Privacy Policy
Last Updated: August 1, 2026
Your privacy is important to us. This Privacy Policy explains what information we collect, how we use it,
where we store it, and how we protect it. By using our Discord Bot, Website, or API services, you agree to the practices described in this policy.
1. Information We Collect
We collect the following types of information to provide and improve our services:
User Data
- Discord Account: User ID, Username, Global Name, Avatar, and OAuth2 tokens (for web login).
- Servers in common: A cached list of the Discord servers you share with the bot, used to render your dashboard without re-querying Discord on every page load.
- Roblox Account: User ID, Username, Display Name, Avatar, ID Verification status, and Group Memberships.
- Linked Accounts: The association between your Discord and Roblox accounts, including a history of link and unlink actions.
What We Do Not Collect
We do not receive or store the content of your Discord messages, and we do not receive or store your
Discord presence, online status, or activity. Our bot does not request the Message Content or Presence
intents from Discord, so this data is never transmitted to us. We never use any data we hold to train
machine learning or AI models.
Operational Data
When you interact with our services (e.g. logging in via the web dashboard), we may collect technical data necessary for the operation, security, and integrity of the Service. This may include:
- IP addresses.
- Browser and device information.
- Persistent identifiers (cookies) used to maintain your session.
- Roblox inventory data (e.g. badge ownership) when required for badge-based role assignment.
Guild (Server) Data
- Guild IDs and configuration settings.
- Role mappings (Roblox Group Ranks and Badge IDs to Discord Roles).
- Nickname formatting preferences.
- Log channel configurations.
API & Service Data
- API Keys (including owner ID, tier, and usage stats).
- Voucher usage history.
2. How We Store Your Data
Your data is stored in a secure MongoDB database. This allows for persistent settings, reliable role synchronization, and service features.
Cookies: We use signed and encrypted cookies for session management when you log in to our web dashboard. We also use persistent tracking cookies to maintain service integrity.
2a. Data Retention
We retain different categories of data for different periods:
- Account and link data is retained while your account is active. The link must
persist so that your roles can be re-applied whenever you rejoin a server or a server
re-synchronizes.
- Disconnecting. Unlinking a Roblox account, or deleting your Discord connection,
immediately erases the associated OAuth tokens and stops the account being used for verification.
A limited record of the connection is retained for security and abuse prevention. To have that
removed as well, request full erasure under Section 7.
- Link and unlink history is automatically and permanently deleted after 90 days by a
database expiry rule.
- Operational data (IP addresses, device information, tracking cookie identifiers) is
capped to a rolling window of the most recent entries, and older entries are discarded automatically
as new ones arrive.
- Cached data (badge ownership, shared servers, avatars) is refreshed on a schedule and
is not retained independently of your account.
- Expired API vouchers are permanently deleted 30 days after expiry.
When you delete your account, all of the above is erased immediately rather than waiting for these periods
to elapse. See Section 7.
3. How We Use Your Information
We use the collected information to:
- Verify your identity and link your Discord account to your Roblox account.
- Automatically update your Discord nickname and roles based on your Roblox group data and badge ownership.
- Provide access to the web dashboard for managing server settings.
- Manage API access and enforce rate limits based on your API key tier.
- Maintain the security and integrity of the Service.
- Troubleshoot technical issues and improve service performance.
4. Data Sharing
We do not sell your personal data to third parties. However, to function correctly, our service interacts with:
- Discord API: To fetch your profile, manage roles, and update nicknames.
- Roblox API: To verify your account ownership, fetch group rank information, check badge ownership, and confirm ID verification status.
- Third-party services: We may use external services to process operational data (e.g. IP address validation) for the purpose of maintaining service integrity. These services only receive the minimum data necessary.
5. Roblox Inventory Access
If a Discord server has configured badge-based roles, we will check your Roblox inventory for specific badge ownership using the Roblox Open Cloud API. This check only retrieves badge data relevant to the configured roles. If your inventory is set to private, badge-based roles cannot be assigned and you will be notified.
6. Data Security
We implement industry-standard security measures to protect your data:
- Encryption at rest: All data is stored in MongoDB Atlas, where every storage volume
is encrypted at rest with AES-256 by default. Encrypted database backups are covered by the same
protection.
- Encryption in transit: All connections to our website use HTTPS (TLS), and all
connections between our application and our database are TLS-encrypted and enforced.
- Session security: Sessions use signed, HTTP-only, secure cookies, and state-changing
actions are protected by CSRF tokens.
- Access control: Database access is restricted to the application, and administrative
dashboard functions are limited to authorized accounts.
API Keys should be kept secret and are the responsibility of the user.
7. Your Rights
You have control over your data:
- Unlinking a Roblox account: You can unlink any Roblox account at any time from the
web dashboard ("Roblox Accounts" section). Its OAuth tokens are erased immediately
and it stops being used for verification.
- Deleting your Discord connection: You can do this yourself at any time, without
contacting us, from Dashboard → Settings → Danger Zone. It unlinks every connected
Roblox account, erases your stored Discord and Roblox OAuth tokens, and removes your verified roles
and nickname from every server. Logging in again reactivates your account; each Roblox account has
to be re-linked.
- Guild Data Deletion: Guild Owners can permanently delete all data associated with their Discord server via the "Guild Settings" page on the web dashboard.
- Full erasure (by request): The options above disconnect your accounts but retain a
limited record for security and abuse prevention. To have everything we hold about you permanently
and irreversibly erased, email us at the address in Section 8. Please email from an address we can
reasonably associate with the account, or include your Discord user ID.
- Access: You can view the data we hold about you via the web dashboard. The
/lookup command is a tool available to authorized users (based on API Key tier) to query linked user information for verification and administration purposes.
8. Contact Us
If you have any questions about this Privacy Policy, please contact us at xingfutang0669@gmail.com.
9. Updates to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last
Updated" date at the top of this page.