Legal

Privacy Policy

Effective July 6, 2026

This policy explains what data the StaffGuard Discord bot and web dashboard (the “Service”) collect, why they collect it, and the choices you have. The short version: we store what your staff team records through the bot and dashboard so it can be shown back to them, we use no analytics or advertising trackers, and we never sell data.

1. Data we collect

When you sign in to the dashboard (via Discord OAuth with the identify and guilds scopes):

  • your Discord user ID, username, and avatar;
  • the list of servers you belong to, used only to show you which servers you can manage (cached in server memory for about 60 seconds and not stored in our database);
  • a Discord access token, held inside your encrypted session cookie so the dashboard can act on your behalf.

When your server uses the bot, we store the records your staff team creates:

  • server configuration: settings, staff role hierarchy, branding, embed designs, and ticket panel setup;
  • moderation cases: the affected user’s Discord ID, the acting staff member’s ID, action type, reason, timestamps, and any proof images staff attach;
  • staff HR records: strikes/infractions, promotions, quota progress, and leave-of-absence requests;
  • tickets: messages exchanged in ticket channels and the HTML transcripts generated when tickets close;
  • audit entries recording configuration and moderation activity, and blacklist entries where applicable.

We do not read or store general server messages outside these features.

2. Cookies

The dashboard uses one first-party cookie: an encrypted session cookie (up to 30 days). There are no analytics, advertising, or third-party cookies. Details are in the Cookie Policy.

3. How we use data

  • to operate the Service: showing cases, tickets, quotas, and settings back to your staff team;
  • to authenticate you and check which servers you may manage;
  • to keep the Service safe: enforcing blacklists and investigating abuse;
  • to maintain reliability, including routine encrypted backups of the database.

We do not sell personal data, do not share it with advertisers, and do not use it to train machine-learning models.

4. Sharing

Data is shared only with:

  • Discord, as the platform the Service runs on (messages, embeds, and images the bot posts are delivered through Discord);
  • our hosting infrastructure provider, which stores the database and backups;
  • authorities, if we are legally required to disclose it.

Within your server, records are visible to the staff members your administrators authorize — who can see what is controlled by the role hierarchy your server configures.

5. Retention

Server data is retained while the server uses the Service so that case history, staff records, and transcripts remain available to your team. Routine backups are kept on a rolling basis. If your server stops using the bot and you want its data deleted, contact us (section 9) or have a server administrator request deletion, and we will remove the server’s records within 30 days, after which they also age out of backups.

6. Your rights

Depending on where you live (for example under the GDPR or CCPA), you may have rights to access, correct, export, or delete personal data about you. Because most records in the Service are created by a server’s own staff team about its members, the fastest route is usually your server’s administrators; you can also contact us directly (section 9) and we will assist. We do not discriminate against anyone for exercising these rights.

7. Security

Sessions are encrypted (JWE) and dashboard access is gated by Discord permissions — configuration requires Manage Server in the target server. Data is transmitted over HTTPS and stored on access-controlled infrastructure. No system is perfectly secure, but if we learn of a breach affecting your data we will notify affected servers without undue delay.

8. Children

The Service is not directed at children under 13 (or the higher minimum age Discord requires in your country), and we do not knowingly collect data from them. If you believe a child is using the Service, contact us and we will act on it.

9. Contact and changes

Privacy questions and data requests can be raised through the StaffGuard support Discord server or the contact information on the bot’s Discord App Directory page. We may update this policy over time; material changes will be reflected on this page with a new effective date.