Legal · Your data

Privacy Policy

Last updated: April 19, 2026

01 Who We Are

This Privacy Policy explains how ToTheMoon Picks ("ToTheMoon," "we," "us," or "our") handles personal information in connection with tothemoonpicks.com, our Discord community, and the premium DubClub subscription service (collectively, the "Service").

02 What We Collect

We operate a static marketing website plus a Discord community plus a third-party DubClub subscription. The data we directly collect is minimal:

Website (tothemoonpicks.com)

  • Server logs: our hosting and content-delivery providers record standard request metadata such as IP address, user agent, referring URL, and timestamp for security, diagnostic, and abuse-prevention purposes. These logs are retained briefly and not sold.
  • No cookies for tracking. The site itself does not set tracking cookies. Our content-delivery and typography providers may set minimal technical cookies strictly required to deliver the page.

Discord community

  • When you join our Discord server, Discord collects and processes your profile data under Discord's own Privacy Policy. We see your Discord username, avatar, and messages you post in our server.
  • Future functionality may include a Discord bot that relays selected public channel content (for example, messages from the wins or testimonials channels) to the website. If and when that runs, only content you voluntarily post in designated public channels is mirrored.

DubClub subscription

  • All billing, identity, and payment-method data for subscribers is collected and processed by DubClub under its own privacy policy. We do not see or store your card details. We receive subscription status and (optionally) a display name so we can grant premium access.

What we never collect

  • We do not collect Social Security numbers, government IDs, precise geolocation, or health data.
  • We do not buy data from brokers. We do not enrich user profiles with third-party data.

03 How We Use It

We use the minimal data we have to:

  • Operate and secure the website, Discord server, and subscription gating.
  • Diagnose outages, performance issues, and abuse.
  • Provide customer support when you reach out in Discord.
  • Communicate service updates in Discord or through DubClub's notification system.
  • Comply with legal obligations and enforce our Terms.

We do not sell, rent, or trade personal information. We do not use personal information for automated decision-making with legal or similarly significant effects.

04 Third Parties

The Service relies on the following categories of third parties. User-facing platforms are named so you know where your data goes; back-end infrastructure vendors are described by role. Each has its own privacy policy governing the data they independently collect.

User-facing platforms

Back-end infrastructure (categories)

  • Hosting & content delivery providers that serve the website and cache assets globally.
  • DNS and edge-security providers that route traffic and mitigate abuse.
  • Typography provider that serves the web fonts used on the site.
  • Analytics (privacy-preserving, cookieless) to measure aggregate traffic and site performance.

We may add or change infrastructure vendors without notice. Material changes to the user-facing platform list above will be reflected here on the next update. To request specific vendor names for data-subject-access purposes, contact us through the Discord.

05 Cookies & Tracking

We do not use first-party marketing or analytics cookies on the website as of the date above. Third-party services (Fontshare CDN, Vercel edge) may set minimal technical cookies strictly necessary to serve content. If we later add analytics, we will update this section and, where required, present a consent banner to visitors from qualifying jurisdictions.

06 Data Retention

We retain data only as long as needed to provide the Service and meet legal requirements. Server logs are typically retained for a short, rolling window (days to weeks) for security diagnostics. Discord messages remain under Discord's retention controls and may be deleted by users or moderators. DubClub retains subscription records per its own policy and applicable financial-records laws.

07 Your Rights: California (CCPA/CPRA)

California residents have the right to:

  • Know what personal information we collect, disclose, or sell (we do not sell personal information).
  • Access the personal information we hold about you.
  • Delete personal information we hold about you, subject to legal exceptions.
  • Correct inaccurate personal information.
  • Limit the use of sensitive personal information (we do not collect sensitive categories).
  • Non-discrimination for exercising these rights.

To exercise a right, contact us through the Discord and mark your request "CCPA REQUEST." We will verify your identity before responding.

08 Your Rights: European Economic Area (GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation, including:

  • Right of access, rectification, and erasure.
  • Right to restrict or object to processing.
  • Right of data portability.
  • Right to lodge a complaint with your local Data Protection Authority.

Our legal bases for processing are (a) legitimate interests in operating, securing, and improving the Service, (b) performance of a contract where you have an active subscription, and (c) legal obligations we must meet. To exercise a right, contact us in Discord and mark the request "GDPR REQUEST."

09 Children

21+ only. The Service is not intended for anyone under 21 years of age. We do not knowingly collect data from anyone under 13 as defined by COPPA, and we prohibit use of the Service by anyone under 21 per our Terms.

If you believe a minor has provided us with personal information, contact us in Discord so we can delete it.

10 Security

We take commercially reasonable measures to protect the minimal personal data we handle, including TLS encryption for traffic and access controls on any administrative systems. No system is perfectly secure; if we become aware of a breach that materially affects your data, we will notify affected users as required by law.

11 International Users

The Service is operated from the United States. By using the Service from outside the United States, you understand that your data may be transferred to and processed in the United States and other jurisdictions where data-protection laws may differ from those of your country.

12 Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced in the Discord and reflected at the top of this page with a revised "Last updated" date. Your continued use after an update constitutes acceptance.

13 Contact

Reach us through our Discord community: discord.gg/hxNeEkkfue. For privacy-specific requests, mark your message "PRIVACY REQUEST" or the applicable framework ("CCPA REQUEST," "GDPR REQUEST") so it routes to the right reviewer.