Privacy Policy
What we collect, why, how long it stays, and who can reach it.
Last updated:
The short version
- We do not store your server's message content, do not read it, and build nothing from it.
- We never see or store your card number. PayPal alone processes the payment.
- We store no raw IP address anywhere. It becomes a salted fingerprint that does not reverse.
- We do not sell or rent your data, do not use it for advertising, and send it to no marketing company.
- What we keep is what the features you turned on need, and it is deleted when you remove the bot.
1. Who is responsible for your data
The service is operated by Kivo Bot, which is responsible for the data described on this page.
There is an important division. For the data about your server's members, you — the server owner — decide which features run and therefore which data is collected; we carry out that decision and store its result. Your obligations to your members are set out in the terms of service.
2. What we collect about you when you sign in
Signing in happens through Discord, and what we receive is what you approved on Discord's own screen.
- The access and refresh tokens are stored encrypted and used only within the scope you approved.
- We do not request permission to read your direct messages, and we do not request your email address.
| Data | Why | Source |
|---|---|---|
| Your Discord user ID | To identify your account and attach subscriptions to it | Discord |
| Username and display name | To show you in the dashboard and in the staff log | Discord |
| Your avatar hash | To show your picture in the dashboard | Discord |
| Your servers and your permissions in them | To know which server you may configure | Discord |
| Access token and refresh token | To renew your session without making you sign in again | Discord |
| Last sign-in time and sign-in count | Account security and spotting suspicious use | The service |
3. What we collect about your server
When you add the bot we store what the features need in order to work: the server's ID, name, icon and language, the settings of every feature you turned on, and the IDs of the channels and roles you chose in those settings.
The settings themselves are what you wrote: the welcome text, the rules text, command replies, auto replies, and so on.
4. What is recorded about members
This section covers what the bot records about your server's members. All of it results from features a server owner turned on. A feature that is off records nothing.
- No server message text is stored in any of these tables.
- What appears in your server's log channels is written by the bot into a channel inside your server. It lives with you on Discord, not with us.
| What is recorded | The feature that records it | When |
|---|---|---|
| Member ID, name and avatar | Logs, moderation and levels | When they appear in an event a live feature records |
| Warnings, their reason and who issued them | Moderation | When a warning is issued |
| Case file: a summary of what moderation already recorded | Member case file | Assembled from the above; collects nothing new |
| Staff notes about a member | Member case file | When a staff member writes one |
| Command use and refusal counts | Usage limits | On every command |
| Who accepted the rules, and which wording | The rules accept button | On the click |
| Points and level | Levels | On activity |
| Game scores | Games | On play |
| Who invited whom | Invites | When a member joins through your link |
| Daily check counts | The AI guard | When a message is examined, if it is turned on |
5. Your server's messages
Everyone asks about this, so it is stated plainly: we do not store your server's message text in our databases, do not read it, do not analyse it, and do not train anything on it.
The bot reads a message at the moment it arrives in order to apply the rules you turned on — anti-spam, banned words, auto replies — and when that processing ends the text is not kept.
The only two exceptions are in the next two sections, and neither runs until it is explicitly turned on.
6. First exception: the AI guard
If a server owner turns this feature on, messages that pass a suspicion threshold in the ordinary rules have their text sent to an external AI provider for a verdict, and the verdict comes back.
The feature is off by default on every server, and not every message is sent: a message first passes through local rules, and only what is still suspicious after them reaches the provider.
- What is sent: the text of the suspicious message, and your server's rules text if you set one. Nothing else.
- What is not sent: the member's ID, their name, their avatar, their history, or your server's ID.
- We do not store the sent text or the returned verdict as text. We store a counter of checks and their cost.
- The provider is a third party with its own policy, and its processing is governed by its own terms.
- If you do not want anything sent to a third party, leave this feature off.
7. Second exception: the server owner conversation
If a server owner writes to us through the private conversation between the service operator and a server owner, that conversation's text is stored with us, because the conversation is the feature.
This is a conversation between you and us, not between your server's members. It only opens at your request or when we contact you.
8. Payment data
Payment goes through PayPal. When you pay, you go to PayPal and enter your details there, not here.
- We do not receive your card number, its expiry or its security code, and we could not receive them.
- What we store: PayPal's order ID, the amount, the currency, the order's status, and which server it opened.
- The capture ID is stored so that one payment cannot be counted twice.
- PayPal's own policy governs what PayPal collects about you.
9. The site and cookies
The site uses no advertising cookies and no cross-site tracking.
- The session cookie is HttpOnly and Secure, and cannot be read from JavaScript.
- We use no Google Analytics and no third-party tracking tool.
- Article read counts use a salted fingerprint of the IP address and the browser. The raw address is never stored, and the fingerprint does not reverse to it.
| Cookie | Why | How long |
|---|---|---|
| saas_session | Your session after signing in; the dashboard needs it | Seven days |
| The anti-forgery cookie | Stops another site sending a request in your name | The session's lifetime |
| Cloudflare Turnstile cookies | Confirms you are not automated on some actions | Set by Cloudflare |
10. Third parties
These are every party data reaches, and none of them is a marketing company.
- We do not sell your data, do not rent it, and do not share it for marketing, with anyone.
| Party | What reaches it | Why |
|---|---|---|
| Discord | Everything that passes through the platform itself | The service runs on it |
| PayPal | The payment details you enter there | Payment processing |
| Cloudflare | What Turnstile needs to verify | Stopping automated abuse |
| The AI provider | The text of suspicious messages only | If you turned the feature on; it is off by default |
| The hosting provider | What passes through the servers by the nature of running them | Running the service |
11. How long data is kept
Removing the bot from a server starts the deletion of that server's data. Infrastructure backups may retain a trace for a short period before they rotate.
| Data | How long |
|---|---|
| Your server's settings and its members' data | Until you remove the bot, then deleted |
| Your account and your tokens | Until you ask for your account to be deleted |
| Payment records | For as long as accounting obligations require, even after the account is deleted |
| The diamond ledger | For the life of the account, because it is a sealed ledger that is never edited |
| The staff action log | Kept, because it is an accountability record of who took an action |
| AI counters | Kept by month, and they carry no text |
| Server backups | Until you delete them, or remove the bot |
12. Your rights
You may ask for any of the following at any time, through the support server.
- To know what is held about you, and to receive a copy of it.
- To correct anything inaccurate.
- To have your account and what follows it deleted, apart from what must be retained by law.
- To withdraw your consent by removing the bot and revoking the account link in your Discord settings.
- To object to a particular processing, or to ask for it to be restricted.
13. If you are a member, not a server owner
If you are a member of a server where the bot runs and you want what was recorded about you deleted, start with the server owner: they turned the feature on, and they can delete what it recorded.
We may point you to them because they are the party who decides, but if they do not respond, contact us through the support server and we will deal with your request.
14. Children
The service is not directed at anyone below Discord's minimum age in their country, and we do not knowingly collect their data.
If we learn that we hold data for an underage account, we delete it.
15. How we protect data
- Discord tokens are stored encrypted, never as plain text.
- IP addresses are never stored raw; they become a salted fingerprint.
- Traffic to the site and the API is encrypted over HTTPS.
- The session cookie is HttpOnly, Secure and SameSite.
- Staff panel access is protected by two-factor verification, and its permissions are split rather than all-or-nothing.
- The diamond ledger is cryptographically sealed, and any change to it is detectable.
- Database accounts are separated: the bot holds fewer privileges than the API.
- No system is perfectly secure, and we cannot promise absolute safety.
16. If a breach happens
If a breach affects your data, we announce it on the site and on the support server, explain what was exposed, what we did and what we advise you to do, as soon as is reasonable after confirming it.
17. Where data is processed
Your data is processed on servers that may be outside your country, and by using the service you accept it moving to them.
The third parties named above have their own locations and their own policies, and may process data in other countries.
18. Changes to this policy
We may change this policy, and the date at the top of this page is the date of the last change. A substantial change is announced on the site before it takes effect.
How to reach us
For any question about your data, or to ask for it to be deleted, open a ticket on the support server and we will answer.
