Privacy Policy
Last updated: July 16, 2026
1. Who We Are
This policy covers Iris ("the Bot") and its website and web dashboard ("the Website"). The operator of Iris is the data controller for the data described in this policy. You can contact us for any privacy matter, including exercising your rights, through the Bot's support server on Discord (see Contact below).
2. Information We Collect
Iris collects only the data necessary to provide its features. We do not collect personal information beyond what Discord makes available through its API.
Data Collected Automatically
- Discord User ID - your unique Discord identifier, used to track moderation actions, giveaway entries, verification status, and ticket ownership.
- Guild (Server) ID - used to store and retrieve your server's configuration.
- Channel and Role IDs - stored as part of module configuration (e.g., log channels, staff roles, verification channels).
Data Stored Through Configuration
- Server Configuration - module settings, enabled features, assigned channels and roles, custom messages, embed content, and thresholds configured through the dashboard or commands.
- Moderation Records - warnings, mutes, bans, kicks, and associated user IDs with timestamps and reasons.
- Giveaway Data - giveaway settings, participant entries (user IDs), winners, and end times.
- Ticket Records - ticket channel IDs, creator user IDs, and ticket status.
- Verification Records - user IDs and verification completion status.
- Starboard Data - message IDs and reaction counts that meet the starboard threshold.
- Invite Records - which invite code a member joined through, who created it, and the resulting per-member invite counts.
- Reminders - the reminder text you write, together with your user ID and the target channel, until the reminder fires or you delete it.
- Language Preference - the language you choose for the Bot's responses, tied to your user ID.
Message Content
Messages are processed in real time for auto-moderation and are not stored for that purpose. Message content is stored in these specific cases, all of which exist so that server administrators can review what happened:
- Message Logs - if a server enables the logging module, the content of deleted and edited messages is stored (up to 4,000 characters) together with the author's user ID, channel, and timestamp.
- Ticket Transcripts - when a ticket is closed, a transcript of the ticket channel (message content, author names and IDs, attachment links, and embed content) is stored for the server's ticket history and also sent by direct message to the ticket creator and the staff member who closed it.
- Anti-Link Violations - if a server enables the anti-link module, the content of messages removed for containing blocked links is stored together with the detected URL.
Data We Do Not Collect
- Email addresses or personal contact information
- Voice or video data
- Payment or financial information
3. Website and Dashboard
When you log in to the web dashboard, you authenticate through Discord OAuth2 with the "identify" and "guilds" scopes. During your login session we process:
- Discord account data - your user ID, username, and avatar identifier.
- Server list - the servers you belong to and your permissions in them, used only to determine which dashboards you can access.
- OAuth2 access token - held for the duration of your session so we do not need to re-authenticate you on every request.
This data lives only in your login session. It is discarded when you log out, when the token expires, or when you close your browser. We do not store your session data in any database. One exception: when you change a server's configuration through the dashboard, your Discord user ID is recorded with that change so administrators can see who made it. The Website loads all fonts, scripts, and styles from our own server; no analytics or tracking services are used. The verification page may show sponsored content, which is covered in section 4 below. Server and avatar images are loaded directly from Discord's content delivery network (cdn.discordapp.com), which means your browser makes requests to Discord when viewing the dashboard. Standard technical logs (such as IP addresses and request times) may be processed transiently for security and debugging; they are not used to identify or profile you.
4. Sponsored Content
The verification page may show sponsored boxes, clearly labelled "Sponsored". These are sold and served entirely by us: the images are hosted on our own server and no advertising network, exchange, or third-party tracking script is involved at any point. Nothing about you is shared with, or made available to, an advertiser.
We count how many times each sponsored box is shown and how many times it is clicked, so that advertisers can be billed for what was delivered. These counts are stored as daily totals per advertisement. They are not linked to your Discord account, your IP address, or any identifier for you, and they cannot be used to work out that a particular person saw a particular advertisement. Clicking a sponsored box sends you to the advertiser's own site, where their privacy policy applies rather than ours.
Servers on a paid plan do not show sponsored content to their members at all.
5. Cookies
The Website uses a single cookie: a session cookie that keeps you logged in to the dashboard. It is strictly necessary for the login feature to work, is HttpOnly (not readable by scripts), and expires when you log out or close your browser. Because it is strictly necessary and used for nothing else, it does not require consent under the EU ePrivacy rules. We use no analytics, advertising, or other third-party cookies of any kind, and the sponsored content described above sets no cookie.
6. How We Use Your Data and Legal Bases
Collected data is used exclusively to:
- Deliver and operate Bot features (moderation, tickets, giveaways, logging, etc.).
- Store and apply your server's configuration preferences.
- Display server management information on the web dashboard.
- Enforce moderation actions and maintain moderation history.
- Process auto-moderation rules in real-time (message content is not stored for this purpose).
Where the EU or UK General Data Protection Regulation (GDPR) applies, our legal bases are:
- Performance of a contract (Art. 6(1)(b)) - providing the Bot's features and the dashboard you have asked for, including login sessions.
- Legitimate interests (Art. 6(1)(f)) - keeping the service secure, preventing abuse, and maintaining moderation records that server administrators create.
We do not sell, share, or transfer your data to third parties, and we do not use it for advertising or profiling.
7. Data Storage
All data is stored in SQLite databases on the server hosting the Bot, one database per module (configuration, moderation, logging, tickets, giveaways, verification, starboard, invites, reminders, notifications, and similar). Data is not replicated to external services or cloud providers.
8. Data Retention
- Dashboard sessions - session data (including your OAuth2 token) is deleted when you log out, when the token expires, or when your browser session ends.
- Active servers - configuration and module data is retained as long as the Bot remains in your server.
- Removed servers - server data is not deleted automatically when the Bot is removed. It is deleted promptly on request (see Data Deletion below).
- Moderation records, message logs, and ticket transcripts - retained until cleared by a server administrator or deleted on request.
- Reminders - deleted when the reminder fires or when you cancel it.
9. Data Access
Your server's data is accessible only to:
- Server administrators with the "Administrator" permission in Discord.
- Bot operators listed in the OWNER_IDS configuration (for maintenance and support).
The web dashboard requires Discord OAuth2 authentication. Only users with administrator permissions for a given server can view or modify that server's configuration.
10. Data Deletion
You may request deletion of your server's data at any time by contacting us by email or through the support Discord server (see Contact below). Deletion requests are honored promptly. Removing the Bot from your server stops all further collection for that server, but does not by itself erase previously stored data; send us a deletion request if you want it removed.
Individual moderation records can be cleared by server administrators using the Bot's moderation commands. Individual users may also request deletion of data tied to their Discord user ID (such as giveaway entries or verification records) through the support server.
11. Your Rights
Depending on where you live (for example under the GDPR, UK GDPR, or the California Consumer Privacy Act), you have the right to:
- Access - request a copy of the personal data we hold about you.
- Rectification - request correction of inaccurate data.
- Erasure - request deletion of your data ("right to be forgotten").
- Restriction - request that we limit processing of your data.
- Portability - receive your data in a structured, machine-readable format.
- Objection - object to processing based on legitimate interests.
To exercise any of these rights, contact us through the support server (see Contact below). We will respond within 30 days. We never sell personal information, so there is nothing to opt out of under the CCPA's "Do Not Sell or Share" provisions. If you are in the EU or UK, you also have the right to lodge a complaint with your local data protection supervisory authority.
12. Third-Party Services
The Bot interacts with the following third-party service:
- Discord API and CDN - to receive events, send messages, manage server features, and display server and avatar images. Your use of Discord is governed by Discord's Privacy Policy.
- Content platforms for notifications - if a server administrator configures social notifications, the Bot polls the public APIs of the chosen platforms (such as Twitch, YouTube, Reddit, TikTok, Kick, or Twitter/X) for the configured creators' public content. Only the configured creator or community names are sent to those platforms; no personal data about you or other server members is transmitted.
No other third-party services receive your data.
13. Children's Privacy
The Bot and Website are not intended for use by anyone below the minimum age required to use Discord in their country (13 years, or higher where local law requires). We do not knowingly collect data from children below that age; if you believe we have, contact us and we will delete it.
14. Changes to This Policy
We may update this Privacy Policy at any time. Changes are indicated by the "Last updated" date at the top of this page. Continued use of the Bot after changes constitutes acceptance of the revised policy. We recommend reviewing this page periodically.
15. Contact
For privacy-related questions, data deletion requests, or to exercise any of the rights described above, contact us by email at yourbotdev.daniel@gmail.com or through the Bot's support server on Discord. Requests are handled by the Bot's operator, who acts as the data controller.