DPaletteDiscord Bot Builder
Back to DPalette
DPalette

Privacy Policy

How DPalette collects, uses, stores, and shares information when you use the Discord Bot Builder.

Effective date: 2026-09-07
Operator informationOperator: Disclosed without delay upon a lawful requestContact: midoristar@empengineer.coolCommercial Transactions Act Disclosure

1. Scope

This Privacy Policy applies to DPalette, operated by the DPalette operator, including the public website, editor, Discord application, APIs, webhooks, billing features, and related services.

2. Information we collect

We collect information you provide or generate through the service, technical information needed to operate it, and limited information received from connected services. This can include account identifiers, guild/workflow configuration, execution metadata, database records you create, IP/network and request metadata used for security and rate limiting, and service logs.

3. Discord account and server information

When you sign in with Discord OAuth, DPalette receives your Discord user ID, username, display name, avatar reference, and a snapshot of servers you are permitted to manage. To keep you signed in for up to 30 days and verify your current server permissions, OAuth access and refresh tokens are stored encrypted on the server, bound to your login session. They are never exposed to the browser or workflows. Renewing Discord authorization does not extend the login session. Expired credentials are cleared by periodic cleanup, and logout deletes the session and its credentials. The DPalette bot also processes Discord events and resources required by published workflows.

4. YouTube API Services

DPalette's YouTube features use YouTube API Services. When you configure a public @handle, DPalette sends it to YouTube to resolve the canonical channel ID. DPalette uses that ID to subscribe to public upload feeds and, when live monitoring is enabled, queries public video and live-broadcast metadata to detect an actual live start. We store the configured channel reference, canonical channel ID, monitoring status, and notification metadata needed to run the workflow, such as video ID, title, URL, and publication, update, or start times. DPalette begins revalidating canonical channel IDs resolved from @handles after 27 days. If an ID cannot be revalidated by day 28 or the handle resolves to a different channel, DPalette expires the API-derived ID and subscription, retains the raw channel reference you configured and a minimal paused-status record, and pauses monitoring. A fixed monitor resumes only after you republish the bot behavior; a dynamic monitor resumes only after Add YouTube Monitoring runs again. YouTube API-derived event and item operational data expires after 28 days and is scheduled for deletion before YouTube's 30-day policy limit. These features do not request access to private YouTube account data. Use of YouTube features is also governed by the YouTube Terms of Service, and Google's handling of information is described in the Google Privacy Policy, linked below.

YouTube Terms of Service · Google Privacy Policy

5. Text-to-speech

When speech is explicitly configured in a workflow, only the text selected for reading is sent to Google Cloud Text-to-Speech. Calls are not recorded and participant audio is not collected. Generated audio is used temporarily for playback and is not stored long-term by DPalette. Source-channel viewing and history permissions are checked to prevent reading private text to participants without access. The policies elsewhere on this page continue to apply to workflow settings and execution history.

6. Workflows, messages, secrets, and DPalette Database

We store workflow definitions, revisions, configuration, execution history, and DPalette Database records so your automations can run. Depending on your workflow and privacy settings, execution details may contain Discord identifiers or content. Guild Secrets are encrypted at rest. Do not store information in DPalette that you are not authorized to process.

7. Billing information

Paid subscriptions are processed by Stripe. DPalette stores billing identifiers and subscription status needed to provide your plan and prevent duplicate processing. New payment records use a random, expiring reference for Stripe correlation while the association with Discord guild and user IDs remains inside DPalette. Stripe records created by older versions may contain those Discord identifiers. Payment card or bank details are handled by Stripe and are not intentionally stored by DPalette.

8. Cookies and local storage

DPalette uses essential cookies for Discord OAuth state and authenticated sessions, and local storage for preferences such as language and your analytics choice. These are used for login, security, and remembering settings. Google Analytics cookies are created only after analytics consent. Disabling essential browser storage may prevent authentication or preference features from working.

9. Google Analytics

If Google Analytics is configured, DPalette uses Google Consent Mode v2 in Advanced mode. From the first visit, the tag loads with analytics_storage=denied. Before consent or after rejection it does not read or write Analytics cookies, but sends Google cookieless pings that may include consent state, page information, user agent, screen resolution, and an IP address as part of the network request. Google states that it does not store or log that IP address. After consent, Analytics cookies are also used. DPalette does not intentionally send workflow contents, Discord message contents, Guild Secrets, or DPalette Database record values. Google Signals and advertising personalization are disabled.

10. Purposes of processing

We use information to authenticate users, determine server-management permissions, execute workflows, provide Discord interactions, store user-configured data, process subscriptions, secure and debug the service, prevent abuse, provide support, comply with law, and understand aggregate website usage through Google Consent Mode.

11. Service providers and disclosures

DPalette may use service providers such as Discord for identity and bot APIs, Stripe for billing, Neon/PostgreSQL for database hosting, Fly.io or other infrastructure providers for hosting, and Google Analytics according to the selected consent state. Information may also be disclosed when required by law, to protect users or the service, or in connection with a lawful business transfer.

12. Retention

Login sessions have a maximum lifetime of 30 days. Execution history is normally retained for the period shown by your plan (currently 7 days on Free and 30 days on Plus, subject to configuration and error-retention settings). Regardless of those general periods, YouTube API-derived event and item operational data expires after 28 days and is scheduled for deletion before the 30-day policy limit. DPalette Database records derived from that data inherit the same absolute expiry. Other workflows and DPalette Database records are retained while needed to provide the service or until removed. Billing and security records may be retained longer when required for legal, fraud-prevention, accounting, or dispute purposes.

13. Security

We use access controls, tenant isolation, encrypted Guild Secrets, bounded execution, and other technical safeguards. No internet service can guarantee absolute security. You are responsible for protecting credentials and for limiting what data your workflows collect.

14. International processing

Our service providers may process information in countries other than yours. Where required, the operator will use legally recognized safeguards for international transfers.

15. Your choices and rights

Depending on applicable law, you may have rights to access, correct, delete, restrict, object to, or receive information about processing of your personal data. You may withdraw consent for Analytics cookies at any time from this page. Limited cookieless measurement signals continue after rejection. Contact midoristar@empengineer.cool to exercise applicable rights.

16. Children

DPalette is not directed to children below the minimum age required to use Discord or enter into these terms in their jurisdiction. Do not use DPalette if you do not meet those requirements.

17. Changes to this policy

We may update this policy when the service, law, or our processing changes. Material changes will be indicated by an updated effective date and, where appropriate, additional notice.

18. Contact

For privacy questions or rights requests, contact midoristar@empengineer.cool. The operator’s legal name, address and telephone number will be disclosed without delay upon a lawful request. See the Commercial Transactions Act Disclosure for the disclosure process.

© DPalette
English日本語简体中文한국어
Privacy PolicyTerms of ServiceCommercial Transactions Act Disclosure