← Back to Home

Privacy Policy

Last updated · July 23, 2026

1. Who We Are

NeoBot ("we", "us", "our") is a Discord bot and web dashboard operated by its founder. The service is accessible at www.neobot.one. For privacy questions, use our Feedback page.

2. Data We Collect

We collect only what is necessary to operate the bot's features. All data originates from your Discord server activity.

User Data

  • Discord User ID — used to identify you across servers
  • Username & display name — used to display leaderboards, rank cards, and notifications
  • XP, level, and coin balance — stored per-server for the leveling and economy systems
  • Message count & voice activity hours — used for XP rewards and achievement tracking
  • Achievement progress — actions tracked: messages, reactions, voice joins/minutes, invites, casino games, daily claims, purchases, and level milestones
  • Economy records — job history, quest completions, shop purchases, gambling results
  • Warning history — moderation actions applied to a user by server staff
  • Invite records — invite codes used to join a server, for the Invite Tracker feature
  • Reaction-role & self-role assignments — which roles you gain or lose by using role panels
  • Event sign-ups — your response/role selection when you sign up for a scheduled event
  • Birthday date — if you provide it for the birthday-announcement feature

Server (Guild) Data

  • Guild ID, name, and icon — used to identify and display your server in the dashboard
  • Channel IDs and role IDs — stored when you configure features (welcome channels, log channels, role panels, etc.)
  • Configuration settings — XP rates, economy multipliers, AutoMod rules, AutoMod bad-word lists, ticket panel settings, reaction-role panels, birthday channels, stats channels, and webhook configurations
  • Custom commands — command names and response text you define
  • Ticket transcripts — message history of closed support tickets, stored until deleted by a server administrator
  • Server logs — when logging is enabled, records of moderation actions and server events (e.g. message edits/deletes, joins/leaves, role changes) written to the log channels you choose
  • Event data — scheduled-event details, templates, reminders, and the sign-up list for each event
  • Server backups — snapshots of your server's structure (roles, channels, categories, and their settings) that you create for the backup/restore feature, stored until you delete them
  • Subscription tier — whether your server has an active Premium or Ultimate plan

Dashboard Authentication

  • Discord OAuth2 access token — session-based, encrypted, used only to verify your identity and server permissions. Never stored long-term.
  • Server membership and administrator status — checked at login to confirm you have permission to manage a given server

Payment Data

Payments are processed by Stripe. We do not store credit card numbers, bank details, or full payment information. We receive only a subscription status and customer reference from Stripe. Redemption codes (if used) are stored as text alongside your guild record.

Content Processed for AI & Media Features

Some features process content you provide only to generate a response, and do not store it beyond what is needed to operate the feature:

  • AI Assistant / AI Buddy / AI Moderation — when you message the bot's AI, the text of your message (and, for image understanding, the image or GIF you send) plus limited recent conversation context is sent to a third-party AI provider to generate a reply. See Data Sharing for the providers used.
  • GIF & image commands — the GIF creator and social/action commands fetch or process images and GIFs (including images you upload or link) to produce the result. Uploaded media is processed to render the output and is not retained as a user profile.

3. How We Use Your Data

  • Operate leveling, economy, moderation, music, ticket, giveaway, birthday, invite-tracking, and achievement systems
  • Display analytics, leaderboards, rank cards, and statistics in the dashboard
  • Send automated Discord notifications (level-up messages, birthday announcements, achievement unlocks, welcome messages)
  • Authenticate and authorise access to the dashboard
  • Apply AutoMod rules and sync them with Discord's native AutoMod API
  • Enforce subscription tier limits and redeem promotional codes
  • Generate achievement unlock images using server-side canvas rendering

4. Legal Basis for Processing (GDPR)

If you are in the European Economic Area or the United Kingdom, we process your data under the following lawful bases:

  • Performance of a contract / legitimate interests — to provide the bot and dashboard features that a server administrator has enabled and that you choose to use (leveling, economy, tickets, events, moderation, etc.).
  • Consent — where a third party we embed asks for it. For example, the optional Buy Me a Coffee support widget on the dashboard presents its own cookie consent (see our Cookie Policy), which you may accept or decline.
  • Legal obligation — where we must retain or disclose data to comply with applicable law.

Server administrators act as the data controller for the member data they choose to collect within their own server; NeoBot acts as a processor for that activity and as a controller for dashboard accounts and billing.

5. Data Storage & Infrastructure

All data is stored in a PostgreSQL database hosted on our secure AWS EC2 infrastructure. Session tokens are encrypted. We do not use Replit or any third-party managed database hosting for production data.

Data is stored per-server (guild). A user's XP in Server A is completely separate from Server B — nothing carries over between Discord servers.

6. Data Retention

  • User activity data (XP, coins, levels, achievements) — retained while the bot is active in your server
  • Ticket transcripts — retained until a server administrator deletes them via the dashboard
  • Moderation records (warnings) — retained until cleared by a server administrator
  • Session tokens — expire automatically; not retained after logout or session timeout
  • Server configuration — retained until you remove the bot from your server or request deletion

7. Cookies & Local Storage

The dashboard uses a single strictly-necessary session cookie (connect.sid) to keep you signed in and carry the anti-forgery (CSRF) token, plus browser local storage to remember your interface preferences on your device. We run no analytics or tracking cookies. The optional Buy Me a Coffee widget is a separate third party that presents its own cookie consent. The bot itself does not use cookies. Full details, including durations and how to change your choice, are in our Cookie Policy.

8. Data Sharing & Third-Party Processors

We do not sell, rent, or share your data with third parties for advertising or commercial purposes. Data is shared only in these narrow cases, each acting as a service provider/processor for the specific feature:

  • Discord — we call Discord's API to read server structure, send messages, manage roles, and sync AutoMod rules. Discord's own Privacy Policy governs their use of that data.
  • Stripe — payment processing only. Stripe's Privacy Policy governs their handling of payment data.
  • AI providers (OpenRouter, Groq, and Google Gemini; Anthropic where configured) — when you use an AI feature, your message text and any image/GIF you send are transmitted to the active AI provider to generate a response. These providers process the request under their own privacy terms. We do not send them your Discord password or payment data.
  • GIF & image sources (Tenor, GIPHY, nekos.best, waifu.pics) — the GIF and social/action commands query these services to fetch or search media. Search terms and category names are sent; no personal account data is included.
  • Fluent Emoji CDN — emoji images for the webhook emoji picker are loaded from Microsoft's CDN. No user data is sent.
  • Lavalink music nodes — audio stream URLs are passed to our Lavalink node to play music. No personal data is included.
  • Buy Me a Coffee — an optional donation widget on the dashboard, governed by Buy Me a Coffee's own privacy/cookie policy and its own cookie consent. We do not receive your donation or payment details from it. See our Cookie Policy.

We may also disclose data where required by law, to enforce our Terms, or to protect the rights, safety, or property of NeoBot, our users, or the public.

9. International Data Transfers

NeoBot's infrastructure is hosted on AWS. Some of our processors (including Discord, Stripe, and the AI and media providers listed above) are based in, or process data in, the United States and other countries outside the EEA/UK. Where data is transferred internationally, it is protected by the safeguards those providers rely on, such as the EU Standard Contractual Clauses and equivalent mechanisms.

10. Your Rights & Data Requests

Depending on where you live, you have the right to:

  • Access — request a copy of the personal data we hold about you. You can also view much of it via the dashboard analytics and leaderboard pages.
  • Rectification — ask us to correct inaccurate data.
  • Erasure ("right to be forgotten") — delete your user data by submitting a request via the Feedback page with your Discord User ID; we will remove your records from all guilds within 30 days. Server data is deleted when you remove NeoBot and request permanent deletion for your guild.
  • Portability — request an export of the data you provided in a structured, machine-readable format.
  • Restriction / objection — ask us to limit or stop certain processing, and withdraw any consent (e.g. the support widget) at any time.
  • Opt out of specific tracking — server administrators can disable individual features (voice XP, invite tracking, etc.) via the dashboard.
  • Complain — EEA/UK users may lodge a complaint with their local data-protection authority.

California residents (CCPA/CPRA): we do not sell or share your personal information as those terms are defined under California law, and we do not process it for cross-context behavioural advertising. You have the right to know what we collect, to request deletion, and to be free from discrimination for exercising these rights. Submit requests the same way, via the Feedback page.

11. Data Breach Notification

We maintain safeguards to protect your data (see Security below). In the event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where required by law, inform affected users, describing the nature of the breach and the steps we are taking.

12. Children's Privacy

NeoBot operates within Discord. Discord requires users to be at least 13 years old (or older in some jurisdictions). We do not knowingly collect data from users below Discord's minimum age requirement.

13. Security

We implement encrypted session storage, CSRF protection, parameterised database queries, and access-level checks on all API endpoints. However, no system is completely secure, and we cannot guarantee absolute protection against all threats.

14. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or applicable law. The "Last updated" date at the top of this page will be revised accordingly. Continued use of NeoBot after an update constitutes acceptance of the revised policy.

15. Contact & Data Controller

NeoBot is operated by its founder, based in Poland, who acts as the data controller for dashboard accounts and billing. For privacy questions, data-subject requests, or to report a concern, please use our Feedback page or reach us in our Discord server. We aim to respond to verified requests within 30 days.

NeoBot
About Terms of Service Privacy Policy Cookie Policy Feedback Join Neonowka
© 2026 NeoBot. All rights reserved.