Privacy Policy
Last updated 4 July 2026. This is an initial version and will change as the bot changes. It describes what Lowkey Mod Bot and its management portal actually collect and keep today, nothing more.
What the bot stores, why, and for how long
The bot stores only what its moderation features need. Every category below has a retention window, and nothing is kept indefinitely by default.
| data | why | kept |
|---|---|---|
| Moderation log entries: the action, the target and acting member (numeric ids and the display names they had at the time), the reason, whether it succeeded, and when | The server's moderation audit trail, shown in the portal's log | 90 days by default, then purged on schedule |
| Violation records: member id, the violation's name, and when it happened | Escalation rules (a threshold of violations can trigger a rule) | 30 days by default, then purged |
| Rule change history for deleted rules | So an accidental deletion is recoverable and reviewable | 90 days after the rule is deleted |
| Member role state (member id, role ids, join date), only in servers that turn member-leave tracking on | So a member-leave rule can evaluate roles for someone who already left | While the member is in the server; on departure it becomes a departure record (final roles, time, how they left) kept for the server's audit and removable per server or per member request |
| The servers the bot is in, and each server's public role and channel structure | So the portal can offer your servers and populate its pickers | While the bot is in the server, removed when it leaves |
| Configuration your administrators write: rules, custom variables, default reasons, per-server toggles | It is the product: the moderation your server configured | Until an administrator removes it or the bot leaves the server |
What is never stored
Message content is never stored. Rules that read message text (such as the pattern trigger) evaluate it in the moment and keep nothing. When a rule deletes a burst of messages, the bot stores references to which messages, never their text. The bot never sees or stores passwords, and it never asks for credentials of any kind.
The management portal
Signing in uses Discord itself (OAuth). The portal learns your Discord id, username, avatar, and which servers you manage, holds them in a signed session cookie, and re-checks your access on every sensitive action. It stores no password, and the cookie's signing keys live server-side. Signing out ends the session. Public pages like this one involve no sign-in and no data at all.
Deletion requests
Your stored data can be located and deleted on request: moderation log entries about you, violation records, and member-leave records. Ask through the Discord server where the bot operates (its administrators can act and escalate), reach the operator through the bot's Discord application profile, or email the operator at lowkey@medrunner.space. Requests are honored for the data this policy lists.
Changes
When the bot's data practices change, this page changes with them and the date above moves. The Terms of Service cover use of the bot and portal.