ServerMod
Privacy Policy
Last updated: 26th August 2026
This policy explains what the ServerMod Discord bot collects in any Discord server it has been added to, what it collects from social accounts connected to it, why it collects those things, how long they are kept, and how to have them removed. It applies to every server running ServerMod.
Each server gets its own separate instance. ServerMod is self-hosted: every server it runs in has its own deployment, locked at the application level to that one server, with its own separate database. Data is never combined, compared or shared between servers — a moderator in one server cannot see anything ServerMod holds about you from another.
Nothing is sold, rented, or shared with advertisers or data brokers, in any server, ever.
1. Who is responsible
ServerMod is operated by JammyJK, who runs the infrastructure the bot and its databases sit on. Contact: hello@jammyjk.net.
The administrators of each Discord server decide which of ServerMod's features are switched on in their server, how long message logs are kept there, and who on their team can see what. For questions about how ServerMod is configured in a particular server, contact that server's administrators — through ModMail, or however that server prefers. For access, correction or deletion requests, or anything ServerMod does everywhere, use the address above.
2. What is collected from Discord members, and why
Account and membership information
- Your Discord user ID, username and display name
- Your roles, and when you joined or left the server
- Your account creation date
Used to attribute moderation actions correctly, to check whether you are exempt from automated moderation, to power role-based features (levels, birthdays, subscriber perks), and to produce membership statistics. Records of moderation are retained even after you leave, so a ban or warning remains attributable.
Message content
- The text of messages you send in the server, and attachments to them
- Messages you send to the bot by direct message, when using ModMail
- Messages you report, or that are reported about you
Used to detect scams, phishing, spam and NSFW content; to let moderators investigate an incident after the messages involved have been deleted; to attach evidence to a moderation case; and to operate ModMail, text-prefix commands and auto-responders.
Presence and activity
- Games you are playing, streams you are broadcasting, and music you are listening to, as published by your Discord presence
- Your online / idle / do-not-disturb / offline status over time
Used only to produce aggregate community statistics — for example, which games are most played, so the server can plan events around them. Presence data is never used to make a moderation decision about you.
Voice activity
The times you join and leave voice channels, and total time spent, for participation statistics. No audio is ever recorded, listened to or stored.
Inferred demographics
Where enabled by the operator, approximate region, country, language and age band may be inferred from information you have chosen to publish, such as an introduction post. These are estimates, are never treated as verified, and are used only for aggregate community statistics.
3. Connected social accounts
A server administrator may connect a social account — TikTok, Instagram or X — so that new posts from that account are shared into a channel in their Discord server. Connecting an account is always an explicit, opt-in action taken by someone who controls that account, and it is never done on anyone else's behalf.
How the connection is made
The connection is made through the platform's own OAuth flow. You sign in on the platform's website, not on ours, and you see the exact permissions being requested before you approve them. ServerMod never asks for, receives or stores your password.
What is requested
ServerMod requests read-only permissions, limited to what the feed needs — on
TikTok, the user.info.basic and video.list scopes. ServerMod
cannot publish, edit or delete content, cannot read direct messages or
private content, and cannot act as you anywhere on the platform.
What is stored
- The connected account's public profile handle, display name and avatar
- For each public post: its ID, caption, thumbnail URL, permalink and publication time
- Access and refresh tokens for the connection, encrypted at rest
- The channel the feed posts into, and when the account was last checked
Post IDs are stored so that the same post is never shared twice. Content is shared as an embed linking back to the original post on the platform — ServerMod does not rehost media, and members watch the post where it was published.
Who it is shared with
Nobody. Data retrieved from a connected account is used only to build the feed in that one Discord server. It is not sold, not shared with third parties, not combined across servers, and not used to train or fine-tune any machine-learning model.
Disconnecting
An administrator can disconnect a social account at any time from the ServerMod dashboard. On disconnection, the stored tokens are revoked with the platform and deleted immediately, and the stored post metadata for that account is deleted within 30 days. You can also revoke ServerMod's access from within the platform's own settings, which stops all further access at once.
4. Automated content scanning and AI
Where the operator has enabled it, message text, links, images, stickers and emoji may be sent to the OpenAI API to be classified — for example, "is this a scam?". The classifier returns a verdict, which raises an alert for a human moderator to review.
- This is inference only. No machine-learning or AI model is trained, fine-tuned or otherwise built from your content by us.
- Images are downscaled and re-encoded before transmission.
- AI scanning is off by default and must be explicitly enabled by the operator.
- It is never applied to a member who has opted out (see section 7).
- It is never applied to content retrieved from a connected social account.
OpenAI processes this data as a service provider under their own terms. Automated detection can raise an alert or, where the operator has configured it, apply a sanction; every case can be appealed to a human moderator (see section 9).
5. How long data is kept
| Data | Retention |
|---|---|
| Message content (message log) | Operator-configured. 60 days by default, 365 days maximum. Deleted automatically after that. |
| Messages archived to a moderation case | Kept for as long as the case is kept, as evidence for that case |
| Moderation cases and audit history | Retained indefinitely, including after you leave |
| Presence / game / music activity | Retained for statistics; erased immediately if you opt out |
| Voice session times | Retained for statistics |
| Inferred demographics | Retained until re-scanned; erased immediately if you opt out |
| Levels / XP, achievements, birthdays | Retained while you are a member |
| ModMail transcripts | Retained as a record of the conversation |
| Social account tokens | Held encrypted while connected; revoked and deleted immediately on disconnection |
| Social post metadata (IDs, captions, links) | Retained while the account is connected; deleted within 30 days of disconnection |
The operator may also exclude entire channels or categories from all logging, and may switch message logging off completely. Excluded channels are left out of the message log, archives, edit and delete records, and AI scanning alike.
6. Who can see it
- Moderators and administrators of the server the data came from, through the bot's dashboard, and only as far as their assigned permissions allow — access is controlled per page and per action. They see data from their server only.
- JammyJK, as the operator of the infrastructure, for the purpose of running and maintaining the service.
- OpenAI, as a processor, for the content scanning described in section 4, and only where that feature is enabled.
Your data is not sold, rented, or shared with advertisers or data brokers. It is not combined with data from any other Discord server: each server's deployment has its own database, and there is no shared or cross-server dataset.
7. Opting out
You can ask for privacy mode to be enabled on your account. Contact a moderator via ModMail or at the address in section 1. Once enabled, ServerMod immediately:
- stops recording your games, streams and listening activity, and deletes what was already recorded;
- stops storing the text of your messages — a record that a message existed, in which channel and when, is kept, but not what it said;
- deletes message content of yours that was already stored;
- stops all AI scanning of your content;
- stops demographic inference, and deletes any demographics already inferred about you.
Privacy mode does not erase moderation records. Cases, warnings and bans remain, and the fact that a message existed and was removed remains. This governs profiling, not accountability — a moderation record that could be erased on request would not be a moderation record.
8. Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, have it erased, restrict or object to its processing, or receive it in a portable form. To exercise any of these, contact hello@jammyjk.net. Requests are answered within one month.
Erasure requests are honoured except where a record must be kept for moderation accountability, as described in section 7. Where we cannot erase something, we will say so and explain why.
9. Appeals
If you are warned, muted, kicked or banned, the notification you receive explains how to appeal. An appeal is reviewed by a human moderator, including where the action originated from automated detection.
10. Children
Discord requires users to be at least 13, or older where local law sets a higher age. ServerMod is not directed at children below that age. If we learn that data has been collected from someone below the applicable age, it will be deleted.
11. Security
Data is stored in a database on infrastructure operated by JammyJK, reachable only by the bot and its dashboard. Dashboard access requires signing in with Discord and is restricted by role-based permissions. Traffic to the dashboard is encrypted in transit. Access and refresh tokens for connected social accounts are encrypted at rest and are never written to logs or exposed through the dashboard.
12. Changes to this policy
This policy may be updated as the bot changes. The date at the top reflects the most recent change; material changes will be announced in the servers ServerMod runs in.
13. Contact
JammyJK
hello@jammyjk.net
For questions about one particular server, you can also open a ModMail conversation with the
bot in that server.