This document applies to the PaulCLI Discord bot, its companion web dashboard, and the underlying database/API services (together, the “Service“). It is provided by the operator of the Service (“we“, “us“, “our“). By inviting the bot to a Discord server (“guild“), logging into the dashboard, or otherwise interacting with the Service, you (“you“, “user“) agree to the Privacy Policy and Terms of Service below.
Part 1: Privacy Policy
1. Who we are
The Service is operated by PaulCLI. For any privacy-related question or request, contact us at m@pawelb.link or via our support server: https://discord.gg/8MsZrjwJjD.
2. What data we collect
The Service is a Discord bot with modular features (moderation, leveling, economy, giveaways, tickets, starboard, auto-roles, auto-voice, RSS feeds, suggestions, welcome messages, server statistics) plus a web dashboard used to configure those features. Depending on which features a guild administrator enables, we may process the following categories of data:
| Category | Examples | Source |
|---|---|---|
| Discord identifiers | User IDs, usernames/tags, guild IDs, channel IDs, role IDs, message IDs | Discord API / gateway events |
| Dashboard authentication | Discord OAuth2 access & refresh tokens (identify guilds scopes), session tokens | NextAuth / Discord OAuth2 login |
| Moderation records | Warn/kick/timeout case history, reason text, moderator ID, target ID, duration | /warn, /kick, /timeout and dashboard moderation panel |
| Leveling & economy data | XP, level, wallet/bank balances, shop purchases, daily/work/crime cooldown timestamps | Message activity, voice activity, economy commands |
| Giveaway data | Entrant user IDs, prize, host ID, winner IDs | Giveaway entry buttons |
| Suggestions | Suggestion title and body text (stored AES-256-GCM encrypted at rest), author ID/tag, votes | /suggest command |
| Tickets | Ticket channel ID, opener/claimer IDs, and a full transcript (HTML + JSON) of messages exchanged in a support ticket at the time it is closed | Ticket system |
| Starboard, auto-roles, auto-voice, stats, RSS, welcome config | Channel/role IDs, message thresholds, configured templates, feed URLs | Guild admin configuration via commands or dashboard |
| Webhook URLs | Logging webhook URLs (stored AES-256-GCM encrypted at rest) | Dashboard logging configuration |
| Bot telemetry | Per-shard guild/user counts, memory/CPU usage, ping, uptime | Internal heartbeat, not tied to individual users |
| Technical data | IP address, browser user agent, and similar metadata processed transiently by the web server/hosting provider for security and abuse prevention | Dashboard HTTP requests |
We do not intentionally collect payment information, government ID data, precise geolocation, or special categories of data (e.g. health, biometric data). We do not knowingly collect data from users under Discord’s minimum age requirement (13, or higher where required by local law).
3. How we use data
We use the data described above to:
- Provide and operate the features a guild administrator enables (moderation logging, leveling, economy, giveaways, tickets, starboard, auto-roles, auto-voice, RSS, suggestions, welcome messages, statistics channels).
- Authenticate dashboard users via Discord OAuth2 and determine which guilds they can manage (based on Manage Server / Administrator permission or guild ownership).
- Maintain moderation history so staff can review a member’s prior cases.
- Detect, prevent, and investigate abuse, security incidents, or violations of these Terms.
- Display server statistics, leaderboards, and shard/uptime telemetry.
- Sync real-time state between the bot and dashboard (e.g. live suggestion vote counts) via our internal Redis pub/sub channel. This data is transient and is not persisted beyond what is described above.
We do not sell personal data, and we do not use message content or user data for advertising or profiling purposes.
4. Legal basis for processing (EEA/UK users)
Where applicable, we rely on:
- Contract/legitimate interest: providing bot functionality that a guild explicitly configures and invites the bot to perform.
- Consent: given via Discord OAuth2 authorization when you log into the dashboard.
- Legitimate interest: security, abuse prevention, and service reliability (e.g. shard telemetry).
5. Data storage & security
- Data is stored in a SQLite database managed via Prisma, and accessed by both the bot and the dashboard.
- Two sensitive free-text fields, suggestion content and logging webhook URLs, are encrypted at rest using AES-256-GCM before being written to the database.
- The dashboard applies security headers (
X-Frame-Options: DENY,X-Content-Type-Options: nosniff, a restrictiveReferrer-Policy, andPermissions-Policy), guild-access checks on every configuration endpoint, and outbound-URL validation (SSRF protection) for user-supplied RSS/webhook URLs. - Ticket transcripts are viewable only by members of the guild the ticket belongs to, rendered in a sandboxed iframe.
- Access to the dashboard requires Discord OAuth2 login; a user can only manage guilds they own or have Manage Server/Administrator permission in.
- No security measure is perfect. We cannot guarantee absolute security of data transmitted over the internet.
6. Data retention
- Moderation cases, ticket transcripts, and suggestions are retained indefinitely as a permanent record unless a guild administrator or we delete them, or the guild removes the bot (see below).
- Economy, leveling, and configuration data are retained for as long as the bot remains in a guild and the corresponding feature is in use.
- Bot telemetry (shard stats) is overwritten on each heartbeat and does not accumulate history.
- When the bot is removed from a guild, guild-scoped data is deleted in a cascading manner from our database (all models are keyed to the guild and cascade-delete with it), except where we are required to retain records (e.g. for security investigations) for a limited additional period.
- Dashboard session/OAuth tokens are stored only for the duration of an active session and are refreshed or discarded per standard OAuth2 token lifetimes.
7. Data sharing & third parties
We do not sell or rent personal data. Data may be shared only with:
- Discord, Inc., as the platform the Service operates on. Your use of Discord is separately governed by Discord’s Privacy Policy and Terms of Service.
- Hosting/infrastructure providers (e.g. server hosting, database hosting) strictly to operate the Service.
- Law enforcement or regulators, only where required by valid legal process.
- Third-party RSS feed sources you configure. The bot fetches content from the URLs you provide; we validate these URLs to prevent abuse (SSRF protection), but we are not responsible for the content or privacy practices of third-party feeds.
8. Your rights
Depending on your jurisdiction (e.g. GDPR for EEA/UK residents, CCPA/CPRA for California residents), you may have the right to:
- Request access to, correction of, or deletion of your personal data.
- Object to or restrict certain processing.
- Request a copy of your data in a portable format.
- Withdraw consent (e.g. by revoking the dashboard’s Discord OAuth2 authorization in your Discord settings) at any time.
To exercise these rights, contact m@pawelb.link. Note that some data (e.g. moderation case history) may be retained by the guild administrator independently of us, as they control the guild’s use of the Service; requests concerning guild-specific records may need to be directed to that guild’s staff as well.
You can also remove most of your own data at any time by asking a server administrator to remove the bot from the guild, or by using any in-app “delete my data” commands the guild has enabled, where available.
9. Children’s privacy
The Service is not directed at children under the age required by Discord’s Terms of Service (currently 13, or higher where local law requires). We do not knowingly collect data from such users. If you believe a minor has provided data to us in violation of this policy, contact us to request deletion.
10. International transfers
Data may be processed and stored in countries other than your own. Where required, we take reasonable steps to ensure an adequate level of protection for such transfers.
11. Changes to this Privacy Policy
We may update this policy from time to time. Material changes will be announced via the support server or dashboard. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
Part 2: Terms of Service
1. Acceptance of terms
By inviting the bot to a guild, using any of its commands, or logging into the dashboard, you confirm that you (a) have the authority to do so (e.g. you are a guild owner/administrator, or a member interacting with bot features made available to you), (b) agree to these Terms, Discord’s own Terms of Service and Community Guidelines, and (c) meet Discord’s minimum age requirement.
2. Description of the Service
The Service provides Discord server moderation, engagement, and utility features, including but not limited to: moderation logging and case tracking, auto-moderation, leveling/XP, a virtual economy with a shop, giveaways, support tickets with transcripts, a starboard, auto-roles and reaction roles, temporary “auto-voice” channels, RSS feed announcements, member suggestions with voting, welcome messages, dynamic statistic channels, and a web dashboard for configuring these features.
3. Eligibility & guild administrator responsibilities
- You must comply with Discord’s Terms of Service and Community Guidelines.
- Guild owners/administrators who configure the Service are responsible for how it is used within their guild, including which features are enabled, what content is entered into configuration fields (e.g. welcome messages, ticket panel text, embed colors, RSS feed URLs), and for informing their members that a moderation bot with logging is active, where required by applicable law.
- Administrators granting the dashboard access to their guild via Discord OAuth2 must ensure only authorized staff obtain such access.
4. Acceptable use
You agree not to:
- Use the Service to violate any applicable law, Discord’s Terms of Service, or the rights of others.
- Attempt to exploit, abuse, reverse-engineer, or interfere with the Service’s operation, including but not limited to spamming commands, attempting to bypass rate limits, or using the RSS/webhook features to target internal or non-public network addresses (SSRF).
- Use the moderation, ticket, or logging features to harass, discriminate against, or unlawfully surveil members.
- Use the virtual economy/shop features to facilitate real-money trading, gambling for real value, or any illegal transaction. All in-Service currency has no monetary value and cannot be exchanged for real money.
- Upload, submit, or configure content (including via suggestions, ticket messages, welcome text, or embeds) that is illegal, infringing, hateful, or otherwise violates Discord’s Community Guidelines.
5. Moderation actions & disputes
Moderation actions (warnings, kicks, timeouts) performed through the Service are initiated and are the responsibility of the guild’s own staff/administrators. We provide the tooling but do not control how individual guilds apply it. Disputes about a specific moderation action should be directed to that guild’s staff.
6. Availability & modifications
- The Service is provided on an “as available” basis. Features may be added, changed, or removed at any time, and the Service may be temporarily unavailable for maintenance, upgrades, or due to factors outside our control (including Discord API outages).
- We may modify these Terms at any time. Continued use of the Service after changes take effect constitutes acceptance.
7. Data & content ownership
- You retain ownership of content you submit (e.g. suggestion text, ticket messages), subject to the license needed to operate the Service (e.g. storing, encrypting, displaying, and transcribing it as described in the Privacy Policy).
- Guild-scoped configuration and records are tied to the guild; removing the bot from a guild results in deletion of that guild’s data as described in the Privacy Policy.
8. Disclaimer of warranties
THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE.
9. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF DATA, REVENUE, OR GOODWILL, ARISING FROM YOUR USE OF (OR INABILITY TO USE) THE SERVICE, INCLUDING LOSS OF VIRTUAL CURRENCY, SHOP ITEMS, GIVEAWAY ENTRIES, TICKET TRANSCRIPTS, OR MODERATION RECORDS.
10. Termination
We may suspend or terminate access to the Service (including removing the bot from a guild or revoking dashboard access) at any time, with or without notice, for conduct that violates these Terms, Discord’s policies, or applicable law. Guild administrators may terminate use at any time by removing the bot from their guild or revoking the dashboard’s OAuth2 authorization.
11. Governing law
These Terms are governed by the laws of the Republic of Poland, without regard to its conflict-of-laws principles, unless otherwise required by mandatory local consumer-protection law.
12. Contact
Questions about these Terms or the Privacy Policy can be sent to m@pawelb.link or via our support server: https://discord.gg/8MsZrjwJjD.