Privacy Policy
Last updated: 26 August 2026
This policy describes what the ServerMod Discord bot collects, why, how long it is retained and how to have data removed. It covers the software as a whole rather than any single installation of it.
ServerMod is self-hosted, and each installation stands alone. A copy runs on infrastructure controlled by the operator of the Discord server it serves, stores its data in a database that operator controls, and is locked at the application level to the servers it has been authorised for. Nothing is pooled across installations, sold, or shared with advertisers. The one exception is a network ban report, which is described in section 05 and is a report about an account that has already been banned.
01 Who is responsible for what
Two parties, and the split matters when you want something changed.
- The server operator - the person or team running the Discord server the bot is in - decides which features are switched on, how long things are kept, who on their staff can see what, and what moderation happens. For anything about a specific server and the data held in it, they are the controller and the right people to ask. Reach them through that server, ordinarily by ModMail or by contacting a moderator.
- ServerMod publishes and maintains the software itself, and operates this site. Write to [email protected] about the software, about this policy, or if you cannot get an answer from an operator and need a request routed.
02 What is collected, and why
Not every item below is collected in every server. Most of it belongs to a feature the operator can switch off, and a feature that is off collects nothing.
Account and membership
- Your Discord user ID, username, display name and avatar
- Your roles, your nickname history, and when you joined or left
- Your account creation date, and whether the account was newly made when it arrived
Used to attribute moderation correctly, to check whether you are exempt from automated moderation, to run role-based features, and to produce membership statistics. Records of moderation survive you leaving, so that a ban or a warning stays attributable.
Message content
- The text of messages you send, and attachments to them, where message logging is enabled
- Edits and deletions, so that a moderator can see what a message said before it changed
- Messages archived to a moderation case. A kick or a ban captures up to thirty days of what the account said, because it is leaving and that is the last chance to keep the record; a mute captures the preceding three hours, which is the conversation the sanction was about. Both include messages that were deleted, which is usually the point - the messages that caused an automatic sanction are often removed by the rule that applied it.
- ModMail conversations between you and the moderators, kept as a transcript
- Messages you report, messages reported about you, and any evidence attached to a report
- Messages that trip an automod rule, a keyword monitor or a content watcher
- Messages pinned to a starboard by community reactions
Used to detect scams, phishing, spam and prohibited content; to let a moderator investigate an incident after the messages involved have been deleted; to attach evidence to a case; and to operate ModMail, prefix commands, auto-responders and the starboard.
Reactions, voice and presence
- Reactions you add, counted for participation statistics
- The times you join and leave voice and stage channels, and total minutes spent
- Where activity tracking is enabled: the games you play, streams you broadcast and music you listen to, as published by your Discord presence, and your online status over time
No audio is ever recorded, listened to or stored. Voice tracking is a timestamp when you join and a timestamp when you leave. Presence data is used for aggregate community statistics and is never used to make a moderation decision about you.
Progression and community features
- Levels and XP, the events that granted them, and leaderboard position
- Achievements earned, and the milestones that issued them
- Birthdays, where you have chosen to give one
- Event RSVPs and attendance, giveaway entries, and survey responses
- Your tenure in the server, and any server subscription or boost the operator tracks for perks - the fact and the dates, not payment details, which ServerMod never sees
- Your yearly Wrapped summary, generated from statistics already held
Moderation records
- Cases: warnings, mutes, kicks, bans, the reason, the moderator, and any expiry
- Moderator notes about you, and the audit trail of who changed what
- Evidence files attached to a case, including screenshots supplied by a moderator or a reporter, stored on the operator’s server
- Automated findings: suspicious-join flags, impersonation sweep results, automod trips and watcher escalations
- Where a finding is about impersonation, the identity the account appears to be posing as, recorded as a field of its own. It is kept separately from the sentence describing the finding so that several accounts posing as the same person can be recognised as one coordinated attempt rather than as unrelated coincidences. It is a judgement, not a fact about you, and it is cleared with the flag.
Inferred demographics
Where the operator enables it, an approximate region, country, language or age band may be inferred from what you have chosen to publish about yourself, such as an introduction post. These are estimates, are never treated as verified, and are used only in aggregate.
Dashboard and command use
If you are a moderator or administrator, the bot records your sign-ins to its dashboard, the administrative actions you take, and the commands you run. This is an accountability record and is not subject to the opt-out in section 08.
03 Automated scanning and AI
Where the operator has enabled it, message text, links, images, stickers, emoji, usernames and avatars may be sent to the OpenAI API to be classified - for example, “is this a scam?” or “is this account impersonating somebody?”. The classifier returns a verdict, which raises an alert for a human moderator or, where the operator has configured it, applies a sanction.
- This is inference only. No machine-learning model is trained, fine-tuned or otherwise built from your content by us.
- Images are downscaled and re-encoded before they are sent.
- AI features are off by default and must each be explicitly enabled.
- They are never applied to a member in privacy mode (section 08).
- The dashboard also carries a read-only assistant for moderators. It has no ability to change anything, because it has no tool that writes. What it may read is a declared list rather than a description: every subject it can be asked about, and the tables behind each one, are shown on the assistant’s own page in the dashboard, so an operator can answer “can it see X” by reading a list instead of trusting a sentence. ModMail is on that list as volume and timing only - it cannot read what was said in a thread.
OpenAI processes this data as a service provider under its own terms. Every automated determination can be put to a human moderator; see section 09.
04 What leaves the machine it runs on
Most of what ServerMod holds never goes anywhere. This is the complete list of what does.
| Goes to | What | When |
|---|---|---|
| Discord | Everything the bot posts, sends or fetches - messages, embeds, generated images, moderation actions | Constantly. It is a Discord bot. |
| OpenAI | The content being classified, as described in section 03 | Only where an AI feature is enabled, and never for a member in privacy mode |
| ServerGuard | A ban report: the banned account’s ID and tag, the category, the reason text, the server ID and name, who banned them, the case number, and links to any evidence | Only when an account is banned and the server participates in the network. Described in section 05. |
| Social platforms | Nothing about members. Requests for the public posts of accounts the server has chosen to follow - YouTube, Reddit, Twitch, X, TikTok, Instagram, RSS | On the schedule the operator sets, where feeds are configured |
Nothing is sold, rented, shared with advertisers, or combined with data from an unrelated Discord server.
05 Network ban reports
When a server participating in the network bans an account, ServerMod may report that ban to ServerGuard, a separate bot that maintains a shared blacklist. Two things about this are worth being exact about.
- It only ever happens to an account that has already been banned from the server doing the reporting. That ban is the server’s own decision and has already taken effect. The report asks that ServerGuard’s staff consider a wider ban; they may decline.
- ServerMod does not read or enforce the blacklist. It reports and nothing more. No account is ever sanctioned by ServerMod because a different server banned them.
Evidence attached to a report travels as a signed link that expires, not as a copy of the file, so access ends with the link. An operator can leave the network at any time, which stops future reports going out.
06 How long things are kept
| Data | Retention |
|---|---|
| Message log | Set by the operator. 60 days by default, 365 days maximum. Deleted automatically after that. |
| Messages archived to a case | As long as the case, because they are its evidence. Thirty days’ worth for a kick or ban, three hours’ worth for a mute. |
| Evidence files attached to a case | As long as the case. Links shared outside the dashboard expire after 30 days. |
| Moderation cases, notes and audit history | Indefinitely, including after you leave |
| Suspicious-join flags | 14 days, then they stop counting |
| ModMail transcripts | Indefinitely, as the record of the conversation. Each thread has a transcript address from the moment it opens, which keeps working after it closes - the page is built from the conversation on request rather than being a stored copy, and it is not public (see section 12). |
| Presence, game and listening activity | Kept for statistics; erased at once on opting out |
| Voice and stage minutes, message and reaction counts | Kept for statistics |
| Inferred demographics | Until re-scanned; erased at once on opting out |
| Levels, XP, achievements, birthdays | While you are a member |
| Appeal text, and the reviewer’s reason | 30 days after the appeal is resolved. That an appeal happened and what was decided stays on the case, as moderation history. |
| Dashboard sign-ins and administrative audit trail | Kept as an accountability record |
An operator can exclude whole channels or categories from logging, or switch message logging off entirely. An excluded channel is left out of the message log, archives, edit and delete records and AI scanning alike.
07 Who can see it
- Moderators and administrators of that server, through the dashboard, and only as far as their assigned permissions allow - access is granted per page and per action, so a moderator with reports access does not thereby get the message log.
- A staff channel in that server, where the operator has set one up. Reports, watcher alerts, case logs and the impersonation sweep’s findings can each be posted to a channel so that moderators see them without opening the dashboard. Those posts name the member concerned. Which channels these are, and who can read them, is the operator’s decision.
- The operator, who controls the machine the data sits on.
- OpenAI, as a processor, for the scanning in section 03, where enabled.
- ServerGuard, for a ban report, on the terms in section 05.
08 Privacy mode
You can ask for privacy mode to be enabled on your account. Ask a moderator, by ModMail or otherwise. Once it is on, ServerMod immediately:
- stops recording your games, streams and listening activity, and deletes what was already recorded;
- stops storing what your messages say - the fact that a message existed, in which channel and when, is still kept, but not its text;
- redacts message content of yours already stored, across the message log, case archives, monitor hits, reports, AI event records and ModMail;
- stops all AI scanning of your content;
- stops demographic inference, and deletes any demographics already inferred about you.
Privacy mode does not erase moderation records. Cases, warnings and bans remain, and the fact that a message existed and was removed remains. It governs profiling, not accountability - a moderation record that could be erased on request would not be a moderation record.
It also is not retroactive in the other direction: turning it off resumes collection from that moment. It does not bring back what enabling it deleted.
09 Your rights, and appeals
Depending on where you live you may have the right to access a copy of your data, correct it, have it erased, restrict or object to its processing, or receive it in a portable form. Ask the operator of the server concerned. If you cannot reach them, write to [email protected] and the request will be routed. Requests are answered within one month.
Erasure is honoured except where a record has to be kept for moderation accountability, as in section 08. Where something cannot be erased, you will be told so and told why.
If you are warned, muted, kicked or banned, the notification you receive explains how to appeal. An appeal is read by a human moderator, including where the action began with automated detection. Appeals are handled on this site, and you will need to sign in with the Discord account concerned so that the appeal can be matched to the sanction.
10 When the bot leaves a server
Removing ServerMod from a Discord server stops all collection immediately. It does not automatically delete what was already stored, because the database belongs to the operator and a bot cannot be trusted to empty it on the strength of being kicked. An operator who wants the stored data destroyed should delete it, and can ask [email protected] for help doing so.
11 Children
Discord requires its users to be at least 13, or older where local law sets a higher age. ServerMod is not directed at anyone below that age. If we learn that data has been collected from someone below the applicable age, it will be deleted.
12 Security
Data is held in a database on infrastructure the operator controls, reachable only by the bot and its dashboard. Dashboard access requires signing in with Discord and is restricted by role-based permissions. Traffic to the dashboard is encrypted in transit. Evidence files are served only to an authenticated session or through a signed link that expires, and are excluded from search engine indexing.
A ModMail transcript address is not a public link. Opening one requires signing in with Discord and holding the permission to read cases in that server; an unguessable address on its own gets you a sign-in page and then a refusal. Transcripts are never cached by a browser or a proxy and are excluded from indexing, for the same reason: they are a member’s private correspondence with the staff team.
13 Changes to this policy
This policy is updated as the software changes. The date at the top is the date of the most recent change; material changes are announced in the servers where the bot runs.
ServerMod is independent software and is not affiliated with, endorsed by or sponsored by Discord Inc. Your use of Discord itself is governed by Discord’s Privacy Policy and Terms of Service.