Privacy Policy
Last updated: August 29, 2026
This policy explains what Arclo — the Discord bot, the website and the dashboard — collects, why, who it goes to, how long it is kept, and what you can do about it. It is deliberately specific: where a feature stores something, this policy names the feature and the retention window rather than reserving the right to collect "certain information".
1. Overview
The short version
- We never receive your email address, password, payment details or private messages. Signing in asks Discord for two things only: who you are, and which servers you are in.
- We do not sell personal data, we run no advertising, and we set no tracking cookies.
- The bot does read message content — auto-moderation, levels and starboards cannot work otherwise. Almost all of it is judged in memory and never written down. Section 5 lists every case where it is stored, and for how long.
- Automated moderation, the AI classifier included, runs inside Arclo. No message content is sent to any outside service, ever.
- Most of what Arclo holds belongs to a Discord server, and the people who run that server decide what is switched on. Section 2 explains what that means for you.
This box is a summary, not a substitute for the sections below — where the two differ, the sections govern.
Arclo is a Discord bot paired with a web dashboard, operated by the Arclo team (“we”, “us”). This policy covers the bot, the arclo.gg website, the dashboard and the public pagesArclo publishes. Your use of the service is also governed by our Terms of Service.
It does not cover Discord itself, which collects and processes data independently of us under Discord’s Privacy Policy, nor the rules and practices of the individual servers Arclo runs in. Arclo is not affiliated with Discord Inc.
2. Our Role: Controller and Processor
Arclo does two different jobs, and data-protection law treats them differently.
- We are the controller for the website, the dashboard and your sign-in — your Discord account details, your session, the images you upload and the record of dashboard actions.
- We are a processor for what the bot does inside a Discord server. The people who run that server choose which systems are on, what gets logged, who on their staff can read it, and what is kept. They are the controller for that data; we hold and process it on their instructions.
If you are a server member: requests about a server — your moderation history there, your form submission, your level — are usually fastest with that server’s administrators, who can act on them from the dashboard themselves. You can always come to us instead (section 14); where we are only the processor we will pass the request on and help them answer it, and where the law requires us to act directly, we will.
If you run a server: you are responsible for having a lawful basis for what you switch on, and for telling your members about it. The data-protection section of our Terms sets out the processing terms that apply between us.
3. Data From the Website and Dashboard
Signing in uses Discord’s OAuth2 flow. We request exactly two scopes — identify and guilds — and with your authorization Discord gives us:
- your Discord user ID, username, display name and avatar; and
- the list of servers you are in and your permissions in each, so the dashboard can show the ones you may manage. This list is fetched live from Discord on each request rather than stored.
We do not request the email scope, so we never receive your email address. We never see your Discord password, your direct messages, or any payment details.
Beyond sign-in, the website stores:
- Your session — a signed token in the
arclo_sessioncookie holding your user ID, username, avatar URL and the Discord access token the dashboard uses to ask Discord for your server list. It is HTTP-only, secure, same-site, and expires after seven days. - A dashboard activity log — who changed what, in which server and when, shown to that server’s administrators on its Settings page so an unexpected change has an author.
- Images you upload — the file itself, its dimensions and checksum, and the Discord ID of whoever uploaded it (for the audit trail and per-user rate limiting).
- Public form and appeal submissions — if you fill in a server’s form or submit a ban appeal on our site, we store your answers, any files you attach and your Discord ID. Marking a form anonymous hides you from the server’s reviewers; the ID is still held so one person cannot submit a hundred times. A file attached to a form is re-posted into that server’s submissions channel and reachable at a long, unguessable link on arclo.gg for as long as that message exists — deleting the submission, or the message, removes access.
- Ordinary server logs — our hosting providers record request metadata such as IP address, user agent and timestamp. We use these to run and secure the service, not to profile you.
4. Data From the Bot in Your Server
What the bot stores depends entirely on which systems a server has enabled. A server running only welcome messages stores almost nothing about its members; one running levels, analytics, moderation and invite tracking stores a good deal. Across the whole product, the categories are:
- Server records — the server’s Discord ID, name, icon, approximate member count and when Arclo joined.
- Configuration — everything an administrator sets in the dashboard, including the message text, embeds and images they design, and the channel, role and message IDs those settings point at.
- Activity records — Levels and Achievements keep XP, levels, voice time and progress; Analytics keeps per-member message and voice totals per day and the hours a member was active; Invite Tracking records who invited whom and with which code. Boards store a snapshot of a member’s name and avatar so a leaderboard renders without a Discord lookup per row. Bot-wide rather than per server, Arclo also keeps the Discord IDs of the users who ran a command or used a button, menu or form in a given hour, so the operator can see how many distinct people use the bot.
- Moderation records — cases (type, reason, duration, the moderator, any evidence attached), private staff notes, appeals, member reports, and per-member counters used by escalation ladders.
- Protection records — Auto Moderation violations, honeypot triggers, Security events and quarantine records, each with the member involved.
- Things members give the bot — your birthday (day and month, plus the year if that server asks for one and you choose to give it), the text of your reminders and the time zone your browser reported when you set the first one, giveaway entries, poll and suggestion votes, suggestion and suggestion-report text, ticket details, form answers, temporary-voice preferences.
- Backups, chat logs and published templates — created deliberately by a person, and described separately below.
Backups are the one thing that outlives the server. A backup or chat log belongs to the Discord user who created it, not to the server it was taken from — that is what lets someone rebuild a community elsewhere after losing it. Depending on the options chosen at capture, a backup can contain the server’s channels, roles, permissions, emojis, its ban list with reasons, which members held which roles, and the most recent messages of each channel together with their authors’ names and avatars. A chat log is the same thing for a single channel. Both survive Arclo being removed from the server, and are deleted when their owner deletes them.
Two things the bot deliberately does not do: it keeps no copy of the log events it delivers to your server — the Logging system sends them straight to the Discord channel you nominated, and they live there under your control — and it does not request the direct-message intent at all, so it cannot see your DMs, with it or with anyone else. It can send you a DM (a punishment notice, a reminder), and you can press a button in one, but it never receives your private conversations.
5. Message Content
Arclo uses Discord’s Message Content privileged intent, which Discord grants on review. It is what makes auto-moderation, chat protection, levels, starboards, sticky messages, tags, custom commands and message analytics possible: none of them can judge a message they cannot see.
Reading is not storing. The overwhelming majority of messages Arclo sees are evaluated in memory — matched against the filters a server enabled, counted toward a total — and then dropped. What follows is the complete list of cases where message text is written to our database, every one of which a server’s administrators switch on themselves:
- Auto Moderation violations — a trimmed copy of the message that tripped a rule, kept so the alert can say what happened after the message itself is deleted. It expires on the window that rule counts over.
- Honeypot triggers — what was posted in a trap channel, kept 30 days.
- Member reports — the reported message, quoted on the report card staff act on.
- Moderation cases — the reason a moderator wrote and any evidence they attached, which may quote or link to a message.
- Ticket transcripts — the full conversation in a ticket, saved as a transcript when a server turns transcripts on.
- Backups and chat logs — recent messages, when whoever took the snapshot chose to include them.
- Content you submit on purpose — a suggestion, a form answer, an appeal, a reminder, a tag, a poll question.
- AI moderation — scored in memory and not stored, beyond the violation record any other rule would produce. See section 11.
Everything else is counted, not kept. Starboards store a message’s ID, its author and its star count, never its text; Levels and Analytics store numbers; Auto Purge deletes without recording. Message content is never used for advertising or profiling, and it is never shared with anyone but the parties in section 12.
6. Publicly Visible Data
Some of what Arclo shows is public by design:
- Public boards — a server can publish its level leaderboard, achievement board or invite board at a public address on arclo.gg. These pages are rendered on the server, so they can be opened by anyone with the link and indexed by search engines. They show member display names, avatars, ranks and the counts the board is about. A server’s administrators turn these on and can turn them off, which removes the page.
- Uploaded images — images added in the dashboard are served from our CDN at long, unguessable URLs. They are not access-controlled: anyone holding the URL can open the image. Treat anything you upload as public.
- Published server templates — if you publish a template to the community library, the template and your name as its publisher are public until you delete it.
- Anything the bot posts — a welcome message, a case in a log channel, a starboard post or a ticket transcript delivered to a channel lives in Discord under that server’s control, and deleting our copy does not remove Discord’s.
8. How We Use Data
We use the data described above to:
- operate the features a server has configured — sending its messages, running its moderation and protection rules, awarding XP, drawing giveaways, tracking invites, building its boards and reports;
- authenticate you, show you the servers you may manage, and keep the dashboard and Discord in sync;
- keep the service secure and available — preventing abuse, enforcing rate limits, investigating incidents, and diagnosing faults;
- answer your support requests and act on your privacy requests; and
- comply with legal obligations and enforce our Terms.
We do not use your data for advertising or profiling, we do not sell or rent it, and we do not train machine-learning models on it.
9. Legal Bases
Where the GDPR, the UK GDPR or a comparable law applies, we rely on these bases:
- Performance of a contract — holding your session and a server’s configuration is what providing the service consists of.
- Legitimate interests — keeping the service secure and available, preventing abuse and spam, understanding faults, and defending legal claims. You may object to processing on this basis (section 15).
- Consent — where you volunteer something you did not have to, such as a birthday year, or authorize the Discord sign-in. You can withdraw it at any time, which does not affect what was done beforehand.
- Legal obligation — where we must retain or disclose something to comply with the law.
For what the bot does inside a server, the basis is chosen by that server’s administrators as controller — most often their legitimate interest in running a safe community. We process it on their instructions.
10. Automated Moderation and Appeals
Arclo can act on a member automatically: deleting a message, warning, timing out, kicking, banning, quarantining or restricting them. Every threshold, ladder and exemption behind those actions is set by the server’s administrators, not by us — we supply the mechanism, they decide the policy.
There is always a human route out of an automated decision:
- every punishment produces a numbered case a moderator can review, reverse or pardon;
- servers can enable appeals, which put your side of it in front of a human on that server's staff; and
- you can raise it with the server's administrators directly, and with us if you believe we have processed something unlawfully.
To the extent a decision would be a solely automated one with legal or similarly significant effects, those routes are how you obtain human intervention, express your point of view and contest the outcome. Arclo keeps no cross-server reputation score and no global ban list — a punishment in one server has no effect in another.
11. AI Moderation
Auto Moderation includes an optional classifier that scores a message against categories such as insults, threats or spam, so that a server can catch what a word list never will — the message that is cruel without swearing, or the hundredth new spelling of a slur. It runs entirely inside Arclo.
Concretely, that means:
- no message content is sent to an external service, an AI provider, or anyone else — there is no outbound request to make;
- nothing is used to train any model, ours or anybody else's;
- the message text itself is not stored — only the outcome, in the same violation record any other rule would produce; and
- it is off unless a server enables it, it runs only on messages no other rule already handled, and it is log-only on a fresh install, recording what it would have done without acting.
The classifier is a statistical model over language features — the words used, who the message is aimed at, whether it is quoted, negated or joking. It is not a large language model and we make no claim that it is. Like any classifier it is probabilistic and will sometimes be wrong, which is why a server’s administrators set the thresholds, why the safe default acts on nothing, and why section 10’s human-review routes exist.
13. Retention
Data tied to a server is kept while Arclo is in that server. When the bot is removed, it confirms with Discord that it really has left and then marks the server’s record for deletion. The record and everything hanging off it — configuration, cases, levels, entries, submissions, statistics — is kept for 14 days and then deleted permanently. Re-adding the bot within those 14 days cancels the deletion and restores the server’s setup exactly as it was; after them, nothing is recoverable. The grace period exists so that an accidental removal, a permissions change or a short test does not destroy a server’s history. Beyond that, the specific windows are:
| What | How long | Why |
|---|---|---|
| Server configuration and per-member records | Until 14 days after the bot is removed from the server | It is the server's own settings and history, and a removal is often a mistake |
| Backups, chat logs, published templates | Until their owner deletes them, or an older one is pruned by the per-user cap | They belong to the person who made them, not the server |
| Files attached to a form | As long as the message holding them stays in the server's submissions channel — deleting the submission deletes it | A reviewer has to be able to open an application weeks later; Discord removes an uploaded file about a day after the popup closes unless it is re-posted |
| Closed tickets and saved transcripts | The newest 500 closed tickets and 100 transcripts per panel by default; each panel sets its own limits, up to 5,000 and 1,000 | A support history is read for a while, not forever, and transcripts are the largest thing a server stores |
| Form submissions | The newest 1,000 decided submissions per form by default; each form sets its own limit, up to 5,000. Pending reviews are never removed | The record of a decision outlives it by a long while, not indefinitely |
| Analytics — hourly activity | 40 days | Nothing on the page looks further back |
| Analytics — hourly presence | 3 days | Only the Today view reads it |
| Analytics — per member and per channel, per day | 800 days (about 26 months) | Covers the 1-year view and the year it is compared against |
| Analytics — daily server totals and join records | Kept while the server row exists | One small row per day; the only record of early growth |
| Security events | 30 days, and at most 500 per server | An incident feed, not an archive |
| Honeypot triggers | 30 days | The window the dashboard shows |
| Bot usage — which user IDs interacted with the bot, per hour | 62 days | Only the operator's daily, weekly and monthly usage report reads it |
| Auto Moderation violations | The window the rule counts over | They exist to feed an escalation ladder |
| Custom command and automation cooldowns | Until the cooldown expires | A member or channel ID and an expiry, so a restart cannot hand out a free run |
| Daily message counts (giveaway requirements) | 40 days | A requirement never looks back further than a month |
| Lifetime message totals, levels, achievements and invite records | Kept while the server row exists — leaving a server does not delete them | So rejoining a server does not cost you the progress you earned; a server can reset them at any time |
| Dashboard activity log | The newest 1,000 entries per server | The Settings page shows the latest forty |
| Dashboard sessions | 7 days, or until you log out | Re-authentication is cheap |
| Database backups and provider logs | A short rolling window, then overwritten | Disaster recovery and security |
We may keep something longer where the law requires it, or where it is needed to establish or defend a legal claim — and no longer than that.
14. Deletion and Your Controls
Much of this you can do yourself, immediately:
- remove the bot from a server to have that server's stored configuration and records deleted after a 14-day grace period — re-adding it inside that window cancels the deletion;
- log out to end your dashboard session;
- delete your own backups, chat logs and published templates from the dashboard;
- remove your birthday, your reminders and the tags you own with the matching command; and
- ask the server's administrators to remove your level, your form submission or a moderation record — they can do all three from the dashboard.
For anything else, write to contact@arclo.gg. To protect other people’s data we need to be satisfied you control the Discord account in question — usually by asking you to sign in to the dashboard, or to send the request from a channel tied to that account. We will not ask you for identity documents.
There are limits worth stating plainly. We cannot delete messages Discord holds, or anything the bot already posted into a server — that is Discord’s copy and the server’s. Where we act only as a processor we will forward your request to the server’s administrators and help them answer it. And we may decline to erase a record where keeping it is necessary for legal claims, for fraud and abuse prevention, or where erasing it would delete another person’s record — for example a moderation case that names the moderator who filed it.
15. Your Rights
Subject to your local law, you have the right to ask us to: give you access to the personal data we hold about you; correct it if it is wrong; delete it; restrict or object to how we process it (including processing based on legitimate interests); provide it in a portable format; and withdraw a consent you gave.
Requests go to contact@arclo.gg. We do not charge for them, and we answer within 30 days — if a request is unusually complex we may extend that by up to two further months and will tell you why within the first 30 days. We will not treat you worse for exercising a right. If you are unhappy with how we handled it, you can complain to your local data-protection authority, and we would rather you told us first so we can put it right.
16. Regional Rights
- EEA and United Kingdom. The rights in section 15 are those of the GDPR and the UK GDPR. You may lodge a complaint with your national supervisory authority or the UK Information Commissioner’s Office.
- Israel. We process personal data in line with the Protection of Privacy Law, 5741-1981. You have the right to inspect the information held about you and to ask for it to be corrected or deleted, and to complain to the Privacy Protection Authority.
- United States. Where a state privacy law applies to you, you may request to know, delete, correct and receive a copy of your personal information, and appeal a refusal. We do not sell personal information, do not share it for cross-context behavioural advertising, and do not use sensitive personal information to infer characteristics about you.
- Everywhere else. Use the same address. We apply the controls in this policy to everyone, whether or not a local law compels them.
17. International Transfers
We operate from Israel — recognized by the European Commission as providing an adequate level of protection for personal data transferred from the EEA — and our providers process data in the European Union, the United Kingdom, the United States and other countries. Where a transfer is not covered by an adequacy decision, we rely on the Standard Contractual Clauses or another transfer mechanism approved under applicable law, as set out in our agreements with those providers.
18. Security
We take technical and organizational measures appropriate to the risk, including: encryption in transit for every connection to the site, the API and Discord; encryption at rest by our database and storage providers; signed, HTTP-only session tokens; unguessable identifiers on uploaded assets; authorization re-checked against Discord on every dashboard request, with short-lived caches that fail closed rather than open; secrets held as environment configuration rather than in code or the database; and access to production data limited to the people who need it.
We also try to reduce the blast radius of any incident by storing as little as the features allow and expiring what we do store. No online service can promise absolute security. If a breach affects your personal data, we will notify you and the relevant regulators where the law requires, without undue delay.
19. Children
The service is intended for people who meet Discord’s minimum age requirement — at least 13, and higher in countries where local law sets a higher age (16 in parts of the EEA). We do not knowingly collect personal data from anyone below the applicable age. If you believe a child has provided us data, write to contact@arclo.gg and we will delete it.
20. Changes to This Policy
We may update this policy as the product changes. We will revise the “Last updated” date above, and for changes that materially affect your rights or how we use your data we will give more prominent notice — on the website and in the support server — before they take effect. Previous versions are available on request.
21. Contact
Privacy questions and requests go to contact@arclo.gg, which is also the address for anything legal. For help using the bot, the faster routes are support@arclo.gg and the support server.
The operator’s full details are available on request. See also our Terms of Service.
