Privacy Policy
Last updated: 11 Oct 2026
This policy explains what data the Discord Bot bot and its dashboard process, why, on what legal basis and for how long, and how you can manage your data. It applies to dashboard users, members of Discord servers where the bot runs, and visitors of the dashboard website.
In short
- We do not sell data, show ads, or use analytics or trackers.
- We do not receive your email address or password: sign-in goes through Discord.
- The bot checks the text of members' messages in memory only and does not store it.
- We do not make automated decisions about people and do not build profiles.
- You can get a copy of your data or have it deleted — see the “Your rights” section.
Who is responsible for the data
The data is processed under the responsibility of the private individual who provides the bot and the dashboard — the controller within the meaning of the EU General Data Protection Regulation (GDPR). Their name and contact details are given below. No Data Protection Officer (DPO) has been appointed: the law does not require it.
Discord server administrators decide for themselves what the bot publishes on their server, which commands to set up, and whether to enable the command usage log. They are responsible for the content they create in the dashboard and for informing the members of their server.
What data we process and why
Signing in to the dashboard
When you sign in with Discord, the dashboard requests the “identify” and “guilds” permissions. Discord provides your profile details (ID, username, display name, avatar and technical profile flags) and the list of your servers with your permissions on them. The dashboard uses the ID, the names, the avatar and the permissions. The dashboard does not request your email address.
The ID, names and avatar are stored in an encrypted session cookie in your browser. The database holds a session record: your ID and your Discord access token in encrypted form. The list of servers is kept only in the dashboard's memory for a few minutes, so that Discord does not have to be asked on every action.
Purpose: signing in to the dashboard and checking which servers you can manage. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Server settings and content
Server administrators create posts, custom commands and the bot persona in the dashboard, and upload images and videos. They are stored together with the server name, channel and role IDs, and the Discord ID of whoever created a post or command, last changed it, or uploaded a file.
Purpose: publishing posts, command replies and the bot's appearance on the server. Legal basis: performance of a contract with the server administrators (Art. 6(1)(b) GDPR). If a post or command text contains personal data of other people, for example mentions, the author of the text is responsible for the lawfulness of using it.
Dashboard activity log
Every change made in the dashboard is recorded in the activity log: who (Discord user ID and name), when, on which server and what was changed, for example the time of a post or the trigger of a command. The log is visible to the administrators of that server in the dashboard.
Purpose: transparency for server administrators, troubleshooting and protection against abuse. Legal basis: legitimate interest of the server administrators and the operator (Art. 6(1)(f) GDPR).
Messages of server members
The bot receives new messages in the server channels it can see, to check whether a custom command is triggered. Discord provides it with the message text, the IDs of the author, the channel and the message, and the author's roles. The text is not stored: the bot checks it in memory and discards it right away. To keep the interval between repeated uses of a command (cooldown), the bot remembers when a member last used a command; this information disappears when the interval ends or when the bot restarts.
Purpose: replying to messages with the commands that server administrators have set up. Legal basis: legitimate interest of the server and its members in the bot working (Art. 6(1)(f) GDPR).
Command usage log
If a server administrator has enabled the command usage log, each bot reply records the command, the ID of the member who triggered it, the channel, the ID of their message and the time. The log is off by default. The dashboard shows only summary statistics from it, without naming members.
Purpose: command usage statistics for server administrators. Legal basis: legitimate interest of the server administrators (Art. 6(1)(f) GDPR).
Direct messages from the bot
If a scheduled post could not be published, the bot sends the post's author a direct message with the reason. For this it uses the author ID stored in the post. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Technical logs
The bot and dashboard services write sign-in and sign-out events, changes made in the dashboard and errors to logs, with user and server IDs, and, when the request limit is exceeded, the client's IP address or network. For each request, the web server records the IP address, the time, the method and address of the requested page, the response status and size, and browser details (User-Agent). If a request fails (for example, while the dashboard is unavailable), the web server records the IP address, the time, the request and the address of the page you came from (Referer) in its error log.
Purpose: security, protection against attacks and abuse, and troubleshooting. Legal basis: legitimate interest of the operator (Art. 6(1)(f) GDPR).
Backups
Backups of the database and the uploaded files are made once a day and before every update of the service. They are stored on the same server and used only for recovery after a failure. Legal basis: legitimate interest of the operator in keeping the service safe (Art. 6(1)(f) GDPR).
Where we get the data
From Discord — when you sign in to the dashboard with your permission, and through the bot that a server administrator added to a server. The rest is entered by dashboard users.
Retention periods
| Data | Kept for at most, days |
|---|---|
| Sign-in session and encrypted Discord token (deleted right away when you sign out of the dashboard) | 7 |
| Dashboard activity log entries | 365 |
| Command usage log entries | 90 |
| Server data after the bot is removed from the server: posts, commands, persona, files and logs | 90 |
| Technical logs of the services | 30 |
| Web server logs with IP addresses | 14 |
| Backups | 14 |
While the bot is on a server, posts, commands, the persona and files are kept until the server administrators delete them. Deleted data disappears from backups and logs when their retention periods end.
Who receives the data
- Discord Inc. (USA). The bot and the dashboard work through the Discord API: they publish messages, change the bot's profile on a server, and get lists of servers, channels and roles. Discord processes this data as an independent controller under its Privacy Policy.
- The server's hosting provider stores the data on its equipment in the Netherlands (EU) on our behalf as a processor (Art. 28 GDPR) and does not use it for its own purposes.
- Public authorities — only when the law requires it.
- We do not share or sell data to anyone else.
Avatars and server icons in the dashboard are loaded from Discord's image server (cdn.discordapp.com), so Discord sees your browser's IP address.
Transfers outside the EU
Discord Inc. is located in the USA. Data is transferred to Discord because without it the bot and the dashboard cannot work on the Discord platform that you use: the transfer is necessary for the performance of a contract (Art. 49(1)(b) GDPR). All other data is stored in the Netherlands (EU).
How we protect the data
The dashboard is available only over HTTPS. The server disk is encrypted. Discord access tokens are stored in encrypted form, and the encryption keys are not included in backups. The database is not reachable from the internet, and only the operator has access to the server. The dashboard serves uploaded files only to signed-in administrators of the server they belong to.
Your rights
Under the GDPR you can:
- get confirmation of whether we process your data, and a copy of it (Art. 15);
- correct inaccurate data (Art. 16) — your name and avatar are updated from your Discord profile the next time you sign in;
- request erasure of your data (Art. 17);
- request restriction of processing (Art. 18);
- receive the data you provided in a machine-readable format (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- lodge a complaint with a data protection supervisory authority in the EU country where you live or work or where you believe the infringement took place (Art. 77).
To exercise your rights, write to the operator — the contact details are in the “Contact” section. We reply within one month; if the request is complex, this period may be extended by two more months, and we will tell you so. We may ask you to confirm that the request comes from the owner of the Discord account, for example by replying to a direct message in Discord.
What happens on erasure
Your sessions and the command usage log entries with your ID are deleted. In the activity log and in the author details of posts, commands and files, your ID and name are replaced with the mark “User data erased”. The changes themselves and the servers' content remain: they belong to the servers and their administrators, and mentions of you in the texts of posts and commands are removed by the server administrators. In backups and technical logs the data disappears when the periods from the “Retention periods” section end. If you sign in to the dashboard again or trigger a command, data starts to be collected again.
What you can do yourself
- sign out of the dashboard — the session and the Discord token are deleted right away;
- revoke the dashboard's access in Discord: “User Settings” → “Authorized Apps”;
- remove the bot from the server — the server's data is deleted when the period from the “Retention periods” section ends, or earlier at the server owner's request;
- turn off the command usage log on the “Settings” tab of “Commands”, if you are a server administrator.
If you are a server member
The bot's work on a server and the command usage log are set up by the server administrators — contact them or us. To stop the bot from receiving your messages, you can leave the server or ask the administrators to remove the bot's access to channels.
A server owner can ask for the server's data to be deleted right away, without waiting for the period to end: remove the bot from the server and write to the operator from the owner's account.
Children
The bot and the dashboard are not intended for children below the age from which Discord allows its service to be used in your country. We do not collect information about age. If you believe a child has given us data in violation of these rules, write to us and we will delete it.
Data breaches
If a personal data breach occurs, we will notify the supervisory authority within 72 hours of becoming aware of it, when the GDPR requires this, and the affected users without undue delay if the breach poses a high risk to their rights. We will also notify Discord, as the Discord developer terms require.
Changes to this policy
When the policy changes, we update the revision date at the top of the page. We announce significant changes in advance on the dashboard website.
Contact
How to report a violation or a vulnerability is described on the Contact page.