Privacy policy

Last updated

Auttaja is a moderation bot for Discord, with a dashboard for the people who run the servers it is in. This page says what it stores, why, for how long, and how to have it removed. It is operated by the Auttaja Dev Team; the way to reach them is the support server.

What the bot stores in a server

Everything the bot keeps is filed under Discord's own identifiers: the numeric ids of servers, channels, roles, members and messages. In a server it has been added to, it stores:

  • Moderation records. Punishments (who was punished, by whom, when, for how long and the reason given), staff notes, purges, reports and appeals including any text or evidence link submitted with them, nickname requests, and which staff member ran which command.
  • Message content, only where logging asks for it. A server's staff can turn on logging of deleted and edited messages. In that server the bot keeps a copy of each message so the log can show what was removed or changed: the text, the sender, the channel, and links to any attachments, never the files themselves. Copies are deleted automatically after fourteen days by default, and are never kept longer than thirty.
  • Onboarding and roles. How far a new member has got through the server's gatekeeper steps, the roles to give back when a member returns, roles granted in voice channels, and the permissions a channel had before it was locked so they can be restored.
  • Things members set themselves. Reminders, with their text and time, and any profile fields the server offers and the member has filled in.

Usernames and nicknames are checked against the server's workflows as they change; the name a workflow acted on is kept in that server's run history for the same retention window as messages, and otherwise only in the logs the server has turned on. Automod looks at each message as it arrives and keeps only short-lived counters, in memory, to spot floods.

What the dashboard stores about you

Signing in to the dashboard goes through Discord. Discord tells Auttaja who you are (your user id, username, display name and avatar) and which servers you are in, along with whether you can manage each one. That list is what the server picker shows, and it is refreshed from Discord every few minutes while you use the dashboard.

  • The session cookie holds a random token and nothing else. The server keeps only a hash of it, so a copy of the database yields no usable sessions. The Discord tokens that let the dashboard ask Discord about you are stored encrypted. A session lasts thirty days from sign-in; signing out deletes it and revokes the Discord tokens straight away.
  • Your theme choice (light or dark) is kept in your browser only and never sent anywhere.

The dashboard sets no other cookies and uses no analytics or advertising scripts.

Who can see it

The staff of a server see that server's records, through the bot's commands and the dashboard, and only if they hold the Discord permissions their server has given them. No server can see another's data. Members who are punished are told the reason and the record's id so they can appeal.

Auttaja does not sell data and does not share it with anyone other than Discord, whose service it runs on, and the provider that hosts it. The team operating the bot can reach the database to run the service, fix faults and answer the requests below. Aggregate figures such as how many servers the bot is in and how many commands run are collected for monitoring; they identify nobody.

How long it is kept

  • Message copies: at most thirty days, fourteen by default, then deleted automatically.
  • Dashboard sessions: thirty days from sign-in, or until you sign out. Expired sessions are purged.
  • Moderation records and settings: for as long as the server keeps them. Staff can remove a punishment or note with the bot's commands or from the dashboard.

Your choices

  • A server's staff can turn message logging off at any time, or remove the bot altogether.
  • To ask for a copy of what is stored about you, or to have it deleted, contact the team in the support server. Some records are a server's, not yours; a punishment you received is deleted at that server's request or when the record is removed by its staff.

Age

Auttaja is used through Discord and is subject to Discord's minimum age, which is thirteen or higher where local law says so. It is not directed at children below that age.

Changes

If this policy changes, the new text appears here with a new date at the top. A change that affects what is stored or shared is announced in the support server.