The short version: we store Discord IDs and the settings you configure, on a private server we own and administer ourselves. The database is not exposed to the internet, not hosted with a third-party cloud database provider, and never sold or shared with advertisers. Message content is only kept where a feature you enabled requires it, and it expires.
Summary table
- Controller: the operator of Royal Bot.
- Storage: self-hosted MongoDB on a private server, bound to the loopback interface.
- Third-party processors: none for the database. Discord itself is unavoidably involved as the platform.
- Selling data: never.
- Deletion: automatic on removal, or on request.
1. Who we are
This policy applies to Royal Bot, a Discord application operated by the operator. For the purposes of data-protection law, we act as the data controller for the information described below. You can reach us at support@example.com.
2. What we collect
We collect the minimum needed for the features you enable.
Always stored
- Discord identifiers: guild IDs, channel IDs, role IDs, user IDs and message IDs. These are numeric references, not personal profiles.
- Server configuration: prefixes, enabled modules, log channel choices, automod rules, XP rates, ticket categories and similar settings you set yourself.
Stored only if the relevant feature is enabled
- Moderation records: case type, target user ID, moderator ID, reason text you type, timestamp and duration.
- Ticket transcripts: the messages sent inside a ticket channel, saved when the ticket is closed so staff can review it.
- Audit and message logs: where you enable message-delete or message-edit logging, the content of the affected message is processed and posted to your chosen log channel; a short-lived copy may be cached to make that possible.
- Leveling data: XP totals, level, last-message timestamp and accumulated voice minutes.
- Invite tracking: invite codes, inviter user IDs, join and leave counts.
- Giveaways and reminders: entrant user IDs, prize text, reminder text and scheduled times.
Operational data
- Diagnostic logs: command names, error stack traces, latency and timestamps, used to fix bugs. These are rotated and deleted regularly.
3. What we never collect
- Your Discord password, email address, phone number, or payment details.
- Your Discord authentication token.
- Direct messages between users, or messages in servers where the Bot is not present.
- Message content stored "just in case" — if a feature doesn't need it, it isn't kept.
- Biometric data, precise location data, or any special-category personal data.
- Anything used to train machine-learning models. Your data is never used for that.
4. Why we collect it (and our legal basis)
We process this data to provide the features you asked for, to keep the Service secure and abuse-free, and to diagnose faults. Where the UK/EU GDPR applies, our legal bases are performance of a contract (delivering the functionality you invited the Bot to provide) and legitimate interests (keeping the Service running, secure and free from abuse). Where consent is the appropriate basis, you give it by enabling the optional feature in question.
5. Where your data is stored
This is the part most bots gloss over, so here is the detail.
- The database is MongoDB running locally on a private server that we own and administer directly. It is not a shared cloud database service, and no managed-database vendor holds a copy or has query access.
- The database process listens on
127.0.0.1only. There is no publicly routable database port, so it cannot be reached from the internet at all — not with a password, not with a leaked connection string. - The bot process and the database sit on the same machine and communicate over the loopback interface, so query traffic never crosses a public network.
- The administrative dashboard is likewise bound to localhost and reached through an authenticated SSH tunnel or a TLS-terminated reverse proxy. It is not open to the public web.
- Server logs and backups stay on infrastructure under our control.
6. How it's secured
- Host hardening: SSH key authentication only with password login and root login disabled, a default-deny firewall exposing only the ports we actually need, fail2ban on repeated failures, and automatic security updates.
- Database authentication: authorisation is enforced, and the application connects with a least-privilege user scoped to its own database rather than an administrative account.
- Secrets management: tokens and connection strings live in environment variables with restrictive file permissions, never in the source tree or a public repository, and are rotated if exposure is suspected.
- Encryption in transit: all traffic to Discord uses TLS. Dashboard access is over TLS or an encrypted SSH tunnel.
- Encryption at rest: the storage volume is encrypted, and backups are encrypted before they leave the machine.
- Backups: taken on a regular schedule, stored on controlled media, rotated, and restore-tested. Expired backups are destroyed rather than kept indefinitely.
- Access control: only the bot owner holds shell access. There is no shared login and no third-party contractor access.
- Monitoring: process, resource and error monitoring with alerting so anomalies are noticed quickly.
No system is perfectly secure. We apply the measures above in good faith and keep the amount of data we hold small precisely so that the impact of any incident stays small — but we cannot guarantee absolute security, and you should not send genuinely sensitive personal information through Discord.
7. Sharing and disclosure
We do not sell, rent, trade or licence your data to anyone. We do not run third-party advertising or analytics inside the Bot.
Data may be disclosed only in these narrow cases:
- To Discord, unavoidably, since the Bot operates on their platform — their handling is governed by their own privacy policy.
- Within your own server, where the Bot posts to log or ticket channels you configured. Who can read those channels is controlled by your permissions, not ours.
- To authorities, where we are legally compelled, or where disclosure is necessary to prevent serious harm — such as reports of child sexual abuse material, which we report without hesitation.
8. How long we keep it
- Guild configuration: kept while the Bot is in your server, then deleted within 30 days of removal.
- Moderation cases: retained while the Bot is in the server so history stays useful, unless you delete a case yourself.
- Ticket transcripts: retained per your configured period, defaulting to 90 days.
- Cached message content for logging: short-lived, typically minutes to hours, and never a permanent archive.
- Diagnostic logs: rotated and deleted, typically within 14 days.
- Backups: rotated on schedule, so deleted records may persist in an encrypted backup for a short additional window before being overwritten.
9. Your rights
Depending on where you live, you may have the right to access the data we hold about you, correct it, delete it, restrict or object to processing, receive a portable copy, and complain to your local data-protection authority. We honour these requests regardless of jurisdiction where we reasonably can.
To exercise a right, contact us with your Discord user ID. We may ask you to verify control of that account, and we aim to respond within 30 days.
10. Deleting your data
- Server data: remove the Bot from the server and the associated records are purged on the retention schedule above. For an immediate wipe, ask us from an account with Manage Server permission.
- Personal data: ask us to erase records tied to your user ID — XP, cases, invites, reminders and so on. Some moderation records may be retained where a server operator has a legitimate interest in keeping an accurate enforcement history; we'll tell you if that applies.
- Turnaround: usually within 72 hours, and always within 30 days.
11. Children
The Service is not directed at children under 13, or under the minimum age required by Discord in your country, whichever is higher. We do not knowingly collect data from anyone below that age. If you believe we hold data about a child, contact us and we will delete it promptly.
12. This website
This site is a static page hosted on GitHub Pages. It sets no cookies and runs no advertising or analytics scripts. GitHub may log standard request information such as IP address for security and abuse prevention, as described in the GitHub Privacy Statement. Fonts are loaded from Google Fonts, which receives the request in order to serve the file; self-host the font files if you would rather avoid that.
13. Breach notification
If a security incident affects your data, we will investigate promptly, take steps to contain it, and notify affected server owners through the support server and, where required, the relevant supervisory authority — normally within 72 hours of becoming aware.
14. Changes to this policy
We may update this policy as the Bot changes. The "last updated" date will change and material updates will be announced in the support server. Continued use after an update means you accept the revised policy.
15. Contact
Privacy questions, access requests and deletion requests go to support@example.com or to the support server.
Template notice: this is a general template written to match a self-hosted setup, not legal advice. Adjust every claim so it describes what you actually do — and if a bullet above isn't true of your server yet, either implement it or remove the line. Overstating your security posture is worse than saying nothing.