Privacy Policy
Effective and last updated: October 9, 2026
1. Scope
This Privacy Policy explains what data ChatSift collects, why, and how you can reach us about it, for our bots (AutoModerator, AMA, ModMail, Social and Appeals), the ChatSift dashboard, and the appeals site at unban.app.
2. Information we collect
We only collect what the Service needs to do the thing you're using it for:
- Discord identifiers and names. Mostly the raw identifiers Discord itself uses: user IDs, guild (server) IDs, channel/message IDs. Usernames and avatars are generally fetched from Discord and only cached for a short while. The exceptions are moderation records (AutoModerator cases and reports) and AMA attendance lists, which keep a snapshot of the username at the time, so the record still makes sense if someone later changes their name.
- AMA content. Questions submitted through an AMA session, tied to the submitting user's ID. If a server's staff answer a question and publish it, that question and its answer can also be viewed on a public, unauthenticated answers page - anyone with the link can see it, no Discord account or server membership required. That page shows the question, the answer (and image, if any), and who asked and who answered, unless staff chose to keep the asker anonymous. If staff merge duplicate questions together, the extra askers are kept on record for that server's staff; the public page only ever shows the original asker.
- AMA attendance. If a server's staff set a stage or voice channel for an AMA, we record who joined that channel and when while attendance is being tracked, along with a snapshot of their username, display name, avatar, when they joined the server and their roles at the time, and how many messages each of them sent in that channel's chat (only the number, never what they said). This is visible to that server's staff and the AMA's guests, and is kept with the AMA. To make this work, the AMA bot keeps track of who is currently in each voice channel of the servers it's in, but only for as long as they're there, and it is told when a message is sent in those servers (Discord leaves out the text unless the message mentions the bot); it never stores anything about voice channels without an AMA attached, or about any other message, beyond that.
- ModMail content. Basic thread records (who opened a thread, which staff handled it, when) are always kept. The messages themselves are only stored beyond the lifetime of the Discord conversation if a server's staff explicitly turn on transcript recording for that server - it's opt-in per server, off by default. When it's on, that includes staff-only notes in the thread, and edited or deleted messages. Server config (snippets, greeting messages, category setup) is always stored, since it's how the bot is configured.
- AutoModerator content. Moderation cases (who was actioned, by whom, and why) and reports. A report keeps a copy of the reported message and any image link, plus who reported it and their reason; when a member reports something from their DMs, the few messages they choose to include come along with it. To log edited and deleted messages, recent messages are held in a short-lived in-memory cache (about a day) and never written to our database - the logs themselves are posted to the server's own channels, not kept by us.
- Social content. Each member's XP in a server, which is what levels and the leaderboard are worked out from. We don't store the messages that earn it. If a server's staff turn on its public leaderboard (off by default), anyone with the link can see members' names, avatars, levels and XP.
- Appeals content. Your answers to a server's appeal form, the ban reason at the time you appealed, and the staff's decision. For servers using Appeals, we also note who gets banned, so we know who can appeal. When you sign into unban.app, we request the
identify,applications.commands, andguilds.joinscopes, and keep an encrypted Discord token so we can message you the outcome and, if the server allows it, add you back once you're unbanned. It's only kept for as long as we need it for that. - Dashboard session data. When you log into the dashboard via Discord OAuth, we request the
identify,guilds, andguilds.members.readscopes - enough to know who you are and which servers you can manage - and hold a Discord access/refresh token in an encrypted session cookie so you stay logged in. We don't request or store your email address. If you ask about a custom bot instance for your server, we note who asked and for which server, so we know who to reach out to. - Error reports. When something breaks on the dashboard, the details (what page you were on, your browser, and what went wrong) are reported to an error tracker we host ourselves, so we can fix it. The tracker may also record the IP address the report came from, which is deleted along with the report.
Other than that, we don't log your IP address or use it to identify you, and we don't run any analytics or tracking scripts on our sites.
3. How we use it
Solely to operate the Service: running the moderation, levels, AMA, ModMail and appeals features you or your server's staff have set up, remembering your server's bot configuration, keeping you logged in, and finding and fixing problems when something goes wrong. We don't use your data for advertising, profiling, or anything unrelated to the feature you're actually using.
4. How long we keep it
Server configuration and the records each bot keeps (AMA questions, moderation cases and reports, levels, appeals, and, where a server has opted in, ModMail transcripts) are kept indefinitely - this is what powers the dashboard's historical views, which server staff rely on as an ongoing record, not just a live queue. If a feature is discontinued, we will purge all data associated with it.
Everything else is short-lived: caches last from minutes to a few days, and our own server logs, error reports and encrypted backups roll over after a few weeks. Dashboard and unban.app sessions expire after 30 days of inactivity. If you'd like something deleted sooner, see Section 7 below.
A published AMA answers page (see Section 2) stays reachable for as long as the underlying question data does - an AMA being marked as ended doesn't take its answers page down. If you'd like a question removed from a public answers page, see Section 7 below.
5. Who we share it with
We don't sell or rent your data, and we don't share it with anyone for their own use. It goes to Discord's own API, because that's how the Service works in the first place, and to the infrastructure we run on: the provider that hosts our servers, Cloudflare (which sits in front of our sites), and the storage provider that holds our encrypted backups. We don't use any third-party analytics or advertising services, and our error tracking is self-hosted.
Within a server, what the bots collect is visible to that server's staff, since that's who it's for.
6. Security
We take reasonable technical measures to protect your data, including:
- Your Discord OAuth tokens are encrypted, not just signed, wherever they're embedded in your session. The longer-lived one is only ever transmitted over an
httpOnly, secure cookie, never accessible to client-side JavaScript; a short-lived (5-minute) one is held in memory by the dashboard itself so it can attach it to your requests, and is refreshed automatically. - Credentials stored in the database (such as custom bot tokens and the Discord tokens kept for Appeals) are encrypted (AES-256-GCM).
- Our database disk and our backups are encrypted too.
- Access to production systems is restricted to the ChatSift team.
In the event of a data breach affecting your information, we will notify Discord as required by their Developer Terms of Service and post an announcement on our support server.
7. Your rights & how to reach us
If you'd like to know what data we hold about you, or want it deleted, reach out to a ChatSift Team member on our support server - we'll handle it directly.
8. Children's privacy
The Service is only for people who meet Discord's own minimum age requirement (13, or older where local law requires it) - we don't knowingly collect data from anyone younger, and access is gated entirely through your Discord account.
9. Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we'll update the "last updated" date above. Continuing to use the Service after a change means you accept the updated policy.