Privacy Policy
Last updated: 7 August 2026
The short version: we store what the service needs to work for you, and nothing else. We do not sell data, we do not run third-party trackers, and we do not share your information without your consent unless the law requires it.
What we store, and why
- Your Discord identity - your Discord ID, username and avatar, captured when you sign in. It is how you log in and how names are shown instead of numbers.
- Your servers and settings - server IDs and names, threads, templates, alert preferences: the configuration you create by using the product.
- Credentials you provide - your forum login, session and bot token, stored encrypted at rest. They are never displayed back to anyone, staff included, and exist only so the service can act on your behalf.
- Activity records - what the service did under your name (bumps, vouches, messages, price changes), kept as an audit trail you can read on your own dashboard and in your own Discord log channel.
- Server backups - if you are on a plan with backups, copies of your Discord server's structure, messages and media, stored so it can be rebuilt. Old backups are pruned automatically per the retention rules shown on your backups tab.
- Basic web logs - IP address, requested page and browser type for requests to the site, kept for a limited period for security and abuse prevention. Query strings (which can contain sign-in codes) are never logged.
- Support conversations - messages you send us through the dashboard chat, kept so we can help you later.
What we do not do
- No selling or renting of your data, to anyone, ever.
- No sharing without your consent, except where the law leaves us no choice.
- No third-party analytics or advertising trackers - the site sets a session cookie for sign-in and remembers your light/dark preference in your own browser, and that is it.
- No reading of your forum inbox - the inbox watcher reports that a message arrived and who sent it; it never opens the message.
Where it lives
Data is stored on our own servers. Secrets (credentials, sessions, tokens) are encrypted at rest; transport is HTTPS.
Your choices
- You can replace or remove stored credentials at any time from your dashboard.
- You can revoke any staff member's access at any time; it takes effect on their next action.
- Members who joined your member-link can revoke that consent themselves, on the link page or in Discord's own Authorized Apps.
- Want your account and its data removed? Ask us in your support channel and we will delete what the law does not require us to keep.
Changes and contact
If this policy changes, the date above changes with it. Questions go where the rest of the support happens: your private channel in the Zorabot community Discord, or the chat on your dashboard.