Policies
Privacy Policy
Effective and last updated September 8, 2026
We collect data
ServerShield collects Discord account and server information, settings, content you submit, and limited technical and security data. We use it to provide and secure the bot and dashboard, enforce abuse controls, respond to requests, and understand site performance. We do not sell personal data or use it for targeted advertising.
1. Who is responsible
ServerShield is operated by SlayStudios. This policy covers the ServerShield bot, dashboard, and related support and moderation workflows. A Discord server owner or administrator may also control how the bot is configured and how data generated in that server is used.
2. Data we collect and where it comes from
- Discord account data: your Discord user ID, username, display name, avatar, and the servers Discord makes available under the OAuth permissions you authorize. We do not receive your Discord password.
- Server and configuration data: server, channel, role, and member-count information; moderation, welcome, logging, and similar settings; and the permissions needed to decide which servers you may manage.
- Discord content and event data: message text, links, attachments, user and channel identifiers, and join, leave, moderation, or other event data when the bot must process it to provide an enabled protection or logging feature. We may store relevant excerpts or metadata in a threat or audit record.
- Content you submit: appeals and evidence, bug reports, suggestions, feedback, labels, votes, and communications with support or moderators.
- Moderation and security data: blacklist status and reasons, threat and audit events, action timestamps, the responsible account or moderator, and action outcomes.
- Technical data: IP address, a pseudonymous hash derived from an IP address, browser/device information, requested pages, timestamps, referral information, and usage or performance events produced by our hosting, logs, and Vercel Analytics.
We receive this data from you, Discord, server administrators, the ServerShield bot, and our hosting and security providers. Please do not submit passwords, tokens, government identifiers, financial information, health information, or other sensitive personal data in free-text fields.
3. Why we use data
- Authenticate you, maintain your session, and verify your Discord and server permissions.
- Provide moderation, anti-raid, alerts, configuration, analytics, and server-management features.
- Process appeals, reports, suggestions, votes, feedback, and support requests.
- Rate-limit traffic, investigate abuse, detect ban evasion, maintain audit records, and secure the service.
- Measure reliability and site usage, debug failures, and improve ServerShield.
- Comply with law, enforce our Terms, and protect users, SlayStudios, Discord, and the public.
Where applicable law requires a legal basis, we rely on performing the service you request, our legitimate interests in operating and securing ServerShield, consent where requested, and compliance with legal obligations. You may withdraw consent at any time, but withdrawal does not undo prior lawful processing.
4. Cookies and local storage
We use encrypted, signed, HttpOnly cookies for your authenticated session and a short-lived OAuth state cookie to protect the Discord sign-in flow. These cookies are necessary to provide and secure the dashboard. Discord and Vercel may use their own cookies or similar technologies under their policies. ServerShield does not store your Discord access token in browser localStorage and does not use advertising cookies.
5. AI and automated decisions
ServerShield uses rule-based automated systems for functions such as spam and raid detection, rate limiting, and ban-evasion checks. For example, an account may be automatically restricted when its pseudonymous network identifier matches one associated with a blacklisted account. These systems can be wrong. You may submit an appeal and request human review of a restriction.
SlayStudios may use AI-assisted tools to help develop the service, analyze operational patterns, or assist a human reviewing support and safety issues. AI output is not treated as conclusive for consequential moderation or appeal decisions. We do not use Discord message content or other Discord API data to train general-purpose AI models, and we do not intentionally provide access tokens, webhook credentials, passwords, or other secrets to such tools. Before introducing an AI feature that materially changes how personal data is processed or sends it to a new provider, we will update this notice and request consent where required.
6. When we share data
We share only what is reasonably needed with service providers that operate ServerShield, including Discord for authentication and bot functions, Vercel for website hosting and analytics, Cloudflare D1 for database storage, and Discord webhooks used to deliver support, appeal, bug, suggestion, and operational notifications. Server administrators and authorized moderators can see data connected to servers they manage. We may also disclose information to comply with law, respond to valid legal process, investigate fraud or abuse, protect safety and rights, or as part of a merger, financing, acquisition, or sale with appropriate safeguards.
We do not sell personal data, share it for cross-context behavioral advertising, or use Discord API data for advertising. Our providers may process data in the United States and other countries where they operate.
7. Retention
- OAuth state expires after about 10 minutes; the authenticated session expires with the Discord token or when you sign out.
- Server configuration remains while needed to provide the service or until it is removed.
- Appeals, reports, suggestions, moderation records, and audit events remain while needed to resolve the matter, enforce our Terms, meet legal obligations, or establish and defend legal claims.
- Active blacklist records remain while the restriction is in force. Approval of an appeal removes the related blacklist entry and its stored network hash.
- Rate-limit, hosting, security, and analytics records are retained according to operational need and provider settings, then deleted or de-identified when no longer needed.
A legal or security hold may delay deletion. Backup copies may persist for a limited period until overwritten.
8. Your privacy rights
Depending on where you live, you may have rights to know or access, correct, delete, restrict or object to processing, receive a portable copy, withdraw consent, appeal a denied privacy request, and request human review of certain automated decisions. You may also complain to your local data-protection authority. We will not discriminate against you for exercising a privacy right.
To make a request, contact us using the method below and identify your Discord account and request. We may need to verify your identity and authority over a server before acting. Removing ServerShield from a server stops future collection from that server but does not automatically erase records we must retain for security, disputes, or law.
9. Children
ServerShield is not directed to children under 13 or anyone below Discord's minimum age in their country. If you believe a child provided personal data contrary to these rules, contact us so we can investigate and delete it where required.
10. Security and incidents
We use technical and organizational safeguards designed to protect data, including encrypted transport, access controls, server-side authorization, and environment-managed secrets. No system is completely secure, so we cannot guarantee absolute security. If a breach creates a legal notification duty, we will notify affected users and authorities as required.
11. Changes and contact
We may update this policy as ServerShield changes. We will post the revised date here and provide additional notice before a material change when required.
For privacy questions, deletion or access requests, AI concerns, or an appeal of a privacy decision, contact the ServerShield team in the official SlayStudios Discord. Do not post personal data in a public channel; open a private support request. You can also review our Terms of Service.