Privacy Policy
Last updated August 22, 2026
Here’s the plain version of what Desync Panel stores and why. The short answer: only what we need to run the panel and keep your account safe. We don’t sell your data.
1. What we keep
- Your account — email, a hashed password, and, if you link it, your Discord name and avatar.
- Security info — your 2FA and PIN settings, trusted devices, and recent sign-ins (including IP and rough location) so we can spot anything sketchy and protect your account.
- Your activity — balance, top-ups, orders, delivered keys, and tier, so your history and account work.
- Your team and integrations — the support staff you add and what each can do, your linked Discord, and your bot token, API keys, and notification or webhook settings (secrets are stored encrypted or hashed, never in the clear).
- Anti-fraud signals — at sign-up and sign-in we check things like VPN or proxy use and repeat-signup patterns, so we can stop fraud and ban evasion.
- Support and reports — anything you send us, plus bug reports or screenshots you submit.
We never store full card numbers or crypto wallet credentials. Payments run through trusted providers, and we only get back enough to confirm a payment went through.
2. What we do with it
We use your info to run the panel (sign-in, orders, delivery, balance), to keep accounts secure, to process payments and stop fraud, and to help you when you reach out. That’s it.
3. How it’s protected
Passwords are stored as hashes, never plain text. Keys and sensitive integration secrets are encrypted. API keys and webhook tokens are stored hashed and shown to you in full only once. We add rate limits, audit logs, and access controls on top. No system is perfect, but keeping your data safe is one of our top priorities.
4. Who else sees it
Only the services that make the panel work: payment providers (to take a top-up), suppliers (just enough to deliver a key when an order is filled from them), Resend (our email provider, which sends order deliveries, sign-in codes, security alerts, top-up receipts, and tier changes), proxycheck.io (which gets the IP address you apply from, so we can check it for VPN or proxy use), and our hosting and Discord integration. Working out the rough location behind an IP happens on our own servers from a local database, so your location isn’t sent anywhere. We share information beyond that only if the law genuinely requires it. We never sell it.
5. How long we keep it
We keep your account and order records while your account is active and for a reasonable time after, for security and basic accounting. Sign-in and audit logs stick around to protect the platform. When we don’t need something anymore, we delete or anonymize it.
6. Your controls
You can update your profile and security settings, link or unlink Discord, and turn on 2FA and a PIN any time in the panel. You can ask us to close your account; we may keep a few records where we need to (for example, to stop ban evasion or for accounting).
To be specific about what that leaves behind: if an application was denied, we keep a small record of it holding the Discord ID, the reason, when you can apply again, and a hashed version of the IP rather than the IP itself. Audit log entries also stay, with the account details stripped out of them.
7. Cookies
We use only the cookies needed to keep you signed in and to run security features like the short PIN unlock. No ad tracking.
8. Updates
If this changes, we’ll update the date at the top and, for anything significant, mention it in the panel.
9. Reach us
Questions about your data? Reach us through your reseller support channel.