Privacy Policy
1. Who we are
“Blazie Security”, “we”, “us”, and “our” refer to the operator of the Blazie Security Discord bot and the website at blaziesecurity.com. Contact options are listed on the Website and official support Discord.
2. Scope
This Policy covers data processed through:
- The Discord bot (commands, moderation, security features, tickets, XP, feeds, logs);
- The Website and any control panel / dashboard;
- Related support communications you send us.
Discord also processes data under Discord’s own Privacy Policy when you use Discord.
3. Information we process
| Category | Examples | Why |
|---|---|---|
| Discord identifiers | User IDs, server (guild) IDs, channel IDs, role IDs, message IDs | Operate features, apply settings, moderate, log actions |
| Server configuration | Feature toggles, thresholds, channel mappings, automod lists, tracked games | Remember your setup across restarts |
| Moderation records | Warns/strikes, case notes, evidence metadata, ticket transcripts, action logs | Staff tools, accountability, abuse response |
| Message content (limited) | Content of messages flagged by AutoMod or included in ticket transcripts / case evidence | Enforcement, tickets, documentation |
| XP / engagement data | XP totals, levels, leaderboard stats, voice activity metrics | Leveling and rewards features |
| Website / panel data | If OAuth is enabled: Discord user id, username, avatar, guild list, session data | Authenticate admins and show authorized servers |
| Technical logs | IP addresses and browser data for Website access; application error logs on our servers | Security, debugging, abuse prevention |
We do not intentionally collect special categories of personal data (e.g. health data). Please do not submit sensitive personal information through tickets or case files unless necessary for your server’s moderation purposes.
4. How we use information
- Provide, maintain, and improve Bot features;
- Apply security and AutoMod rules you configure;
- Generate logs, transcripts, and staff tools;
- Authenticate Website/control panel users (when enabled);
- Prevent abuse, fraud, and attacks against the Service;
- Comply with law and enforce our Terms.
5. Legal bases (EEA/UK where applicable)
Where GDPR-style rules apply, we rely on: performance of a service requested by server admins; legitimate interests (security, abuse prevention, service improvement); and consent where required (e.g. certain cookies or optional integrations).
5a. GDPR compliance details (EEA / UK)
Where the EU General Data Protection Regulation (GDPR) or UK GDPR applies, we provide the following additional information.
Roles
- Server administrators often determine the purposes of moderation logging, ticket content, and case evidence in their Discord servers and may act as independent controllers for that community data.
- Blazie Security processes Discord identifiers and configuration data to provide the hosted Bot and Website. For Website accounts and our own server logs, we act as a controller.
Lawful bases we rely on
- Art. 6(1)(b) — performance of a contract / requested service (providing Bot features you invite and configure);
- Art. 6(1)(f) — legitimate interests (securing our infrastructure, preventing abuse, improving reliability, fraud prevention) balanced against user rights;
- Art. 6(1)(c) — legal obligation where disclosure or retention is required by law;
- Art. 6(1)(a) — consent, where we optionally rely on it (e.g. non-essential cookies if introduced).
Your GDPR rights
- Access (Art. 15)
- Rectification (Art. 16)
- Erasure (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection (Art. 21), including to processing based on legitimate interests
- Withdrawal of consent where processing is consent-based
- Complaint to a supervisory authority in your EU/UK country of residence
To exercise rights regarding data we control, contact us with your Discord user ID and a description of the request. For message content or cases stored because a server admin configured those features, we may direct you to that server’s administrators or coordinate with them.
Data minimization & security
We aim to process only data needed for Bot operation. Security measures include restricted server access, least-privilege practices, and protection of configuration storage on our dedicated infrastructure.
International transfers
If personal data is transferred outside the EEA/UK, we use appropriate safeguards recognized under GDPR (such as Standard Contractual Clauses) where required, or rely on other lawful transfer mechanisms.
Processors
Hosting and infrastructure providers that process data on our behalf are bound by contractual terms requiring appropriate protection of personal data.
Retention summary (GDPR)
- Guild configuration: while the Bot remains in the server, then deleted or anonymized within a reasonable period after removal (subject to backups);
- Moderation/ticket artifacts: until deleted by staff tools, server removal cleanup, or scheduled retention;
- Website/security logs: limited diagnostic windows unless needed for ongoing investigations.
6. Sharing
We do not sell your personal information. We may share data with:
- Infrastructure providers (hosting, storage, networking) under contract;
- Discord as required to operate a Discord bot;
- Service providers that power optional features (e.g. AI APIs if you use those commands);
- Authorities when required by law or to protect rights and safety;
- Server staff — moderation data is visible to administrators of that server according to how the Bot is configured.
7. Retention
We retain configuration and operational data for as long as the Bot remains in a server and as needed to operate the Service. After the Bot is removed, data may remain in backups for a limited period before deletion. Ticket transcripts, cases, and strikes may persist until deleted by server configuration, staff action, or our retention schedule. Website logs are kept for a limited security/diagnostic window.
8. Security
We use reasonable technical and organizational measures to protect data on our dedicated servers (access controls, least-privilege practices, and secure configuration). No method of transmission or storage is 100% secure.
9. International transfers
Data may be processed in the country where our servers or providers are located. If transfers from the EEA/UK occur, we will use appropriate safeguards as required by law.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, or export personal data, or object to certain processing. To exercise rights related to Bot data in a Discord server, contact that server’s administrators first (they control much of the moderation content). You may also contact us via Website support channels. We may need to verify your identity and Discord user ID.
11. Children
The Service is not directed to children under 13 (or the minimum age required by Discord in your region). Do not use the Service if you do not meet Discord’s age requirements.
12. Cookies & Website analytics
The Website may use essential cookies for session/security if login is enabled. If we add analytics cookies, we will update this Policy and provide choices where required.
13. Controller vs. server admin roles
For many moderation features, server administrators decide what to log, which channels to use, and what evidence to store. In those cases, administrators may act as independent controllers of member data for their community. We process that data to provide the Bot features they request.
14. Changes
We may update this Policy by posting a new version on the Website with a revised effective date. Material changes will be highlighted when practical.
15. Contact
Privacy questions: contact us through blaziesecurity.com or the official support Discord linked on the Website.