01
Who is responsible for your information
Ash’s Mod Bot, its website, dashboard, and related features (the “Service”) are operated by Russell Leedham (“we”, “us”, or “our”). Russell Leedham is the controller responsible for the personal information described in this policy.
Privacy questions and requests can be sent to Miragedev21@gmail.com.
The Service operates through Discord but is not created, operated, sponsored, or endorsed by Discord Inc. Discord processes information under its own privacy policy.
02
When this policy applies
This policy applies when the bot is present in a server; you use or are affected by a feature or moderation action; you use the website, dashboard, or a temporary setup or settings session; an authorised person configures the Service; or you contact us about support, privacy, security, a bug report, or an appeal.
03
Information the Service processes
Discord account and server information
We may process Discord user, server, channel, role, and message identifiers; usernames, display names, avatars, and server names; and ownership, membership, roles, and permissions needed to operate features or determine access. Discord OAuth sign-in supplies profile and server-membership information through the identify and guilds permissions. Not every server in that list is necessarily owned by the person signing in.
Moderation and configuration records
These include moderator-supplied warning reasons, timestamps and moderator identifiers; moderation preferences and thresholds; command settings and direct-message opt-outs; quarantine status and role-restoration identifiers; AutoMod settings; welcome and leave templates; channel selections; reaction roles, AutoRole, statistics and levelling settings; and other server configuration.
Global blacklist records may contain a user or server identifier, an identifying name where available, expiry information, and administrative information needed to operate or review a restriction.
Activity information
Message counts, XP, levels, and information needed for configured rewards or statistics may be stored against user and server identifiers. These are derived records, not stored copies of the ordinary messages from which they were calculated.
Delegated access and temporary sessions
We store the users or roles granted dashboard access by a server owner, their permitted settings and channels, and separately granted Bot Messages access. A separate owner-controlled server-wide switch determines whether /say and website Bot Messages may use mentions; it is off by default. Official service-announcement mention preferences are separate. The dashboard does not currently maintain a separate history of delegated-grant changes.
Temporary setup or settings access involves a token hash, the issuing Discord account and server, authorised scope, creation and expiry times, and redemption or completion state. Opening a temporary setup or settings link redeems it for that browser without a separate Discord confirmation step. Temporary choices and a settings snapshot are stored while you prepare and review setup; they are removed when the session finishes, is cancelled, or expires. A redeemed link establishes a restricted browser session limited to the server and settings authorised when the link was issued. The raw access token is a secret: do not share it or include it in a report. Account approval does not prove who physically operated the account or browser.
Bot Messages and service announcements
Custom messages deliberately submitted through website Bot Messages or the Discord /say command are recorded for accountability and safety when a confirmed send is attempted. Records include the submitting Discord account identifier; username where available; server and destination channel; submitted content; mention types permitted for the attempt; authorisation category (server owner, administrator, or delegated access); attempt time; delivery outcome; and a resulting Discord message identifier when available. They do not contain a full copy of the sender’s grants or role membership. The dashboard does not currently store separate review notes. Other automatically generated bot posts, such as role panels, are not included in this custom-message audit.
An audit identifies the account or authorised session used. It does not establish who physically operated that account or device.
Official service-announcement records may include the developer account, notice wording, time, intended servers and channels, and delivery outcomes. Per-server announcement preferences determine whether notices are received and, where supported and explicitly enabled, which mentions are permitted.
Website and dashboard information
We process Discord sign-in information, a random session-cookie identifier, server-side sign-in or temporary-session state, and request-verification information. The hosting provider may process limited technical information such as IP addresses, browser or device information, request times and pages, and operational or security logs.
Some changes made through the normal signed-in dashboard require a confirmation preview. The Service temporarily stores the proposed settings, any submitted role-panel text, an existing-settings snapshot, and account/session-binding information while that preview remains valid.
The website does not currently use advertising cookies or analytics trackers.
Information you send to us
Support messages, emails, appeals, and security reports may contain your contact details, Discord identifiers, message contents, attachments, and information you choose to supply.
Bug reports may include severity, a title and description, reproduction steps or additional details, submission time, affected server information, and a report identifier. Signed-in reports and Discord-command reports may include the reporter’s Discord username and identifier. Website reports submitted without signing in do not include Discord account details; ordinary hosting and security information may still be processed.
Do not include passwords, access tokens, API keys, payment details, or unnecessary sensitive information in messages, warning reasons, configuration fields, reports, or appeals.
04
How Discord message content is handled
Configured AutoMod checks may examine new messages in real time for blocked words or phrases, invite links, mention counts, and spam timing.
Ordinary Discord message content may be processed in real time but is not automatically stored in the Service’s database. It is processed only long enough to perform the configured check and action. Short-lived spam timing information is held temporarily in memory and discarded when no longer needed or when the bot restarts.
This is different from content deliberately submitted through Bot Messages, configuration templates, warning reasons, bug reports, support messages, appeals, or specific evidence supplied to us. Those submissions may be stored as described in this policy.
We do not use Discord message content to train artificial-intelligence or machine-learning models. Discord may separately retain messages under its own policies. Deleting a message or audit from the Service does not delete copies held by Discord, channel recipients, or other people.
05
Why information is used
We use information to provide configured features; authenticate users and enforce owner-approved access; remember preferences; deliver requested messages and service notices; maintain appropriate accountability records; investigate errors and misuse; protect users and the Service; operate blacklists and consider appeals; handle bug reports and notify the developer; answer support and privacy requests; and meet applicable legal and Discord requirements.
Review of Bot Messages
Bot Messages audit records may be reviewed by the server owner and, where reasonably necessary, the developer to investigate reports, identify misuse, protect users, and enforce the Service’s Terms and Discord’s rules.
Reviews may concern hateful or discriminatory conduct, harassment, bullying, threats, child exploitation or endangerment, prohibited transactions, and other harmful or unlawful use. Reviews will consider context and will not be treated as proof that a criminal offence has occurred.
This does not involve routinely storing or reviewing all ordinary Discord conversations. Access to audits is restricted to authorised reviewers. Any separate preservation or disclosure must be necessary, lawful, and consistent with this policy.
We do not sell personal information or use Discord API data for advertising, data brokering, or unrelated profiling.
06
Lawful bases
Where UK data-protection law applies, we rely primarily on legitimate interests to provide requested community features, prevent abuse, secure access, investigate reported problems, maintain proportionate accountability, and support users. We assess necessity and balance those interests against affected people’s rights and reasonable expectations, including those of users under 18.
Some processing may be necessary to provide a Service you directly request under the Terms. We may also process information to meet a legal obligation or establish, exercise, or defend legal rights, using an applicable lawful basis.
Where additional conditions apply to sensitive information or criminal-offence information, those conditions must also be satisfied. Describing a purpose in this policy does not itself authorise that processing.
Where consent is legally required, we will request it separately and explain withdrawal. We do not rely on consent where there is no genuine choice.
07
Who receives information
Information may be processed by:
- Discord, for the platform, APIs, sign-in, posted messages, and private developer bug-report notifications;
- Render, for hosting, technical requests, and operational logs;
- MongoDB Atlas, for stored records and website sessions;
- Google, for the Gmail account used for correspondence; and
- Mailjet, for private bug-report email notifications when configured and enabled.
Developer notifications through Discord and, when enabled, Mailjet may contain the report details described above. This does not mean all Bot Messages audit records are automatically emailed or sent by direct message.
Messages posted into Discord are visible to people who can access the destination channel. Server owners may access their server’s Bot Messages audits, and the developer may access records for the limited purposes described above. Delegated settings access does not automatically grant audit-review access.
Relevant information may be disclosed where required by law or a valid order, or where otherwise lawful and reasonably necessary to address abuse, security threats, or an appeal of platform enforcement. We aim to disclose only what is relevant and necessary.
Providers have their own privacy and security terms. Discord may act as a separate controller for its own processing.
08
International processing
Providers may process information outside the United Kingdom. Where UK law requires safeguards, an applicable lawful transfer mechanism must be used, such as appropriate contractual safeguards. Further information can be requested using the contact address above.
09
How long information is kept
Information is kept only while necessary for its stated purpose, subject to applicable legal and security requirements.
- Ordinary Discord message contents are not automatically stored; deliberately submitted content follows its relevant retention rule below.
- Normal website sessions and their cookie expire after up to 12 hours of inactivity, refreshed during active use.
- Unused temporary access links expire no later than 30 minutes after issue. Starting the secure setup in the browser redeems and consumes the raw link. The resulting restricted session ends on completion, cancellation, or expiry, and cannot extend access beyond that original 30-minute deadline. Short-lived confirmation data, setup drafts, settings snapshots, and session results are deleted on completion or cancellation where no longer needed, or through automatic cleanup after the original expiry. Expiry is enforced immediately even if background deletion has not yet run. Separate audit entries follow the audit rule below.
- Normal-dashboard resource-change confirmation previews expire after ten minutes. Expired previews cannot be applied, and the stored preview records are removed through automatic cleanup after expiry.
- Routine custom-message audits expire 90 days after the send attempt. They are hidden from audit viewers immediately on expiry and removed automatically by database cleanup, which may run shortly afterwards. Later viewing, server departure, or rejoining does not restart that period.
- Active delegated grants are retained as server configuration while needed; revocation removes the active permission. There is currently no separate delegated-grant change-history record.
- Spam timing information is held only temporarily in memory.
- Active server settings and necessary server-associated records remain while needed for configured features.
- When a member leaves, stored message counts, XP, and levels are scheduled for deletion six calendar months after departure. Rejoining before then cancels that scheduled deletion.
- Warning history, direct-message preferences, and quarantine-restoration records follow their operational and deletion rules. Active restoration information may remain until quarantine ends so roles can be restored.
- When the bot leaves a server, its settings and server-associated user records are archived for up to six calendar months. Rejoining during that period restores the archived configuration and records. This does not extend the separate 90-day audit limit.
- Global blacklist records remain separately while a restriction is active or while reasonably needed to prevent evasion, review appeals, document decisions, or protect the Service.
- Specific incident evidence is placed into the preserved-evidence area only by a manual decision. Its initial review/deletion deadline is two calendar months after the recorded submission date, or the preservation date if no submission date is recorded. Records are automatically deleted after their deadline unless the developer manually extends it and records a reason. The controls allow extensions of one to twelve calendar months at a time; this is a technical limit, not permission to retain information unnecessarily. Each extension must be justified by an ongoing necessary and lawful purpose, such as handling a specific unresolved incident or applicable legal requirement, and information should be removed sooner when no longer needed.
- Bug reports, support messages, emails, appeals, security reports, and operational service-announcement delivery records remain only while reasonably needed to handle the matter, maintain an appropriate record, resolve disputes, or meet applicable obligations. Bug reports may have copies in the developer panel, private Discord notifications, and email when enabled.
A valid deletion request may result in earlier deletion, subject to applicable exceptions. The six-month server archive does not govern global blacklists, preserved evidence, correspondence, provider logs, or routine message audits. Discord API data is deleted when no longer necessary for permitted functionality or when otherwise required by Discord or law.
Providers may retain backups and operational or security logs under their own retention schedules.
11
Your choices and rights
Server owners can revoke delegated permissions and configure supported features. Revocation prevents further authorised use but does not automatically erase earlier audit records.
Server administrators can use /clear-data to delete a user’s stored message count, warning history, XP, direct-message preference, and inactive quarantine-restoration history for that server. Active restoration information may remain until quarantine ends. The command does not reverse Discord timeouts or bans and does not automatically erase separate message audits, global restrictions, or preserved evidence.
Email Miragedev21@gmail.com to request access, correction, or deletion. Include the relevant Discord user or server identifier and only enough information to identify the records. We may verify identity or authority proportionately. Never send secrets.
Depending on applicable law and circumstances, you may also request restriction, object to processing based on legitimate interests, or request portability. We consider requests individually; lawful exceptions may apply. Corrections to an accountability record may be documented separately rather than silently rewriting its original history.
Privacy requests are distinct from blacklist appeals and will be handled within applicable statutory periods. An appeal does not guarantee a response or removal of a restriction.
You may complain to the UK Information Commissioner’s Office: https://ico.org.uk/make-a-complaint/.
12
Security
We use reasonable safeguards including restricted access, session protections, request-verification controls, and provider security features. Original message audit entries are not editable through the dashboard. These measures do not make records independently tamperproof or guarantee absolute security.
Blacklisted users or servers may be denied management access, including dashboard and temporary setup or settings access. Public legal information and applicable reporting or appeal routes remain available.
Report vulnerabilities privately to Miragedev21@gmail.com without account secrets or unnecessary personal information.
13
Children and minimum age
The Service is intended for people meeting Discord’s minimum age in their country. Discord communities may include teenagers, so we aim to minimise collection and apply protective defaults. Contact us if you believe the Service holds information relating to someone below the applicable minimum age.
14
Changes to this policy
We may update this policy as features, providers, processing, or requirements change. Material changes may be announced through the website, dashboard, support server, a service notice, or another appropriate channel, with advance notice where reasonably practical.
The policy shows its effective and last-updated dates. New processing will be reflected before it begins where required. Privacy Policy and Terms dates are maintained separately.
15
Contact
Russell Leedham
Email: Miragedev21@gmail.com
Please provide only information reasonably needed to explain your request.