Privacy Policy

Last updated 12 August 2026. This describes what ArtSoul OS stores about the people on your Discord server, why, and how to get rid of it. It is written to be checkable: the data model it describes is published in full, so you can confirm there is no column holding something we have not mentioned.

What we store

WhatWhy
Discord user ID, username and avatar reference of membersTo award XP, roles and prizes to the right person, and to show a member list to your moderators
Discord server ID, name, icon and the roles and channels you mapTo act on the right server and know which role means what
Counts and timestamps: messages sent, XP, levels, daily and per-channel activityLevels, leaderboards and the activity view
Moderation records: warnings, timeouts, protection events, the audit logSo a moderator can see what happened and who did it
Your server's configuration: which modules are on, schedules, branding, templates installedTo run the server the way you set it up
An email address for the server owner: only if you consent at sign-inSolely to warn you before a subscription lapses. Never marketing, never shared
Payment records: the transaction hash, amount, and the wallet address you declaredTo match a transfer to your subscription and not credit it twice
A wallet address, if a member submits one to claim a wallet prizeTo pay the prize. Visible to your moderators, not to other members

What we do not store

  • The content of messages. XP counts that a message happened, not what it said. The one place this needs care is the duplicate-spam filter, which has to recognise the same message sent twice: it keeps a one-way fingerprint of the last few messages, for seconds, which cannot be turned back into text. The rename of that column from contents to content_hashes is visible in the published schema.
  • Direct messages, voice, attachments, or anything from a channel the bot cannot see.
  • Passwords. Sign-in is Discord's OAuth; we never see your Discord password.
  • Payment card details, because we do not accept cards.
  • Analytics or advertising trackers of any kind. There are none in the dashboard.

Who can see it

The people you grant dashboard access to, at the level you grant them, on your server only. One server can never read another's data.

Including us. The operator's account has no automatic access to a customer server's members, logs or configuration. It is subject to the same check as anybody else. What the operator can do across every server is billing: see subscription status and grant, extend or revoke it. If you want hands-on help with your server, you grant it the way you would to any helper: make the account an administrator in Discord. You revoke it there too.

Where it lives, and for how long

  • A managed PostgreSQL database in the EU (Supabase, eu-west-1), and a server in Germany (Hetzner, Falkenstein).
  • Audit and moderation logs: 7 days on the Free tier, 365 days on Premium.
  • Spam-filter fingerprints: seconds, then deleted by a sweep.
  • Server configuration after a subscription lapses: 30 days, then cleared.
  • Everything else: while the bot is on your server. Remove the bot and processing stops immediately.

Third parties

We use as few as possible, and none of them receive message content: Discord (the platform itself), Supabase (database hosting), Hetzner (the server), Cloudflare (DNS, and mail forwarding for our own addresses), Resend (sending the subscription emails), and a Base RPC provider, which sees the transaction hashes we look up. We do not sell data to anyone, and there is no advertising in this product to sell it for.

Your rights

If you are in the EU or UK, the GDPR applies and we honour it everywhere rather than only where we must. You can ask for a copy of what we hold about you, ask for it to be corrected, or ask for it to be deleted. For members of a server, the server owner can act on your behalf, or you can write to us directly.

Write to [email protected] from an address we can tie to the request, or open a ticket on your server and have the owner forward it. We answer within 30 days and usually much sooner. Deletion is real deletion, not a flag.

If something goes wrong

If data is exposed, we will tell affected server owners within 72 hours of finding out, describe what happened and what we did about it, and say so publicly if members are affected. To report a vulnerability, see security.txt: the policy, including what we promise in return, is published.

Changes

Material changes are announced in the dashboard and by email to owners who have given us an address, at least 14 days before they take effect.

Contact

[email protected]. There is no legal department; you get an answer from a person.