Overview
This Privacy Policy explains how Bucky ("Bucky", "we", "our" or "us") collects, uses, stores and protects information when you use the Bucky Discord bot, dashboard and related services (together, the "Service"). We collect the minimum data required to operate the Service and we never sell it.
By adding Bucky to a server or signing in to the dashboard, you agree to the practices described here and in our Terms of Service and Cookie Policy.
Information we collect
We collect only what is needed to provide each feature. Application answers, ordinary message contents and direct messages are not stored: security detections record the metadata of what triggered them (for a blocked link, the domain only) rather than the message itself.
Support tickets are the exception. Messages sent inside a ticket, and the transcript generated when it is closed, are stored so staff can handle and review the request; they are deleted 48 hours after the ticket is closed. A transcript that has already been posted into a Discord channel stays there, because it is then a Discord message under Discord's own retention.
| Category | Examples | Why |
|---|---|---|
| Discord identifiers | User ID, Server (guild) ID, role & channel IDs | Associate settings and data with the right account and server |
| Security configuration | Module toggles, thresholds, punishment chains, ignore rules, SOC rules | Run and enforce your server's protection |
| Security events | Incident metadata, audit-log derived events, quarantine records including a cached username & avatar URL, snapshots of server structure | Detection, recovery and the audit trail |
| Purchases | Which premium plan you hold, when it started and whether the monthly cache has been claimed; which Security Boosts you own, which server each one is applied to, when it was assigned and when it ends. Received from Discord; we never see your payment details | Give you what you bought, keep the monthly cache honest, and apply a boost to the server you chose |
| Economy & gameplay | Balances, inventory, level and progression, organisation membership and contribution | Power the economy, the arcade and your organisation |
| Support tickets | Ticket messages and transcripts, with the display name of each author | Handle your request and let staff review how it was handled |
| Giveaways | Entries, and the display name of each drawn winner | Draw winners and show who won |
| Reminders | Reminder text and scheduled time | Deliver reminders you create |
| Technical | Session token, IP address at sign-in, basic request logs | Authentication, security and abuse prevention |
How we use your information
Your data is used solely to operate and improve the Service: authenticating dashboard access, enforcing security settings, powering the economy and story systems, delivering reminders, and diagnosing problems. We do not sell, rent or monetise your data, and we do not use it for advertising.
Lawful basis for processing
Where the GDPR or similar laws apply, we rely on: performance of a contract (to provide features you request), legitimate interests (to keep servers secure and prevent abuse), and consent (for optional cookies, withdrawable at any time).
Data retention
Data that expires on a fixed schedule is deleted automatically:
| Data | Retention |
|---|---|
| Premium plan and cache state | While the plan runs, and for as long afterwards as we need it to settle claims and answer questions about a purchase |
| Security incidents, audit log, rule executions, risk history, closed quarantine records and finished recovery jobs | 14 days. Up to 365 days for a server that holds an active Security Boost: the server's administrators choose the period, and it is shown in the Security Center. When a boost ends the server keeps the longer period for 7 days and then returns to 14 days, at which point older data is deleted |
| Security snapshots (server structure) | The newest 10 per server (25 with a Security Boost) and none older than the server's retention period, except the one snapshot the server has chosen as its restore point |
| Security Boost records | While the boost runs and for as long afterwards as we need them to settle claims and answer questions about a purchase |
| Ticket messages and transcripts | 48 hours after the ticket is closed |
| Giveaway entries | 72 hours after the giveaway ends or is cancelled |
Everything else is kept for as long as it is needed to provide the Service. Configuration, economy and progression data have no fixed expiry, because deleting them would reset your server or your account. Security snapshots are kept to support recovery and you can delete them from the dashboard at any time. If Bucky is removed from a server, associated configuration and security data may be deleted after a reasonable period unless earlier deletion is requested.
Sharing & sub-processors
We do not share personal data with third parties for their own purposes. We rely on a small number of processors to run the Service:
- Discord - the platform the Service operates on; governed by Discord's own Privacy Policy.
- Google Translate - receives the text you ask Bucky to translate, and only then; it is the primary translation provider.
- MyMemory - receives the same text as a fallback when Google Translate does not answer; governed by its own privacy policy.
- Discord - also the seller for every paid plan. Discord takes the payment and tells us which plan you hold; your payment details stay with Discord and never reach us.
- Hosting & database providers - to store configuration and run the bot and dashboard.
We may disclose information if required by law or to protect the rights, safety and security of our users and the Service.
Your rights
Depending on your location, you may have the right to access, correct, export or delete your data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, contact us via the Contact page with your Discord User ID. We respond to verified requests within a reasonable timeframe.
Security
We use industry-standard measures to protect your data, including encrypted transport, scoped access tokens and least-privilege access to production systems. No method of transmission or storage is completely secure, but we work to protect your information and to promptly address any issues.
Children's privacy
The Service is not directed to anyone under the minimum age required to use Discord in their country (at least 13). We do not knowingly collect data from children below that age. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected here with an updated date, and where appropriate we will provide additional notice.
Contact
Questions about privacy or a data request? Reach us through the Contact page or our Discord support server.