01 Who this applies to
This policy covers Xristina Bot ("Xristina", "the bot") and this website. It applies to every server the bot is in and to every member of those servers, whether or not they use her commands.
Discord itself also collects data about you. That is governed by Discord's Privacy Policy, not this one.
02 How messages are handled
Xristina uses Discord's Message Content intent. This means she receives the text of messages sent in servers she's in. This is unavoidable — a spam filter cannot check a message it cannot read.
Message content is processed in memory, in the moment. It is checked against the spam, zalgo, phishing, link, and wall-of-text rules and then discarded. Message text is not written to a database and is never used for training, profiling, analytics, or advertising.
When a message trips a rule, a short summary of what happened — the user, the rule, and the action taken — is posted to your own log channel, inside your own server. That log lives in your Discord server and is under your control, not ours. Deleting that channel deletes those records.
03 What is stored
Xristina keeps a small database so she remembers your setup between restarts. It holds only the following:
| Data | What it contains |
|---|---|
| Server settings | Server ID, your log channel ID, which filters are on or off, welcome and leave message settings, ticket category configuration. |
| Warnings | Server ID, the warned user's ID, the moderator's ID, the reason text, a timestamp, and the running warning count used by the escalation ladder. |
| Blacklist | Server ID, the blacklisted user's ID, the reason, and the ID of the staff member who added them. |
| Tickets | Server ID, ticket channel ID, the opener's user ID, and ticket status. Transcripts are stored in your server, not ours. |
| Short-lived counters | In-memory tallies used to detect a flood — for example, "this user sent 5 messages in the last 5 seconds", or "3 bans happened in 10 seconds". These exist for seconds and are never written to disk. |
Where a "user ID" is stored, it is Discord's numeric snowflake ID — not your name, email, or IP address.
04 What is never stored
- Message content, attachments, images, or links
- Direct messages between you and other users
- Voice data of any kind
- Email addresses, real names, phone numbers, or IP addresses
- Payment information — the bot is free and takes no payments
- Anything used for advertising, tracking, or resale
05 Why we store it
Every stored field exists because a feature would break without it:
- Server settings — so your configuration survives a restart and alerts reach the right channel.
- Warnings — so the escalation ladder knows whether a user is on their first strike or their fourth.
- Blacklist — so a banned user who rejoins is caught, including when they slip in while the bot is offline.
- Tickets — so an open ticket can be closed by the right people.
Our legal basis, where GDPR applies, is legitimate interest: keeping a Discord community safe from spam, raids, and destructive attacks.
06 How long it's kept
- Server settings, warnings, and blacklist entries are kept for as long as the bot is in your server.
- In-memory counters expire within seconds.
- When the bot is removed from a server, that server's stored data is deleted. It is not retained for future re-invites.
- Individual warnings can be cleared at any time by your server staff.
07 Sharing and third parties
Data is never sold, rented, traded, or shared with advertisers, data brokers, or any other bot or service. There is no cross-server "global ban list" — a blacklist in your server stays in your server.
Data is transmitted to and from Discord's API, because that is how a Discord bot works. The bot runs on third-party hosting infrastructure, which necessarily stores the database on its servers. We may disclose data if legally compelled to do so by a valid legal request.
08 Security
The bot's credentials are held in environment variables and never committed to source control. Access to the database is limited to the bot itself and its maintainers.
No system is perfectly secure. Because the bot stores no passwords, emails, or payment data, the impact of a breach would be limited to server IDs, user IDs, and warning reasons. If a breach ever affected user data, it would be announced in the support server.
09 Your rights
Depending on where you live, you may have the right to:
- Ask what data is held about you
- Request a copy of it
- Ask for it to be corrected
- Ask for it to be erased
- Object to it being processed
To exercise any of these, contact us in the support server. We will respond within 30 days.
10 Deleting your data
If you're a server owner
Remove the bot from your server. Its settings, warnings, blacklist, and ticket records for that server are deleted. If you'd like written confirmation, ask in the support server.
If you're a member of a server
Your warnings and blacklist entries belong to the server that issued them, so ask that server's staff to clear them first. If you want your data removed from the bot's database directly, contact us with your Discord user ID and the server in question.
What we can't delete
Anything sitting in your own Discord server — log channel embeds, ticket transcripts, welcome messages — is Discord data under your control. Delete those channels or messages yourself.
11 Children
Xristina is not directed at children. In line with Discord's own rules, the service is not for anyone under 13, or under the minimum age of digital consent in their country. If we learn that data belonging to a child under that age has been stored, we will delete it.
12 Changes to this policy
This policy may be updated as the bot changes. The effective date at the top of the page always reflects the current version, and material changes will be announced in the support server.
13 Contact
- Support server: discord.gg/dragonmusic
- Email: support@example.com ← replace with your real address
See also the Terms of Service.