Supper policy
Privacy Policy
Updated: July 12, 2026 · Effective date: July 12, 2026 · Version: 2026-07-12.v1 · Operated by Atmosphere Money Inc.
Supper uses your atmosphere account to sign you in and to show your public identity, such as your stable account identifier, handle, display name, and avatar. Sign-in uses your account host's OAuth: Supper stores OAuth session tokens so it can keep you signed in and write records you ask it to publish, and Supper never sees or stores your account password. We also store Supper-specific settings such as your page profile, customization, posts, products, commissions, DMs, reports, and order workflow information. You can also support creators as a guest without an atmosphere account; guest contact details are collected by ATM during checkout rather than through a Supper account.
Supper is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information to Supper, contact us so we can review and delete it where appropriate. Users under the age of majority should use Supper only with permission and supervision from a parent or legal guardian. Purchases, paid memberships, sales, and payouts require a person who can form the applicable payment contract; otherwise a parent or legal guardian must complete and be responsible for the transaction.
Some Supper activity is intentionally public. Public atmosphere account records may be stored on your atmosphere account and read by other apps, relays, indexers, or archives. ATM publicly confirms completed payments from its own atmosphere account. When a supporter confirms checkout with the public option selected, Supper uses that one choice for both a matching public payer record and public purchase or support context on Supper's feed. A signed-in supporter's payer record is stored on their atmosphere account; ATM hosts an anonymous payer record for a guest. When the public option is off, neither record is created, though ATM's payment proof still exists for verification. A creator may separately publish or opt into a public creator proof and minimal entitlement record. Depending on the record type, public payment records may include public payer or recipient identifiers, the originating app, final amount and currency, payment status, payment type or cadence, public catalog or product references, timestamps, and proof references or status. The repository that hosts a record also identifies its account owner. ATM- and Supper-controlled public payment fields do not include emails, billing or shipping addresses, private buyer notes, card details, raw processor account or payment identifiers, private files, or DMs. Text or context you choose to publish to a public feed is public. You should not put private personal information in public page text, public feed messages, product descriptions, or public commission listings.
Supper can also display public social content from Bluesky and other compatible apps, such as posts, replies, profile details, handles, avatars, public engagement counts, and links to original posts. Supper reads this public information so creator pages and support feeds can show social context. If you delete, edit, label, appeal, or report that original social content, you may also need to use the app or service where it was posted, because Supper does not control the original Bluesky post, atmosphere account record, or third-party app view. Bluesky content is also subject to Bluesky's Terms of Service and Community Guidelines.
Private purchase and fulfillment information is kept private. This can include email addresses, shipping addresses, phone numbers, buyer messages intended for creators only, commission briefs, attachments, paywalled files, download keys, and moderation evidence. We share the minimum information needed with creators, ATM, and the vendors that help Supper operate. Today those vendors include Stripe (payment processing, through ATM), Cloudflare R2 (image and file storage — public images such as avatars and previews are served from a public bucket, while paywalled files live in a private bucket and are delivered through short-lived signed links), Resend (transactional email such as receipts and order updates), Vercel (web hosting), Neon (database hosting), and Upstash Redis (sign-in session storage). We do not sell private buyer contact information. See what personal information is shared for more detail.
Supper DMs, commission discussions, and supporter notes that were not submitted to the public feed are not public atmosphere posts. They are not end-to-end encrypted. Participants can read them, and Atmosphere Money Inc. and service providers may process or review them when needed to deliver the service, investigate reports, enforce policies, protect users, or comply with law. Do not send passwords, full payment-card details, government identifiers, medical information, private keys, or other highly sensitive information through Supper DMs.
Supper uses cookies, local storage, and session storage to keep you signed in, remember account and interface choices, protect sessions, prevent abuse, and support checkout or return flows. We may also keep server logs, request metadata, IP address, browser/device information, referrer information, error reports, and security events so we can run the service, debug problems, detect fraud, enforce rate limits, and protect users. If Supper uses analytics or diagnostics, we use them to understand product health and usage patterns rather than to sell private supporter contact information.
When you accept Supper's policies, we keep an immutable acceptance record containing your stable atmosphere account identifier, the policy version, the acceptance source and time, and keyed hashes of the observed IP address and browser user-agent. We do not store the raw IP address or raw user-agent in that acceptance record. We use this evidence to administer our agreement, resolve disputes, and demonstrate compliance.
ATM currently uses Stripe to securely process payments. Payment details, checkout sessions, Stripe Connect information, KYC/KYB details, card network information, chargebacks, refunds, and tax/payment reporting may be handled by ATM, Stripe, banks, card networks, or other payment partners. Payment-method entry is hosted by Stripe through ATM. Supper and ATM do not receive or store raw full card numbers or card security codes; Stripe and the relevant payment networks handle those payment credentials. Supper passes order context — and, if you are signed in with a confirmed account email, that email as a checkout prefill — to ATM. After a payment completes, ATM sends Supper signed webhook updates with the payment status and the buyer contact and shipping details collected at checkout so Supper can deliver purchases, send receipts, and run order workflows. Guest subscription management links that ATM emails to guests are single-use and expire within 24 hours. ATM's own Privacy Policy explains how ATM handles payment data. Our checkout help, creator payments guide, and refunds policy explain how those flows work.
Creators receive the supporter information needed to fulfill a purchase or manage a supporter relationship. Creators must use that information only for the transaction, support relationship, compliance, and related communications. They must not add supporters to unrelated mailing lists or disclose supporter information without a lawful basis.
Atmosphere Money Inc. is the controller of personal information used to operate Supper and ATM, although each product uses information for its own purposes described in its privacy policy. A creator is generally an independent controller of buyer information the creator receives to fulfill an order or manage a supporter relationship. Vendors process information under our instructions for hosting, storage, email, security, and product operations, while Stripe and financial institutions may also act under their own legal obligations.
We process information to perform our contract with you (including sign-in, publishing, checkout coordination, delivery, subscriptions, and support); to comply with legal, tax, accounting, sanctions, and payment obligations; with consent where required; and for legitimate interests such as securing and improving Supper, preventing fraud and abuse, moderating content, communicating about the service, and protecting users. Where consent is the basis, you may withdraw it for future processing, without affecting earlier lawful processing.
We do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising or use it for targeted advertising. We may disclose information to vendors, creators, payment partners, account hosts, professional advisers, authorities, or a successor in a corporate transaction for the purposes described here. Public information and disclosures you direct are not private disclosures.
We keep information for as long as needed to provide Supper, maintain public records you asked to publish, fulfill purchases, manage subscriptions, comply with accounting/tax/payment obligations, resolve disputes, enforce our policies, preserve trust-and-safety evidence, and protect against fraud or abuse. OAuth sessions and app sessions are retained while they are needed to keep you signed in or perform actions you authorized, and can expire or be revoked. Public atmosphere account records may remain available from your atmosphere account, relays, archives, or other apps even if Supper stops displaying them.
Depending on where you live, you may have rights to know or request access, correction, deletion, or a portable copy; to restrict or object to processing; to withdraw consent; to opt out of sale, sharing, targeted advertising, or certain profiling; and to appeal a denied request. We do not discriminate against you for exercising a privacy right. An authorized agent may submit a request where local law allows, although we may verify both the agent's authority and your identity. We may need to verify your identity and may keep certain records where required or permitted for legal, payment, safety, fraud-prevention, accounting, or dispute reasons. To ask about Supper-held private information or exercise an applicable privacy right, contact contact@atmosphere.money or use the report or appeal flows if the request relates to a safety or moderation action. Manage your portable atmosphere account through your account host rather than Supper.
Supper is operated from the United States and uses service providers that may process information in the United States or other countries. Where required for an international transfer, we rely on an adequacy decision, standard contractual clauses, a provider's approved transfer framework, or another lawful safeguard. You may contact us for more information about applicable safeguards. We use reasonable administrative, technical, and organizational safeguards, but no online service can guarantee perfect security. You are responsible for keeping your atmosphere account, email account, and devices secure.
We may update this policy as Supper, law, or our data practices change. We will post the updated date and version and provide advance notice of material changes when reasonably practicable, seeking new consent where required. Questions or privacy complaints may be sent to contact@atmosphere.money. You may also contact or lodge a complaint with your local privacy regulator.
Need to report something? Report abuse. Questions about these policies? Email contact@atmosphere.money or see the Atmosphere Money legal hub.