Privacy Policy
Effective date: 2026-06-11 — Last updated: 2026-06-11
This policy describes what information the bot ("Service") collects when it is added to a Discord server, how that information is used, and your rights regarding it. By adding the bot to your server you agree to this policy.
1. What we collect
The Service processes messages in memory only in order to scan for policy violations. The following data is written to a local SQLite database when a relevant event occurs:
- Violations — when a message triggers the filter: Discord user ID, username at the time, channel ID, server ID, the matched term, a copy of the message content, a confidence score, and a timestamp.
- Warnings — when a moderator issues a warning: the warned user's ID, the moderator's ID and name, reason text, channel ID, and a timestamp.
- False-positive reports — when a user or moderator flags an incorrect match: user ID, username, the flagged word, the original phrase, and a timestamp.
- Voice activity — when a member joins or leaves a voice channel: user ID, channel ID, server ID, join time, and session duration (in seconds). No audio is retained.
- Bot usage summaries - when a user actually uses the bot or is scanned by it: Discord user ID, username at the time, server ID, channel ID, first/last seen timestamps, last command/component name, and aggregate usage counters. Message text is not stored in these summaries.
- Admin & whitelist IDs — Discord user/role/channel IDs that have been granted admin access or added to the whitelist via bot commands.
- Learned patterns — normalised word roots (no usernames or IDs) derived from violation text by the self-learning engine.
- Moderation cases — timeouts, kicks, bans, unbans, and moderator notes: the affected user's ID and username, the moderator's ID and name, reason text, and a timestamp.
- Tickets & appeals — support ticket subjects, status, and who claimed/closed them; ban appeal text and its review outcome. Tied to the submitting user's ID.
- No-contact orders — the Discord IDs of the two users placed under a no-contact order and any nicknames/aliases a moderator adds for name-mention detection.
- Premium status — for servers with premium: the tier, who granted it, and its expiry date. No payment details are stored (see section 5).
Message content that does not trigger a match is never written to disk.
2. Why we collect it
- Violation records let moderators review what was caught and appeal decisions.
- Warning history lets moderators track repeat offenders.
- Voice activity is used only for the
/activityserver-statistics command. - Bot usage summaries show who actually used or was processed by the bot without storing message content.
- Learned patterns improve detection accuracy over time.
We do not use any data for advertising, analytics, or sale.
For users in the European Economic Area or United Kingdom: we process this data on the basis of legitimate interest — specifically, the legitimate interest of you and your server's admins in maintaining a safe community and enforcing your server's rules.
3. How long data is retained
We automatically delete the following on a rolling basis, regardless of whether the bot is still in your server:
- Violation records — after 90 days.
- Voice/server activity records — after 90 days.
- Ban appeals — after 180 days.
- Moderation cases (timeouts, kicks, bans, notes) — after 365 days.
Warnings, tickets, no-contact orders, admin/whitelist IDs, and premium status are not subject to a fixed retention period and persist as long as the bot remains in your server, since they're actively relied on for ongoing moderation. Server owners and admins can delete individual warnings, whitelists, and other records directly using bot commands or the dashboard where those controls are available. Data you'd like deleted sooner, or data associated with a server that has removed the bot, can be requested for deletion by contacting us (see section 11).
4. Who can access your data
- Server admins & owners — can view and delete violations, warnings, and whitelists for their server via bot commands and the web dashboard.
- Bot owner — has access to all stored data for maintenance and debugging purposes only.
- Third parties — data is never shared, sold, or disclosed except where required by law.
5. Third-party services
- Discord — the bot operates on Discord's platform. Discord's Privacy Policy governs data they hold.
- Google Translate — when translation scanning is enabled, non-English message
text is sent to Google Translate. Message text sent to this API is subject to
Google's Privacy Policy.
You can disable translation scanning at any time with
/settranslation off. - Sightengine — when a server owner enables NSFW image scanning with their own Sightengine API credentials, images posted in that server are sent to Sightengine for content classification. Off by default and requires the server's own API keys to enable.
- Ko-fi / Stripe — premium purchases are processed entirely on Ko-fi's or Stripe's own checkout pages. We never receive or store payment card details — only a webhook notification confirming the guild ID, tier, and duration purchased.
6. International data transfers
Your data may be processed or stored in a country other than your own, including the United States, where the bot's hosting provider and the third-party services listed in section 5 (Google Translate, Sightengine) operate. Where required, we rely on the transfer safeguards those providers make available (such as their own compliance with recognised data-protection frameworks) to protect data moved across borders.
7. Security
The database is stored locally on the server running the bot. The web dashboard requires Discord OAuth authentication and uses signed, HTTP-only session cookies. We take reasonable steps to protect stored data but cannot guarantee absolute security.
8. Cookies
The dashboard sets a single session cookie when you log in with Discord OAuth. It's strictly functional — it identifies your logged-in session so the dashboard knows which server(s) you can manage — and is not used for tracking, analytics, or advertising. It's cleared when you log out or expires automatically after a period of inactivity. We do not use any other cookies.
9. Data breach notification
If we become aware of a security breach that compromises your personal data, we will notify affected server owners and/or users without undue delay, as required by applicable law.
10. Children's privacy
The Service is not directed at children under 13 (see the age requirement in our Terms of Service), and we do not knowingly collect data from anyone under that age. If you believe a child under 13 has provided data through the Service, contact us (see section 11) so we can delete it.
11. Your rights & contact
For the purposes of applicable data-protection law, the bot owner is the data controller for the data described in this policy.
You may request the following by contacting us: deletion of your personal data (violation records, warnings, voice activity, and bot usage summaries associated with your user ID); access to a copy of it; correction of inaccurate data; and, where applicable under EU/UK GDPR, restriction of, or objection to, our processing of it, and portability (a machine-readable copy to transfer elsewhere). Server owners may also use bot commands to manage records within their own server without contacting us.
California residents: we do not sell or share your personal information, so there is nothing to opt out of. You may still request access to or deletion of your data as described above.
Contact: legendzz749@gmail.com
12. Changes to this policy
We may update this policy. Material changes will be announced in the support server. Continued use of the bot after changes constitutes acceptance.