Privacy Policy
Last updated: draft, not yet reviewed by counsel.
This is a good-faith draft describing what the product actually collects and does today, written to be accurate rather than generic boilerplate. It has not had legal review and should not be treated as a finished, binding policy until it does.
What we collect
When you log in with Discord, we receive and store:
- Your Discord user ID, username, and avatar
- Your Discord OAuth access and refresh tokens, encrypted at rest (AES-256-GCM) and never sent to your browser
- The list of servers you have Manage Server permission in or own, used only to populate the server picker
For servers the bot is added to, we store the server's ID, name, icon, owner ID, and member count, plus whatever module settings are configured for it (channel/role IDs, message templates, and similar). We do not store message content beyond what a specific module needs to function (for example, a Logging module event, or a moderation case's reason).
Billing data
Payments are processed by Stripe. We store your subscription status, plan, and Stripe customer/subscription IDs — not your card details, which never touch our servers.
How it's used
Solely to operate the product: authenticating you, syncing which servers you can manage, running the modules you've enabled, and processing billing. We don't sell data, and we don't use it for advertising.
Deletion
Removing the bot from a server stops it from acting there but doesn't immediately delete stored data, in case you re-add it. To request full deletion of your account or a specific server's data, contact us from the Support page.
Third parties
Discord (authentication and bot functionality) and Stripe (payments) are the only third parties we share data with, each solely to provide their respective service to you.