Legal

Privacy Policy

Effective 24 July 2026. This policy explains what data Licentry ("we", "us") handles when you use licentry.cc, the vendor dashboard, the Licentry API and the Licentry Discord bot, and what your choices are. Contact for anything privacy related: [email protected].

Two roles matter here. For vendor accounts (the businesses that sign up), we decide how the data is used, as the controller. For end user licensing data (the people who run software licensed through a vendor), we process technical data on that vendor's behalf so their licensing works; the vendor is the controller of that data and your first point of contact about it.

1. Data we collect from vendors

  • Account. Email address, a hash of your password (never the password), optional company name, two factor secrets stored encrypted, and backup code hashes.
  • Security history. Sign in events with IP address, browser user agent and coarse location derived from the IP, kept so you can spot an account takeover.
  • API keys. Name, scopes, a display prefix and a hash of the key. The full key is shown to you once and never stored.
  • Billing. Invoices with plan, USD amount, the crypto currency, payment address and on-chain transaction details needed to recognize your payment. We do not perform KYC and we never see or store card numbers; card payments arranged through support happen outside our systems.
  • Support. Emails you send to support, so we can answer them.

2. End user licensing data we process for vendors

When software licensed through Licentry activates or validates a key, the API records what licensing needs and nothing more:

  • license keys as one way hashes (the plaintext key is never stored server side);
  • device identifiers as one way hashes, never raw hardware serials;
  • IP address, user agent, timestamps and coarse IP based location of licensing calls;
  • runtime session records: activation, heartbeat and refresh times, and why a session ended.

Purpose: making license checks work, enforcing the device and session limits the vendor configured, and giving the vendor evidence when one key is shared by many people. We never sell this data or use it for advertising.

Retention. Validation logs are deleted after 90 days, dashboard sign in history after 180 days, and the security audit trail after 365 days. Runtime session and device records live as long as the license they belong to. Encrypted backups rotate out after 14 days.

3. The Licentry Discord bot

The bot connects a vendor's Discord server to their Licentry account. This section is the complete inventory of what it touches.

  • Server link. The server id and name, the id and username of the admin who ran /link-account, and when. Channel ids you point logs at, and the role id the bot grants after a redeem.
  • Redeems. When a customer redeems a key (panel button or /redeem), we store their Discord user id and username on that license, with time and server id, so the vendor can see which Discord account a key belongs to.
  • Commands. Staff key commands (generate, reset, ban, unban, revoke, extend) are written to the vendor's audit log with the acting person's Discord username and id.
  • Account verification. Vendor owners and their staff verify through Discord sign-in with the identify and guilds.join permissions. We store the verified user id and username, and the sign-in tokens encrypted at rest; guilds.join is used for one thing, adding verified vendor people to the official Licentry server.
  • Log posts. Activity embeds queued for delivery are held only until posted, then only the delivery outcome is kept.

What the bot does not do. It does not read messages (it is built without the message content intent), does not collect member lists or presence, does not track voice, and only sends a DM when the vendor turned on DM confirmations and you redeem a key. It never posts publicly on your behalf.

Sharing. Discord bot data is visible to the vendor whose server and keys are involved, and to us for operating the service. It is not sold and not shared with anyone else. Discord itself processes everything you do inside Discord under its own privacy policy.

Removal. A vendor can detach any customer from a key in the dashboard, and can disconnect the whole server at any time; kicking the bot from the server ends all collection for that server. If you are a customer and want your Discord link removed, ask the vendor who sold you the key, or email [email protected] with the server name and we will handle it.

4. Cookies

The dashboard sets one session cookie so you stay signed in, plus a short lived cookie during two factor sign in. There are no advertising or cross site tracking cookies, and no third party analytics scripts.

5. Where data lives and who touches it

  • Hosting. The service runs on DigitalOcean infrastructure. Data is stored on encrypted disks; backups are encrypted before they are written.
  • Discord. When the integration is enabled, log embeds and command replies flow through Discord's platform.
  • Email. Transactional email (password resets, sign in codes) goes through our email delivery provider.

These providers process data only to provide their service to us. We disclose data beyond that only if the law forces us to, and we tell you when we are allowed to.

6. Security

Secrets are encrypted at rest, credentials are stored as hashes, transport is TLS everywhere, tenants are isolated with per vendor cryptographic material, and administrative actions land in an append only audit log. No system is unbreakable; if a breach ever affects your data we will notify you without undue delay.

7. Your rights

You can ask us for a copy of your data, ask us to correct it or delete it, and object to a specific use. Vendors can self serve most of this in the dashboard: revoke keys, unlink Discord accounts, disconnect the server, or ask support to close the account. Depending on where you live (for example under the GDPR or the CCPA) these rights are backed by law, and you can also complain to your local supervisory authority. We answer every request at [email protected], normally within 30 days.

8. Children

Licentry is a business tool and is not directed at children under 16. We do not knowingly collect their data; if you believe a child's data ended up here, write to support and we will delete it.

9. Changes

When this policy changes in a way that matters, we announce it in the dashboard or by email before it takes effect. The date at the top is always the current version. Earlier versions are available from support on request.