Data & privacy
What SUPREO stores for your server, how long it keeps it, where it lives, and how to have it deleted.
This page is the practical companion to the Privacy Policy: the same facts, from the point of view of someone running a server. It is also what you need when Discord asks about your data handling.
What is stored
| Data | Why | Where |
|---|---|---|
| Server settings — panels, categories, questions, roles, messages, hours | To run the bot as you configured it | Database |
| Open tickets — channel, opener, category, subject, claimer, priority | To operate the ticket | Database |
| Transcripts of closed tickets — messages, authors, timestamps, ratings, internal notes | So staff can review a ticket after the channel is deleted | Database |
| Ticket attachments — the files sent in a ticket | So they outlive Discord's expiring links | Server disk |
| Verification records — who passed, when, by which method, flags | To enforce verification and show the statistics | Database |
| Honeypot catches — the account, the message, the action taken | So staff can review a catch | Database |
| Statistics snapshots — member and boost counts, once a day | The growth chart | Database |
| Audit log — administrative actions on the dashboard | To see who changed what | Database |
| Your dashboard account — Discord id, name, avatar, email | To sign you in | Database |
| Billing — customer and subscription id, plan, status, renewal date | To apply your plan | Database + Polar |
| Whitelabel bot token — encrypted with AES-256 | To run your own bot | Database |
The bot does not read messages outside ticket channels, its own direct messages and the honeypot channel; it does not request the Presence intent; and message content is never used to train models.
How long it is kept
| Data | Retention |
|---|---|
| Server settings | Until you change or delete them, or remove the bot |
| Transcripts and attachments | Until you delete them or remove the bot. (The free plan only shows the last 7 days; Premium shows all of it.) |
| Verification records | 90 days |
| Verification network fingerprint (web check) | 30 days, as a salted hash — never the address itself |
| Honeypot catches | 90 days |
| Statistics snapshots | 60 days |
| Audit log | 15 days |
| Reopening notifications, operational alerts | 14 and 30 days |
Where it lives
The database is MongoDB Atlas, which encrypts data at rest; attachments are on the server that runs SUPREO. Payments go through Polar — SUPREO never sees your card details. The processing aims to stay inside the EU; where a provider is outside it, the transfer is covered by standard contractual clauses. The full list of sub-processors is in the Privacy Policy.
Storing less
- Archive transcripts in the database — switch it off in Ticket setup → Logging and no message content is stored at all. You lose Ticket History, transcripts, ratings and team analytics along with it.
- Alt detection — off by default; on, it stores a salted hash of the visitor's network for 30 days, never the address (Verification → Hardening).
- Internal notes are staff-only and never shown to the member, but they are part of the archived ticket — including in the export a staff member downloads with notes.
Deleting
| You want to… | Do this |
|---|---|
| Delete one ticket's record | Ask us — there is no delete button in Ticket History yet |
| Stop all processing for a server | Remove the bot from the server. Ask us to delete what is left. |
| Delete a member's data | Email contact@supreo.xyz with the Discord user id, or open a ticket in the support server |
| Delete your dashboard account | Email us — sessions and account data go with it |
| Delete a Whitelabel bot token | Bot Settings → Danger zone → Delete Whitelabel Bot |
Requests are honoured within 30 days. Members of your server can write to us directly; we will ask you to confirm the request concerns your server before acting on anything that is yours to decide.
Telling your members
If your server is in the EU, you are the controller of what happens on it and SUPREO is your processor. Two things are worth doing:
- Say in your rules, or in the panel text, that opening a ticket records the conversation and that staff can read it afterwards.
- Point members at the Privacy Policy — the panel description is a good place for the link.
