Privacy Policy
Effective August 6, 2026 · Last updated August 6, 2026
This policy describes what the Assistance Discord bot, dashboard, docs, package registry, ticket portal, and verification pages (together, the "Service") collect about you, why, who else sees it, and how long it is kept. It is a description of what the Service does today, not a list of things we reserve the right to do.
The short version: we collect what the features you use require, we do not sell or share your personal information, we do not run advertising or analytics trackers, and content you create inside a Discord server is visible to that server's staff.
1. Who we are
Assistance is operated by TODO_LEGAL_NAME (TODO_MAILING_ADDRESS). For the purposes of the EU and UK General Data Protection Regulation, we are the controller of the personal data described in this policy, except where a server operator configures the Service for their own community — in that case they decide what to collect and why within their server, and we act on their instructions.
This policy does not cover Discord itself, Roblox, or any other site the Service links to. Their handling of your data is governed by their own policies.
2. What we collect
We collect only what a feature needs to work. If your server does not enable verification, no verification data is collected; if you never sign in to the dashboard, no OAuth tokens are stored.
| Category | What it includes | Where it comes from | Why we have it | How long we keep it |
|---|---|---|---|---|
| Discord account | Discord user ID, username, display name, avatar, account flags, and the OAuth access and refresh tokens you grant when you sign in. | Discord, when you sign in or interact with the bot | Authenticating you, showing you the servers you can manage, and acting on your behalf within the scopes you approve | Until 90 days after your last sign-in, or sooner on request |
| Server configuration | Server ID, name, icon, the settings you choose (log channels, dashboard role permissions, feature toggles, verification setup), and encrypted server secrets and API tokens. | You and other administrators of the server | Operating the features the server has enabled | Until 30 days after Assistance is removed from the server |
| Tickets and transcripts | Ticket metadata, participants, status, feedback ratings and comments, and a snapshot of the channel's messages — including message text, embeds, component layouts, and attachment URLs. | You and other members of the server, captured from Discord | Providing the ticket system and letting staff read a ticket after its channel is gone | Until the ticket or the server's data is deleted |
| Library and package content | Templates, custom commands, automations, files and their versions, folders, package names and descriptions, and password hashes for protected packages. | You, through the dashboard | Storing, versioning, and — for public packages — distributing the content you author | Until you delete it, or the server's data is deleted |
| Moderation reports | Reporter account ID, the package reported, the reason category, and the details you write. | You, when you submit a report | Reviewing reports, preventing duplicate and automated reports, and keeping a record of moderation decisions | 2 years from resolution |
| Roblox verification | Your Roblox user identifier, the verification method used, the time you verified, and — for the OAuth method — Roblox access and refresh tokens. | Roblox, when you complete verification | Confirming a Roblox account belongs to you so a server can grant access | Until you unlink the account or your Assistance account is deleted |
| Verification risk signals | A keyed hash (HMAC) of your IP address and of a browser fingerprint, how long the verification took, a risk score, and the reasons behind it. The raw IP address and fingerprint are not stored, and the hashes are scoped to a single server so they cannot be used to correlate you across servers. | Your browser during a verification attempt | Detecting alt accounts and automated verification in the server you are joining | Set by each server between 1 and 90 days; 30 days by default |
| Member risk profiles | Discord user ID, username, display name, whether a custom avatar is set, account creation and join dates, message and activity counters, and a risk score. Counters only — message contents are not stored here. | Discord activity in a server that has enabled the feature | Giving server moderators a signal about likely spam and raid accounts | Until the server's data is deleted |
| Notification preferences | Whether direct messages are enabled, dashboard preferences, and a flag set when Discord repeatedly refuses delivery to you. | You, and Discord's delivery responses | Respecting your notification choices and not retrying deliveries that always fail | With your account |
| Logs and diagnostics | Timestamps, request paths, error traces, release identifiers, and the account or server an action related to. IP addresses may appear in infrastructure logs held by our hosting providers. | Automatically, as you use the Service | Diagnosing faults, investigating abuse, and keeping the Service reliable and secure | 30 days |
We do not collect precise geolocation, biometric data, government identifiers, health data, or financial account numbers.
3. How we use it
We use the information above to:
- Operate tickets, templates, custom commands, automations, the library, the package registry, and verification.
- Sign you in, keep you signed in for seven days, and let you switch between linked accounts.
- Carry out the actions you request in Discord on your behalf, within the OAuth scopes you granted.
- Score verification attempts for risk and give server moderators the signals they configured.
- Review reports of abusive, infringing, or misleading packages and enforce our Acceptable Use Policy.
- Investigate faults, security incidents, and abuse of the Service.
- Comply with law and respond to valid legal process.
We do not use your information for advertising, for profiling unrelated to abuse prevention, or to train general-purpose AI models.
4. Legal bases (EEA and UK)
If you are in the European Economic Area or the United Kingdom, we rely on the following bases:
| Purpose | Legal basis |
|---|---|
| Running the features you or your server asked for | Performance of a contract |
| Authenticating you and keeping your session | Performance of a contract |
| Verification risk scoring and abuse prevention | Legitimate interests — keeping servers free of alt accounts, raids, and automated abuse, which is also why the underlying identifiers are hashed and expire |
| Diagnostics, error monitoring, and security logging | Legitimate interests — operating a reliable and secure service |
| Responding to legal process | Legal obligation |
Where we rely on legitimate interests, we have considered the effect on you — which is why verification identifiers are hashed before storage, scoped to a single server, and deleted on a schedule rather than kept indefinitely. You can object to processing based on legitimate interests at any time; see your rights.
6. Automated features and AI
The Service uses automated processing in three places.
- Ticket descriptions. When a ticket is opened, the first few messages from its creator may be sent to a third-party large language model, through our AI provider, to generate a short title. If the messages do not reveal what the ticket is about, no title is generated. Server operators can turn this off.
- Documentation search. The assistant on our docs site sends your question, and passages from our public documentation, to the same provider. Do not put confidential information in it.
- Verification risk scoring.A score is calculated from the hashed signals described above. A high score can require a moderator to review your verification before you are given access to a server. This is not a decision with legal or similarly significant effects, it is never the only thing standing between you and access, and a human moderator in that server can always override it. If a score has blocked you, ask that server's moderators to review it, or contact us at TODO_EMAIL_PRIVACY.
Our AI provider processes this content to return a response and does not use it to train its models. We do not use your content to train models of our own.
7. International transfers
We operate from the United States, and our providers store and process data in the United States and other countries. If you are in the EEA, the UK, or Switzerland, this means your information is transferred outside your country. Where a provider is not covered by an adequacy decision, transfers rely on the European Commission's Standard Contractual Clauses, and on the UK Addendum for UK transfers. The specific location of each provider is listed on our Subprocessors page.
8. Retention
Retention periods are stated per category in section 2. In summary:
- Server data is deleted within 30 days of Assistance being removed from the server.
- Account data is deleted within 90 days of your last sign-in, or sooner if you ask.
- Verification risk signals expire on the schedule the server chose, between 1 and 90 days, and expired rows are removed automatically before each new observation rather than on a nightly sweep.
- Logs and diagnostics are held for 30 days.
We may keep information longer where we need it to resolve a dispute, enforce our agreements, or comply with a legal obligation — and where we do, we keep only what that purpose needs.
9. Security
These are the measures actually in place:
- Discord and Roblox OAuth tokens and server secrets are encrypted at rest with a key held separately from the database.
- Sessions are signed, HTTP-only, and expire after seven days. Package passwords are stored as hashes, never in plain text.
- IP addresses and browser fingerprints used for verification risk are hashed with a keyed function before they are written, so the stored values cannot be reversed into the originals.
- All traffic is served over TLS. Administrative access is limited to people who need it.
No system is completely secure, and we do not claim otherwise. We hold no security certifications. If you believe you have found a vulnerability, please report it privately — see our Acceptable Use Policy for the disclosure process.
10. Your rights
Everyone
Whatever jurisdiction you are in, you can ask us for a copy of the data we hold about you, ask us to correct it, or ask us to delete it. You can remove Assistance from a server to stop further collection there, and you can revoke the dashboard's access to your Discord account in your Discord Authorized Apps settings.
EEA and UK
You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection — including objection to processing based on legitimate interests. Where processing is based on consent, you can withdraw it at any time without affecting what came before. You also have the right to complain to your national supervisory authority; in the UK that is the Information Commissioner's Office.
United States
Residents of California, Colorado, Connecticut, Texas, Virginia, and other states with comprehensive privacy laws have rights to know, access, correct, delete, and obtain a portable copy of their personal information, and to opt out of targeted advertising, sale, and certain profiling. We do not conduct targeted advertising or sales, so the opt-out has nothing to act on — but the request will be honored as a matter of record if you make it. We honor Global Privacy Control signals. If we deny a request, you may appeal by replying to our decision; we will respond to an appeal within 45 days and tell you how to contact your state attorney general if you remain unsatisfied.
11. How to exercise your rights
Email TODO_EMAIL_PRIVACY from the address associated with your account, or ask through our support server. Tell us which right you are exercising and, for server data, which server you mean.
We verify requests by asking you to authenticate with the Discord account concerned, because that account is the only identifier we hold for most users. An authorized agent may act for you if they provide written permission signed by you, and we may still ask you to confirm it directly.
We respond within 45 days, and will tell you if we need a single extension. There is no charge, unless a request is manifestly unfounded or repetitive. Exercising a right will never result in a worse service — we do not offer financial incentives for data, and we do not degrade features for people who make requests.
12. California privacy rights
We are a small operator and do not currently meet the thresholds that make the California Consumer Privacy Act apply to a business. We extend its rights to California residents anyway, as described in section 10, and we will state it plainly here if that ever changes.
Sale and sharing.We have not sold or shared personal information for cross-context behavioral advertising in the preceding twelve months, and we do not do so now. We do not disclose personal information to third parties for their own direct marketing, so there is nothing to request under California's Shine the Light law.
Sensitive personal information. The only category of sensitive personal information we hold is account credentials — the Discord and Roblox OAuth tokens that let the Service act on your behalf. We use them solely to perform the actions you request within the scopes you granted, which is a use the CCPA permits without a right to limit it. We do not collect racial or ethnic origin, religious beliefs, health data, sexual orientation, precise geolocation, or the contents of your private messages outside a ticket you opened.
Inferences. Verification risk scores and member risk profiles are inferences about the likelihood that an account is automated or evading a ban. They are drawn only from the signals listed in section 2, they are scoped to one server, and they are not used to infer anything about you as a person.
Do Not Track. Browsers send Do Not Track signals in inconsistent ways and there is no agreed standard for honoring them, so the Service does not respond to DNT. We do honor Global Privacy Control signals, which are a recognized opt-out mechanism.
Users under 18. If you are a registered user under 18, you can ask us to remove content you posted through the Service by emailing TODO_EMAIL_PRIVACY. Removal may not be complete or comprehensive — for example, content already copied by others, or messages that exist on Discord independently of us.
13. Cookies and similar technologies
The Service sets a small number of cookies, all of them necessary to sign you in, keep your session, unlock password-protected packages, or run the anti-bot check on the verification page. We set no analytics, advertising, or tracking cookies. Each cookie is named and explained in our Cookie Policy.
14. Children
The Service is not directed to children. You must be at least 13 years old, or older where Discord requires it in your country, to use it. We do not knowingly collect personal information from anyone below that age. If you believe a child has provided us with personal information, email TODO_EMAIL_PRIVACY and we will delete it.
15. Changes to this policy
We review this policy at least once a year. When we change it, we update the dates at the top of this page. If a change materially affects how we handle your information — a new category of data, a new purpose, a new recipient — we will give notice in the dashboard or our support server before it takes effect, and where the law requires consent we will ask for it rather than assume it.
16. Contact
TODO_LEGAL_NAME
TODO_MAILING_ADDRESS
Privacy: TODO_EMAIL_PRIVACY
See our Terms of Service for the terms governing the Service, and our Subprocessors page for the current list of vendors that process data on our behalf.