Privacy Policy
Last updated: 27 July 2026
TipsterVault ("we", "the service") operates a Discord bot and this website. This policy explains exactly what we collect, why we collect it, and how long we keep it. We have tried to write it plainly rather than defensively.
1. What we collect
| Data | Why | When |
|---|---|---|
| Your Discord user ID | To identify your wallet and credit your balance | Whenever you use the bot |
| Discord username and avatar | Shown while signed in to the faucet | Only if you sign in on the website |
| Balances and transaction history | To operate the wallet and keep an auditable ledger | Whenever value moves |
| A one-way hash of your IP address | To stop one person draining the faucet from many accounts | Only when you claim from the faucet |
| A one-way hash of a browser fingerprint | Same reason: repeat-claim friction | Only when you claim from the faucet |
| Deposit and withdrawal addresses | To send and receive on-chain transactions | When you deposit or withdraw |
| Server ID and settings | To store per-server configuration set by admins | When an admin uses /config |
| A last-active timestamp | So features that pay out to active members, like airdrops and random tips, know who is active | When you post or use a command in a server the bot is in |
2. What we do not collect
- We do not collect your email address, real name, phone number or date of birth.
- We do not ask for or store payment card details.
- We never ask for your wallet's seed phrase or private keys. Nobody legitimate ever will.
- We do not store what you write in Discord. No message content is saved to our database.
- We do not sell or rent your data to anyone.
Worth spelling out, because "we do not store it" is not the same as "we never see it": the bot can see message text in servers it has been added to, and one feature uses it. While a phrase drop is running in a channel, each message in that channel is compared against the winning phrase so the bot can tell who typed it first. That comparison happens in memory; the text is not written down or sent anywhere. Everything else the bot does runs on slash commands and buttons.
Separately, we note the time you were last active in a server, as listed above. That is a timestamp only - never a record of what you said or where you said it.
3. About the IP and device hashes
We do not store your IP address or device fingerprint in readable form. Both are passed through a keyed one-way hash before they are written, so the stored value cannot be reversed back into your IP. For IPv6 we hash the network prefix rather than the full address. These values exist for one purpose only: enforcing the faucet's one-claim-per-period limit.
4. Cookies
We set two cookies, both strictly necessary. We do not use analytics or tracking cookies.
- Session cookie - records that you signed in with Discord. Cryptographically signed, HTTP-only, and expires after 7 days.
- Sign-in state cookie - a short-lived value that protects the Discord login from cross-site request forgery. It is deleted as soon as sign-in completes.
Advertisements shown on the faucet page are served by a third party in an isolated frame and may set their own cookies, which we cannot read. See section 5.
5. Third parties
Operating the service means data passes through these providers:
- Discord - authentication and all bot interaction.
- Cloudflare Turnstile - the anti-bot check on the faucet. Cloudflare receives your IP as part of that check.
- A-ADS - advertising on the faucet page, served in a sandboxed frame.
- top.gg - only if you choose to vote for the bot there to earn a faucet reward. top.gg tells us your Discord ID so the reward can be credited.
- CoinGecko and QuickChart - price data and chart images. CoinGecko receives no personal data about you. QuickChart draws the QR code on your deposit screen, so it receives the deposit address that code encodes.
- ip-api.com - only if you claim from the website faucet, and only to check whether your connection is a VPN, proxy or datacenter. Your IP address is sent to them to answer that question. This request is made over plain HTTP because the encrypted endpoint is a paid feature, so treat the address as visible in transit. Nothing else about you is sent, and the answer is cached for about an hour.
- Google Cloud - hosting. Server logs may contain IP addresses transiently.
- Public blockchains - see section 6.
6. Blockchain transactions are public and permanent
When you deposit or withdraw, that transaction is recorded on a public blockchain (Stellar, BNB Chain, Polygon, Avalanche or Solana). Those records are permanent, worldwide, and outside our control. We cannot edit or delete them. Anyone can view them, and an address may be linkable to you by someone who already knows it is yours.
7. How long we keep things
- Balances and transaction records are kept for as long as the service operates, because they are the record of what you are owed.
- Faucet abuse hashes are kept only as long as the relevant cooldown needs them.
- Backups of the database are retained on a rolling basis and older copies are deleted automatically.
8. Your rights
You can ask us what we hold about you, ask for a correction, or ask for deletion. Contact us through the Discord server or at the address in section 11. Two honest limits: we cannot delete on-chain transactions (section 6), and we may need to retain a minimal record where doing so is required to resolve a dispute about funds.
Deleting your data means giving up any balance held for you, so please withdraw first.
9. Security
Traffic to this site is encrypted with TLS. Secrets are held on the server only. Balances are tracked in a double-entry ledger and the service is checked against real on-chain holdings. That said, no online service is perfectly secure, and this one is custodial by design: we hold funds on your behalf. Please read the Terms, and do not keep more in the bot than you are comfortable being exposed to.
10. Age
You must meet Discord's minimum age for your country to use Discord, and therefore this service. We do not knowingly collect data from anyone below that age. If you believe a child has used the service, contact us and we will remove the data.
11. Contact
Questions about privacy: ask in our Discord server, or email jointipster@gmail.com. Support is normally handled in Discord.
12. Changes
We may update this policy. The date at the top will change, and material changes will be announced in the Discord server.