Privacy Policy

Effective: 23.06.23

Last updated: 30.08.2026


1. Introduction

At SupportMail, I take the protection of your privacy seriously. I do not collect any personalized data. Any information you provide while using my services may be used to improve the products and services I offer. However, this is not done automatically, and your personal data will not be shared with third parties.

SupportMail does not use message content, ticket conversation content, or attachment content for ML/AI training or other automated model-training purposes. I do not store message text in my database for analytics, model development, or off-platform processing.


2. What data do I collect?

Overall, the following information is stored in my database:

  • User IDs
  • Role IDs
  • Guild IDs
  • Message IDs
  • Channel ID
  • Guild icon hashes
  • Guild names
  • Timestamps
  • Access tokens (encrypted)
  • Every other data that you provide when interacting with the bot, including when you execute commands, send direct messages, or send messages in ticket posts

2.1. Use of the access token

The access token is used to determine the mutual guilds between the user and the bot as this is also the most efficient way to check users’ permissions on a specific server.

2.2. Use of collected data

I use all collected data to provide my services and improve them.

I use the information to personalize and improve your user experience.

I use the data to manage tickets and reports.

I also access the stored data and Discord’s data in order to provide support as described in the next section.

2.3. Temporary Data Retrieval

I, as the owner of the App, along with the manager and moderators of the support server, may retrieve certain information about you and your interactions with the App, including but not limited to:

  • User data (e.g., username, user ID, and avatar)
    Please note that I store your access token securely, generated when you log in with Discord, in an encrypted format. When I retrieve your data, I only see whether or not you have an access token set.
  • Guild data and configuration (e.g., guild name, guild ID, and also any configurations like the ticket forum and the tickets)

This information is only accessible to me and, in limited cases, to moderators of my support server.

If you want to know more about this and see an example, kindly ask in the support server.

2.4. Appeal System Data

When you submit an appeal through my appeal system, I collect and store the following information:

  • Appeal form responses, including explanations, context, and any statements you provide
  • Contact information (email address, Discord username and ID)
  • Supporting evidence you voluntarily upload (screenshots, logs, or other files)
  • Appeal timestamps and submission metadata
  • Confirmations provided during the appeal process

This data is used solely for:

  • Processing and reviewing your appeal
  • Investigating the circumstances of your restriction or ban
  • Maintaining records for security and abuse prevention
  • Improving my moderation and appeal processes

Appeal data is accessible only to authorized SupportMail staff and relevant moderators involved in the review process. I retain appeal data for a minimum of 90 days after resolution to maintain proper records, and may retain it longer for cases involving serious violations or security concerns.

If your appeal is successful, appeal data may be retained to monitor compliance with any conditions of reinstatement. If you withdraw your appeal or it is denied, the appeal data will be retained according to my policy.

You may request deletion of your appeal data by contacting me directly (through a ticket on the support server or via email), though I reserve the right to retain certain information for security and legal compliance purposes.

2.5. Error Monitoring and Performance Tracking

I use Sentry (Functional Software, Inc.) for error monitoring and performance tracking. When you interact with the bot — for example by executing a command — certain technical data may be transmitted to Sentry in order to detect errors, diagnose issues, and monitor the reliability of my services. This data may include your Discord user ID, guild ID, channel ID, and command-related metadata (such as the command name). I do not send raw message text, attachment content, ticket conversation content, or other message-body data to Sentry; only non-content identifiers and diagnostic metadata are transmitted.

Sentry acts as a data processor on my behalf and processes this data solely for the purposes described above. I have entered into a Data Processing Addendum (DPA) with Sentry in accordance with Art. 28 GDPR. The legal basis for this processing is my legitimate interest in maintaining a stable and secure service (Art. 6(1)(f) GDPR).
Data transmitted to Sentry may be stored on servers located outside the European Economic Area. Appropriate safeguards are in place for such transfers in accordance with applicable data protection law. For more information on how Sentry handles your data, please refer to Sentry’s Privacy Policy.

2.6. Blog Accounts and Comments

My website includes a blog. You can read blog posts without an account. If you want to post a comment, you must register a separate account for the blog. This account is independent of your Discord account and of the access token described in Section 2.1 — the two are never linked.

When you register and use a blog account, I collect and store:

  • Your email address (used only for account verification, login, transactional emails, and, if needed, contacting you about your account or your comments)
  • A display name, which is shown publicly alongside your comments
  • Your password, which I never store in plain text — only a salted cryptographic hash (PBKDF2-SHA256) is kept
  • A short-lived email verification code, stored as a hash, to confirm you control the email address you registered with
  • A session identifier stored in a cookie (sm_comment_session) for up to 30 days, used to keep you signed in; the token itself is hashed before storage
  • The content of comments you post, including replies to other comments

I use this data solely to operate the comment system: to let you register, verify your email, sign in, post and manage comments, and to prevent abuse (e.g. spam or ban evasion) of the comment system.

If you delete your own comment, its visible text and author attribution are removed, but the underlying record may be kept to preserve the structure of the discussion thread it was part of (for example, so replies to it remain readable). If you want your account and associated data fully removed, see Section 6.2a.

To tell people from automated scripts during registration and login, I use Cloudflare Turnstile, a CAPTCHA-style challenge provided by Cloudflare, Inc. Turnstile may process technical signals about your browser and device to determine whether you are human, in accordance with Cloudflare’s Privacy Policy. I do not receive or store the underlying signals Turnstile evaluates — only its pass/fail result.

Verification and account-related emails are sent using Cloudflare’s transactional email sending service, under the same infrastructure agreement covering the rest of my Cloudflare Workers usage.

The legal basis for processing this data is the performance of a contract with you (providing the comment feature you signed up for, Art. 6(1)(b) GDPR) and, for abuse prevention (e.g. Turnstile), my legitimate interest in keeping the comment system secure and free of spam (Art. 6(1)(f) GDPR).


3. Security

All servers and databases used to provide my services are not available to the public. Some information may be available through designated endpoints but only with proper authorization.

It should be noted that I am doing my best to protect your information, but no method of electronic transmission or storage is 100% secure and no one can guarantee absolute data security. I am not liable for any data loss or data breach.

For transparency, when a configuration is reset - if it was not initiated by the server owner - the bot sends the details to the owner. This includes the username, user ID, and avatar of the user who performed the reset, along with detailed information about what was reset.

3.1. Cloudflare Managed Challenge (Dashboard)

The dashboard is protected by Cloudflare’s Bot Management (“Managed Challenge”) to detect and block bots and other automated or abusive traffic before it reaches my infrastructure.

This processing is carried out by Cloudflare in accordance with its own Privacy Policy. I only receive aggregated data from Cloudflare about how many requests were allowed or blocked — I do not receive any personal data collected by Cloudflare as part of this service.


4. Data sharing

I do not sell or share any information with third parties for commercial purposes. However, I use select third-party service providers who act as data processors on my behalf (see Section 2.5 and Section 2.6, which covers Cloudflare Turnstile and Cloudflare’s email sending service). All such providers are bound by appropriate data processing agreements and may only process your data as instructed by me.


5. Use of Message Content Intent

The bot utilizes this intent to read messages within the ticket forum. This is achieved by using the /setup tickets command. Please note that the bot will not view any other message content within a guild. This is because the function will be cancelled if the channel ID does not match a ticket post ID in the database.

The bot does not retain any message content retrieved by this intent. Only message and post identifiers are stored while a ticket is open; the actual message text and attachment content themselves are never written to my database. The bot edits its own messages (in both DMs and ticket posts) based on the new message content and attachments. In the event that a message is edited and the channel ID matches a post ID from the database, and the ticket is still open, the bot will attempt to edit its message in the user’s DM to align with the new content and new attachments in the ticket post.

The bot does not use message content or attachment content for ML/AI training, analytics, automated profiling, or any off-platform model-training purpose.


6. Duration

6.1. Guild data

Guild data is stored for the duration of the bot’s presence within the guild. Once the bot is removed from the guild, the data will be stored for an additional seven days for reasons related to user experience.

Should a user wish to have the data of their guild deleted immediately, they are required to create a ticket in the support server (ID: 1064594649668395128), including their guild ID, and proof of ownership of the guild. Please note that this process may take up to 24 hours, depending on the time the ticket is submitted. While I will try to process your request within 24 hours, I cannot guarantee a reply within that same timeframe.

6.2. User data

The access token will expire after seven days, but it may be stored for a longer period. Please be advised that if no updates are made to your data for a period of one year, it will be deleted.

Should you wish to request the immediate deletion of your user data, please send a direct message to LukeZ (ID: 506893652266844162) on Discord.

Please be advised that any direct messages you send to the bot will result in the collection of new data.

Blog account data

Blog account data (email, display name, password hash, and session data) is stored for as long as your account remains active. Unverified accounts, and their pending email verification codes, are deleted automatically after the verification code expires (15 minutes) if never used, or after a reasonable grace period if left unverified.

Should you wish to request deletion of your blog account and associated personal data, please contact me via a ticket on the support server or by email. Comment content you posted may be retained in de-identified form (author information removed) after account deletion where necessary to preserve the readability of discussion threads, consistent with Section 2.6.

6.3. Subscription data

Please note that subscription data will not be deleted automatically and cannot be manually deleted. This is done for security and legal compliance reasons.

6.4. Log data and backups

Note that data deletion may not apply to log data and backups.


7. Cookies and other tracking technologies

Google’s cookies and other tracking technologies are used by the website to collect and store your information, but I do not have access to that. The policies of Google provide specific information about how they use such technologies and how you can refuse certain cookies.

When you access my website, Cloudflare may collect and store certain user data. This includes information such as the country from which you are accessing the website. Cloudflare uses this data for the purpose of providing security services, optimizing website performance, and ensuring a reliable and secure browsing experience. Please note that Cloudflare’s data collection and storage practices are governed by their own privacy policy, which you can review for more information on how they handle user data.

If you register or sign in to comment on my blog, I also set a first-party session cookie (sm_comment_session) to keep you signed in, and Cloudflare Turnstile may set its own cookies as part of its human-verification check, as described in Section 2.6.


8. Changes to the Privacy Policy

I reserve the right to update this Privacy Policy as needed. Please note that most changes will be announced when they take effect.

Updates will be announced in the support server (ID: 1064594649668395128).

By continuing to use SupportMail, you agree to this privacy policy. If you do not agree to this policy, please uninstall SupportMail from your server and discontinue use.


9. Contact

If you have any questions or comments about this privacy policy, you can email me at contact.lukez@proton.me or reach out in my support server.

Versions