Clear boundaries for money and access.
Creator-owned payments
Stripe handles card information. Memberalia does not store card data or hold creator revenue. Membership payments are created on the connected creator account. Memberalia’s subscription is separate.
Credentials and identity
Stored sensitive integration data uses AES-256-GCM authenticated encryption with an environment-managed key. The shared Telegram bot token lives only in the platform environment secret store; communities never store bot tokens. Identity linking uses immutable Discord and Telegram IDs and expiring single-use tokens.
Webhook and permission checks
Stripe signatures and Telegram webhook secret tokens are verified. Stripe event IDs prevent duplicate processing. Discord hierarchy and forbidden administrator roles are checked again when access changes run.
Workspace isolation
Server-side authorization and database relationships scope workspace data. Roles distinguish owners, administrators, operators and viewers. Production sessions use secure cookies and opaque tokens.
Recovery
Jobs retry temporary failures with backoff. Reconciliation checks desired access against provider access. Persistent errors remain visible.
Backups
Deployment includes persistent database storage. The operator must configure scheduled off-host backups and restore drills. A Docker volume alone is not a backup. No certification or recovery-time guarantee is claimed.
Report a problem
The operator has not published an incident email yet. Use the support contact supplied with your workspace. Do not send credentials.