconnect, as explained above. For other account or community information, contact us to request deletion. We assess what must be removed and what must be retained for a specific legal, payment, dispute or abuse-prevention purpose. Information retained for such an exception is limited to that purpose. Backup copies may remain until the provider’s backup retention period expires.
To request deletion, contact gabriel.naulleau@gmail.com. Requests may require identity verification. Records that must legally be retained should be restricted to that purpose; Telegram and recipients may retain independent copies under their own obligations.
8. Security and international processing
We use access controls, signed authentication checks and encrypted integration credentials to protect information. No online service can promise perfect security. Keep your Telegram account secure and never send card details, passwords or API secrets in a group chat.
Cloudflare, Neon, Google, Telegram and our other service providers may process information in countries outside France and the European Economic Area. International processing is subject to applicable data-protection requirements, including transfer safeguards where required. Contact us for information about the processors and transfers relating to your data.
10. Your choices and rights
Depending on the law that applies to you, you may request access, correction, erasure, restriction or portability of your information, object to certain processing, and withdraw consent. You may also complain to your local data-protection authority. For France, this is the CNIL.
Contact the operator at gabriel.naulleau@gmail.com. Where the GDPR applies, requests are normally answered within one month; lawful extensions and exceptions may apply. Necessary account information is required to provide the account; optional integrations are not required to create a profile.
Matching uses profile criteria and administrator review. Group votes can trigger automated moderation actions. You may request administrator review of a match or moderation outcome.
11. Changes and contact
We will identify updates with a revision date and give additional notice of material changes where required. New uses requiring consent will not be authorized merely by changing this page. For privacy requests, use the contact in section 1.