VaultBot

VaultBot Privacy Policy

Effective date: 26 August 2026

This Privacy Policy explains how VaultBot processes information when installed in a Discord server. It reflects the current VaultBot v0.22.0 service and database schema.

1. Operator and contact

VaultBot is operated by William Smailes, based in England, United Kingdom (“we”, “us”). Privacy, access and deletion requests and security reports can be sent to vaultbot.developments@gmail.com.

2. Service purpose

VaultBot provides server configuration, command access, vouch and reputation records, scam-report workflows, moderation and warnings, AutoMod, automatic punishment thresholds, levels and XP, role milestones and boosts, queues, scheduled messages, backups, operational logs, diagnostics and paid plan entitlements.

3. Information VaultBot processes

Depending on the modules enabled by a server, VaultBot processes:

VaultBot does not store card numbers, CVCs, bank details, Discord passwords or Discord user OAuth access tokens. Stripe Checkout and Stripe's billing portal process payment information.

4. Sources

Information comes from Discord interactions and events, server configuration entered by authorized staff, user and staff actions, signed Stripe events, protected import tools deliberately run by the operator, and infrastructure required to operate the service.

5. Purposes and legal bases

We process information to provide requested bot functions and subscriptions; enforce server-selected rules and plan limits; prevent duplicate, fraudulent or unsafe actions; preserve moderation, reputation and billing integrity; diagnose failures; secure and recover the service; respond to requests; and comply with legal, accounting or dispute obligations.

Depending on the context, processing is based on performing the service agreement with a server operator, our legitimate interests in operating and securing VaultBot, compliance with legal obligations, and consent where the law requires it. Server owners remain responsible for configuring VaultBot lawfully and informing their communities about their use of the service.

6. Automated actions

When enabled by authorized server staff, AutoMod and moderation automation can delete messages, create warnings, notify staff, time out, kick or ban members at configured thresholds. Discord administrators and the guild owner are excluded from automatic AutoMod processing. Automation can make mistakes; server staff must review configuration, cases and appeals. A scam report remains an allegation unless reviewed and confirmed by authorized server staff.

7. Sharing and processors

Information is shared only as needed to operate VaultBot and may be processed by:

We do not sell personal information. These providers may process information outside the United Kingdom under their own terms and applicable transfer safeguards.

8. Security

VaultBot uses guild scoping, parameterized database access, capability and Discord role-hierarchy checks, signed Stripe webhooks, event and job idempotency, secret redaction and private hosted credentials. Access to production infrastructure is restricted. No online service can guarantee absolute security. Report suspected vulnerabilities privately to vaultbot.developments@gmail.com.

9. Retention

VaultBot uses the following retention criteria:

Retention cleanup is performed through protected operator tooling. Reversals may mark records rather than immediately erasing them where history is required to prevent abuse or preserve case integrity.

10. Access, correction and deletion

Users and server owners may request access, correction, deletion, restriction or objection where applicable by emailing vaultbot.developments@gmail.com with the relevant Discord user ID and guild ID. We will verify the request to avoid disclosing or deleting another person's or server's information and aim to respond within 30 days.

Some information may be retained where necessary for security, legal claims, accounting, fraud prevention or the rights of others. Server administrators can remove or change some configuration through VaultBot, but they do not receive direct database access. Complete guild erasure is a protected operator action and is refused while an active Stripe subscription remains linked to the guild.

11. Children

VaultBot is intended only for people eligible to use Discord under Discord's Terms and the minimum age in their country. We do not knowingly design the service for children below that age. Contact vaultbot.developments@gmail.com if ineligible use or a child's information is suspected.

12. International processing

Discord, Railway and Stripe may process information outside the United Kingdom. Where United Kingdom data-protection law applies, we rely on the safeguards offered by the relevant provider and any other lawful transfer mechanism available for the service.

13. Changes

We may update this policy when VaultBot, its providers or legal obligations change. The current policy will show its effective date. Material changes will be announced through the service or another reasonable channel where practical.

14. Contact

Operator: William Smailes

Jurisdiction: England and Wales

Email: vaultbot.developments@gmail.com

This policy describes VaultBot's operational data practices. It is not a substitute for independent legal advice.