01Scope of this policy
This policy explains how personal data is processed when Egestion (the "Service") runs in a Discord server or when you use its web dashboard. It covers the bot, the dashboard, the API behind it, and the background workers that carry out moderation actions.
It does not cover Discord itself. What Discord collects about you, on its own account, is governed by Discord's Privacy Policy. It also does not cover other bots, websites, or services a server administrator may link to.
It should be read with our Terms of Service, which set out the rules of use themselves.
02Who is responsible for what
Two different responsibilities overlap here, and confusing them is the usual source of misunderstanding.
For a server's moderation data, configuration, infractions, logs, message snapshots : the server's administrators decide what is collected and why. Under the GDPR they are the controller; we act as a processor, carrying out their instructions and nothing beyond them. A member's request to see or erase their moderation record is therefore addressed to the server's administrators first; we will assist them, and will act ourselves where they cannot or will not.
For the Service itself, your dashboard sign-in, Premium records, security logs, and the decisions about how the platform is built and secured : we are the controller. Those requests come straight to us, at the address in section 13.
03What we process
The ledger at the top of this page is the authoritative list. In summary, the Service processes: Discord identifiers (user, server, role, channel and message IDs), usernames and avatar hashes, the configuration you enter, moderation events and their reasons, short-lived rate counters, and technical request data.
Discord identifiers are pseudonymous but still personal data: they point at a person. We treat them as such throughout.
When you sign in, Discord is asked for two things only: identify and guilds, who you are, and which servers you are in. We do not request your email address, your connections, or the ability to read your direct messages, so Discord never sends them to us.
04Message content, specifically
This is the most sensitive thing the Service touches, so it is worth stating precisely.
Filtering is done in memory and leaves nothing behind. When anti-spam, the word filter or the link filter examines a message, the check happens as the message passes through and the text is discarded immediately. Only the outcome, that a message was deleted, and under which rule, is written down.
Snapshots are stored only where message logging is switched on. If your server has not configured a message-log channel, no snapshot is ever written for it. Where it has, we keep a reduced copy: the author, the text truncated to about 1,200 characters, embed titles and the first part of their descriptions, and attachment URLs. It is kept for twelve hours, in an hourly bucket that expires as a whole : so a message survives at most thirteen hours.
This exists for one reason: Discord's deletion event contains only identifiers, never the text. Without a snapshot, a deleted-message log can say that something was deleted but never what. After expiry the log says "content unavailable (too old)" : a deliberate limit, not a failure.
The bot receives message content only in channels where Discord grants it visibility. Restricting the bot's channel access restricts what it can ever see.
05Why we are allowed to
Where the GDPR applies, each processing rests on one of these bases:
- Performance of a contract, running the Service you asked for: your session, your configuration, your Premium term.
- Legitimate interests, keeping the Service secure and available, preventing abuse, and letting server administrators moderate their own communities effectively. We have weighed these against the rights of the people concerned, which is why retention is short and the data collected is reduced to what a log actually displays.
- Legal obligation, retaining transaction records for the period accounting and tax law require.
- Consent, where a feature is genuinely optional and switched on deliberately, such as message logging in a given server. Withdraw it by switching the feature off; existing snapshots then expire on their normal schedule.
We do not rely on legitimate interests for anything a member would not reasonably expect from a moderation bot.
06Who else sees it
We do not sell personal data, and we do not share it for anyone else's marketing. The only parties involved are those needed to run the Service:
- Discord, unavoidably. Everything the bot does is a call to Discord's API, and everything it sees comes from there.
- Our payment provider, for Premium. The checkout happens on their pages; card details never touch our servers. We send them only the server ID and the duration purchased, and receive back a transaction reference and a status.
- Hosting and infrastructure providers, who operate the machines and managed databases. They are bound by contract to process data only on our instructions.
- Server administrators and delegated moderators of the server concerned, who see that server's logs and moderation records. That is the point of the product.
We will disclose data to a public authority only where a valid legal demand compels it, and we will notify the affected controller unless the law forbids it.
One further disclosure for completeness: the dashboard loads a small number of web fonts from Google Fonts, which means your browser contacts Google's servers and they see your IP address. The public pages (including this one) load no third-party resource at all.
07Where it is stored
Data is stored on servers located in the European Union. Persistent records live in PostgreSQL; short-lived state lives in Redis, which is memory-first and expires entries automatically.
Discord operates globally, so data transmitted to or from Discord's API leaves the EU by the nature of the platform. Where any of our providers processes data outside the European Economic Area, that transfer is covered by the European Commission's Standard Contractual Clauses or an adequacy decision.
08How it is protected
Traffic to the dashboard and the API is encrypted in transit. Dashboard sessions use a signed token that expires after twenty-four hours and carries only what is needed to authorise a request; every API call re-checks your permissions against Discord's own role data rather than trusting the token alone. Administrative endpoints verify the caller on every single request, so removing someone's access takes effect immediately instead of when their token expires.
Databases are not exposed to the public internet and are reachable only from the application's own network. Access to production systems is limited to the people who operate the Service.
Retention itself is a security control here: data that has already expired cannot be leaked. That is a large part of why the windows in the ledger are as short as they are.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to people's rights, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and inform affected controllers and, where required, the individuals concerned.
09Deleting your data
Removing the bot from a server deletes that server's data. The server record is the parent of its configuration, infractions, moderation log and case counters; deleting it removes them along with it. There is no hidden copy kept for later, and nothing is merely flagged as inactive.
Short-lived Redis state is not deleted on removal because it does not need to be: every key carries an expiry, and the longest of them is thirty days. It disappears on its own schedule whether or not you do anything.
Premium and payment records survive removal, because accounting law requires it. They contain a server ID, dates, an amount and a transaction reference : not message content and not a member's moderation history.
To have a specific person's moderation record erased from a server that still uses Egestion, ask that server's administrators : they hold the controls (and see section 02). If they will not act and you believe the law entitles you to erasure, write to us and we will handle it.
10Your rights
If the GDPR applies to you, you have the right to obtain a copy of your data, to have inaccurate data corrected, to have data erased, to restrict or object to a processing based on legitimate interests, and to receive data you provided in a portable format.
Send the request to the address in section 13, from an address we can tie to your Discord account, and tell us the server concerned. We answer within one month; where a request is complex we may extend by two further months and will say so before the first month is out. There is no charge unless a request is manifestly unfounded or repetitive.
Automated moderation actions (an automatic mute, kick or ban) are decisions taken by rules a server administrator configured, applied to conduct inside their community. Where such a decision has a significant effect on you, you may ask that administrator for human review; they can reverse any sanction the bot applied.
You may also lodge a complaint with your national data protection authority. In France this is the CNIL.
11Children
The Service is not directed at children below Discord's minimum age for their country, and we do not knowingly process the data of anyone below it. We do not ask for a date of birth, and Discord does not give us one, so we cannot verify age ourselves.
If you believe a child's data is held through the Service, write to us with enough detail to locate the record and we will delete it.
12Cookies and local storage
There is no cookie banner on this site, and that is not an oversight: we set no analytics, advertising or tracking cookies, so there is nothing to ask consent for. Only strictly necessary storage is used, and under the ePrivacy rules that kind is exempt from consent.
What your browser actually keeps:
egestion_token, your signed session, so you are not thrown out on every page load. Expires after 24 hours.egestion_theme, light or dark. A display preference, nothing more.egestion_lang,egestion_rail,egestion_legal_track, interface preferences: dashboard language, sidebar state, and how you chose to read this page.- A short-lived cookie during the Discord sign-in redirect, cleared when you log out.
All of it lives in your browser. Clearing your site data removes every item above and signs you out : nothing on our side depends on it.
13Changes and contact
We may update this policy. Every version carries a number and an effective date, shown at the top. Where a change materially affects how personal data is processed, we will give at least 30 days' notice before it takes effect, through the dashboard or the support server. Corrections that do not change meaning take effect immediately.
If a retention window in the ledger changes, the ledger changes with it in the same release. It is meant to describe the system as it actually runs, not as it was described once.
Controller: the Egestion team. Data protection contact: [email protected]. We have not appointed a Data Protection Officer, as the Service does not meet the criteria requiring one; the address above reaches the person responsible.
While the Service is still in development we do not publish a postal address. This is a security decision, not an evasion: Egestion runs anti-raid and anti-DDoS infrastructure, and the people who attack the servers it protects have a standing interest in whoever operates it. Write to [email protected] for any legal, regulatory or data-protection request and we will answer with whatever identification the request calls for, including a postal address where one is legally owed. That mailbox is monitored and is the fastest route to the person responsible.
No section matches that word. Try another, or clear the filter.