1. What the Service is
The Service consists of (a) a Discord application that server administrators add to their Discord server to run a support ticket system with an AI assistant, and (b) a web dashboard at tickets.securitybot.gg where authorised server staff review tickets, configure the Bot, and view analytics. Each Discord server ("guild") that installs the Bot is operated by its own administrators, who decide how the Bot is configured and who counts as support staff.
2. Data we collect
We collect only the data needed to run tickets, and only in the places listed below.
| Data | When it is collected | Why |
|---|---|---|
| Discord user ID and username | When you open a ticket, write inside a ticket thread, rate a ticket, submit a suggestion or feedback, act as staff on a ticket, or sign in to the dashboard | To link tickets, messages, ratings, suggestions and feedback to the person who created them and to show staff who they are helping |
| Ticket intake form answers | When you open a ticket and fill in the form the server configured (for example subject and description) | To describe the issue to the AI assistant and to staff |
| Messages inside ticket threads | Whenever anyone (the ticket creator, staff, or the Bot) posts in a private ticket thread the Bot created | To let the AI assistant respond, to give staff the full conversation when they take over, and to keep a transcript the server can review |
| Image attachment links in ticket threads | When you attach an image to a ticket message | So the AI assistant can look at screenshots you share. Only the Discord link is stored, not a copy of the file |
| Ticket metadata | Automatically while a ticket exists | Status, priority, category, thread ID, timestamps, which staff member claimed it, and AI confidence scores, so tickets can be routed and measured |
| Satisfaction ratings, suggestions, feedback | When you choose to submit them | To measure support quality and collect community input for the server |
| Staff role membership | At the moment a staff-only action is attempted | To check whether you hold a support or admin role configured by the server. Role lists are not stored |
| AI run telemetry | Each time the AI assistant runs | Latency, token counts, tool calls, confidence and outcome, plus a short staff-facing note. Used for reliability and analytics shown to server staff |
| Dashboard sign-in data | When staff sign in with Discord OAuth2 | Your Discord user ID, username, avatar, the list of servers you belong to, and the OAuth access and refresh tokens Discord issues, so we can verify which servers you may manage |
What we do not collect: the Bot does not read, store, or process messages outside ticket threads it created; it does not collect presence or activity data; it does not collect direct messages; and it does not collect payment information.
3. How we use data
- To create and manage tickets and post the AI assistant's replies in your ticket thread.
- To hand the conversation to human staff with full context when the AI cannot help or you ask for a person.
- To show server staff transcripts, ticket status, ratings, suggestions, feedback, and analytics in the dashboard.
- To let server administrators configure categories, knowledge-base documents, staff roles, and integrations.
- To monitor reliability of the AI assistant (errors, latency, escalations) and improve the Service's configuration.
We do not sell personal data, and we do not use it for advertising.
4. AI processing
The AI assistant is powered by third-party large language models accessed through OpenRouter (currently OpenAI models). When you write in a ticket thread, the content of that thread (intake answers, prior messages, image links, and the server's knowledge-base documents) is sent to the model provider so it can generate a reply for that ticket. Suggestions and feedback you submit are likewise sent to generate a summary and categorisation.
Your data is never used to train or fine-tune AI models, neither by us nor, under the terms we use, by the model provider. Model requests are made in a mode that does not retain inputs for training. The AI assistant can be switched off for any ticket by server staff, and any server administrator can disable it entirely.
6. Where and how long data is stored
Data is stored in a PostgreSQL database on servers operated by our hosting provider, protected by access controls and encryption in transit. Secrets that servers configure for their own integrations are encrypted at rest.
| Data | Retention |
|---|---|
| Tickets, transcripts, ratings, AI telemetry | Kept while the ticket record exists. Deleted when the ticket is deleted by staff, when the server requests deletion, or when the Bot is removed from the server and deletion is requested. |
| Suggestions and feedback | Kept until deleted by server staff or the server requests deletion. |
| Server configuration and knowledge-base documents | Kept until the server administrator deletes them or removes the Bot and requests deletion. |
| Dashboard sessions and OAuth tokens | Kept while you are signed in; deleted when you sign out or the session expires. |
| Server logs | Operational logs are kept for up to 30 days for troubleshooting. |
7. Your choices and rights
- Opt out of message processing. The Bot only reads messages inside ticket threads you chose to open. Do not open a ticket, or ask staff to close it, and nothing further is processed.
- Access and deletion. You can ask the server's staff to delete your ticket, or contact us directly to request a copy or deletion of the data we hold about your Discord account. We respond within 30 days.
- Server administrators can delete tickets, documents, suggestions, and feedback from the dashboard at any time, and can request full deletion of all data for their server by contacting us.
- Dashboard. Signing out ends your session and removes the stored OAuth tokens.
If you are in the EU/EEA, UK, or another region with data-protection rights, you may also have rights to restrict or object to processing and to lodge a complaint with your supervisory authority.
8. Children
The Service is intended for users who meet Discord's minimum age requirement (13, or older where local law requires). We do not knowingly collect data from anyone below that age; if you believe we have, contact us and we will delete it.
9. Changes to this policy
We may update this policy as the Service evolves. The date at the top shows the latest revision. Material changes are announced in the dashboard.
10. Contact
For privacy questions, access or deletion requests, email [email protected].