Privacy Policy
Last updated: July 16, 2026
This policy explains what Exolved Bot collects, why we use it, who can see it, how long it is kept, and the choices available to you.
TL;DR Privacy Summary
Exolved Bot stores the information needed to provide the features that you and your Discord server choose to use. We aim to collect useful operational data, not the substance of everyday conversations.
1. Who We Are and Scope
Exolved Bot is operated by Tobias Rothe ("Exolved Bot," "we," "us," or "our"). This policy applies to the Exolved Bot Discord application, website dashboard, related integrations, and supporting services.
Discord server administrators choose which server features to enable, which channels and roles those features use, and which staff members can view server-managed records. A server administrator may therefore have separate responsibilities for data processed through applications, tickets, reports, analytics, and other configured tools.
This policy covers Exolved Bot itself. A Discord server may also have its own rules or privacy notice for the features its administrators enable.
2. Information We Collect
The data we process depends on the features you use and the settings selected by your server administrators.
Identity and Login Data
- Discord account information: Discord user ID, username, avatar, selected server, server membership, and the role, channel, and permission information needed to authenticate you and determine which settings you may manage.
- Website sessions and security: login and session state, CSRF tokens, request metadata, timestamps, rate-limit events, security events, and operational logs.
- Subscription records: Discord entitlement ID, SKU ID, guild ID, purchaser user ID, start and end timestamps, test/deleted state, and the last verification time. Discord handles billing; we use entitlement metadata only to determine the server's plan.
Server Configuration Data
- Server, channel, role, category, panel, and message IDs used by configured features.
- Feature toggles, permissions, templates, custom text, embeds, buttons, modal fields, notification destinations, schedules, and automation rules.
- Settings for welcome and goodbye messages, applications, support tickets, moderation, Reaction Roles, private voice master channels, Twitch Live, Steam alerts, Prompt of the Day, Questboard, Member Passport, Server Weather, and Setup Alerts.
Activity Analytics
- Message activity: message counts by user, channel, server, and date; recent message IDs used to reconcile deleted messages; lifetime message totals; Top Chatter records; and cached activity summaries. Routine message text is not stored for these analytics.
- Chat Streaks: current streak, longest streak, last qualified day, and short-term daily counters. For example, the service records that you reached five messages on a date, not what those messages said.
- Voice activity: voice XP, levels, session timestamps, channel and guild IDs, duration, and mute, deafen, or screen-share state used for configured XP rates and Questboard progress.
- Discord presence: status and rich-presence activity names available from Discord, such as a game, streaming, listening, watching, or shared activity. These signals may support Member Passport, Server Weather, creator tools, or presence-based community features.
Moderation and Safety Data
- Message reports: the reported message ID, author, channel, link, message text, report reason, reviewer details, moderator notes, and attachment links supplied as evidence. Report text, reasons, notes, and attachment URLs are encrypted at rest.
- Media-Only channels: new messages in administrator-selected channels are checked for attachments, supported media links, and Discord-generated media embeds. The check decides whether to enforce the channel rule; this feature does not store the message text.
- Applications, tickets, and staff workflows: answers submitted by users, selected roles or categories, status history, channel links, reviewer IDs, reminders, staff assignments, and related workflow state.
- Operational safety: request validation events, rate-limit events, error details, and security logs used to diagnose abuse and protect the service.
Creator Integrations
- Twitch: linked usernames and user IDs, categories, schedules, live-notification settings, live stream or game snapshots, support-tracking pairs and minutes, chat command and AutoMod settings, shoutout settings, and queued outbound Twitch chat actions. EventSub subscription/message IDs and public stream online/offline payloads are temporarily stored to prevent duplicate processing and retry failures.
- YouTube: channel ID and title, handle, uploads playlist ID, upload-notification settings, last checked video metadata, related statistics, and OAuth tokens when you choose to link YouTube.
- Steam: Steam ID, persona name, avatar, library privacy state, owned-game metadata, multiplayer flags, subscribed game IDs, news/discount preferences, and related LFG data when those features are used.
Optional Community Features
- Questboard: quests created by staff, member joins, automatic progress counters, completions, and reviewer IDs. For example, a message quest stores progress toward the required amount, not the text of each qualifying message.
- Member Passport and Server Weather: configured summaries derived from eligible message, voice, role, join-date, creator, quest, and presence signals. Opted-out users are excluded from eligible activity views.
- LFG and game activity: game preferences, presence-derived game context, waitlists, and session state where enabled.
- Private voice channels: ownership, allowed members, custom names, lock and size preferences, master-channel mapping, and room state needed to create and manage a room.
- Other optional state: birthdays, achievements, onboarding state, polls and votes, POTD posts and votes, checklists, reminders, Reaction Role mappings, and similar feature records.
- Optional commerce tools: cart and product-cache data if shopping features are enabled. These tools may be disabled or unavailable.
Most records are IDs, settings, counters, and feature state. Content is stored when you intentionally submit it to a workflow, or when a message is reported as moderation evidence.
3. Information We Do Not Collect
- We do not collect your Discord, Twitch, Google, YouTube, Steam, or payment-account password.
- We do not receive or store full payment-card or bank-account details. Discord processes Premium subscription purchases and supplies entitlement metadata.
- We do not monitor or archive your general private Discord DM history. The bot may process a command or interaction you intentionally send to it and may send requested notifications by DM.
- We do not store routine Discord message text for message counts, Chat Streaks, leaderboards, voice XP, or message-count Questboard progress.
- We do not store message text inspected by the Media-Only feature. Reported messages are the clearly identified moderation-evidence exception.
- We do not request precise GPS location, address-book contacts, or biometric identifiers.
- We do not sell personal data, build advertising profiles, or use personal data to train a general-purpose AI model.
Everyday activity features are designed around metadata and totals. Sensitive content is limited to user-submitted workflows and moderation evidence.
4. How We Use Information
- Authentication and access control: sign you in, show servers you can manage, and prevent unauthorized configuration changes.
- Server administration: save settings, publish panels and embeds, assign roles, create channels, manage tickets and applications, and perform configured automations.
- Moderation and safety: enforce configured rules, process reports, preserve relevant evidence, support staff review, prevent abuse, and investigate security incidents.
- Community features and analytics: provide XP, leaderboards, Chat Streaks, Questboard, Member Passport, Server Weather, achievements, and related summaries.
- Creator and game integrations: link accounts, publish stream/upload/game alerts, run creator tools, support LFG, and provide integration dashboards.
- Subscriptions: verify whether a server has Free, Premium, test, manual, or Legacy Premium access and enforce the corresponding limits without collecting payment details.
- Reliability: diagnose errors, measure service health, prevent duplicate actions, recover from restarts, and improve performance.
- Legal compliance: respond to valid legal requests and protect the rights, safety, and integrity of users, server communities, and the service.
5. Legal Bases for Processing
Where the GDPR, UK GDPR, or similar law applies, we rely on one or more of the following legal bases:
- Performance of a contract or requested service: processing needed to authenticate you and provide the bot, dashboard, subscription, integration, or community feature you request.
- Legitimate interests: operating a reliable and secure service, preventing abuse, maintaining configuration, troubleshooting failures, and providing proportionate server analytics. We consider user privacy and provide controls such as the analytics pause where applicable.
- Consent: optional account connections and features that you affirmatively choose to enable where consent is the appropriate basis. You may withdraw consent by unlinking or disabling the feature.
- Legal obligations: retaining or disclosing limited information where applicable law requires it.
Server administrators are responsible for choosing an appropriate basis for features they enable and for explaining server-specific uses to their members when required.
We process data to deliver requested features, protect the service, and honor optional choices. Disabling or unlinking an optional feature stops the related future processing where possible.
7. Google User Data and YouTube
When you choose to link YouTube, Exolved Bot requests the https://www.googleapis.com/auth/youtube.readonly scope. This is read-only access.
- Data accessed: YouTube channel ID and title, uploads playlist metadata, and related video statistics needed by enabled features.
- How it is used: to display your YouTube dashboard, generate channel/upload analytics, and post upload notifications you enable.
- How it is stored: OAuth tokens and linked-channel metadata are stored on our service infrastructure to keep the integration active until you unlink or revoke access.
- How it is shared: Google user data is not sold or used for advertising. It is shared only as necessary to provide a requested feature, such as posting an upload notification to a configured Discord channel.
- Your control: unlink YouTube in the dashboard or revoke access through your Google account settings.
Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
8. Data Location and Storage
Service records are primarily stored in a shared SQLite database and supporting configuration, cache, log, and operational files on infrastructure controlled by the Exolved Bot operator. Cloudflare may process request and network data at its edge locations, while Discord, Twitch, Google, YouTube, and Steam process data on their own infrastructure.
Because these providers operate internationally, information may be processed outside your country. Where data-protection law requires safeguards for an international transfer, we rely on the safeguards made available by the relevant provider and take reasonable steps to limit the data transferred to what the feature needs.
HTTPS protects dashboard traffic in transit. Stored message-report content, report reasons, moderator notes, and report attachment URLs are additionally encrypted at rest. This statement does not mean that every database field or local operational file is encrypted at rest.
Your data is stored with the bot's operating infrastructure and may pass through the platform needed to provide a feature. Moderation evidence receives additional field-level encryption.
9. Data Retention
We keep information only for as long as reasonably necessary for the feature, security, moderation, legal, or operational purpose described in this policy. Current feature-specific periods include:
- Routine message activity and recent message IDs: a rolling 28-day window. Lifetime message totals may remain while related analytics features are active.
- User analytics cache: up to 30 days.
- Chat Streak daily counters: 45 days. Current and longest-streak state may remain while the feature is active.
- Twitch EventSub deliveries: successfully processed deliveries are removed after 7 days; deliveries that exhausted automatic retries may remain for up to 30 days for troubleshooting.
- Encrypted message-report evidence: the server administrator selects a period between 7 and 3650 days; the default is 90 days.
- Account links, subscriptions, server settings, applications, tickets, and other workflow records: these may remain longer while the relevant account, server, subscription, or feature is active, or until deletion is requested and no exception applies.
Removing the bot from a server or leaving a server stops applicable future events, but it may not immediately remove stored configuration, moderation evidence, security logs, linked-account records, or workflow history. Residual copies may remain in restricted operational backups until those backups are replaced through their normal rotation.
Short-term analytics expire automatically. Configuration and workflow records can last longer because they are needed to keep enabled features working or preserve moderation history.
10. Your Choices and Privacy Rights
Pause Future Activity Analytics
Use the privacy toggle under Customize settings or run /privacy optout. This pauses future eligible message analytics, Chat Streak updates, voice XP/session analytics, activity cache scans, Questboard progress writes, community-intelligence and rich-presence signals, and Twitch support participation associated with your Discord account.
The toggle does not delete historical records or disable data needed for login, security, moderation, server configuration, private voice preferences, birthdays, applications, tickets, or external accounts you choose to link.
Manage Optional Integrations
You may unlink Twitch or YouTube in the dashboard, revoke OAuth access at the provider, and use available commands or settings to remove optional Steam links, birthdays, and similar feature data.
Your Legal Rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a portable copy of your personal data; object to certain processing; withdraw consent; and complain to your local data-protection authority. These rights may be subject to lawful exceptions, including security, the rights of others, legal obligations, and the establishment or defense of legal claims.
11. How to Request Data Deletion
- Pause new eligible analytics first: use the dashboard privacy toggle or
/privacy optout. - Use self-service controls: unlink connected services and remove optional records where a dashboard setting or command is available.
- Request broader deletion: join the official Exolved Bot Support Discord server and contact the bot administrators. Do not post sensitive evidence in a public channel.
- Identify the relevant account and scope: provide your Discord user ID and describe the servers, integrations, or features covered by the request. We may ask you to verify control of the account before acting.
- For server-managed records: contact that server's administrators for applications, tickets, or moderation records they control. You may also contact us if you need help identifying or processing bot-held data.
Authorized server administrators or HR staff may also use /privacy purge for supported historical voice and Twitch-support analytics. A deletion request does not guarantee removal of information we must retain for security, legal compliance, the rights of other users, or active moderation evidence. We will respond within the period required by applicable law.
Pausing collection and deleting history are separate actions. Tell us what you want removed, and we will verify the request and explain any lawful limitation.
12. Security
We use layered safeguards including HTTPS, OAuth state validation, CSRF protection, authenticated guild-access checks, input validation, rate limiting, restricted staff workflows, and encryption for stored report evidence. We also monitor errors and operational logs to maintain reliability and investigate abuse.
No internet-facing service can guarantee perfect security. If you believe data handled by Exolved Bot has been exposed or misused, contact us promptly through the support server.
13. Children's Privacy
Exolved Bot is not directed to children under 13 or anyone below the minimum age required to use Discord in their country. We do not knowingly seek to collect personal data from anyone who is not permitted to use Discord.
If you are a parent or guardian and believe a child provided personal data through Exolved Bot contrary to these requirements, contact us through the support server. We will review the request and take appropriate steps, which may include deleting the information.
14. Changes to This Policy
We may update this policy when features, data practices, providers, or legal requirements change. The date at the top shows the latest revision. For material changes, we will provide a reasonable notice through the website, dashboard, support server, or another appropriate service channel.
If a change requires consent, including a materially new use of Google user data, we will request that consent before using the data for the new purpose.
15. Contact
For privacy questions, rights requests, deletion requests, or security concerns, contact the Exolved Bot administrators through the official Exolved Bot Support Discord server.
Do not post OAuth tokens, passwords, report evidence, or other sensitive information in a public support channel. An administrator can direct you to an appropriate private process.