Legal

Privacy Policy

Effective August 6, 2026

This policy explains how Dolottle collects, uses, shares, retains, and protects information when you use the Dolottle Discord application, website, or dashboard.

1. Information Dolottle processes

Discord account and authorization information

When you authorize the dashboard, Discord provides your Discord user ID, username, display name, avatar reference, granted OAuth scopes, and access credentials. Dolottle retrieves the servers visible to your account and your permissions in them to determine which installed servers you may manage.

Session and security information

OAuth access and refresh tokens are encrypted before storage. Browser session tokens are random, are placed in secure HTTP-only cookies, and are stored by Dolottle only as cryptographic hashes. Dolottle also stores expiration, creation, and last-seen timestamps needed to operate and secure sessions.

Server, member, and configuration information

Dolottle stores server IDs and names, installation and approval status, enabled modules, and server-specific settings. Depending on the features a server enables, this may include Discord user, member, role, channel, category, message, emoji, and thread IDs; cached role and channel names and hierarchy details; ticket and moderation records; reaction-role and approval activity; auto-role assignment outcomes; and subscriber-benefit eligibility and cosmetic-role settings; Sticky Roles snapshots containing a departed member's Discord user ID and the manageable role IDs selected for restoration if they rejoin; and ticket intake questions and the answers members submit to those forms. Moderation records may include cases, reasons, evidence references, appeal statements and decisions, active mute state, and lockdown records containing the limited channel permission values Dolottle needs to restore after unlockdown. Automated-moderation executions may retain the matched rule ID, action outcome, and optional Discord message link, but not the matched message text or a content fingerprint. To evaluate edited messages safely, automated moderation also retains the message and rule IDs, whether the latest evaluated version matched, a source event ID, and timestamps. Raid protection may temporarily retain member, channel, and message IDs plus join, account-creation, and activity timestamps; it does not retain message content. These records are scoped to the server they belong to.

When an authorized manager uploads a server-specific Dolottle app icon, Dolottle temporarily stores the validated image data in the guild's pending Discord operation so it can apply the icon and show the current preview. Configuration exports do not include uploaded icon data.

When an eligible subscriber or server booster uploads a cosmetic role icon, Dolottle copies the validated image data into that server's subscriber-benefit record so the role can be restored after Discord role loss. Icons are limited to 256 KB and removed when the member replaces or clears the icon, or when the server's subscriber-benefit data is deleted.

For Server Boost insights, Dolottle stores the booster's Discord user ID, current display name, the boost start time reported by Discord, the observed end time, and limited synchronization metadata within that server. Periodic member snapshots repair changes missed while Dolottle is offline. These records do not contain payment information.

Content supplied to configured features

Dolottle stores content that an authorized manager intentionally configures, such as app messages and embeds, sticky messages, templates, thread opening messages, feedback text, and moderation reasons. Authorized moderation staff may also add append-only case evidence notes, HTTPS links, and Discord-hosted attachments. For attachment evidence, Dolottle stores the source Discord message link and limited metadata such as Discord IDs, filename, reported media type, and size; it does not copy or host the file bytes. A member who appeals an eligible moderation case may submit an appeal statement, and reviewing staff may store a decision and response. When a feature reacts to an ordinary Discord message, Dolottle may read that message and temporarily process the minimum content needed to perform the configured action. Configured message edit and deletion logs may temporarily process attachment filenames, reported media types, sizes, and Discord IDs, but Dolottle does not download those files. Durable event payloads are redacted after processing becomes terminal. Dolottle does not create general-purpose message archives. When an authorized server manager enables ticket transcripts, Dolottle stores the ticket messages, authors, timestamps, embeds, reactions, and selected attachment metadata needed to provide a private transcript. Attachment files are not copied into transcript storage. Ticket intake answers are retained as part of the ticket record.

Media-channel rules inspect whether an ordinary message contains the configured content types, such as an attachment, image, video, link, embed, sticker, or permitted text. Dolottle may temporarily read the message content needed to apply the rule and delete a non-matching Discord message. The rule does not create a separate durable archive of that message. Automatic Threads, Reaction Roles, Approval Roles, Sticky Messages, Role Selection, Starboard, tags, and response triggers similarly retain only the configuration and resource or execution records needed for their requested workflows.

When a server enables Suggestions, Dolottle stores each submitted suggestion, its submitter's Discord user ID, publication and staff-review state, optional staff response, and one effective vote per voting member. A server may hide the submitter from the public suggestion message, but authorized server records still retain the submitter ID for abuse prevention and accountability.

Question of the Day submissions include the proposed question, the submitter's Discord user ID, review state, reviewing staff member's Discord user ID, and review timestamps. Approved submissions become active question-bank entries. Denied submissions leave the pending queue while retaining their limited review record and audit trail.

When a member creates a reminder, Dolottle temporarily stores the reminder text, destination channel, creator ID, requested delivery time, and an optional repeating interval. One-time reminder text is removed after delivery is queued. Repeating reminder text remains until the member cancels it so future occurrences can be delivered. Cancelling either kind removes its text. Limited lifecycle metadata remains for idempotency, audit, and troubleshooting.

When a member uses AFK status, Dolottle stores their Discord user ID, optional reason, set time, and optional expiration within that server. The record is removed when cleared, when automatic return detection clears it, or when an expired status is next encountered. Server managers can disable reason display without deleting active status records.

When a member uses Birthdays, Dolottle stores their Discord user ID, birth month and day, and birthday-announcement choice within that server. A birth year is optional and is stored only when the member enters a full date for future server-configured age roles. Dolottle does not use this information to verify identity or legal age. Exact birthday values are excluded from administrative audit records and the server dashboard. Birthday delivery history may retain the member's display name, Discord user ID, delivery year, and delivery timestamp so authorized managers can review whether announcements ran.

When a server enables bump reminders, Dolottle stores the configured DISBOARD channel, notification choice, message templates, most recent eligible bumper's Discord user ID, bump time, and scheduled reminder state. A newer bump replaces the pending reminder state needed for the earlier one.

Dolottle provides a public command that links to its Top.gg voting page. Voting is optional. A signed vote event may credit the voter's existing currency wallet in mutual servers where currency is enabled. Dolottle stores the provider event ID, voter Discord user ID and display name, vote weight, eligibility times, guild-scoped reward outcome, and transaction correlation needed to prevent duplicate rewards. Previously recorded guild-scoped vote history may remain while the retired settings stay disabled, subject to the same server-data deletion and retention controls described in this policy.

When a server enables Levels and XP, Dolottle stores each participating member's Discord user ID, current display name, username, avatar reference, XP total, level, and award timestamps. The server's public leaderboard may display the member's display name, username, avatar, level, and XP total. Server managers may use a public server-ID URL or configure a unique vanity URL for that leaderboard. Authorized managers may also add, remove, or set member XP and levels; Dolottle retains an adjustment ledger identifying the manager, member, requested change, before-and-after totals, and time for idempotency and accountability. When voice XP is enabled, Dolottle stores each completed XP award with the member ID, amount, level transition, and time. It does not retain voice audio, transcripts, or a permanent voice join/leave history. Configured role multipliers store only the server role ID and multiplier.

When a server enables Currency, Dolottle stores each participating member's Discord user ID, current display name and username, separate server-local wallet and bank balances, and an append-only transaction history. Transactions identify the affected balance and record the amount, previous and resulting balance, action type, actor, timestamp, and an optional transfer counterparty. Authorized server managers may add, remove, or set wallet balances. Currency and transaction history are scoped to one server and cannot be transferred to another server.

If a server enables lending, Dolottle stores its loan products and each borrower's selected product, snapshotted terms, principal, amount due, repayment total, due date, and active, paid, or delinquent state. Repayment records identify how much was collected from the server-local wallet and bank. A secured product may also store the specific active store entitlement a borrower chose to pledge, its original purchase value and reward type, and whether it was released or forfeited. Automatic due-date collection never creates a negative balance and does not access currency or property outside Dolottle.

If a server enables the Store, Dolottle stores the server's item definitions and each purchase or gift as a guild-scoped entitlement. Purchase records include purchaser and recipient IDs, current account identity, item and price snapshot, quantity, time, status, and idempotency identifier. Authorized server managers may issue audited refunds, which revoke the entitlement and restore the server-local wallet balance. An entitlement pledged to an active loan cannot be refunded or pledged again. If due-date collection leaves secured debt unpaid, Dolottle may forfeit only that pledged entitlement and credit its original purchase value toward the loan. Store items and entitlements have no cash value and are not transferable between servers.

Currency-backed games additionally store the selected game, wager, member choice, random outcome, result, balance change, and timestamp. Interactive blackjack, Higher or Lower, trivia, bingo, word scramble, Hangman, and Tic-Tac-Toe temporarily store participating members, relevant cards, number board, question-and-answer choices, or selected word, wager, expiry, and action state until the round settles or expires. Word-scramble guesses and full-word Hangman guesses are evaluated in memory and are not stored; Hangman retains only guessed letters and the number of incorrect guesses. Dice, rock-paper-scissors, and Tic-Tac-Toe challenges also store both participants' Discord user IDs, current names, response state, game-specific rolls or choices, and expiration. A unique interaction identifier prevents a retried game from changing its outcome or applying its result more than once. When a member pauses wagered games, Dolottle stores the end of that member-selected pause for this server. Private game statistics are calculated from these records.

Dolottle stores hourly server-activity totals for authorized analytics dashboards, including accepted message counts by channel, human member joins and departures, and voice-channel join counts. These analytics records do not contain message content or identify the members responsible for the activity. Moderation, XP, ticket, and suggestion totals are calculated from the corresponding feature records already described in this policy.

When a server configures an external RSS or Atom feed, Dolottle stores its HTTPS URL, destination channel, polling settings, and limited conditional-request metadata. Dolottle contacts that feed provider from its infrastructure. The feed-item record retains a new item title and link only until the Discord message is queued; the delivery outbox retains the rendered message until delivery becomes terminal and then redacts it. Dolottle does not store article bodies or copy feed-hosted media.

Operational and audit information

Dolottle records limited operational and security information such as user and server IDs, administrative actions, state changes, outcomes, timestamps, correlation identifiers, and safe error codes. Audit records avoid OAuth credentials and raw message content. Our hosting providers may process ordinary request information, such as IP addresses and browser or device details, to deliver, monitor, and protect the service.

2. How information is used

Dolottle uses information only as reasonably necessary to:

  • authenticate dashboard users and maintain secure sessions;
  • verify server approval, membership, permissions, and role hierarchy;
  • provide the Discord features selected and configured by server managers;
  • carry out and reconcile role, message, thread, ticket, and moderation actions;
  • record accountable administrative and lifecycle actions;
  • prevent abuse, investigate failures, and protect the service; and
  • comply with legal obligations and enforce our Terms of Service.

Dolottle does not sell personal information, use it for targeted advertising, or use Discord message content to train artificial-intelligence models.

3. Legal bases

Where applicable law requires a legal basis, Dolottle processes information as necessary to provide the service you or your server requested, based on legitimate interests in operating and securing the service, with consent where requested, and to comply with legal obligations. Server managers are responsible for selecting features and providing notices or obtaining consent from their members when applicable.

4. When information is shared

Dolottle may share or permit processing of information only with:

  • Discord, when necessary to authenticate users or operate Discord features;
  • infrastructure and service providers, including hosting, database, monitoring, and backup providers, that process information to operate Dolottle;
  • authorities or other parties when required by law or reasonably necessary to protect users, Dolottle, Discord, or the public; and
  • a successor if Dolottle is involved in a merger, acquisition, or asset transfer.

Dolottle does not disclose Discord API data to third parties for their own marketing.

5. Retention and deletion

Dashboard sessions expire no later than seven days after creation and may be revoked by signing out. OAuth account records and encrypted credentials are retained while needed to provide authorized dashboard access. Short-lived in-memory server-list caches expire automatically.

Server configuration, feature content, lifecycle records, and Discord resource IDs are retained while needed to provide the selected features. Moderation cases, ticket events, security records, and audit history may be retained longer when needed for accountability, abuse prevention, dispute resolution, or legal compliance. Active mute and lockdown records remain while the corresponding action is active; released records may remain as administrative history. Completed transport events are redacted rather than used as a message archive. Backup copies may remain for a limited period until overwritten through ordinary backup rotation.

Sticky Roles is disabled by default. When enabled, its latest per-member role snapshot is retained to restore manageable roles after a member rejoins. Disabling Sticky Roles stops capture and restoration; server managers may request deletion of retained server data.

Birthday records remain until the member updates or removes them, the server data is deleted, or they are no longer needed to provide the feature. A member can privately view or delete their own server-specific record with `/birthday view` or `/birthday remove`.

Ticket transcripts are disabled by default. Server managers may keep enabled transcripts indefinitely or select a retention period from one to 3,650 days. When that period ends, Dolottle deletes the stored transcript content and retains only limited lifecycle and audit records showing that generation or deletion occurred.

When Dolottle is removed from a server, processing for that server is disabled. Necessary configuration and audit records may remain for a limited recovery, security, or legal period. Dolottle deletes or de-identifies information when it is no longer needed for the purposes described in this policy, subject to legal and security exceptions.

6. Your choices and rights

You can revoke Dolottle through Discord's Authorized Apps settings, sign out of the dashboard, or ask an authorized manager to remove Dolottle from a server. You may request access, correction, export, or deletion of information associated with you or your server by contacting us. Dolottle may need to verify your Discord identity and authority before completing a request. Some information may be retained where required for security, accountability, or by law.

Birthday announcements default off. Members may store month and day without a year, opt in to a full date when age-role automation is desired, change their announcement choice, or delete the record at any time through the private `/birthday` commands.

7. Security

Dolottle uses measures designed to protect information, including encrypted OAuth credentials, hashed session tokens, secure cookies, least-privilege access, server-scoped authorization, current-permission checks, and auditable administrative actions. No method of storage or transmission is completely secure, so absolute security cannot be guaranteed.

8. International processing and age requirements

Dolottle and its service providers may process information in the United States and other locations where they operate. Dolottle is not directed to anyone who is not permitted to use Discord under Discord's terms or applicable law.

9. Changes to this policy

Dolottle may update this policy as the service changes. Material changes will be reflected by a revised effective date and, when appropriate, an additional notice through the service.

10. Contact

Questions, privacy requests, and deletion requests may be sent to support@dolottle.app.