Owlin — Privacy Policy
Last updated: July 19, 2026
This Privacy Policy explains how Owlin collects, uses, stores, shares, and protects personal data when you use the Owlin software, website, Discord community, authentication services, downloads, support, and related services collectively referred to as the “Service”.
The data controller responsible for Owlin is:
Owlin development team (Ukraine)
Contact: Support Channel on our official Discord server
1. Scope
This Policy applies to personal data processed through:
- the Owlin desktop application;
- the Owlin website;
- Discord authentication;
- Owlin account and access systems;
- downloads and software updates;
- support requests;
- security, anti-abuse, and diagnostic systems;
- the official Owlin Discord server where Owlin directly collects or receives information.
Discord separately processes information under Discord’s own privacy terms. Owlin does not control all processing performed independently by Discord, Steam, game developers, or other platforms.
2. Information We Collect
Depending on how you use the Service, we may process the following categories of information.
2.1 Discord account information
When you authenticate through Discord, we may receive:
- Discord user ID;
- Discord username and display name;
- avatar;
- email address, where included in the authorised OAuth scope;
- authentication provider information;
- account metadata supplied through the authentication process.
We do not receive your Discord password.
2.2 Authentication and account information
We may process:
- Owlin user ID;
- authentication session identifiers;
- access and refresh tokens;
- login and last-sign-in timestamps;
- access status;
- plan or entitlement information;
- account creation date;
- account suspension or termination status.
Authentication tokens are used to maintain secure access. They are not intended to be publicly displayed or shared.
2.3 Device and technical information
We may process:
- hardware identifier or device identifier (“HWID”);
- operating system and application version;
- IP address;
- approximate country, region, or network location derived from the IP address;
- request timestamps;
- security events;
- error and diagnostic information;
- information about failed and successful authorisation attempts.
HWID is used as a device-binding and anti-abuse identifier. It is not intended to reveal the contents of your device.
2.4 Purchase and entitlement information
Where paid access is offered, we may process:
- transaction or order identifier;
- purchased plan;
- purchase date;
- subscription or access expiration date;
- payment status;
- refund or chargeback status.
Payment processors may process billing details independently. Owlin should not store complete payment-card numbers or card security codes.
2.5 Support and communications
When you contact us, we may process:
- Discord messages or support-ticket content;
- email address;
- screenshots;
- voluntarily submitted logs;
- device and diagnostic details;
- correspondence history.
Do not send passwords, private keys, authentication tokens, or unrelated sensitive information.
2.6 Terms and policy acceptance
We may record:
- Owlin user ID;
- version of the Terms accepted;
- version of the Privacy Policy acknowledged;
- acceptance timestamp;
- IP address or device information associated with acceptance.
This information may be retained to demonstrate which terms applied to a particular account.
3. How We Use Information
We may use personal data to:
- create and authenticate accounts;
- complete Discord OAuth sign-in;
- provide access to the Software;
- bind access to an authorised device;
- enforce account and access limits;
- prevent account sharing, fraud, abuse, and unauthorised access;
- deliver updates and support;
- diagnose errors and compatibility problems;
- manage purchases, plans, expiration dates, and refunds;
- investigate security incidents;
- enforce the Terms of Service;
- maintain records required by law;
- respond to legal requests;
- protect the rights and security of Owlin and its users.
We do not sell personal data.
We do not use personal data for third-party behavioural advertising unless this Policy is updated and any legally required choice is provided first.
4. Legal Bases
Where the GDPR or similar laws apply, we rely on one or more of the following legal bases.
Contract
Processing necessary to:
- create and authenticate an account;
- provide the requested Software and access;
- manage entitlements;
- provide support;
- perform the Terms of Service.
Legitimate interests
Processing reasonably necessary to:
- secure the Service;
- prevent account sharing and fraud;
- bind an account to an authorised device;
- investigate abuse;
- maintain operational and security logs;
- protect our systems and users.
We consider the effect of this processing on users and limit collection to information reasonably necessary for these purposes.
Legal obligation
Processing necessary to comply with:
- accounting requirements;
- valid legal requests;
- consumer-protection obligations;
- fraud-prevention or regulatory obligations.
Consent
We rely on consent only where specifically requested, such as optional analytics or optional communications.
Consent may be withdrawn at any time, but withdrawal does not affect processing that occurred before withdrawal.
5. Automated Access Decisions
The Service may automatically allow or deny access based on factors such as:
- whether an account has an active entitlement;
- whether access has expired;
- whether the account is disabled;
- whether the submitted HWID matches the registered HWID;
- whether authentication is valid;
- whether a security restriction applies.
A denied request may return a technical reason such as:
- access not found;
- access inactive;
- access expired;
- HWID mismatch;
- unauthorised request.
Where applicable, you may contact support to request review of an access decision.
6. How We Share Information
We may share or make information available to service providers that help operate the Service.
Supabase
Supabase is used for services including:
- database hosting;
- account authentication;
- Discord OAuth integration;
- session management;
- server-side functions;
- security and access records.
Information processed through Supabase may include account identifiers, Discord-related account information, authentication information, HWID, IP address, region, plan, access status, and timestamps.
Discord
Discord is used for:
- OAuth authentication;
- community access;
- support and communications.
Discord processes information under its own terms and privacy policy.
Hosting and infrastructure providers
Information may be processed by providers used for website hosting, content delivery, logging, email, downloads, or other infrastructure.
Legal and safety disclosures
We may disclose information where reasonably necessary to:
- comply with applicable law or a valid legal request;
- investigate fraud, abuse, or security incidents;
- protect the safety or rights of users or another person;
- establish, exercise, or defend legal claims.
We do not permit service providers to use personal data for unrelated purposes on our behalf.
7. International Data Transfers
Owlin and its service providers may process information in countries other than your country of residence.
Where required by applicable law, international transfers will use an appropriate legal mechanism, such as:
- an adequacy decision;
- standard contractual clauses;
- another legally recognised transfer safeguard.
Primary database or hosting region: France
8. Data Retention
Personal data is retained only as long as reasonably necessary for the purposes described in this Policy, including security, dispute resolution, accounting, and legal compliance.
| Data category | Proposed retention period |
|---|---|
| Active account and entitlement data | For the duration of the account |
| Deleted account data | Up to 90 days after deletion, unless legally required for longer |
| HWID and device-binding data | While access is active, plus 90 days |
| IP address, region, and security logs | 180 days |
| Failed login and abuse-prevention records | 180 days |
| Support correspondence | 12 months after closure |
| Terms and policy acceptance records | 5 years or the period needed to establish legal claims |
| Transaction and accounting records | The period required by applicable tax and accounting law |
| Local application logs | Until deleted by the user or automatically removed by the application |
We may retain limited information for longer where necessary to:
- comply with law;
- investigate fraud or security incidents;
- resolve disputes;
- enforce a continuing restriction;
- establish or defend legal claims.
Data should be deleted or anonymised when it is no longer required.
9. Data Security
We use reasonable technical and organisational measures intended to protect personal data, including:
- authenticated server requests;
- access controls;
- database security rules;
- device-binding checks;
- encryption in transit;
- restricted administrative credentials;
- signed server responses where applicable;
- monitoring and security logging.
No system can guarantee absolute security.
You are responsible for protecting your Discord account, device, credentials, and authentication tokens.
Do not share refresh tokens, access tokens, passwords, or protected application files.
10. Local Storage and Credential Storage
The desktop application may store information locally, including:
- configuration settings;
- cached policy versions;
- application logs;
- authentication session information;
- refresh tokens stored through operating-system credential storage where supported.
Local data may remain until:
- the application removes it;
- the user logs out;
- the user clears application data;
- the application is uninstalled;
- the operating-system credential entry is manually removed.
Uninstalling the application may not automatically delete every credential or diagnostic file, depending on the operating system.
11. Your Rights
Depending on your location, you may have rights to:
- receive information about processing;
- access personal data;
- correct inaccurate data;
- request deletion;
- restrict processing;
- object to certain processing;
- receive portable data where applicable;
- withdraw consent where processing is based on consent;
- lodge a complaint with a competent data-protection authority.
These rights may be limited where retention or processing is legally required or necessary to protect security and legal claims.
To exercise a privacy right, contact:
Support Channel on our official Discord server
We may need to verify your identity before completing a request.
12. Account and Data Deletion
You may request deletion through:
Support Channel on our official Discord server
Deleting an Owlin account may remove or anonymise associated account, access, and HWID information, subject to applicable retention requirements.
Deleting your Discord account does not necessarily delete information previously stored by Owlin. You must separately contact Owlin where deletion is requested.
13. Children’s Privacy
The Service is not intended for anyone below the minimum legal age required to use the Service or Discord in their country.
We do not knowingly seek to collect personal data from children who cannot legally consent or use the Service.
A parent or guardian who believes that a child’s information has been collected unlawfully should contact:
Support Channel on our official Discord server
14. Cookies and Website Storage
The Owlin website uses only storage or cookies strictly necessary for security, authentication, and core website functionality. It does not use advertising or optional analytics cookies.
15. Third-Party Links and Services
The Service may contain links to Discord, Steam, TruckersMP, game websites, payment services, or other third-party services.
Their processing is governed by their own terms and privacy policies.
Owlin is not responsible for the privacy practices of independent third parties.
16. Changes to This Policy
We may update this Policy when:
- collected information changes;
- features or providers change;
- security practices change;
- legal requirements change.
The updated date will appear at the top.
For material changes, notice may be provided through the application, website, Discord server, or account interface.
Where legally required, we will request new consent or acknowledgment before applying a materially different processing purpose.
Continuing to use the Service does not by itself create valid consent where applicable law requires an explicit choice.
17. Complaints
Please contact us first so we can review your concern:
Support Channel on our official Discord server
Where the GDPR applies, you may also lodge a complaint with the data-protection authority in your country of residence, employment, or the place of the alleged infringement.
18. Contact
Data controller:
Owlin development team (Ukraine)
Official support server: