Legal

Privacy Policy

Effective August 21, 2026 ยท Version 2.3

Information Saily processes

Saily processes Discord server, channel, role, user, event, and configuration identifiers needed for enabled features. Optional records can include birthdays, XP totals, eligible activity counts, card descriptions, badges, owned and selected card cosmetics, starter choice, earned-roll and shard balances, roll results, pity counters, tickets, moderation cases, uploaded artwork, delivery history, and a private-launch waitlist email address previously entered directly by an applicant.

Website measurement

Saily records anonymous website page views, campaign labels, and Add Saily clicks so the owner can understand which public pages and promotions are useful. A random identifier lasts only for the current browser session. Saily does not store an IP address, full referring URL, advertising profile, or cross-site browsing history in this tracking record.

Former waitlist email

Saily no longer accepts new waitlist applications. An email supplied and verified during private admission was used only for one approval notice. Saily did not request the address from Discord, use it for marketing, export it to application spreadsheets, or include reusable installation links in email. Microsoft 365 processed the address and message only to accept and send that transactional notice.

Message content

Saily does not retain ordinary server conversation content for XP. It processes configured command messages, reminders, prompts, moderation evidence excerpts, and ticket content when those features require it.

Subscriptions and access

Saily stores a server's Free or Premium state, subscription provider, paid-through date, server assignment, and the audit records needed to keep access accurate. Discord and Patreon process payment details. Saily does not receive or store card or bank information.

Creator services

When an administrator configures creator alerts, Saily uses the official YouTube Data API and Twitch Helix and EventSub services. Saily stores the channel or broadcaster identifier, displayed creator name, avatar, selected video or stream metadata, subscription state, provider health, and short-lived webhook receipt identifiers used to prevent duplicate alerts. YouTube metadata is refreshed or removed within 30 days. Twitch profile metadata is refreshed about every 24 hours and removed when its alert is deleted. YouTube use is also governed by the YouTube Terms of Service and Google Privacy Policy.

Uploads and linked storage

Uploaded media and artwork are stored in Cloudflare storage. Premium server administrators and authorized owner-workspace users can connect Google Drive, Microsoft OneDrive or SharePoint, or Dropbox and choose specific files for Saily features that accept uploads. Saily stores an encrypted provider authorization credential and selected-file metadata, then retrieves an imported selection when it is needed. Normal file type, size, and safety validation still applies. Saily imports file content only after an authorized user selects it. Saily does not delete source files from the provider or treat a connected account as public storage. Disconnecting removes Saily's provider authorization and linked references. Imported files are scoped to the server or owner workspace that selected them, a pending review queue, or the global catalog. Reviewers can inspect global artwork submissions and their submitting server before approval. One-time reminder files can be removed after successful delivery. Rejected, replaced, archived, or deleted assets are cleaned up according to moderation, backup, and retention rules. Image submissions are governed by the Saily Image Upload Rules.

Retention

Operational logs use limited retention. Unverified private-launch waitlist email addresses and expired verification tokens are removed after seven days. A waitlist email is removed approximately 30 days after a final application decision unless another active application still uses it. Moderation evidence excerpts expire separately from case identifiers. Departed member profile and birthday data is scheduled for deletion after the recovery period. Account-level card ownership, balances, pity counters, and choices remain until the member deletes them through the Member Portal. Collection and roll ledgers are anonymized after deletion so support investigations and limited-edition integrity can be preserved without retaining the Discord user ID. Encrypted backups can retain deleted information until their retention window ends.

Your controls

Members can manage card visibility, birthday details, card collection data, earned-roll wallet data, exports, and deletion through the Member Portal. Server administrators can remove configuration and assets available to their server. Some moderation case identifiers may be retained for safety and accountability.

Security

Retained private-launch waitlist email addresses are encrypted at rest and masked in administrative views. Tokens, provider credentials, signing secrets, and backup keys are stored as platform secrets rather than in the application database. Owner operations require separate authorization, same-origin checks, rate limits, and audit records.

Contact

Use the Member Portal for personal-data controls or contact support@sailyapp.com.