VaultBot Privacy Policy
Effective date: 26 August 2026
This Privacy Policy explains how VaultBot processes information when installed in a Discord server. It reflects the current VaultBot v0.22.0 service and database schema.
1. Operator and contact
VaultBot is operated by William Smailes, based in England, United Kingdom (“we”, “us”). Privacy, access and deletion requests and security reports can be sent to vaultbot.developments@gmail.com.
2. Service purpose
VaultBot provides server configuration, command access, vouch and reputation records, scam-report workflows, moderation and warnings, AutoMod, automatic punishment thresholds, levels and XP, role milestones and boosts, queues, scheduled messages, backups, operational logs, diagnostics and paid plan entitlements.
3. Information VaultBot processes
Depending on the modules enabled by a server, VaultBot processes:
- Discord guild IDs and names; channel IDs; role IDs; module, permission, logging, branding and setup configuration;
- Discord user IDs and limited username or display-name snapshots needed to present or audit actions;
- vouch actors, recipients, amounts, reasons, references, timestamps, staff adjustments and reversals;
- scam-report reporters and reported users, allegations, reasons, status, assigned staff, confirmations and review history;
- moderation targets and actors, action, reason, duration, warning points and expiry, direct-message outcome, case and log references, reversals and automation outcomes;
- AutoMod configuration, blocked terms and violation metadata. Formal case evidence may retain the configured term that matched, rule and channel, but not the complete message content;
- queue membership and timestamps;
- XP totals and sources, message, media and reaction counters, voice-session timing, cooldowns, milestones, roles and boost configuration. VaultBot counts activity but does not store ordinary message text for XP;
- scheduled-message names, destination channel, content, interval, delivery attempts and errors;
- guild-scoped configuration backup payloads, checksums, creator and restorer IDs and timestamps;
- audit events and before and after configuration snapshots;
- operational activity events such as commands, messages, joins, leaves and AutoMod actions, including relevant user or channel IDs and non-content metadata;
- plan, status and expiry history; Stripe customer, subscription and price-derived plan identifiers; webhook event status and billing-period metadata;
- developer service notices and per-guild delivery status; and
- technical errors and structured logs, which may include Discord, guild, user or entity IDs and redacted error details.
VaultBot does not store card numbers, CVCs, bank details, Discord passwords or Discord user OAuth access tokens. Stripe Checkout and Stripe's billing portal process payment information.
4. Sources
Information comes from Discord interactions and events, server configuration entered by authorized staff, user and staff actions, signed Stripe events, protected import tools deliberately run by the operator, and infrastructure required to operate the service.
5. Purposes and legal bases
We process information to provide requested bot functions and subscriptions; enforce server-selected rules and plan limits; prevent duplicate, fraudulent or unsafe actions; preserve moderation, reputation and billing integrity; diagnose failures; secure and recover the service; respond to requests; and comply with legal, accounting or dispute obligations.
Depending on the context, processing is based on performing the service agreement with a server operator, our legitimate interests in operating and securing VaultBot, compliance with legal obligations, and consent where the law requires it. Server owners remain responsible for configuring VaultBot lawfully and informing their communities about their use of the service.
6. Automated actions
When enabled by authorized server staff, AutoMod and moderation automation can delete messages, create warnings, notify staff, time out, kick or ban members at configured thresholds. Discord administrators and the guild owner are excluded from automatic AutoMod processing. Automation can make mistakes; server staff must review configuration, cases and appeals. A scam report remains an allegation unless reviewed and confirmed by authorized server staff.
7. Sharing and processors
Information is shared only as needed to operate VaultBot and may be processed by:
- Discord, which supplies events and delivers bot messages and actions;
- Railway, which hosts VaultBot services and PostgreSQL infrastructure and may process operational logs;
- Stripe, which handles checkout, payment, subscription and billing-portal services; and
- professional advisers, authorities or replacement infrastructure providers where lawfully necessary.
We do not sell personal information. These providers may process information outside the United Kingdom under their own terms and applicable transfer safeguards.
8. Security
VaultBot uses guild scoping, parameterized database access, capability and Discord role-hierarchy checks, signed Stripe webhooks, event and job idempotency, secret redaction and private hosted credentials. Access to production infrastructure is restricted. No online service can guarantee absolute security. Report suspected vulnerabilities privately to vaultbot.developments@gmail.com.
9. Retention
VaultBot uses the following retention criteria:
- active-server configuration and core feature records are retained while VaultBot remains installed and the records are needed to provide the configured service;
- when VaultBot is removed, the guild is marked inactive and its recoverable guild-scoped data is retained for up to 90 days, unless it is deleted sooner following a verified request or retained longer for an active subscription, security incident, legal claim or legal obligation;
- operational guild activity events and scheduled-message delivery attempts are retained for up to 90 days;
- completed Stripe webhook replay records are retained for up to 90 days; Stripe retains payment and accounting information under Stripe's own policy and applicable law;
- application logs are targeted for a maximum of 30 days, subject to incident preservation and infrastructure-provider controls;
- configuration backups are limited by each guild's configured backup allowance and are removed with the guild record at the end of the inactive-guild period; and
- moderation, scam, vouch and audit records are retained while the server actively uses those integrity and history features. Following removal, they fall under the 90-day inactive-guild period unless a lawful exception applies.
Retention cleanup is performed through protected operator tooling. Reversals may mark records rather than immediately erasing them where history is required to prevent abuse or preserve case integrity.
10. Access, correction and deletion
Users and server owners may request access, correction, deletion, restriction or objection where applicable by emailing vaultbot.developments@gmail.com with the relevant Discord user ID and guild ID. We will verify the request to avoid disclosing or deleting another person's or server's information and aim to respond within 30 days.
Some information may be retained where necessary for security, legal claims, accounting, fraud prevention or the rights of others. Server administrators can remove or change some configuration through VaultBot, but they do not receive direct database access. Complete guild erasure is a protected operator action and is refused while an active Stripe subscription remains linked to the guild.
11. Children
VaultBot is intended only for people eligible to use Discord under Discord's Terms and the minimum age in their country. We do not knowingly design the service for children below that age. Contact vaultbot.developments@gmail.com if ineligible use or a child's information is suspected.
12. International processing
Discord, Railway and Stripe may process information outside the United Kingdom. Where United Kingdom data-protection law applies, we rely on the safeguards offered by the relevant provider and any other lawful transfer mechanism available for the service.
13. Changes
We may update this policy when VaultBot, its providers or legal obligations change. The current policy will show its effective date. Material changes will be announced through the service or another reasonable channel where practical.
14. Contact
Operator: William Smailes
Jurisdiction: England and Wales
Email: vaultbot.developments@gmail.com
This policy describes VaultBot's operational data practices. It is not a substitute for independent legal advice.