๐Ÿ”

Privacy Policy

We respect your privacy. Here's exactly what we collect, why, and how.

Last updated: August 30, 2026
GDPR Compliant
This Privacy Policy explains how StaffBot ("we", "us", or "our") collects, uses, stores, and protects your personal data when you use our Discord Bot and Web Dashboard ("Services"). This document complies with the General Data Protection Regulation (GDPR) (EU) 2016/679 and other applicable data protection laws.
1

๐ŸขData Controller

For the purposes of applicable data protection law, the data controller responsible for your personal data is the operator of StaffBot. As this is a self-hosted service, the data controller is the individual or entity who has deployed and configured this instance of StaffBot.

For data protection inquiries, you can reach us via the support channels listed in our Terms of Service.

We are committed to ensuring that your personal data is handled responsibly, transparently, and in compliance with all applicable legal obligations.

2

โš–๏ธLegal Basis for Processing

We process your personal data on the following legal bases under the GDPR:

  • Legitimate Interests (Art. 6(1)(f) GDPR): Processing data necessary for providing staff management, moderation logging, and dashboard functionality for Discord server administrators who have chosen to use our Services.
  • Contractual Necessity (Art. 6(1)(b) GDPR): Processing your Discord account information required to authenticate and maintain your active session on the Web Dashboard.
  • Consent (Art. 6(1)(a) GDPR): When you explicitly authorize our application via Discord OAuth2, you consent to the collection of the specific data scopes requested (identify, email).
  • Legal Obligation (Art. 6(1)(c) GDPR): In rare cases where we are required by law to retain or process data.
3

๐Ÿ“ฆData We Collect

We collect only the minimum data necessary to operate the Services. Here is a full breakdown:

Discord Account Data (via OAuth2)

  • Discord User ID (unique numeric identifier)
  • Username and global display name
  • Avatar URL (profile picture hosted by Discord)
  • Email address (requested scope: identify, email)

Discord Server (Guild) Data

  • Guild ID, name, and icon URL
  • Guild owner Discord ID
  • Configured channel IDs (logs, announcements, staff)
  • Configured role IDs (staff roles, LOA role, admin roles)
  • Guild membership status and role assignments of staff members

Staff Activity & Moderation Data

  • Message count statistics (per staff member, per guild)
  • Activity timestamps (first message, last active date)
  • Warning, strike, and disciplinary records
  • Leave of Absence (LOA) requests, dates, and reasons
  • Promotion and demotion history
  • Moderation actions issued (bans, mutes, kicks, warns) including proof image URLs
  • Appeal tickets and messages
  • Audit log events generated by the bot

Authentication & Session Data

  • Encrypted JWT session tokens (stored in your browser)
  • OAuth2 access and refresh tokens (stored securely server-side)
  • Account linking information (NextAuth adapter records)

Uploaded Content

  • Proof screenshots uploaded by staff when issuing sanctions (stored as image files)
  • Custom embed images uploaded for server announcements

We do not collect payment information, precise geolocation, or sensitive personal data (racial origin, religion, health data, etc.).

4

๐ŸŽฏHow We Use Your Data

Your data is used exclusively for the following purposes:

  • Authenticating server administrators and staff members via Discord OAuth2 on the Web Dashboard.
  • Providing and maintaining all bot commands and Web Dashboard features.
  • Tracking staff activity, message statistics, and generating activity reports.
  • Managing Leave of Absence requests, automatic reminders, and role restoration.
  • Recording and displaying moderation actions with proof evidence for server accountability.
  • Syncing Discord role and guild data to keep the dashboard current.
  • Sending Direct Message notifications for sanctions, LOA updates, and system alerts.
  • Processing sanction appeals submitted through the dashboard.
  • Generating CSV data exports requested by server administrators.
  • Ensuring the security, integrity, and proper operation of the Services.

We never sell, rent, trade, or commercially share your personal data with any third party.

5

โณData Retention

We retain personal data for the following durations:

  • Account & Session Data: Retained for as long as you maintain an active session on the dashboard. Sessions expire after inactivity.
  • Staff Activity Records: Retained for as long as the Discord server uses our Services and the staff member is part of the system.
  • Moderation Logs & Punishments: Retained indefinitely to maintain a complete moderation history for server administrators, unless deletion is requested.
  • LOA Records: Retained for 12 months after completion, then automatically purged.
  • Audit Logs: Retained for 90 days, after which older entries may be purged.
  • Uploaded Images: Retained until deleted by a server administrator or until the server removes the bot.

Upon removing StaffBot from a Discord server, we will cease collecting new data for that server. Existing data can be deleted upon request โ€” see your rights in Section 7.

6

๐ŸชCookies & Browser Storage

The Web Dashboard uses the following types of browser-side storage:

  • Session Cookies: A secure, HTTP-only session cookie is set upon authentication to maintain your logged-in state. This cookie expires when you close your browser or explicitly sign out.
  • CSRF Tokens: Cross-Site Request Forgery protection tokens are stored to secure form submissions and API calls.

We do not use advertising cookies, tracking pixels, third-party analytics cookies, or behavioral targeting technologies. Our cookies are strictly necessary for the operation of the Services.

7

๐Ÿ›๏ธYour Rights Under GDPR

If you are located in the European Union, European Economic Area, or United Kingdom, you have the following rights:

  • Right of Access (Art. 15 GDPR): Request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete personal data.
  • Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): Request deletion of your personal data, subject to certain legal limitations.
  • Right to Restriction of Processing (Art. 18 GDPR): Request that we restrict processing of your data in certain circumstances.
  • Right to Data Portability (Art. 20 GDPR): Request your personal data in a structured, commonly used, machine-readable format.
  • Right to Object (Art. 21 GDPR): Object to processing based on legitimate interests.
  • Right to Withdraw Consent (Art. 7(3) GDPR): Withdraw your consent at any time by revoking StaffBot's authorization in your Discord account settings.

To exercise any of these rights, contact us via the support channels in our Terms of Service. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your national data protection authority (e.g., APD/GBA in Belgium, CNIL in France).

8

๐Ÿ›ก๏ธData Security

We implement robust technical and organizational measures to protect your personal data:

  • All data transmissions use TLS/SSL encryption (HTTPS).
  • Database connections use SSL-encrypted connections to Neon PostgreSQL.
  • Authentication tokens are encrypted using industry-standard algorithms.
  • File uploads are validated for type, size, and renamed with random UUIDs to prevent path traversal attacks.
  • Role hierarchy enforcement prevents unauthorized privilege escalation within the system.
  • Dashboard access is restricted to authenticated, authorized guild members only.

Despite these measures, no system is 100% secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users and relevant authorities as required by law (within 72 hours under GDPR Art. 33).

9

๐Ÿ”—Third-Party Sub-processors

We rely on the following third-party infrastructure providers to operate the Services. These providers act as sub-processors under GDPR and are contractually required to protect your data:

Discord Inc.ยท United States

OAuth2 authentication, Bot API, user and guild data

Privacy โ†’
Vercel Inc.ยท United States (EU Edge)

Web Dashboard hosting and serverless functions

Privacy โ†’
Render Inc.ยท United States

Discord Bot hosting

Privacy โ†’
Neon Inc.ยท European Union (eu-central-1)

Secure PostgreSQL cloud database storage

Privacy โ†’

Data transfers to the United States are conducted under appropriate safeguards, including Standard Contractual Clauses (SCCs) or adequacy decisions where applicable.

10

๐ŸŒInternational Data Transfers

StaffBot operates with infrastructure located in both the European Union and the United States. When your data is transferred outside the EEA (e.g., to Vercel US, Render US, or Discord US), we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission under GDPR Art. 46.
  • Services certified under the EU-US Data Privacy Framework where applicable.
  • Technical security measures (encryption in transit and at rest) regardless of server location.

The Neon PostgreSQL database is hosted in the eu-central-1 region (European Union) to minimize cross-border data transfer for stored personal data.

11

๐Ÿง’Data of Minors

StaffBot is not intended for use by individuals under the age of 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from minors.

If you believe a minor under the applicable age has used our Services and their data is stored in our systems, please contact us immediately using the support channels in our Terms of Service. We will take prompt steps to delete the relevant data.

12

๐Ÿ“Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or the Services. When we make material changes, we will:

  • Update the "Last updated" date shown at the top of this page.
  • Notify registered users via the Web Dashboard notification system or Discord when changes are significant.

Your continued use of the Services after any changes to this Privacy Policy constitutes your acceptance of the updated terms. We encourage you to review this page periodically.

Previous versions of this policy may be obtained by contacting us directly.

13

๐Ÿ“ฉContact & Data Protection Requests

For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us:

  • Discord Support: Contact a StaffBot administrator via the official Discord support server.
  • Dashboard Tickets: Use the ticket system available in your server's Web Dashboard.
  • Data Deletion: Request erasure of your data by contacting us โ€” we will process requests within 30 days.
  • Supervisory Authority: You have the right to file a complaint with your national data protection authority: