Privacy Policy

Last updated: July 16, 2026

This policy explains what Exolved Bot collects, why we use it, who can see it, how long it is kept, and the choices available to you.

TL;DR Privacy Summary

Exolved Bot stores the information needed to provide the features that you and your Discord server choose to use. We aim to collect useful operational data, not the substance of everyday conversations.

No data salesWe do not sell personal data or use it for targeted advertising.
No passwordsDiscord, Twitch, Google, Steam, and payment credentials stay with those providers.
No routine message text storageMessage analytics use counts and metadata. Encrypted moderation evidence is a limited exception.
Privacy controlsYou can pause future eligible analytics, unlink integrations, and request deletion.

1. Who We Are and Scope

Exolved Bot is operated by Tobias Rothe ("Exolved Bot," "we," "us," or "our"). This policy applies to the Exolved Bot Discord application, website dashboard, related integrations, and supporting services.

Discord server administrators choose which server features to enable, which channels and roles those features use, and which staff members can view server-managed records. A server administrator may therefore have separate responsibilities for data processed through applications, tickets, reports, analytics, and other configured tools.

What this means for you

This policy covers Exolved Bot itself. A Discord server may also have its own rules or privacy notice for the features its administrators enable.

2. Information We Collect

The data we process depends on the features you use and the settings selected by your server administrators.

Identity and Login Data

Server Configuration Data

Activity Analytics

Moderation and Safety Data

Creator Integrations

Optional Community Features

What this means for you

Most records are IDs, settings, counters, and feature state. Content is stored when you intentionally submit it to a workflow, or when a message is reported as moderation evidence.

3. Information We Do Not Collect

What this means for you

Everyday activity features are designed around metadata and totals. Sensitive content is limited to user-submitted workflows and moderation evidence.

4. How We Use Information

6. Sharing and Third-Party Services

We do not sell personal data. Information may be shared only as needed in these situations:

Each external platform processes information under its own privacy policy and may operate in different countries.

7. Google User Data and YouTube

When you choose to link YouTube, Exolved Bot requests the https://www.googleapis.com/auth/youtube.readonly scope. This is read-only access.

Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

8. Data Location and Storage

Service records are primarily stored in a shared SQLite database and supporting configuration, cache, log, and operational files on infrastructure controlled by the Exolved Bot operator. Cloudflare may process request and network data at its edge locations, while Discord, Twitch, Google, YouTube, and Steam process data on their own infrastructure.

Because these providers operate internationally, information may be processed outside your country. Where data-protection law requires safeguards for an international transfer, we rely on the safeguards made available by the relevant provider and take reasonable steps to limit the data transferred to what the feature needs.

HTTPS protects dashboard traffic in transit. Stored message-report content, report reasons, moderator notes, and report attachment URLs are additionally encrypted at rest. This statement does not mean that every database field or local operational file is encrypted at rest.

What this means for you

Your data is stored with the bot's operating infrastructure and may pass through the platform needed to provide a feature. Moderation evidence receives additional field-level encryption.

9. Data Retention

We keep information only for as long as reasonably necessary for the feature, security, moderation, legal, or operational purpose described in this policy. Current feature-specific periods include:

Removing the bot from a server or leaving a server stops applicable future events, but it may not immediately remove stored configuration, moderation evidence, security logs, linked-account records, or workflow history. Residual copies may remain in restricted operational backups until those backups are replaced through their normal rotation.

What this means for you

Short-term analytics expire automatically. Configuration and workflow records can last longer because they are needed to keep enabled features working or preserve moderation history.

10. Your Choices and Privacy Rights

Pause Future Activity Analytics

Use the privacy toggle under Customize settings or run /privacy optout. This pauses future eligible message analytics, Chat Streak updates, voice XP/session analytics, activity cache scans, Questboard progress writes, community-intelligence and rich-presence signals, and Twitch support participation associated with your Discord account.

The toggle does not delete historical records or disable data needed for login, security, moderation, server configuration, private voice preferences, birthdays, applications, tickets, or external accounts you choose to link.

Manage Optional Integrations

You may unlink Twitch or YouTube in the dashboard, revoke OAuth access at the provider, and use available commands or settings to remove optional Steam links, birthdays, and similar feature data.

Your Legal Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a portable copy of your personal data; object to certain processing; withdraw consent; and complain to your local data-protection authority. These rights may be subject to lawful exceptions, including security, the rights of others, legal obligations, and the establishment or defense of legal claims.

11. How to Request Data Deletion

  1. Pause new eligible analytics first: use the dashboard privacy toggle or /privacy optout.
  2. Use self-service controls: unlink connected services and remove optional records where a dashboard setting or command is available.
  3. Request broader deletion: join the official Exolved Bot Support Discord server and contact the bot administrators. Do not post sensitive evidence in a public channel.
  4. Identify the relevant account and scope: provide your Discord user ID and describe the servers, integrations, or features covered by the request. We may ask you to verify control of the account before acting.
  5. For server-managed records: contact that server's administrators for applications, tickets, or moderation records they control. You may also contact us if you need help identifying or processing bot-held data.

Authorized server administrators or HR staff may also use /privacy purge for supported historical voice and Twitch-support analytics. A deletion request does not guarantee removal of information we must retain for security, legal compliance, the rights of other users, or active moderation evidence. We will respond within the period required by applicable law.

What this means for you

Pausing collection and deleting history are separate actions. Tell us what you want removed, and we will verify the request and explain any lawful limitation.

12. Security

We use layered safeguards including HTTPS, OAuth state validation, CSRF protection, authenticated guild-access checks, input validation, rate limiting, restricted staff workflows, and encryption for stored report evidence. We also monitor errors and operational logs to maintain reliability and investigate abuse.

No internet-facing service can guarantee perfect security. If you believe data handled by Exolved Bot has been exposed or misused, contact us promptly through the support server.

13. Children's Privacy

Exolved Bot is not directed to children under 13 or anyone below the minimum age required to use Discord in their country. We do not knowingly seek to collect personal data from anyone who is not permitted to use Discord.

If you are a parent or guardian and believe a child provided personal data through Exolved Bot contrary to these requirements, contact us through the support server. We will review the request and take appropriate steps, which may include deleting the information.

14. Changes to This Policy

We may update this policy when features, data practices, providers, or legal requirements change. The date at the top shows the latest revision. For material changes, we will provide a reasonable notice through the website, dashboard, support server, or another appropriate service channel.

If a change requires consent, including a materially new use of Google user data, we will request that consent before using the data for the new purpose.

15. Contact

For privacy questions, rights requests, deletion requests, or security concerns, contact the Exolved Bot administrators through the official Exolved Bot Support Discord server.

Please protect your information

Do not post OAuth tokens, passwords, report evidence, or other sensitive information in a public support channel. An administrator can direct you to an appropriate private process.