Privacy policy
Last updated: September 23, 2026 · Version française
This English version is a translation provided for convenience. In case of any discrepancy between the two versions, the French version prevails.
This policy describes the personal information the Agora operator ("we") collects through the website, the licensing service, updates and support, why we collect it and how you can exercise your rights. It relies on Québec's Act respecting the protection of personal information in the private sector and on PIPEDA (Canada).
1. Who is responsible
The Agora operator is responsible for the personal information processed by the Service. The point of contact for any privacy question is the support Discord server (open a ticket).
2. What we collect
We only collect what the Service needs to work:
- Account: sign-in is done through Discord, with only the "identify" and "email" OAuth2 scopes. Discord thereby sends us your Discord ID, username and display name, avatar and the e-mail address linked to your Discord account. We request neither the list of your servers ("guilds") nor access to your messages, and we do not keep the access tokens Discord issues at sign-in. We also keep your chosen language, the date your account was created on the site and the date of your last sign-in.
- Discord roles: at sign-in, if you are a member of our support Discord server, we look up your roles on that server to determine your access rights on the site (customer, support team, administration); only the resulting role is kept. For team members, the two-factor authentication secret and recovery codes are stored encrypted or hashed.
- Support (ticket bot on our Discord server): the bot records ticket channels only. There it keeps message content (latest version; a deleted message is kept and flagged as deleted), attachments (a copy of which is archived on our servers), mentions, the ticket subject and the answers to the ticket form, as well as participants' Discord ID, username, display name and avatar, and the creation date of their Discord account (derived from the ID). It also logs ticket events (opening, claiming, adding or removing participants, closing and reason), the team's internal notes and, where applicable, a restriction on opening tickets decided by the team. On closure, a transcript is produced: it can be viewed through a secret link, not indexed by search engines, sent by direct message to the ticket's author and passed on to the team; deleted messages and internal notes do not appear in it.
- Suggestions: title, text and category of the suggestions you submit (through the Discord bot or on the site), their status and the team's replies, as well as votes (Discord ID of each voter). Suggestions are public: their content, vote count and the author's display name are visible on the site's Suggestions page and on Discord.
- Payments: customer, subscription or transaction IDs at Stripe or Tebex, plan, amount, chosen currency, applied discount (promo code, trial → paid, additional licence), refunds, status and dates. Card, PayPal and paysafecard details are processed exclusively by Stripe or Tebex; we never have access to them and do not store them.
- Licences: key (stored encrypted), tier, dates, attached installation.
- Assisted installation and domains: for automatic deployment on your Pterodactyl / Pelican panel, the panel address, the ID and name of the server created and the deployment status; the panel API key is kept, encrypted, only for the duration of the installation and is then erased (an abandoned attempt becomes unusable after one hour and its key is erased at the next clean-up). For a custom domain: the host name, the verification token and the verification status.
- Technical telemetry from installations: installation fingerprint, Agora version, host (public URL), source IP address, heartbeat timestamps and licence state. It is used to validate the licence and distribute updates.
- Technical website logs (IP address, user agent, requested pages), kept briefly for security. The country of connection, derived from the IP address by Cloudflare, is used only to preselect the displayed currency and is not kept.
We do not collect the content of your Agora installation: the forum, the MDT, your community's members and their data stay on your server and are never sent to us.
3. Why
We use this information to:
- provide the Service: sign you in, issue and validate licences, distribute updates, process payments;
- provide support: track and answer tickets, keep a history useful for solving problems;
- protect the Service: detect abuse, key sharing and intrusion attempts;
- meet our legal obligations: accounting, taxes, answering authorities' requests where the law requires it.
We never sell personal information and do not run targeted advertising.
4. Your community and your members
If you run an Agora installation, you are responsible for your members' information (forum accounts, MDT records, mugshots). We act only as the software provider and have no access to that data. It is up to you to inform your members and comply with the laws applicable to your community.
5. Sharing
We share information only with the providers the Service needs:
- Discord (OAuth sign-in, support server, ticket and suggestion bot, direct-message notifications — never the licence key itself);
- Stripe and Tebex (payment and billing; Tebex acts as merchant of record for purchases made through it);
- Cloudflare, through which the website's traffic passes (routing and protection against attacks);
- our hosting provider, for the website and the licence and update servers.
These providers may process data outside Québec and Canada (notably in the United States), under their own policies. We may also disclose information where the law requires it.
6. Retention
- Account: as long as your account exists; deleted on request, except what the law requires us to keep.
- Support tickets and transcripts: kept for support follow-up; deleted at the author's request, except for items needed in an ongoing dispute.
- Copies of ticket attachments: deleted automatically 90 days after the ticket is closed; the transcript then points to the original file on Discord, if it still exists.
- Suggestions and votes: kept to follow up on requests; deleted at the author's request.
- Panel API key (assisted installation): erased at the end of the installation, as described above.
- Payments and invoices: seven years, in line with Canadian tax obligations.
- Installation telemetry: for the duration of the licence or trial, then at most twelve months after the installation's last contact.
- Technical logs: at most 90 days.
7. Security
Secrets (tokens, licence keys, API keys) are encrypted at rest. Exchanges with the website, the licence server and the update server use HTTPS, and software versions are signed. Access to data is limited to the people who need it for support or operations.
In case of a confidentiality incident presenting a risk of serious injury, we will inform you and notify the Commission d'accès à l'information du Québec, as required by law.
8. Your rights
At any time, you may:
- access the information we hold about you and obtain a copy;
- have it corrected if it is inaccurate;
- request its deletion (subject to legal retention obligations);
- withdraw your consent where processing relies on it;
- file a complaint with the Commission d'accès à l'information du Québec or the Office of the Privacy Commissioner of Canada.
To exercise a right, open a ticket on the support Discord from the Discord account concerned: this lets us verify your identity with no further formality. We answer within 30 days.
9. Cookies
The site only uses strictly necessary cookies: the sign-in cookies (session, and protection of the Discord sign-in against forgery while it is in progress), the two-step verification cookie reserved for the team (agora_mfa, at most 12 hours), the language cookie (agora_site_lang, one year), the currency cookie (agora_site_currency, one year), the cookie for the promo code you entered (agora_promo, one hour) and the cookie for the trial passed on by your installation (agora_trial_lease, seven days). No advertising cookies and no third-party trackers.
10. Changes
We may update this policy. The current version is published here with its date; an important change is announced in your account area or on Discord.
11. Contact
For any privacy question, open a ticket on our support Discord server (link in the site header).