SALIBA · LEGAL INFORMATION
Privacy Policy
Pre-release draft: the operator’s legal identity and verified direct contact details are still pending. This document describes the reviewed source code and does not certify the live deployment.
1. Scope and operator
The operator’s legal identity and direct data-request contact details have not yet been provided. The contact section contains the Discord support link supplied by the operator. Because these details are missing, this is not a final privacy notice ready for a verification application.
2. Sources and purposes
3. Data categories
| System | Data and use |
|---|---|
| Discord account and dashboard | User ID, username/display name and avatar; server IDs, names, icons, ownership/permissions and the servers the bot has joined. Used to show manageable servers and authorize settings access. OAuth identity responses may be held in memory; collection is not necessarily limited to fields displayed on screen. |
| Server configuration | Server, channel, category and role IDs; feature switches; security thresholds; YouTube channel IDs and Kick usernames. Stored to apply settings to the relevant server. |
| Moderation and logs | Accessible message content, edit/delete events, user and channel IDs, role/permission changes, bans, kicks, timeouts, audit-log actions, actors and timestamps. Previously accessed content of deleted messages may remain visible in a log channel. |
| Tickets and applications | Ticket owners, participants, support staff, channel IDs, opening/closing and rating information; application answers and interview messages. Closure, approval or rejection workflows may generate transcripts of up to 2,000 messages. |
| Activity and levels | User/server IDs, message counts, voice join/leave times and durations, XP, levels, leaderboard positions and rewards. Voice activity tracking is not audio recording; the reviewed version has no feature that records members’ spoken audio. |
| Invites | Invite codes, use counts, inviter and joining-user IDs, departures and suspicious-account assessments derived from account creation time. Attribution may not always be certain. |
| Birthdays | User-provided day/month, optional birth year, age-visibility preference and time zone; celebration/reward year, role and restoration information such as an earlier nickname. Birthdays are not used for age verification. |
| AFK | User ID, status type, submitted reason, start time and previous nickname. The reason may be shown in the server when the user is mentioned. |
| Economy and games | Server/user IDs, virtual balance, reward streak, work level, inventory/properties, claim times and active game sessions. This version does not request payment-card or bank-account details. |
| Giveaways, boosts and analytics | Entrant, winner and organizer IDs, prize description, end time, boost status, member counts and historical graph values. Results and leaderboards may be visible to other Discord members. |
| Music and other tools | Search queries/links, music queues and requesting accounts; selected translation text and target language; content entered into embeds, announcements and forms. Visibility depends on the command and destination channel. |
| Technical information | Errors, operation times, service responses and IDs from events may appear in console logs. Hosting/network providers receive network information such as IP addresses to establish connections. The reviewed application has no separate persistent HTTP access-log module; any hosting-layer logging must be documented by the operator. |
4. Message content and sensitive information
5. Storage and access
The operator can access these stores for maintenance and request handling. Server administrators and people with relevant channel/role permissions may see records sent to Discord. Transcript recipients can download copies. Channel visibility depends on server configuration.
6. External services and transfers
- Discord: authentication, server/member information, commands, messages, files and voice playback. Logs and transcripts go to configured channels and, in some workflows, relevant users’ direct messages.
- Supabase: PostgreSQL hosting and database operations. The selected project region does not guarantee that every support or service operation remains in that country.
- Google translation: requested text and target language are sent through the Google Translate library. Consider this transfer before translating a private conversation.
- QuickChart: chart configuration, server names in titles, date labels and member counts are sent in chart URLs. Anyone receiving the URL can read those parameters.
- YouTube, Kick and music sources: configured channels and stream status are queried for notifications. Music queries and links may reach selected content providers and extractors, including SoundCloud, Spotify, Apple Music and other enabled sources.
- Google Fonts and Discord CDN: the interface loads fonts and profile/server images from external domains, which receive IP addresses and ordinary request information.
The reviewed source has no advertising-network integration, personal-data sale, advertising profiling or integration to train AI models on messages. This does not guarantee independent providers’ practices. Providers may process information in different countries; the operator must separately satisfy applicable transfer requirements.
7. Sessions and browser storage
identify and guilds scopes and does not ask for your Discord password. The server exchanges the authorization code for an access token. That access token is kept in the server’s in-memory dashboard session so the user’s server permissions can be rechecked. It is not returned to the browser by the session API.The application’s own session key is stored in browser sessionStorage. On login it is delivered in a URL fragment, then removed from the address bar. Do not share login-return URLs or session keys. A temporary HttpOnly, SameSite=Lax OAuth-state cookie binds the login to the browser; it is cleared on callback and expires after ten minutes. The selected server may also be stored in sessionStorage to restore the selection after login.
Dashboard sessions expire after eight hours; expired entries are removed during periodic memory cleanup, at most fifteen minutes later. A process restart also ends sessions. Signing out calls the server logout endpoint to delete the dashboard session and removes the browser key. This is separate from revoking the application’s Discord authorization in Discord account settings. The reviewed interface has no advertising or analytics cookies.
8. Retention and deletion limits
- Dashboard sessions: eight-hour validity, bounded by periodic cleanup and process lifetime.
- Server analytics: limited to the latest 30 daily records; days when the bot is offline may have no new record.
- Finished giveaways: records older than 24 hours are removed by hourly cleanup. Discord messages are separate.
- Application state: timestamped applications use a 30-day threshold and panels a 90-day threshold, checked every six hours. This does not delete Discord messages or transcript files.
- Birthdays:
/birthday-removeremoves the user’s record when the command is available in that server. Earlier celebration messages are separate records. - AFK: a returning user’s message may clear the state; disabling the feature may prevent this handler from running.
- Configuration, economy, XP, invites and other persistent records: no general automatic expiry. Removing the bot, disabling a feature or signing out does not automatically delete them.
- Backups and logs: retention depends on hosting and backup arrangements; no single verified deletion period for all backups is established in this version.
The operator reviews controlled data and available copies when handling requests. Copies downloaded by server staff or separately held on Discord may require contacting those recipients or Discord. Disabling a feature does not reverse every ongoing action.
9. Processing grounds and choices
You may decline to provide optional birthday/AFK information, avoid translation and other optional tools, or ask server administrators to disable a feature. You can revoke Discord authorization in your account settings. Revocation is not the same as deleting previously stored data.
10. Rights and requests
Include your Discord user ID, the relevant server ID, request type and affected feature. Do not send passwords or tokens. Only necessary account/authority verification should be requested to avoid disclosure to the wrong person. Requests should be assessed within applicable legal deadlines, with reasons given for additional information or exceptions. There is no central self-service full export/deletion tool in this version; the operator must handle these requests.
11. Security, children and incidents
Users must meet Discord’s minimum age and relevant local requirements. Unnecessary sensitive information about children must not be requested. Reports of inappropriate collection should be investigated. If personal data is accessed without authorization, the operator should investigate, limit the impact and make notifications required by applicable law and Discord obligations.
12. Contact and updates
The policy will be updated when data categories, providers or significant retention practices change. Material changes should be announced through appropriate channels and additional consent obtained where necessary. The version and update date appear above.