Scope and who decides what
This Privacy Policy explains how AioBot handles information when you use our website, dashboard, hosting platform, Commerce tools, and the bots we operate for users. It works alongside Discord's own privacy policy, which covers Discord's processing of your Discord data.
There are two roles to understand. Platform information — your dashboard account, billing relationship, bot credentials, and technical records — is handled by AioBot under this policy. Server-member information — the tickets, messages, moderation events, vouches, giveaway entries, and similar records that a bot generates inside a community — is configured and controlled by that server's owner, who decides which features run and what they collect. AioBot stores and processes that member data on the server owner's instructions as part of hosting their bot.
Information AioBot processes
Discord account information: your Discord user ID, username, avatar, OAuth access and refresh tokens, and the servers Discord reports that you own or can manage.
Billing information: if you subscribe to Premium, AioBot receives and stores records of your Stripe customer and subscription identifiers, plan, status, renewal and trial dates, and the billing name and email that Stripe provides. Card numbers and full payment details are handled by Stripe and never reach AioBot's systems — you enter them on Stripe's checkout and management pages.
Connected bot credentials: the bot token of each Discord application you connect. Tokens are submitted only through the designated connection flow, are encrypted before storage (AES-256-GCM), are used solely to authenticate and operate your bot, and are intentionally never displayed again afterwards. Commerce integration credentials you submit, such as a provider API key, are encrypted the same way.
Server configuration: guild IDs and names, owner IDs, channel and role IDs, module settings, filters, templates, schedules, panel and option configuration, permission assignments, and other dashboard choices.
Server-member and feature data: depending on what a server's owner enables, this can include ticket records, intake-form answers and transcripts, moderation events and relevant message content, vouches and proof links, giveaway entries, invite activity and member join statistics, analytics and counters, welcome and autoresponder content, and Commerce records such as products, orders, customers, invoices, webhook payloads, and provider identifiers.
Technical information: request timestamps, error and security logs, IP addresses and browser information processed by our hosting providers, and bot health, latency, and status data.
How information is used
AioBot uses information to: authenticate dashboard users and verify server-management permissions; operate, host, and keep connected bots online; run the features a server owner has configured; process Premium subscriptions, trials, entitlements, and server-slot capacity through Stripe; operate Commerce tools and integrations; secure the Service, prevent abuse, and troubleshoot failures; respond to support requests; and comply with legal obligations.
We do not sell personal information, and we do not use your content or your members' information to advertise to anyone.
Discord OAuth and bot permissions
AioBot requests the Discord identify and guilds OAuth scopes to identify you and show the servers you can manage. OAuth tokens are used server-side and are not intentionally exposed to browser JavaScript. The bot permissions your connected application needs depend on the features its owner enables and can be reviewed in Discord at any time.
Retention
Retention depends on what the information is and who controls it:
Server-member data (tickets, transcripts, moderation logs, vouches, giveaway entries, Commerce records) is retained while the owning server keeps using the Service and the relevant feature. Ticket transcript retention is configurable by the server owner — from 1 to 3650 days, with a 30-day default — and ticket history is kept until an authorized administrator deletes it, purges it, or requests removal. Giveaway, invite, and analytics records persist until deleted through dashboard controls or a deletion request.
Server configuration is kept while the server or bot remains connected. After a bot is disconnected, configuration is retained for a reasonable window in case the owner reconnects, and is then deleted.
Billing records are kept for as long as Stripe and tax, accounting, and consumer-protection rules require, even after a subscription ends.
Security and technical logs are kept for bounded periods appropriate to investigating incidents and abuse.
Your choices and requests — dashboard users and server owners
You can disable modules, delete stored entries through dashboard controls, disconnect a bot, reset its token in the Discord Developer Portal, revoke Discord permissions, or sign out. Server owners and authorized managers may contact AioBot support to request access, correction, export, or deletion of information held for their servers, subject to identity and ownership verification and applicable legal requirements.
Some records may be retained where necessary for security, fraud prevention, legal compliance, or the protection of others, as described in the retention section.
Your choices and requests — Discord server members
If you are a member of a server that uses AioBot, most of the information described here — your tickets, moderation history, vouches, giveaway entries, and similar records — is collected and controlled by that server's owner, not by AioBot. Your first step for access, correction, or deletion is usually the server's owner or administrators, who can act on your request through their dashboard and Discord controls.
You can also contact AioBot support. Where AioBot holds the data on the server owner's behalf, we will forward your request to them; where AioBot holds it directly (for example, platform security records), we will handle it under this policy, subject to identity verification and legal requirements.
Depending on your country, you may have statutory rights — for example under the GDPR or CCPA — to access, correct, delete, or restrict processing of your personal information. Nothing in this policy limits rights that cannot be waived.
Security
AioBot uses administrative, technical, and organizational safeguards intended to protect information, including TLS in transit, server-side permission checks, and encryption of bot tokens and integration credentials at rest. Credentials are never re-displayed after submission, and OAuth tokens are used server-side only.
No online service is completely secure. In return: never send passwords, bot tokens, payment-card details, government identifiers, or similar secrets through tickets, forms, messages, or support conversations — the only place a bot token or provider credential belongs is the designated connection flow in the dashboard.
Children's privacy
AioBot is not directed to children below Discord's minimum required age, and accounts depend on Discord accounts that are subject to those same requirements. If you believe a child provided personal information contrary to applicable requirements, contact support so we can investigate and take appropriate action.
International processing
AioBot and its service providers — including Discord, Stripe, Supabase, and Vercel — may process information in countries other than your own, which may have different data-protection laws. We use providers and safeguards appropriate to the nature of the Service and the information involved, and mandatory rights in your country of residence remain unaffected.
Policy updates
We may update this policy as the platform, our providers, or legal requirements change. The effective date below identifies the latest version. Material changes will be announced through the website, the dashboard, or the community server in advance where practical.
Questions about this document?
If something is unclear, contact AioBot support through the community server. Never include passwords, bot tokens, or other secrets in a support request.
Contact AioBot support