Data Protection
Privacy Policy
Last updated: August 28, 2026.
LanguageEnglishItalianoFrançaisРусскийУкраїнськаDeutschEspañolPortuguêsPolskiRomânăTürkçeNederlandsSvenskaČeštinaMagyarΕλληνικάБългарскиСрпскиHrvatskiSlovenčinaالعربيةעברית日本語한국어中文हिन्दी
1. Introduction
SecurityBot ("we," "us," "our," "the Service") is a Discord bot operated by the individual operator danidema.xyz. We are committed to respecting your privacy and to handling the personal data we process in connection with the Service in a transparent and careful manner.
This Privacy Policy explains what data we collect, why we collect it, how long we keep it, who we share it with (and why), and what rights you have. It covers the Bot's Discord features as well as the website, dashboard, developer portal, and premium features.
Where this Policy refers to "you" or "your data", this includes server administrators, server members, and visitors to the website. References to "Discord", "Google", "YouTube", "Stripe", and "GitLab" are references to those third-party services as applicable.
2. The Operator (No Company)
The Service is operated by an individual and is not a registered company.
- The Operator does not hold a VAT identification number (Partita IVA) and does not issue formal invoices.
- Payments are processed by Stripe, which issues its own receipts; we do not process or store payment-card data ourselves.
- Because the Operator is a natural person, the processing of your personal data is performed with normal, commercially reasonable administrative and technical safeguards, but the Operator does not maintain the dedicated compliance apparatus of a larger organization (such as a formally appointed Data Protection Officer).
- All contacts regarding privacy may be directed to the addresses listed in Section 19 of this Policy.
This Privacy Policy is intended to be read alongside our Terms of Service.
3. Data Controller
For the purposes of applicable data-protection law, the Operator is the "controller" of the personal data described in this Policy where the Operator determines the purposes and means of the processing. For parts of the Service where administrators of a Discord server configure specific features (for example, recording, tickets, or moderation) the server administrator is a controller (or independent controller) of the resulting data, and the Operator processes such data on the administrator's behalf and to operate the feature.
Where the Operator processes data on behalf of a server administrator, the administrator is responsible for lawfulness of that processing, for providing notice to members, and for responding to members' requests, and the Operator acts as a processor.
4. What Data We Collect
We limit what we collect to what is needed to operate the Service. The categories of data we may process are described below.
4.1 Discord Identification Data
- Discord User IDs, Guild (Server) IDs, and relevant Channel, Role, and Message IDs, used to manage permissions, warnings, economy, XP, tickets, premium access, and blacklists.
- Discord usernames / display names and, where you use the website, avatar data, for identification in dashboards and audit features.
4.2 Server Configuration Data
- Custom settings stored per server: welcome messages, logging channels, auto-roles, ticket panels, temp-voice channels, counters, moderation thresholds, filters, custom commands, tags, auto-publishing, birthdays, and similar configuration.
- Saved embeds, role-reward mappings, leveling settings, and any other server configuration you create through the Bot or dashboard.
4.3 Activity and Community Data
- Leveling/XP amounts, economy balances, inventories, leaderboards, reminders, AFK status, polls, quotes, ship/roll/coinflip results, gamestate, and similar user-generated data required to provide those features.
- Usage of commands (approximate counts and timestamps) in operational logs.
4.4 Moderation Logs and Audit Trails
- Records related to kicks, bans, timeouts, warns, and unwarns, together with the responsible moderator and timestamp, to provide history and audit features to authorized staff.
- Security audit information such as backup timestamps and settings snapshots.
4.5 Message Content (Transient)
- Message content is processed in real time for word filters, anti-raid detection, custom commands, economy rewards, and similar features.
- It is not stored permanently unless it triggers a security alert or moderation action, or unless it is part of a feature that stores content by design (for example, ticket transcripts, suggestions, saved custom-command responses, or queued media).
- "Snipe" features temporarily retain the most recent deleted/edited messages in memory only; these are ephemeral and are never written to permanent storage.
4.6 Tickets and Transcripts
- When a server uses ticket systems, messages exchanged within open or closed tickets may be stored and provided as transcripts to the server's authorized staff.
- Transcripts remain accessible according to the server's configuration and the retention rules of the storage used.
4.7 Voice Recording and Transcription
- Where a server explicitly enables recording, audio captured by the feature, and any transcriptions generated from it, may be stored locally and/or transferred to remote file storage.
- Recording is off by default and only the server's administrators can enable it and access the output.
4.8 Age Verification Data
- For 18+ gated features, an age-verification flow may be completed inside the app or via the website. We retain only a minimal verification marker/result; we do not retain identity documents.
4.9 Developer Portal / API Data
- Generated personal API keys, generation counts, timestamps, and usage logs associated with your User ID.
- Technical identifiers used to validate generated modules and to enforce rate limits.
4.10 Premium and Payment Data
- Your User ID, Stripe customer reference, subscription/session identifiers, and current subscription period.
- Full card data is never stored by us; it is processed exclusively by Stripe.
4.11 Global Blacklist Data
- User IDs and Guild IDs flagged through our blacklist network, together with minimal reason metadata, to protect all servers using the Service.
4.12 Error and Operational Logs
- Short, memory-backed logs of recent errors, which may include the command name, User ID, Guild ID, timestamp, and error message, used to diagnose issues. The buffer is limited in size and rotates automatically.
5. How We Use Your Data
Your data is used strictly for the following purposes:
- Operating the Service, including all commands, features, dashboards, and integrations.
- Ensuring server security via Anti-Nuke, Anti-Raid, filters, permissions auditing, and the Global Blacklist.
- Providing custom community features requested by administrators.
- Processing Premium access, authenticating accounts, enforcing rate limits, and preventing abuse.
- Authenticating access to the website, dashboard, and developer portal, and keeping you logged in.
- Debugging, monitoring, and improving the reliability and performance of the Service.
- Generating aggregate or anonymous statistics for our website.
- Complying with legal obligations and responding to lawful requests.
We do not: sell user data, use it for advertising or profiling for marketing, or share it with third parties beyond what is necessary to operate the Service (as described in this Policy).
6. Legal Bases of Processing
Where the GDPR or equivalent law applies, we process personal data on the following bases:
- Performance of a contract (Art. 6(1)(b) GDPR): processing the data needed to provide the Service and its features to you and your server, in accordance with our Terms.
- Legitimate interests (Art. 6(1)(f) GDPR): operating and securing the Service, maintaining the Global Blacklist, preventing abuse and fraud, debugging, and improving our products. We balance these interests against your rights and freedoms.
- Consent (Art. 6(1)(a) GDPR): for specific processing where we ask for and you grant your consent, which you may withdraw at any time.
- Legal obligation (Art. 6(1)(c) GDPR): where we must process data to comply with the law.
For data processed on behalf of server administrators (controllers), the legal ground for that processing is determined by the administrator, not by us.
7. Data Storage and Security
We store data in a private database with access restricted to the Operator and the Service's core systems. We apply reasonable administrative, technical, and organizational safeguards appropriate to a personal project, including:
- Restricted access to production systems and credentials;
- Use of secrets/environment configuration for sensitive tokens and keys rather than hardcoded credentials;
- Replication and redundancy of core data where configured (e.g., primary/standby server synchronization);
- Transfer of sensitive or large artifacts (backups, recordings, transcripts) to authenticated remote storage rather than leaving them only on the bot host;
- Aggressive cleanup of temporary processing files (downloads, media, exports) after use; and
- Automatic rotation of short-lived operational buffers such as error logs.
No method of transmission or storage is 100% secure. We cannot guarantee the absolute security of your data. Where data is stored or transferred to third-party providers listed in Section 8, the security of that data is additionally governed by those providers' own security measures.
8. Third-Party Services and Sub-Processors
To provide the Service we rely on the following categories of third parties, which may act as processors or independent controllers depending on the context:
- Discord Inc. — the platform on which the Bot operates. Discord receives the data that the Bot legitimately transmits to it (messages, commands, voice events, and API calls) as part of normal Discord usage. See Discord's Privacy Policy for their practices.
- Google / YouTube — used for media resolution, music, and streaming features. Automated requests made to these services are governed by Google's Privacy Policy.
- Stripe — processes payments, issues receipts, and handles all card data for Premium purchases. Stripe acts as our payment processor; we receive from Stripe only transaction identifiers and subscription status.
- GitLab (and similar file/version storage providers) — used to store backups, artifacts, recordings, transcripts, and exported files in authenticated remote repositories.
- Cloud and hosting providers — used for the server, database, networking, and (where applicable) media processing.
- Public package registries and update services — used at runtime only to keep software libraries current; no personal data is transferred to them beyond normal network requests.
- Image-classification and content-filter APIs — used, where enabled, to check shared bot profile images against content policy. Only the image being checked is transmitted, and it is not retained beyond the check.
We do our best to keep this list current. If a provider changes, we will update this Policy. We do not authorize sub-processors to use your data for their own purposes beyond what is necessary to provide their service.
9. International Data Transfers
The Service is operated from servers and uses providers that may be located in the European Economic Area (EEA) and/or outside of it (including the United States and other jurisdictions). By using the Service you acknowledge that your data may be processed in locations outside your country of residence.
Where we transfer personal data outside the EEA to jurisdictions without an adequacy decision, we rely on appropriate safeguards provided by our processors (such as Standard Contractual Clauses offered by our providers, or other equivalent mechanisms), to the extent they apply to our relationship with those providers.
Because the Operator is a natural person, please contact us if you have concerns about a specific transfer and we will explain the safeguards we rely on for that provider.
10. Website and Analytics Data
To operate, secure, and improve the website, dashboard, music dashboard, and owner analytics, we collect limited technical data when you visit:
- IP address — checked against VPN, proxy, and Tor exit lists to protect the site from anonymous network access, and used to determine an approximate country for aggregate statistics.
- Pages visited and the approximate time of each visit.
- Discord identity when you log in through OAuth (user ID and username), associated with your visits for security auditing and to personalize your login experience.
- Console and DevTools error events generated by your browser (e.g., script errors), correlated with your IP and account for debugging.
- Login sessions managed through session cookies and server-side session storage.
This data is stored in our local database, is visible only to the Operator through a restricted owner-only dashboard, and is used solely for security, debugging, abuse prevention, and service improvement. It is never sold and never used for advertising. Raw access-log records are kept for the shortest practical time and are periodically purged.
11. Cookies and Local Storage
We use a minimal amount of cookies and browser storage:
- Session cookies — required to keep you authenticated while using the dashboard and portal.
- Consent cookie (securitybot_consent) — remembers your cookie choice when you use the consent banner.
- Local storage preferences — used to remember basic UI preferences (such as theme) on your own device.
For the full, detailed list of cookies we use, their purpose, and their lifetime, please read our Cookie Policy.
You can delete cookies through your browser at any time; doing so may log you out of the website. Because session cookies are strictly necessary for the dashboard, they are exempt from consent requirements under the ePrivacy Directive.
12. YouTube and Media Features
Media features (music, radio, and streaming) resolve and stream content from third-party platforms such as YouTube (Google). When these features are used:
- automated requests are made to those platforms' services, which may include standard network information and environment signals;
- media extraction tools may check for, and in some cases rely on, browser-session cookies or similar signals to access publicly available content, in accordance with those platforms' rules;
- the content you choose to play is not retained by us beyond the duration of the feature and any minimal operational logs; and
- their handling of your data is governed by their own privacy policies (in particular Google's).
13. Voice Recording and Transcription
The Bot may join voice channels to play music or operate features you configure. It does not continuously listen to, record, or transcribe general conversation.
If a server enables an explicit recording feature:
- recordings are started and accessed only by that server's administrators;
- the administrator is responsible for informing members and obtaining any consent required by law before recording;
- recorded audio and any generated transcriptions may be stored locally and/or in remote authenticated storage until deleted;
- recordings are used only for the feature the administrator enabled and are not used for any other purpose; and
- transcription may be performed by our own tooling or by third-party speech-recognition services where configured; in that case the snippet processed is subject to that provider's processing terms.
14. Content Played or Recorded Through the Bot
The Service only relays, plays, downloads, or records content that you or your server selects. We do not own, create, control, license, or endorse the audio, songs, streams, files, or recordings you choose, and we are not responsible for the material contained in content sourced from third-party platforms such as YouTube.
Any copyright, licensing, consent, or content-related question about what is played, downloaded, or recorded is the responsibility of the person or administrator who selects or enables it. Where media is downloaded or processed for you (for example, to deliver a file), it is processed transiently and deleted afterward unless you save it.
15. Age Verification
Certain features are restricted to users aged 18 or older. When such features are used, an age-verification flow may be performed with the help of external verification services and an in-app web view.
- We receive and store only a minimal confirmation result/marker from the verification process.
- We do not retain identity documents.
- We do not share your information with third parties for marketing purposes.
- You are responsible for the accuracy of the information you provide during verification, and for any legal consequences of providing false information.
16. Automated Decisions and Profiling
Parts of the Service operate automatically:
- Anti-Nuke / Anti-Raid: automated moderation decisions (e.g., banning or timing-out users) based on configurable thresholds and events. These are designed to protect servers in real time and may affect you if you trigger the configured thresholds.
- Global Blacklist: automated restriction based on presence on the shared blacklist network.
- Content policy: automated rejection of images/profile content that matches prohibited terms or categories.
- Anomaly/reputation measures: IP reputation checks (VPN/proxy/Tor) on the website to block anonymous abuse.
These automated decisions are made for security and anti-abuse purposes. Where such a decision affects you and you believe it is wrong, you may contact us to request a human review (see Section 19); automated decisions of this kind are generally made because activity matched clearly defined abuse thresholds.
17. Data Retention and Deletion
We keep data only as long as necessary for the purposes described in this Policy. The general schedule is:
- Configuration and feature data — retained while the server uses the relevant feature, and deleted when the feature is removed or the server is blacklisted, or on request.
- Moderation history — can be cleared by authorized server staff at any time.
- Recordings and transcripts — retained until deleted by the responsible administrator (or on user request); there is no indefinite retention commitment.
- Backups — rotated and purged according to our schedule; older snapshots are deleted automatically.
- Error log buffers — limited and rotating; kept in memory only.
- Website access/analytics records — periodically purged; raw logs are kept only as long as needed for abuse prevention.
- Blacklist entries — retained as long as the flagged behaviour poses a risk to the community.
- Age-verification markers — retained only while needed to enforce the access gate.
We believe in data minimization and will delete data where we control it, as soon as the purpose for which it was collected no longer requires it.
18. Your Rights
Depending on your jurisdiction (in particular if you are in the EEA or the UK), you may have the following rights regarding the personal data we process:
- Access: to obtain confirmation of what data about you we process and a copy of it.
- Rectification: to have inaccurate or incomplete data corrected.
- Erasure ("right to be forgotten"): to request deletion of data about you where we control it and where legal grounds for deletion apply.
- Restriction: to request that we limit how we process your data in certain cases.
- Data portability: to receive the data you provided in a structured, machine-readable format, where technically feasible.
- Objection: to object to processing based on our legitimate interests, on grounds relating to your particular situation.
- Withdrawal of consent: where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Lodge a complaint: to complain to your local data-protection supervisory authority.
How to exercise your rights. Send your request to the addresses in Section 19 with enough detail for us to identify you and locate your data (for example, your Discord User ID and the server(s) involved). We will respond on a best-efforts basis. For data controlled by a specific server's administrators (e.g., recordings, tickets, moderation logs), please contact those administrators first, as they are best placed to act on it; we will assist where we are able as processor.
We may ask you to verify your identity before acting on a request, and we may not be able to fulfil a request where we cannot identify you, where the law requires us to keep the data, or where the data is controlled by a third party.
19. Contact Us
For any privacy-related inquiries, data-deletion requests, promotion or rights requests, or concerns about our processing practices, please contact us:
Please include your Discord User ID and as much context as possible so that we can locate and act on your request efficiently. We aim to respond within a reasonable time; while the Operator tries to respond within 30 days, no specific response time is guaranteed.