Trust & transparency
Privacy Policy
Effective August 28, 2026. This plain-language policy describes the current SetupSheet implementation.
Information we collect
When you sign in with Discord, SetupSheet receives the account information Supabase Auth makes available, such as your Discord user id, display name, avatar, and email address when provided. Your account id is used to associate your contributions with you.
If you contribute, we store the setup metadata, tuning values, lap times, descriptions, tags, rig profile, ratings, upvotes, favorites, follows, comments, requests, notifications, proof links, and files or telemetry you choose to upload. Public setup and profile fields are visible to site visitors.
How we use information
We use this information to authenticate contributors, publish and attribute community setups, calculate ratings and contributor statistics, provide downloads, show notifications, and protect the service from abuse. The current application does not include advertising, analytics, tracking pixels, or third-party chat widgets.
Service providers and public content
SetupSheet uses Supabase for authentication, database, and file storage; Discord for the sign-in provider; and the hosting provider for application delivery. These providers may process technical information as described in their own policies.
Anything you intentionally publish as a setup, comment, profile name, avatar, proof link, or contributor statistic may be publicly visible. Do not upload personal, confidential, copyrighted, or malicious material.
Cookies, local storage, and retention
Supabase Auth uses secure session cookies so sign-in works. The upload form may save an in-progress draft in your browser's local storage, and the browse page may save your last-used filters. These browser values are not sent to SetupSheet until you submit an action.
Contribution data is retained while the account or contribution remains active. The current application does not yet provide an automated self-service account deletion control; deletion requests require a manual review.
Your choices and deletion requests
You can remove your own setups, comments, favorites, follows, and notifications through the available product controls. You can also submit an account and data-deletion request for manual review. Do not include passwords, access tokens, private Discord information, or other sensitive data in a public issue.
The request workflow records your request for a trusted project operator; it does not automatically delete the Supabase Auth account. If the service later operates under a formal legal entity or adds a privacy contact address, that contact should replace the repository link in this policy.
Children and policy changes
SetupSheet is a general sim-racing community and is not directed at children. We may update this policy when the product, providers, or legal requirements change. The effective date above will be updated when the text changes.