Privacy Policy

How we handle information for the </DANSDAY> Discord Bot service and this website.

Privacy Policy Terms of Service

Last updated: August 24, 2026

Overview

This policy describes what </DANSDAY> Discord Bot (the "Service") stores and why, covering the web panel, the Discord bot, the public server pages and the optional AI features.

Two roles matter throughout. A server owner decides which modules are on, and that decision determines what is processed about their members. We operate the hosted Service and the database behind it. Anyone self-hosting from source operates their own deployment, and this policy does not cover it.

Panel accounts

When you register a panel account to configure a bot or server, we store:

  • Your username and email address, used to identify you and to send account email.
  • A bcrypt hash of your password. We never store the password itself.
  • Your most recent IP address, recorded at registration and overwritten on each successful sign-in, kept to detect abuse and duplicate accounts. Only the latest one is stored, and it is visible to the superadmin who operates the bot.
  • Which servers you own or were invited to, and your staff tier in each.

Sign-in activity, including failed attempts, is written to the operational log with the username and IP address so that abuse and brute-force attempts can be spotted. Public endpoints are rate limited by IP, which is held only briefly for that purpose and is not written to the database.

Sessions are held in Redis where configured, or in process memory otherwise, and expire on sign-out or after inactivity. A session cookie keeps you signed in; the demo login is protected by a self-hosted captcha, with no third-party captcha service involved.

Server configuration

For each server the bot joins we store the Discord server ID and name, its categories, channels and roles, your per-module settings, embed styles and templates, and the channel assignments made by /setup. Bot tokens and AI provider keys are stored per bot and are never sent back to the browser.

Member data from Discord

When a member interacts with an enabled module, we store the record that module needs. Nothing here is collected for its own sake; each item exists to make a feature work.

  • Identity — Discord user ID, username, display name, server nickname, avatar, account creation date, server join date, booster status and preferred language.
  • Activity and XP — Message counts, voice, video, streaming and AFK minutes, reaction counts, level, XP totals and a log of XP events with their source.
  • Economy — Bag contents, purchases, item activations and their effects, bounties, gifts, and logs of item use for cooldowns and history.
  • Tasks and streaks — Generated daily and weekly tasks, progress, claims, streak count, freezes and check-in cycle, plus the timezone offset needed to run them on your local day.
  • Minigames and assets — Wagers, outcomes, simulated asset positions and their transaction logs.
  • Roles and moderation — Role assignments, custom supporter roles, AFK status, warnings and moderation actions, staff ratings and reviews, feedback submissions, giveaway entries, quest progress and creator applications.
  • Message content — Read only where a feature requires it, such as the message forwarder, moderation and AI chat. It is used to perform the action and is not retained as a general message archive.

Use of Discord is also subject to Discord's Terms of Service and Discord's Privacy Policy.

Public pages and visibility

If a server owner enables public statistics, that server gets pages at a public URL showing server totals, a leaderboard, a members directory with levels and roles, and per-member account pages. These pages need no login and can be indexed by search engines.

A member account page is reached through a link derived from that member’s Discord ID and join date. Anyone with the link can open that page, so it should be treated as private. Members using the disguise item are hidden from public leaderboards and the members directory.

Turning off public statistics removes every public page for that server, and the sub-toggles for items, minigames, assets and daily tasks control those sections individually.

AI features

AI is off until an operator configures an endpoint, model and key. When it is on, the member’s message and the context needed to answer are sent to that provider. Chat history is kept per member per server in a session that expires 30 minutes after the last message. Voice audio is streamed to the configured provider while the bot is in the channel and is not stored by us afterwards.

Depending on what the operator configured, that provider may be Google and OpenAI. or any other OpenAI-compatible endpoint, including a local model. Their policies govern that processing. Web search, page fetch, image generation and wiki reading send only the query or URL needed for the lookup.

Third-party services

Beyond Discord and any AI provider, the Service contacts these only for the modules that use them:

Live market prices for the assets market come from CoinGecko. Requests carry no member data.

Catalog watching reads public listings from Roblox. for the catalog items a server chooses to watch.

Creator digests read public live data from TikTok. for the accounts a server configures, and never a member’s private TikTok data.

Wiki lookups query the MediaWiki Action API. of the wikis an operator adds, sending only the search term or page title.

We also rely on the infrastructure needed to run the Service: hosting, a MySQL database, Redis for sessions and caching, and an email provider for account mail. We do not sell personal data, and there is no advertising or third-party analytics on the site.

Cookies and similar technologies

The website uses a session cookie to keep you signed in to the panel, and local storage for preferences such as language and theme. There are no advertising or tracking cookies.

How we use information

We use information to run the modules a server has enabled, to keep the Service secure and within rate limits, to respond to support requests, and to comply with law. We do not use member data to train AI models.

Retention and deletion

Removing the bot from a Discord server, or a member leaving one, marks that data for deletion and hides it right away. It stops appearing on leaderboards, the members directory and every public page immediately. After a 7-day grace period the records are permanently deleted, and because everything is chained together by database constraints, the members, levels, items, tasks, assets, logs and settings go with them. If the bot was offline at the time, it catches up the next time it starts.

The grace period is there so accidents are recoverable. Re-adding the bot within those 7 days restores the server, and a member who rejoins gets their XP, level, items and history back as they were. Once the 7 days pass, the deletion is final and nothing can be restored.

Deleting a bot from the panel removes every server under it at once, with no grace period, and deleting a panel account removes the account and what it owns.

If you want your own member record removed sooner, or removed while the bot stays in the server, contact us and we will delete it.

  • AI chat sessions expire 30 minutes after the last message.
  • Wiki page reads are cached for about 10 minutes.
  • Sessions expire on sign-out or after inactivity.
  • Depleted items are purged automatically.
  • Data marked for deletion is hidden immediately and permanently removed after 7 days.

Operational logs are kept only as long as needed to run and secure the Service. Backups may hold removed data for a short period before rotating out.

Security

Passwords are hashed with bcrypt. Traffic is served over HTTPS. Bot tokens and provider keys are stored server-side and never returned to the browser. Public endpoints are rate limited. Panel access is bounded by owner and staff tiers, and permissions map Discord roles to what they unlock.

No method of transmission or storage is completely secure. If you find a vulnerability, email security@dansday.dev. rather than opening a public issue.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal data, or to object to certain processing. Contact us to exercise them; deletion of an individual member record is handled by us on request rather than through a panel control. A server owner can switch off the modules that collect data, and can take public pages dark, which stops further collection and hides existing records from public view.

Children

The Service is not directed at children under the minimum age Discord requires in their country. If you believe we hold data from a child below that age, contact us so we can delete it.

Where data is processed

The Service runs on hosted infrastructure that may be located outside your country, and the third parties listed above may process requests in their own regions. Using the Service means data may be transferred across borders for these purposes.

Changes

We may update this policy from time to time. The "Last updated" date will change when we do. Continued use of the Service after changes means you accept the updated policy.

Contact

For privacy questions, reach us through the support channel listed at dansday.dev. For security reports, email security@dansday.dev.