Privacy Policy
Hedera HTS Token Bot (the “Bot”), operated by Lazy Superheroes. Last updated August 19, 2026.
What the Bot does
The Bot grants and removes Discord roles automatically based on the Hedera tokens and NFTs a member holds (“token gating”). A server admin configures rules that map a token or collection to a role; the Bot then keeps each member’s roles in sync with what their linked Hedera wallet actually holds on-chain.
Data we collect and store
From Discord (via the Discord API): your Discord user ID, username, the IDs and names of servers where the Bot operates, and the role IDs it manages. For the self-service admin website we also read which servers you administer (via Discord OAuth) to show you only those. We do not read, request, or store message content — the Bot uses slash commands only.
From you: the Hedera account ID(s) (wallet address, e.g. 0.0.xxxx) you choose to register, and a one-time signed proof used to verify you control that wallet.
From the Hedera network: the public on-chain token and NFT balances of your registered wallet(s), read from a public Hedera mirror node. This is already public blockchain data; we cache what’s needed to evaluate your gating roles.
Change log: when an admin creates, edits, or deletes a gating rule, we record who did it (their Discord ID and, if provided, the wallet that proved their tier) and what changed, so server owners have an audit trail.
Why we store it (and where)
We store this data solely to provide token gating: to work out which roles you qualify for and to add or remove them across the servers you’re in. The Bot cannot do this without knowing your Discord user ID, the server/role IDs, and your wallet’s holdings.
Data is stored in our own database on a server we control — not on Discord’s platform, and not accessible to the public website’s host. The website is served via Vercel; it talks to our server through an authenticated gateway so database credentials never leave our infrastructure.
Third parties we use
- Discord — to receive commands and apply roles (subject to Discord’s own Privacy Policy).
- Hedera mirror node — to read public on-chain balances.
- WalletConnect / Reown — to let you connect a wallet and sign the ownership proof.
- Upstash — short-lived storage for wallet-link challenge codes and admin sessions.
- HashPack CDN — to display NFT rarity images.
We do not sell your data or share it for advertising.
How long we keep it
We keep your registered wallet and the role/ownership data while your wallet is registered and the Bot is active in a server you’re in. When you unregister a wallet, we remove that wallet and its associated ownership data, and the roles it granted are removed on the next sync. If the Bot is removed from a server, we stop managing that server’s roles. Wallet-link challenge codes and sessions expire automatically within minutes to hours.
Your choices
You can unregister a wallet at any time using the Bot’s slash commands, which deletes the wallet↔account link and de-gates the roles it provided. You can ask us to delete the data we hold about you, or ask what we hold, by contacting us (below). You can also remove the Bot’s access by leaving a server or having an admin remove the Bot.
Security
Database credentials and the Discord bot token are kept on our server and are never exposed to the browser or the website host. Admin actions on the website require a live re-check that you still administer the target server, and wallet-gated actions require a cryptographic proof that you control the wallet.
Children
The Bot is not directed to children under 13 (or the minimum age of digital consent in your country), consistent with Discord’s Terms of Service.
Changes
We may update this policy; material changes will be reflected by the “Last updated” date above.
Contact
Questions or data requests: @SuperheroesLazy or lazysuperheroes.com.