Security Policy

This is a translation provided for convenience. In case of discrepancies, the Russian version prevails.

This Security Policy (hereinafter referred to as the "Policy") defines the approach of IP Abramov Georgy Evgenievich (hereinafter referred to as the "Copyright Holder") to ensuring the protection of users' data and security when using the "True Mafia" Service (hereinafter referred to as the "Service").

Effective date: April 16, 2026


1. General provisions

1.1. The Copyright Holder attaches paramount importance to the protection of users' data and to ensuring security when using the Service.

1.2. This Policy applies to all functionality of the Service, including the processes related to payment for the Premium versions of the Service.

1.3. The terms and definitions used in this Policy have the same meaning as in the License Agreement (EULA), available at: https://truemafia.ru/en/docs/


2. Payment security

2.1. Payment processing model

2.1.1. The Service does not collect, process or store users' bank card data, account details or other payment information.

2.1.2. When a payment is initiated, the Service generates a payment link and redirects the user to the secure page of one of the acquiring partners:

  • YooKassa — an online payment service of YooMoney LLC, holding a Bank of Russia license to carry out banking operations. Website: yookassa.ru
  • T-Bank — TBank JSC, Bank of Russia license No. 2673. Website: tbank.ru
  • OZON Bank — OZON Bank JSC, Bank of Russia license No. 2556. Website: ozon.ru

2.1.3. Payment data (card number, CVV/CVC, expiration date, 3-D Secure data) is entered exclusively on the acquiring partner's side, on its secure pages. The Copyright Holder has no technical ability to access this data.

2.1.4. After the transaction is completed, the acquiring partner passes to the Service only the payment status (success / error) and the transaction identifier, without disclosing the user's payment details.

2.2. Responsibility of the parties for payment

2.2.1. The security of the payment page and of the transmission and storage of payment data is ensured exclusively by the acquiring partner in accordance with the requirements of the PCI DSS standard and the legislation of the Russian Federation.

2.2.2. The Copyright Holder is not liable for the actions, errors or failures on the side of the acquiring partners.

2.2.3. The user shall independently review the security and privacy policies of the chosen acquiring partner before entering their payment data.


3. Protection of user data

3.1. In the payment process, the Copyright Holder receives and stores only:

  • the user's identifier in the Messenger (for example, Telegram ID, MAX ID) — to credit the paid plan to the correct account or group chat;
  • the transaction identifier and its status — to confirm the fact of payment.

3.2. The specified data is used solely to perform obligations under the License Agreement and is not transferred to third parties, except in cases provided for by the legislation of the Russian Federation.

3.3. Personal data is processed in accordance with the Privacy Policy, available at: https://truemafia.ru/en/docs/


4. Technical protection measures

4.1. Interaction between the Service and the acquiring partners is carried out over the HTTPS protocol using up-to-date encryption standards (TLS 1.2 and higher).

4.2. The payment links generated by the Service are single-use or have a limited validity period to prevent their unauthorized reuse.

4.3. The Copyright Holder uses software and infrastructure measures to protect the Service's server infrastructure from unauthorized access, including network filtering, anomaly monitoring and regular updating of components.


5. Recommendations to users

To ensure their own security when making payments, the user is recommended to:

  • Check the address of the payment page — it must belong to the official domain of the acquiring partner (for example, yookassa.ru, tbank.ru, ozon.ru), and the browser must display the secure connection icon (🔒).
  • Not follow payment links from unknown sources or messages from strangers, even if they look like links for payment in the Service.
  • Not disclose to anyone their bank card details, CVV/CVC codes, or one-time passwords from SMS.
  • Use a separate card or a limited-access account for online payments.
  • Promptly notify their bank of any suspicious transactions.

6. Incident notification

6.1. If you have discovered a vulnerability in the Service, suspicious activity or any other security incident, immediately report it to the Copyright Holder at: [email protected]

6.2. In your report, specify:

  • a detailed description of the problem found;
  • steps to reproduce it (if applicable);
  • the date and time of discovery.

6.3. The Copyright Holder undertakes to consider reports on security issues as a matter of priority and, if necessary, to take immediate measures to eliminate the threat.


7. Changes to the Policy

7.1. The Copyright Holder has the right to make changes to this Policy unilaterally. The current version of the Policy is always available at: https://truemafia.ru/en/docs/

7.2. Continued use of the Service after the changes are published means the user's consent to the updated version of the Policy.


8. Copyright Holder's details

Individual Entrepreneur ABRAMOV GEORGY EVGENIEVICH
INN (Taxpayer ID): 772352138223
OGRNIP (Primary State Registration Number): 320774600179302
Email: [email protected]

Version dated April 16, 2026