Privacy Policy
Draft - not yet reviewed by a lawyer. The data inventory below is accurate to what the code actually stores, which is the hard part and the part worth keeping. The legal framing around it still needs review, especially if you take customers in the EU or UK (GDPR) or California (CCPA).
What we store
This is the complete list. It is short on purpose.
-
Your Discord identity. User ID, username, display name and avatar hash,
from the
identifyOAuth scope. -
The servers you administer. From the
guildsOAuth scope, so the dashboard can show a server picker. We store the ID, name and icon of servers where you hold Manage Server, and nothing about servers you merely belong to. - Your Discord access token, server-side only, used to re-check that you still administer a server when you make a request. It is never placed in a cookie or sent to your browser.
- Position records. Ticker or contract, entry, stop, target, exit, notes you wrote, timestamps, and the Discord message and channel IDs the card lives at.
- Server configuration. Which channel you post to, which role you ping, your branding, your analyst seat list, your plan.
- An audit log of administrative actions taken in the dashboard.
What we do not store
- Message content from your server. The bot requests only the
Guildsgateway intent and cannot read chat. - Your member list, or any personal data about your members.
- Brokerage credentials, account numbers or balances. There is no brokerage connection.
- Payment card details. When billing is live, those go directly to our payment processor and never touch our servers.
Your session
Signing in sets one cookie, __session. It is HTTP-only, cryptographically
signed, expires after seven days, and contains only your Discord user ID and display name.
Before you sign in, the same cookie briefly holds a random value used to verify the
sign-in request itself. There is no tracking cookie, no advertising pixel and no
third-party analytics on the dashboard.
Who we share it with
Nobody, other than the infrastructure providers required to run the service: Google Cloud and Firebase for hosting and storage, and Discord itself. We do not sell data, and we do not share it with advertisers or data brokers. We will disclose data if compelled by valid legal process, and will notify you unless legally prohibited from doing so.
Getting your data out, and deleting it
Full CSV and JSON export of your position history is available in the dashboard on Pro and above. To delete your account and everything associated with it, email us; we complete deletions within 30 days. Removing the bot from a server keeps your history exportable for 30 days before deletion, so an accidental removal is recoverable.
Cards already posted to Discord are messages in your own server. Deleting your Entry Point data does not remove them, and only you can.
Contact
Privacy questions or deletion requests: entrypoint.support@gmail.com.