Clear choices. Careful handling.
What CharmBot processes, why it is needed and how you can control it.
Last updated September 8, 2026
Scope
This policy explains how CharmBot processes information through its public website, Discord bot and server dashboard. Discord server owners and administrators decide which optional features are enabled and how they are configured for their communities.
Information CharmBot processes
CharmBot processes only the information needed for the features you use:
- Discord account details used for login, including your Discord user ID, username, display name, avatar, server list and server permissions.
- Server details and configuration, including server, channel, role, member and message identifiers, server name, icon, member count and settings selected by authorized server managers.
- Feature data created when a feature is used, such as moderation cases, audit actions, ticket metadata, quotes, suggestions, polls, birthdays, profiles, experience points, virtual currency records, playlists and configured update sources.
- Plural and roleplay profile data, including the profile owner's Discord user ID and origin server, profile names, server choices, optional saved picture bytes, file type and digest, and whether a profile was explicitly shared for cross-server use. Each saved picture is limited to 256 KB and each member to 2 MiB in total.
- Arcade account and safety data, including server and user IDs, balances, aggregate counters, daily claim markers, self-exclusion choices and settled chance-game receipts. Arcade is not linked to payment data or the transferable server economy.
- Aggregated activity analytics, such as hourly message, member and command counts. These analytics do not store the text of ordinary messages.
- Optional invite analytics, including hourly counts of observed, attributed, unknown and ambiguous joins, observed and recovered invite-counter uses, campaign labels and collection quality. These analytics do not store joining member IDs or referral graphs.
- Optional Server Counter data, including current and hourly aggregate member, non-bot voice-user and scheduled-event counts, managed channel IDs, applied channel names and delivery status. Counter analytics do not store which members were connected to voice channels.
- Optional private keyword notification settings, including the server and member IDs, the member's chosen term, optional channel scope, matching style, cooldown, enabled state and timestamps. Delivery records contain only the subscription, source message, channel and author IDs plus delivery status and timestamps; they do not contain the matched message text or an excerpt.
- Optional sticky-message settings, including the chosen channel, message content, presentation, timing controls and the exact IDs of CharmBot-managed posts awaiting replacement or cleanup.
- Billing identifiers and subscription state when paid billing is used. Payment details such as card numbers are collected by Stripe, not by CharmBot.
- Limited technical logs needed to operate, secure and troubleshoot the service. Secrets and authorization values are redacted from application logs.
Message and voice content
CharmBot does not store the text of ordinary Discord messages unless a server manager enables a feature that specifically needs selected content. Examples include saved quotes, suggestions, custom commands, moderation notes or evidence, and optional edited or deleted message logging.
Private keyword notifications compare an incoming message with active member-selected terms. Before sending an alert, CharmBot checks that the member can still view the source channel and reads the source message again to confirm the match. It does not store the matched message text or include that text in the private alert. The alert can identify the author and channel and provide a Discord jump link.
Live transcription is opt-in for each speaker. CharmBot processes short audio segments and discards the audio after transcription. It does not keep a transcript copy in its database. Captions posted to Discord remain subject to that server's channel permissions and Discord message history. Text to speech processes text supplied for playback and does not create an audio archive.
When a member uses a plural or roleplay profile, CharmBot does not store the proxy message body or attachment URL. It keeps a limited delivery and moderation receipt containing the underlying Discord actor and profile owner, server, channel, message, webhook and interaction identifiers, the displayed profile name, attachment count, delivery status, timestamps and keyed security fingerprints. The visible proxy marker and staff inspection tools preserve accountability without publishing the member's underlying identity.
For an invite campaign, Discord generates the invite code. CharmBot processes it only long enough to return the new link once and create a server-bound protected fingerprint. Plaintext invite codes are not stored in campaign settings, aggregate analytics or dashboard responses. A replayed create request cannot reveal the link again.
How information is used
Information is used to provide requested bot features, confirm that a dashboard user is allowed to manage a server, deliver notifications, prevent duplicate actions, keep reliable audit records, process subscriptions, protect the service and diagnose failures. Where law requires a legal basis, processing may rely on performance of the service, legitimate interests in security and reliability, consent for optional features, or compliance with legal obligations.
Cookies and dashboard sessions
The public website does not use advertising or behavioral tracking cookies. Discord login uses essential, secure cookies for OAuth safety, the active session and the last selected server. The session cookie contains a random identifier. The encrypted server-side session can contain Discord OAuth tokens and expires at most one hour after login. Signing out deletes the active server-side session immediately.
Service providers and disclosures
CharmBot uses Discord to authenticate users and operate inside servers. Stripe processes hosted checkout and subscription billing. Optional integrations contact the provider selected by a server manager. Optional accurate transcription may send consented audio segments to OpenAI when that mode is available and selected.
Information may also be disclosed when required by law, to protect users and the service, or during a business transfer with appropriate safeguards. CharmBot does not sell personal information or use it for targeted advertising.
These providers maintain their own policies. See the official Discord privacy policy and Stripe privacy information.
Quote of the Day uses only active quotes saved in the requesting Discord server. It does not request daily quotes from a third-party quote provider or make another server's saved quotes eligible.
Retention and deletion
Retention depends on the feature. Dashboard sessions last no more than one hour. Aggregate analytics are kept for 90 days. Discord event history is configurable for 7, 30 or 90 days. Closed tickets and any generated transcript records use a 30-day retention period. Short lived delivery and idempotency records expire on their feature's operational schedule.
Invite analytics retain hourly aggregate counts for the server's configured period, from 7 to 400 days and 90 days by default. Campaign names and lifecycle records can remain while the server is installed so managers can interpret retained aggregate history and audit campaign changes. Ending a campaign disables its Discord invite but does not rewrite historical aggregate totals.
Server Counter hourly aggregates expire after the server's configured retention period. Current configuration, managed channel bindings and bounded operation history remain while the server is installed so CharmBot can update or safely detach those channels. Voice activity is stored only as a count, not as a list of participating members.
General server audit logs are bounded rather than permanent. Operational and failure entries are kept for 90 days. Security, privacy and configuration transitions are kept for 400 days. A per-server daily limit coalesces excess operational failures into an aggregate counter; security transitions are never dropped by that limit.
When Discord confirms that CharmBot has left a server, CharmBot deletes the server record and its associated server-scoped feature data. Minimal subscription, payment event and redeemed access records can be retained separately to preserve entitlements, prevent fraud, support accounting and comply with law. Deleted data may remain in access-restricted backups until those backups expire through their retention schedule.
Arcade play, ledger, daily usage and related audit history expires after 90 days. Current balances, lifetime aggregate counters, the last daily claim marker and self-exclusion state remain while the server is installed so CharmBot can prevent duplicate grants and preserve safety choices.
Quote of the Day stores its server schedule and destination, saved quote and attribution fields, and one delivery receipt for each local date. Terminal delivery receipts expire after 90 days. Saved quotes remain until a manager hides them or the server record is deleted. Hiding a quote prevents future selection but does not erase the saved record.
Active private keyword subscriptions remain until the member removes or clears them, or the server data is deleted. Completed, failed or otherwise terminal keyword-delivery metadata expires after 7 days. Running /notify clear confirm:true deletes that member's keyword subscriptions and associated live delivery history for the current server. Matched message text is never retained in those records.
Sticky-message content, settings and exact managed message IDs remain while the sticky is configured. When an authorized manager disables or deletes it, CharmBot queues ownership-checked cleanup of only the exact stored CharmBot post. Deleting the sticky removes its live configuration after that safe cleanup; unrelated channel messages are not selected.
Plural and roleplay profiles are server-local by default. Reuse in another server requires both the profile owner's explicit choice and permission from that destination server. Saved profile pictures are served through content-addressed links that do not contain a user, server or profile ID. Managed webhook credentials are encrypted and are never included in member exports or public responses.
Server managers choose a 7 to 90 day retention period for plural and roleplay delivery attribution, with 30 days as the default. After a member deletes their profile data, names in retained moderation receipts are removed, while the minimum actor attribution remains until that server's retention period ends. An active staff safety block remains until server staff removes it. Messages already posted in Discord remain until the member or server staff deletes them.
The server dashboard shows only an aggregate count of retained plural and roleplay receipts. Exact actor attribution is available through /persona inspect only after CharmBot confirms that the requesting staff member can view and manage messages in the receipt's source channel.
Arcade command replies are private to the member. Authorized server managers can view up to 90 days of settled receipt details in their dashboard, including the member ID, outcome, stake, payout, resulting balance and time. This supports server safety and dispute review.
Your choices and rights
You can sign out, decline optional voice transcription, reset a custom profile, export or delete your plural and roleplay profile data, and remove a saved birthday. You can also clear your private keyword alerts and their delivery history with /notify clear confirm:true. Server managers can disable features, change retention choices and remove CharmBot. Depending on your location, you may also have rights to access, correct, delete, restrict or object to processing, and to receive portable information. Follow the data deletion instructions or use an available method on the contact page.
Security, children and changes
CharmBot uses access controls, tenant isolation, encrypted transport, encrypted dashboard sessions, secret redaction and restricted backups. No online service can guarantee absolute security. Do not send secrets or unnecessary sensitive information through bot features.
CharmBot is intended only for people permitted to use Discord in their location. This policy may change as features, providers or legal requirements change. The date above will be updated when changes are published.
