Compliance
Oqim is for organizations messaging people who expect to hear from them. This page sets out what Telegram requires, what Oqim enforces for you, and what stays your responsibility.
Telegram API Terms of Service#
Oqim connects to Telegram as a third-party client over the MTProto API, so every deployment is bound by the Telegram API Terms of Service. In practice:
- The platform operator owns the api_id.
TELEGRAM_APP_IDandTELEGRAM_APP_HASHbelong to whoever runs the deployment, registered at my.telegram.org, and the operator answers for how they're used. Organizations on the deployment don't bring their own. - No spam or unsolicited messaging. Telegram prohibits using its API to send bulk unsolicited messages. Oqim sends only to recipients with a recorded basis for contact, and never to people who opted out.
- Flood limits are honored. A
FLOOD_WAITis obeyed exactly. Nothing is retried early or moved to another account to get around it. - Restricted accounts stay stopped. When Telegram restricts an account, Oqim stops it and pauses its campaigns. It resumes only after a person confirms the restriction was resolved in Telegram.
- Account owners stay in control. A session can always be ended from Telegram under Settings → Devices; Oqim then marks the account as needing sign-in and stops using it.
Consent and the basis for contact#
Every recipient needs a documented reason you may message them: they opted in, authorized contact, or have an existing relationship with you. Record which one in consent_status, where it came from in consent_note, and when in consent_timestamp.
- Recipients with unknown consent are skipped. Platform administrators can allow them deployment-wide; that setting is off by default.
- The pre-launch checks show how many recipients in an audience are skipped for consent, opt-out or suppression before anything is sent.
- A campaign whose failures and unreachable recipients climb past the platform's threshold is paused and reviewed, because that pattern usually means the audience didn't expect the message.
- A running campaign is also paused and reviewed when people opt out right after receiving it: by default once at least 5 of them have, and they make up 5% or more of its deliveries. An opt-out counts against a campaign when its message reached the person first, whether they used the opt-out link or you recorded their request.
Opt-out#
{{opt_out_url}}gives every recipient a personal link to stop your messages. It's recommended for every campaign, and platform administrators can require it.- The opt-out page speaks Uzbek, Russian and English, and takes one tap to confirm.
- Opt-outs take effect immediately, apply to every campaign of the organization, and are permanent. The person joins the suppression list, which survives deleting the recipient and blocks re-imports.
- Requests made outside Oqim (a reply, an email, a call) are yours to record: opt the recipient out, or add them to the suppression list. See Opt-out.
Data minimization#
- Phone numbers of connected accounts are stored only as a keyed hash, used to recognise a number connected again, and a masked form for display such as
+998 •• ••• 45 17. - Oqim stores each campaign's message template, not the personalized text sent to each person.
- Recipients hold only what you import. Attributes exist to fill in messages; import only the ones your messages use, and leave out sensitive categories of data.
- Deleting a recipient removes their record. If they opted out, only their suppression entry remains, so they're never contacted again.
- Telegram sessions, proxy credentials and webhook secrets are encrypted at rest. See Security.
Acceptable-use policy#
An Owner or Admin must accept the current acceptable-use policy before the organization can connect accounts or send. When the policy changes, its version changes (the current default is 2026-09) and every organization accepts it again before sending. Acceptance is recorded with the version, the time and the person who accepted.
Permitted use
You may use Oqim to send messages, through Telegram accounts you own or are authorized to operate, to people who have agreed to hear from you or who have an existing relationship with you, and who haven't asked you to stop.
Prohibited uses
You must not use Oqim for:
- Unsolicited bulk messaging: messaging people who haven't agreed to hear from you, including purchased, scraped or harvested contact lists.
- Harassment: threats, intimidation, abuse, or repeated contact with someone who doesn't want it.
- Phishing: any attempt to trick people into revealing passwords, codes, payment details or other information.
- Impersonation: pretending to be another person, company, organization or official body.
- Fraud: scams, deceptive offers, fake prizes and other dishonest schemes.
- Malware distribution: sending malicious files, or links to them.
- Credential theft: collecting other people's login details, one-time codes or session data.
- Account theft: taking over, or helping take over, Telegram accounts that aren't yours.
- Evading Telegram enforcement: working around flood limits or restrictions, for example by rotating accounts, phone numbers or proxies.
- Using compromised accounts: sending from purchased, rented, stolen or otherwise unauthorized Telegram accounts.
- Bypassing platform security: probing, disabling or working around Oqim's limits, checks or access controls.
- Targeting opted-out recipients: contacting people who opted out, through Oqim or by re-importing them under another identifier.
Enforcement
Oqim opens abuse reports for platform administrators when it pauses a campaign for a high failure rate or an opt-out spike, and when an organization has three or more restricted accounts; administrators add reports that reach them from recipients or Telegram. A breach can lead to suspension: running campaigns pause, messaging stops, the organization becomes read-only, and its members see the reason.
Your responsibilities#
- Having a lawful basis for contact under the laws that apply to you and your recipients.
- Keeping consent records accurate, and being able to show where each one came from.
- Honoring requests to stop that reach you outside Oqim.
- The content of your messages, and whatever they link to.
- Operating only Telegram accounts your organization owns or is authorized to use.