Back
Privacy policy
Last updated October 5, 2026. This policy explains what this bot and dashboard collect, why, who can see it, and how long it stays. Developed and Maintained by ₳ncint₳narchist. It should be read with the Terms of service.
1. Who is responsible
The operator and admin of this bot is ₳ncint₳narchist. The contact email is havejack@gmail.com. The bot is self-hosted. Information described here is stored on the computer that runs the bot, not on a separate public cloud account run by the operator for this purpose. That computer is controlled by the operator. For privacy questions, email that address. You can also use the Discord server that hosts the bot. Do not send passwords or tokens in that message.
This policy is written to meet, and where it fits this small tool to go past, the kind of disclosure Discord gives its users, and to line up with Canada’s Personal Information Protection and Electronic Documents Act and Quebec’s privacy rules, including the right to be informed and the right to ask for access or deletion. It is not a Discord or VRChat policy. Those companies have their own.
2. What this policy covers
It covers the Discord bot, this website, request and moderation tools, strike and warning records, evidence files, logs the bot writes, and the member-name cache. It does not cover Discord itself, VRChat itself, or other websites a join link opens. When you use Discord or VRChat, their policies apply to what those companies collect.
3. Information the service collects
Discord account, when you sign in
Sign-in uses Discord’s login. The dashboard receives your Discord user id, username, global display name if Discord sends it, and avatar. It also receives the list of servers you share with the bot, so the server menu can be built. For a server you open, the bot reads your roles and your Manage Server permission, if Discord grants that, so it can show or hide Mod, Strikes, Logs, and Setup. The bot does not receive your Discord password. It does not read your private messages, except a warning DM the bot itself sends when a moderator chooses that.
Session
After login, a session id is stored in a cookie in your browser and the session record is stored on the host. The saved session holds your Discord id, username, and the shared-server list. It is encrypted on disk with the bot’s data key. It exists so a bot restart does not force you to sign in again. Signing out deletes that browser cookie and the matching saved session.
Member names
For the strike board, the bot keeps a cache of people in each server it is in: Discord id, display name, and avatar address. Bots are skipped. A person is removed from that cache when they leave the server, once the bot is told about the leave. The cache is saved in a file on the host so it is not downloaded from Discord again on every page view. It is not a secret file. It is not sold.
Requests and rooms
A request stores the Discord id and name of the person who asked, the world, minutes, region, instance type, and related queue state. Open rooms keep the same kind of fields, plus close time and join activity the bot can see from VRChat’s instance listing. The bot does not join the VRChat room as a user to read a private player list beyond what VRChat’s API already returns to the account the server configured.
Moderation records and evidence
Warnings and strikes store the target Discord id, the moderator’s Discord id and name, the reason, the time, whether the record is a warning or a strike, and whether it is still active. Evidence files you or a moderator attach (images, PDF, or plain text, within the size limits shown in the product) are stored for that server. The file bytes are encrypted on disk. The dashboard shows them only to people who can already open strikes. Discord messages only say that files exist. They do not include the files.
Server configuration
Setup stores the channels, roles, limits, world lists, rules text, and dashboard rules that staff save. VRChat logins for the bot’s own accounts (a username and password, plus a 2FA code when VRChat asks for one) can be entered only by server managers, meaning people with Manage Server, either in Discord /setup or on the dashboard Setup page. From the dashboard they are sent to the bot over the dashboard connection, used to sign in to VRChat, and stored with the server’s encrypted bot data, the same way as the Discord flow. A saved password, 2FA code or VRChat session cookie is never shown back: not on the dashboard, not in the logs, and not in Discord. The audit log only records that an account was logged in, verified, re-checked or removed, by whom, and VRChat’s error message if it failed. This website does not ask members for a VRChat password.
Logs
The bot writes an operational log on disk and can post a short audit line to the Discord channel the server selected. Those lines can include Discord ids, world names, and the action that was taken. The bot log is trimmed of token-shaped strings before the Logs page shows it. Audit messages live in Discord under Discord’s own retention, and also in the bot log until that file rolls over or is deleted.
Technical data from normal use
Like any web server, the process sees your IP address while it handles a request. The dashboard does not add a separate analytics product, advertising profile, or tracking pixel. It does not sell a browsing history. A short copy of the session id may sit in the browser’s local storage so the page can send it with requests.
4. Information the service does not try to collect
- Your Discord password, or your personal VRChat password. The only VRChat passwords the service stores are for the bot’s own accounts, entered by server managers as described above.
- Your direct messages, other than a warning the bot sends.
- Payment card numbers. This service does not charge you.
- A precise location from your device. An IP address can imply a rough region to the host operating system, and the bot does not store a location history.
- Contacts, microphone, camera, or files on your computer, other than files you choose to attach as evidence.
5. Why it is used
The service uses the information above to:
- Sign you in and keep you signed in.
- Show only the servers and tools your roles allow.
- Open, list, queue, extend, and close instances.
- Apply the server’s request rules, cooldowns, and strike locks.
- Let moderators warn, record, review, and remove strikes, and let managers delete history.
- Show staff the audit trail they configured.
- Keep the bot running, fix failures, and protect the host from abuse.
The operator relies on these reasons: you asked to use the service (for example by signing in or sending a request); the service cannot run the feature you used without that data; the server that installed the bot has a real need to moderate its own rooms; and, where the law asks for it, a legal duty. You can stop future use by signing out and leaving the server. Some records the server already made can remain until staff delete them, as described below.
6. Discord and VRChat
Discord receives whatever its own product collects when you log in, when roles are checked, when an audit message is posted, and when a warning DM is sent. VRChat receives the calls the bot’s configured account makes, such as listing instances or opening one. The operator does not control those companies. Their terms and privacy policies govern what they do with data on their systems. A join button only builds a VRChat launch link. It does not send your dashboard session to VRChat.
7. Developer diagnostics
One Discord account, chosen by the operator, can open a developer page. No other account is given that page, and the stats interface rejects everyone else. The page is not described in the member FAQ.
That page shows the bot process only. Processor time is the process, not the whole computer. Memory is the process, not the computer’s installed memory. Storage is the bot’s own data files, not the rest of the disk. Network figures are bytes the bot process sends and receives, not every program on the computer. It also shows this bot’s own Discord and VRChat calls: route, status code, timing, rate limits, account sign-in state, and poll timing. It shows Discord’s and VRChat’s public status pages as the bot last read them. It shows the bot’s Discord tag, guild count, member count, gateway ping, how many dashboard sessions exist, process uptime, and whether the contact email, Discord client secret, and data key are set. It does not show the values of those secrets, passwords, tokens, evidence contents, or message text.
The count of dashboard sessions is a number, not a list of other people’s private activity. These diagnostics are used to operate and debug the bot. They are visible only to that one account.
8. Cookies and local storage
The dashboard uses one session cookie named so the browser sends it back to this site only. It is marked HttpOnly and SameSite. The page also keeps the session id in local storage as a fallback. There are no advertising cookies and no third-party analytics cookies. You can sign out, or clear the site’s cookies and local storage in your browser. Clearing them signs you out.
9. Who can see it
Access follows Discord roles on that server:
- Members who can open the dashboard see instances, the queue, and their own request tools.
- Mods can see the mod tools, strike history, evidence, and logs, as the menu allows.
- Hosts and people with Manage Server can open setup and, for managers, delete strike history.
- The operator can see what is stored on the host, because they run the computer. The developer page does not give that view to anyone else.
- Discord can see content that was posted into a Discord channel or DM. VRChat can see API calls made with the server’s VRChat account.
The operator does not sell personal information. The operator does not share it with advertisers. The operator may disclose information if the law requires it, or if it is necessary to deal with abuse, a security incident, or a claim about the service. Server staff already see the moderation records of their own server through the tools above.
10. How long it is kept
- Session records last until you sign out, the session file is removed, or they are replaced. A session that is still in use is refreshed.
- Member-cache names stay while the person is in the server, and are removed when the bot records that they left.
- Strike and warning history stays until a moderator expires it, a manager deletes it, or the server’s bot data is deleted.
- Evidence stays with the record it is attached to and is removed when that record or the person’s history is deleted.
- Bot log files rotate with the bot’s logging. Audit lines in Discord follow that channel until someone deletes them there.
- Request and instance fields last while the queue item or room exists, and can remain in logs after the room closes.
If the bot’s data folder is deleted, the local copies go with it. Copies already sent to Discord or VRChat are not pulled back by deleting the folder.
11. Security
Sessions and evidence file bytes are encrypted with the bot’s data key. Server configuration is stored with that same protection. The member-name cache is a local file of names and avatar addresses and is not given that same encryption. No method is perfect. A person with access to the host and the data key can read what the bot stores. You should not submit evidence you would not trust that server’s staff and the operator to hold.
12. Children
The service is not directed at children under 13, or under a higher age if Discord requires one where you live. It does not knowingly ask a child under that age to create a separate account. Login is your Discord account. If you believe a child’s information was stored by mistake, contact the operator or the server staff and ask for it to be removed.
13. Where the data sits
Data in the bot’s files stays on the host computer. The operator does not run a separate multi-country processing network for this dashboard. Discord and VRChat may process data in other countries under their own policies when the service talks to them. If you use the dashboard from outside the host’s country, your requests cross the network to that host.
14. Your choices and rights
You may:
- Sign out, which drops your dashboard session.
- Stop sending requests, and leave the Discord server.
- Ask the server’s staff to expire a lock, delete a strike, or erase your history. Managers have those controls. Staff do not have to delete a record they still need for a real moderation reason, but they should not keep it without one.
- Ask the operator and admin, ₳ncint₳narchist, for access to the bot-held personal information about you, for a correction, or for deletion, by emailing havejack@gmail.com. The operator can send a zip of the records this bot holds for that Discord id. That zip leaves out who issued a strike or warning, and it does not include evidence files. The operator may need to confirm you are the Discord account in question. Some information can also sit in Discord, and only Discord can delete that.
- Withdraw consent for future use by signing out and stopping use. Withdrawal does not undo a record already shared inside the server’s moderation tools, until that record is deleted.
- Complain to a privacy regulator. In Quebec, that includes the Commission d’accès à l’information. Under federal rules, that includes the Office of the Privacy Commissioner of Canada. You may also have a right to complain in the place where you live.
The operator will answer an access or deletion request within a reasonable time, and within the time the applicable law requires if it is shorter. If a request is refused, the operator will say why, unless the law forbids that.
15. Changes to this policy
The operator may update this page and change the date at the top. If you keep using the service after the new policy is posted, the new policy applies to later use. A material change may also be announced in the server that hosts the bot when that is practical.
16. Contact
The bot operator and admin is ₳ncint₳narchist. Privacy questions go to havejack@gmail.com. You can also use the Discord server that runs this bot.
Developed and Maintained by ₳ncint₳narchist