Privacy Policy
Summary
- SecureKy does not sell personal data or share data with ad networks.
- We only store what is needed for the bot, dashboard, and enabled modules per server.
- No tracking or ad cookies; on the marketing site we count cookieless anonymous page views (no IP, no cookies, DNT respected).
- Erasure and privacy requests: privacy@secureky.eu — handled within 30 days.
- Terms of Use v3.0 — see /terms (economy, Twitch linking, premium, shutdown policy).
- Anti-scam OCR runs locally on our server; AI-moderator may optionally use a cloud LLM (see below).
Why we process data
| Data | Purpose |
|---|---|
| Discord user ID + name | Dashboard, mod log, levels, tickets, applications |
| Server configuration | Modules know which channels, roles, and templates to use |
| Warnings + mod log | Moderation history (DB warnings + Discord log channel) |
| Leveling XP | Levels, leaderboards, global levels (optional) |
| Economy balance | /daily, /balance, /coinflip (optional per server) |
| Panel login history | Security and abuse detection |
| Anti-scam image hashes | Recognition of staff-approved scam screenshots |
| Global ban / fleet data | Cross-server abuse prevention |
Retention periods
| Data type | Period |
|---|---|
| Server config + module data | While the bot is in the server + 30 days after leave (configurable 7–365 days) |
| Premium servers (active subscription) | No automatic purge while premium is active |
| Warnings + tickets | While the server exists or until guild purge |
| Dashboard session | 24 hours after login (or until logout) |
| Panel login history | 12 months, then automatically deleted |
| Anti-scam hashes (approved) | Max ~50,000; oldest clean hashes pruned |
| Twitch link records | Until guild purge; link codes 10 minutes |
| Global ban / alt-links / fleet | Kept longer for security; reviewed on request |
| Module metrics | 30 days |
Sub-processors
| Party | Purpose | Data sent |
|---|---|---|
| Discord Inc. (US) | OAuth, Bot API | User ID, server ID, messages for active modules |
| EU hosting (Germany) | Bot + dashboard | All stored data on EU VPS |
| Bunny CDN | Static assets, TLS | Standard traffic logs (no tracking configured by us) |
| YouTube (Google) | Video alerts | Public channel IDs via RSS only |
| TikTok / optional RapidAPI | Live/video alerts | Public usernames only |
| Twitch (Amazon) | Alerts, IRC chatbot, analytics | Public channel data; optional Twitch↔Discord link |
| OpenRouter (optional) | AI-moderator cloud backend | Message/OCR text when module is configured that way |
| Hugging Face | Local AI model download | No ongoing user data to HF at inference |
| ip-api.com | Login geo (dashboard) | IP on login (cached 7 days, non-commercial) |
Who we are
SecureKy is a modular Discord bot with web dashboard (panel.secureky.eu), operated by Kylian's Car Service (sole proprietorship, trading as Kylian's Hosting Service), based in the Netherlands.
The shared bot and dashboard are mostly free; premium and custom-bot services are optional paid offerings. For platform login and bot infrastructure we are the data controller under the GDPR.
Server owners who invite the bot are often controllers for their members' data; SecureKy then provides tooling/configuration as processor.
Contact
Privacy requests (access, erasure, objection): privacy@secureky.eu — formal channel, response within 30 days.
Security reports: security@secureky.eu (see also /.well-known/security.txt).
Quick questions: our Discord server (footer link) — no guaranteed response time.
General contact: contact@secureky.eu or /contact on the marketing site.
Discord user data
When signing in via Discord OAuth (scopes: identify and guilds): Discord user ID, username, avatar URL, and the list of servers you belong to. We do not request email via OAuth and never see your Discord password.
Dashboard access to server settings is filtered to servers where you have admin rights; the OAuth guilds scope provides the full guild list for that filtering.
Server-specific data
Per Discord server we may store: server ID and name, module settings, warnings, leveling XP, economy balance, tickets, custom commands (max 25), stream goals (manually updated), application answers, and optional Twitch links.
The logging module posts mod events (joins, bans, message deletes, etc.) to a channel you choose; warnings are also stored in the guild database.
We do not have a suggestions module; that data is not processed.
Anti-scam (local OCR)
The anti-scam module scans text and images with local Tesseract OCR (eng+nld) on our server. Images are not sent to Google, OpenAI, or other external OCR services.
On detection we store a SHA-256 hash and short OCR snippet after manual staff approval; no image copy in our database. Review may use Discord CDN for the team.
We do not use external domain blacklist APIs (such as Sinking Yachts); only built-in patterns and staff-approved hashes.
AI-moderator (separate from anti-scam)
The optional AI-moderator module may use local sentiment per server or — if configured — send message text (including OCR text from images) to OpenRouter for classification. This is separate from the anti-scam OCR pipeline.
Web panel
On dashboard login we store login events: Discord user ID, IP address, browser (user-agent), success/failure, and estimated geo (via ip-api.com). Retention: 12 months.
Sessions: token in cookie and/or localStorage, maximum 24 hours after login. CSRF tokens protect changes.
No Google Analytics, ad networks, or third-party tracking on the panel.
Marketing site & analytics
On site.secureky.eu we count cookieless first-party page views: page path, optional referrer host, and date only — no cookies, no IP storage, Do Not Track is respected.
Static files and TLS may be served via Bunny CDN; standard server and traffic logs may exist at CDN/hosting.
The contact form processes name, email, and message only to answer your inquiry.
Data we do not store
No general chat log of entire servers.
No private message (DM) content, except application answers when the applications module uses DM mode.
No passwords, phone numbers, or payment card data in the bot. Premium billing is outside the bot.
No StreamElements/Streamlabs donation integration in the bot.
Twitch (optional)
With Twitch modules: live alerts, optional IRC chatbot, and Discord↔Twitch linking via temporary code (10 minutes, single-use). We do not store Twitch passwords; IRC uses a bot token in server configuration.
Twitch chat messages are not permanently stored. We do not offer per-viewer watch time, bits/sub/raid events, channel-point redemptions, or automatic unlink like extended Twitch economy bots.
Stream analytics aggregates public VOD statistics (~30 days) via the Twitch API — no per-viewer tracking.
Global ban, scam trap & platform data
For abuse prevention, global ban reports, alt-account links, scam-trap fleet events, and related security data may be kept platform-wide, even when a server's module data is purged.
On erasure requests we assess whether security records must remain for other servers' safety.
Security
HTTPS everywhere, CSRF on changes, API key and optional IP whitelist for the bot API, Discord OAuth for login, and per-server access control in the dashboard.
Data is stored on a European VPS (Germany). Database files (SQLite) are filesystem-protected; sensitive tokens are AES-encrypted where applicable.
We do not claim full-disk encryption in this document until verified internally (see infra checklist).
Your rights (GDPR)
You have rights to access, rectification, erasure, restriction, objection, and data portability where applicable.
Requests: privacy@secureky.eu (primary) or Discord. We handle manually within 30 days; no self-service export.
Data on a specific Discord server: also contact the server owner. Guild module erasure follows retention policy; global-ban/security data may remain longer.
Complaints: contact us first; you may also file with your supervisory authority (e.g. Autoriteit Persoonsgegevens in the Netherlands).
Cookies
Functional: session token (dashboard, 24 hours), CSRF token, language preference (cookie ~1 year).
No tracking, advertising, or third-party analytics cookies.
Minors
Our service is intended for users aged 16 and over (Dutch GDPR, Article 8). Discord requires at least 13+; for our EU processing we apply 16+.
The optional economy module includes entertainment with virtual coins (/coinflip) with no real monetary value. Server admins are advised to disable this for young audiences.
Suspected data from minors without consent: privacy@secureky.eu.
Changes
We may update this policy. Version and date are shown at the top. For material changes we inform users via the dashboard or Discord where appropriate.