Legal
Your data
Last updated
The plain-English version of what we hold and how to get rid of it. The privacy policy is the formal document; this page is the one that answers the question you probably came with.
The fastest answers
- Remove everything for a server: kick the bot. Its data for that server is deleted when it leaves — no form, no waiting period.
- Remove your ticket transcripts: they expire on their own after 18 days, and a server admin can delete any stored copy immediately from the dashboard.
- Remove your personal music library: delete your favourites and playlists from the SeshTunes dashboard.
- Anything else: ask us — details below.
What's actually stored
| What | Detail | Kept for |
|---|---|---|
| Server settings | Everything you configure — ticket categories, automod thresholds, welcome messages, level-up channels. Keyed to your server's ID. | Until changed, or until the bot leaves the server |
| Ticket metadata | Who opened a ticket, its category, when it opened and closed, who handled it. No message content. | Until the bot leaves the server |
| Ticket transcripts | The message content of a closed ticket, only if your server enabled stored archives. Always DM'd to the participants regardless. | 18 days maximum, then deleted automatically |
| Activity counters | Message and voice-minute totals used for levels, streaks and achievements. Counts, not message content. | Until wiped by an admin, or the bot leaves |
| Saved roles | Role IDs held so they can be returned if you rejoin. Administrator roles are never stored. | Until restored, purged by an admin, or the bot leaves |
| Music library | SeshTunes favourites, playlists and listening history tied to your Discord ID. | Until you delete them |
| Security logs | IP addresses and request patterns recorded by the site's protection layer to block attacks and abuse. | Kept only as long as needed to investigate abuse |
| Payment records | Only if you chose to support us. Stripe handles the payment; what reaches us is the amount, date, country and the email you gave Stripe — never your card. | As long as tax and accounting rules require |
What we never store
- Your Discord password or your card details — we never see them. Card numbers go to Stripe and never touch our servers. The one exception to “no email”: if you support us, Stripe passes on the email address you gave them, which is not your Discord one unless you make it so.
- General channel messages. They're read to run moderation and counted for XP, then discarded.
- Voice audio. Nothing is recorded, at any point.
- Message content inside server backups — those hold configuration only.
Your rights
If you're in the UK or EU these come from the UK GDPR and GDPR; in California, from the CCPA as amended by the CPRA. We apply them to everyone regardless of where you live, because splitting people into tiers of privacy is not a thing we want to build.
- Know what's held
- Ask for a copy of anything associated with your Discord ID or your server.
- Have it corrected
- If something stored about you is wrong, tell us and we'll fix it.
- Have it deleted
- Ask for erasure. For a whole server, removing the bot does this automatically and immediately.
- Object or restrict
- Ask us to stop a particular use of your data while a question is resolved.
- Opt out of 'sale' or 'sharing'
- We don't sell or share personal information, and never have. The right exists anyway and we'll confirm it in writing on request.
- Not be treated differently
- Exercising any of these changes nothing about the service you get.
Making a request
Message the team in The Sesh Shed, or email [email protected]. Include your Discord user ID, and the server ID if the request is about a whole server, so we can find the right records.
We'll respond within 30 days, which is what both GDPR and the CCPA require. We may ask you to confirm you control the Discord account in question — not to be awkward, but because handing someone else's data to whoever asks would be the actual privacy failure.
If you're unhappy with how we handle it, you can complain to your data protection authority. In the UK that's the ICO.