What we collect through Discord OAuth and Stripe, why we collect it, and how you stay in control of it.
Here's the gist in plain English. The full legal text — with all the detail and your formal rights — is right below if you need it.
Sign in with Discord OAuth — no separate password to manage or leak.
Stripe handles billing — we never see or store your card number.
Ticket messages go to our AI provider so it can generate an answer.
We never sell your personal data. Full stop.
One login cookie. No ad trackers, no cross-site tracking pixels.
Ask anytime and we'll delete your account data.
We rely on Discord, Stripe, Groq, MongoDB & Vercel to run Suppy.
Not directed at children under 13.
Suppy ("Suppy", "we", "us", "our") provides an AI-powered support ticket bot and web dashboard for Discord communities. This Privacy Policy explains what information we collect, why we collect it, and the choices you have.
Discord account information. When you log in via Discord OAuth2, we receive your Discord user ID, username, avatar, email address (if you grant the email scope), and the list of servers you belong to along with your permissions in each.
Server & ticket data. When Suppy is added to a server, we store the server ID, name, member count, icon, and the configuration set on the dashboard (admin role, ticket panel message, AI behavior settings, knowledge base entries). When a member opens a support ticket, we store the ticket messages, AI-generated responses, and metadata (status, timestamps) needed to run the support flow.
Billing information. If you subscribe to a paid plan, payment is processed by Stripe. We never see or store your card number — only your Stripe customer/subscription IDs and plan status.
Usage & log data. Basic technical logs (timestamps, request metadata) used for debugging, reliability, and abuse prevention.
Ticket messages sent to Suppy's AI assistant are forwarded to our AI provider (currently Groq, or a self-hosted model you control on eligible plans) to generate a response. We don't use your data to train third-party foundation models beyond what your chosen AI provider's own policy allows.
We rely on the following providers to operate Suppy, each governed by their own privacy policy:
We retain account and server data for as long as your account or the bot remains active on a server, plus a reasonable period afterward for legal and accounting purposes. Ticket transcripts are kept as configured by your server's admins and are removed when a ticket channel is closed or the bot is removed. You can request deletion at any time — see "Your rights" below.
We do not sell your personal data. We share data only with the service providers listed above, as required to operate Suppy, or when required by law.
We use a single HTTP-only session cookie (suppy_token) to keep you signed in, and your browser's sessionStorage to temporarily remember an in-progress checkout after a Discord login redirect. We don't use third-party advertising trackers.
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, or to object to certain processing. To exercise any of these rights, contact us using the details below.
Suppy is not directed at children under 13 (or the minimum age required to use Discord in your country). We do not knowingly collect data from users below that age.
We use industry-standard measures — encrypted connections and signed, expiring session tokens — to protect your data. No system is ever 100% secure; please contact us right away if you believe your account has been compromised.
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page.
Questions about this policy? Email us at ytvrgames@gmail.com.