Effective 24 July 2026. This policy explains what data Licentry ("we", "us") handles when you use licentry.cc, the vendor dashboard, the Licentry API and the Licentry Discord bot, and what your choices are. Contact for anything privacy related: [email protected].
Two roles matter here. For vendor accounts (the businesses that sign up), we decide how the data is used, as the controller. For end user licensing data (the people who run software licensed through a vendor), we process technical data on that vendor's behalf so their licensing works; the vendor is the controller of that data and your first point of contact about it.
When software licensed through Licentry activates or validates a key, the API records what licensing needs and nothing more:
Purpose: making license checks work, enforcing the device and session limits the vendor configured, and giving the vendor evidence when one key is shared by many people. We never sell this data or use it for advertising.
Retention. Validation logs are deleted after 90 days, dashboard sign in history after 180 days, and the security audit trail after 365 days. Runtime session and device records live as long as the license they belong to. Encrypted backups rotate out after 14 days.
The bot connects a vendor's Discord server to their Licentry account. This section is the complete inventory of what it touches.
What the bot does not do. It does not read messages (it is built without the message content intent), does not collect member lists or presence, does not track voice, and only sends a DM when the vendor turned on DM confirmations and you redeem a key. It never posts publicly on your behalf.
Sharing. Discord bot data is visible to the vendor whose server and keys are involved, and to us for operating the service. It is not sold and not shared with anyone else. Discord itself processes everything you do inside Discord under its own privacy policy.
Removal. A vendor can detach any customer from a key in the dashboard, and can disconnect the whole server at any time; kicking the bot from the server ends all collection for that server. If you are a customer and want your Discord link removed, ask the vendor who sold you the key, or email [email protected] with the server name and we will handle it.
The dashboard sets one session cookie so you stay signed in, plus a short lived cookie during two factor sign in. There are no advertising or cross site tracking cookies, and no third party analytics scripts.
These providers process data only to provide their service to us. We disclose data beyond that only if the law forces us to, and we tell you when we are allowed to.
Secrets are encrypted at rest, credentials are stored as hashes, transport is TLS everywhere, tenants are isolated with per vendor cryptographic material, and administrative actions land in an append only audit log. No system is unbreakable; if a breach ever affects your data we will notify you without undue delay.
You can ask us for a copy of your data, ask us to correct it or delete it, and object to a specific use. Vendors can self serve most of this in the dashboard: revoke keys, unlink Discord accounts, disconnect the server, or ask support to close the account. Depending on where you live (for example under the GDPR or the CCPA) these rights are backed by law, and you can also complain to your local supervisory authority. We answer every request at [email protected], normally within 30 days.
Licentry is a business tool and is not directed at children under 16. We do not knowingly collect their data; if you believe a child's data ended up here, write to support and we will delete it.
When this policy changes in a way that matters, we announce it in the dashboard or by email before it takes effect. The date at the top is always the current version. Earlier versions are available from support on request.