Legal
Privacy Policy
Last updated August 2, 2026. What we collect, why we collect it, and how to get it removed.
What we collect
We collect the minimum needed to run the product:
- Account data
- Your email address and a hashed password. Passwords are hashed with a salted key derivation function — we can't read them and can't recover them for you.
- Staff identity
- For staff who sign in with staff access keys: a hashed key identifier, label, and permission set you configured. Panel staff login does not use Discord OAuth.
- Server credentials
- The host, port, and RCON password for each server you connect. Passwords are encrypted before storage and are never shown back in full in the panel.
- Game data
- Data your server reports over RCON — player names and gamertags, session activity, bans, and events like kills that drive Discord feeds.
- Discord data
- When you link a guild and enable bot features: Discord guild ID, channel IDs you configure, Discord user IDs for player links and moderation, IGN↔Discord link records, and message or slash-command content needed for feeds, VIP, tickets, and related bot tools.
- Billing data
- Your subscription status and a Stripe customer reference. Card numbers go directly to Stripe and never reach our servers.
- Operational logs
- Technical logs including IP addresses and error traces, used to debug problems and limit abuse.
How we use it
To operate your workspace, authenticate you and your staff, connect to your servers, deliver the Discord features you enable, take payment, and support you when you ask. We don't sell your data, and we don't use it to advertise to you or your players.
Player data
Managing a game server means handling data about the people playing on it. That data comes from your server (and, when linked, from Discord), it's visible to you and the staff you authorize, and it stays isolated to your workspace — no other customer can see it.
If a player asks you to remove their data, contact us and we'll remove it from your workspace. Note that bans are records you may need to keep to enforce them.
Who processes it
We use a small number of providers to run Usely. Each only receives what it needs:
- Supabase — database hosting for workspace, account, and server data.
- Stripe — subscription payments and card handling.
- Resend — transactional email such as setup links and password resets.
- Discord — bot features, guild linking, and player Discord↔IGN links (not panel staff login).
- Vercel and Railway — hosting for this website and the application.
- Sentry — error monitoring for the application (with sensitive fields scrubbed where configured).
Cookies and analytics
We set a session cookie so you stay signed in to the admin panel. Clearing it signs you out. We don't use advertising cookies or cross-site profiling.
The marketing site on www.usely.dev uses Vercel Web Analytics — a first-party, privacy-oriented pageview counter hosted by our site host (Vercel). It is not used for advertising and does not load on the admin panel or Discord bot. Continuing to browse the marketing site after this disclosure constitutes acknowledgment of that pageview measurement. If you prefer not to be counted, avoid loading the marketing site or use a browser privacy tool that blocks analytics scripts.
Retention
We keep workspace data while your subscription is active. After cancellation we retain it for 30 days so you can reactivate or request an export, then delete it. Operational logs rotate out on a shorter cycle. Records we're legally required to keep, such as invoices, are kept as long as the law requires.
Your rights
You can ask us to show you the data we hold about you, correct it, delete it, or export it. Email support@inbound.usely.dev (or use the contact page) and we'll respond within 30 days. Deleting your account removes your workspace and the server data in it after any applicable retention window, except invoices and records we must keep by law.
If you are in the EEA, UK, or California, you may have additional rights under GDPR or CCPA/CPRA, including access, deletion, and (where applicable) opting out of “sale” or “sharing” of personal information. We do not sell personal information. To exercise these rights, use the same contact email.
Security
Server credentials are encrypted at rest, passwords are hashed, traffic is encrypted in transit, and each workspace's data is isolated from every other workspace. Permissions are enforced on every action rather than only at sign-in. No system is perfectly secure — if you find a vulnerability, please report it to support@inbound.usely.dev rather than disclosing it publicly.
Children
Usely is a tool for server administrators and isn't directed at children. We don't knowingly create accounts for anyone under 13.
Changes
If we change this policy materially, we'll email subscribers before it takes effect and update the date above.
Contact
Privacy questions or requests: support@inbound.usely.dev, or use the contact page.