Privacy Policy
Last updated: June 2026
1. What we collect
When you use ServerPulse, we collect only what is necessary to provide the service:
- Account data: email address, Discord user ID, Discord username, avatar URL
- Server data: Discord server IDs, server names, server icons, member counts (one snapshot per day)
- Discord tokens: OAuth access and refresh tokens (encrypted, server-side only) used to fetch your server list
- Alert history: leave spike events, timestamps, and acknowledgement status
- Security incidents (Guard): audit log events that triggered detections — who acted, on whom, when
- Billing data: Stripe customer ID (your payment details are held by Stripe, not us)
2. What we do not collect
We are explicit about what we never touch:
- Message content from any channel
- Direct messages sent between users on your server
- Voice channel activity or audio
- Individual user data from your server members (we only track aggregate member counts)
- Any data from servers you have not explicitly connected to ServerPulse
3. How we use your data
All data collected is used solely to operate ServerPulse: to display your analytics dashboard, detect leave spikes, monitor audit logs for Guard subscribers, send Discord DM alerts, and process payments. We do not sell, rent, or share your data with third parties for marketing or advertising.
4. Guard audit log monitoring
Guard subscribers enable audit log polling on a per-server basis. When enabled, ServerPulse reads your server's audit log every 5 minutes to detect bulk member removals and permission escalations. Audit log entries are processed in-memory to check detection thresholds. When an incident is detected, the relevant event details (actor ID, target count, timestamp) are stored in your incidents history. Raw audit log data is not retained beyond what is needed to power the incidents dashboard.
5. Data retention
- Member count snapshots: rolling 90 days (free: 14 days)
- Alert and incident history: retained while your account is active
- Discord OAuth tokens: retained to refresh your server list; revocable from Discord at any time
- Account deletion: all data is permanently removed within 30 days of account deletion
6. Third-party services
- Supabase — database and authentication hosting (EU-compliant infrastructure)
- Stripe — payment processing (PCI-compliant; your card data never touches our servers)
- Vercel — application hosting
- Discord — OAuth identity provider and bot platform
7. Security
All data is accessed via row-level security policies — your data is only accessible to your account. Discord tokens and service credentials are stored server-side and never exposed to the browser. All connections are encrypted in transit.
8. Your rights
You can delete your account at any time from Settings → Danger Zone. This permanently removes all data associated with your account. You may also revoke Discord access from your Discord account settings at any time, which will disable server list syncing.
9. Contact
Privacy questions or data requests: support@serverpulse.app