Draft — not yet legally reviewed. This document describes how Guildvane works today, but it hasn't been reviewed by a lawyer and isn't final. Placeholders in [brackets] must be filled in before launch.
Privacy Policy
Last updated: September 2026 (draft)
Who we are
Guildvane is operated by [legal entity name, address, country]. Contact: [privacy contact email].
What we collect
- Your Discord account when you log in: user ID, username, display name, avatar, and the list of servers you can manage (with your permissions there). We never ask for your password or a bot token.
- Login session: a random session token (stored hashed) and your Discord OAuth tokens, encrypted at rest, used only to refresh your server list.
- Server configuration you set in the dashboard: panels, messages, roles and channels chosen, module settings.
- Tickets: who opened, claimed and closed them, times, form answers, internal notes and ratings. When a ticket closes, a transcript of its channel (message text, author names and attachment links) is saved if transcripts are enabled.
- Community & engagement: verification records (who verified and when), automod actions (member, rule, reason — not the full message), suggestions and their votes, poll votes, giveaway entries, and XP/levels.
- Analytics: daily counts per server (joins, leaves, messages, active members) and per-member daily message counts used to count active members. Message text is not stored for analytics.
- Audit log: which dashboard or bot actions were taken, by whom and when.
- Billing (once payments open): plan, status and payment records received from our payment provider. Card details are handled by the payment provider and never reach our servers.
How long we keep it
- Transcripts: 30 days (Free), 180 days (Pro) or 730 days (Business), then deleted automatically.
- Per-member activity counts: about 13 months.
- Sessions: until they expire or you log out. Expired verification challenges are purged within hours.
- Other server data: while the bot is in the server, and [N days] after it is removed. [Define deletion-on-request process.]
Why we process it
To provide the service you or your server administrators asked for (running the bot and dashboard), to keep it secure and prevent abuse, and — for billing — to meet legal obligations. [Map each purpose to a legal basis for your jurisdiction, e.g. GDPR Art. 6.]
Who we share it with
Discord (the platform the bot runs on), our hosting provider [name, region], and — once payments open — our payment provider [name]. We don't sell personal data and don't use it for advertising.
Your rights
You can ask for a copy of your data, correction or deletion at [privacy contact email]. Server administrators can export tickets and audit logs from the dashboard. [Add rights and supervisory authority for your jurisdiction.]
Children
Guildvane follows Discord's minimum age requirements. [Review age-related obligations for your markets.]