Last updated July 24, 2026
Privacy Policy
This policy explains the information ottr uses to operate customer accounts and game servers.
Information we collect
- Discord account ID, display name, avatar, and verified email when available.
- Your email address if you choose to join the capacity waitlist.
- Server configuration, lifecycle events, server-running time, player counts, and operational logs.
- Limited first-party campaign or referral parameters that explain how you found ottr.
- If you choose a future paid plan, subscription, payment status, and billing identifiers from the payment provider. We do not store full card numbers.
- Security information such as request metadata needed to prevent abuse.
How we use information
We use it to authenticate you, manage the capacity waitlist, provision and operate servers, measure fair use, understand acquisition and referrals, manage any billing you choose, provide support, secure the service, and meet legal obligations. We do not sell personal information.
Providers and transfers
Discord handles sign-in, and our hosting providers run the application and game infrastructure. If you choose a future paid plan, its disclosed payment provider will handle payment and billing. Each provider processes information under its own terms and privacy policy.
Retention and deletion
We retain account, waitlist, campaign, referral, security, and operational records only as long as needed for the purposes above. Removing a free server schedules teardown after a final infrastructure snapshot; it does not promise a customer recovery period. Some records may remain where needed for security, disputes, fraud prevention, or law.
Your choices
You may update Discord profile details through Discord. If a support destination is published on ottr.gg, you may use it to request access, correction, or deletion. Future paid plans will include their own billing-management path. Some records may be retained where legally required.
Cookies, attribution, and security
We use secure, HTTP-only cookies to maintain sessions. A first-party campaign cookie lasts up to 30 days, uses SameSite=Lax, and is readable by the site so allowlisted campaign tags can survive sign-in. A separate verified referral cookie lasts up to 30 days, uses SameSite=Lax, and is HTTP-only. Neither cookie records click history or a raw referrer.
Referral attribution records which shared server led to a successful claim; it does not grant access to that server. We apply technical and organizational safeguards, but no online service can promise absolute security.