Legal
Privacy Policy
Last updated: 3 September 2026
This policy explains what data the Suzune Discord bot ("Suzune", "the bot", "we") collects, why, and what you can do about it. It applies to every Discord server where Suzune is installed. By adding Suzune to a server, the server owner agrees to this policy on behalf of that server.
The short version
Suzune does not store your messages. Automod inspects message content in memory to make a decision and then discards it. Ticket transcripts are generated and delivered to Discord as a file — never written to our database.
What we do store is configuration and moderation records: Discord IDs, your settings, and the case history your moderators create.
What we store
Configuration data
Settings you choose through the bot's commands and panels, stored per server:
- Discord server ID
- Channel IDs (log channels, alert channels, welcome channels, ticket categories)
- Role IDs (moderator roles, mute role, quarantine role, autoroles, level rewards, exempt roles)
- Feature toggles, thresholds, and time windows for anti-nuke, anti-raid, automod, logging, leveling, tickets, welcome, /appwatch, and lockdown
- Custom message templates you write (welcome messages, ticket prompts)
Moderation records
When a moderator takes action, we store a case record:
- Server ID, sequential case number, action type
- Target user ID and moderator user ID
- The reason text your moderator types
- Timestamps and expiry times
Note: reason fields are free text written by your moderators. Anything typed there is stored. Advise your staff not to put sensitive personal information in reasons.
Feature data
- Anti-nuke whitelist — trusted user and role IDs, plus who added them, and their per-action caps
- Anti-nuke/lockdown snapshots — transactional restore data for reverted channels, roles, emojis, stickers and lockdown overwrites, held with a short TTL
- /appwatch — installed-app metadata (app ID, name, scopes, installer, install time), risk scores, and inventory-report history
- Invite tracking — which member joined via which inviter and invite code, join timestamp, whether they left
- Leveling — accumulated XP per user per server
- Reaction roles / autoroles — message ID, emoji, and role ID mappings
- Tickets — ticket number, channel ID, opener ID, claimer ID, status, timestamps, and the reason text the opener provides
- Action-window counters — rolling counts used to detect bursts, periodically flushed to the database so a restart doesn't reset an attacker's window
What we never store
- Message content
- Ticket transcript contents
- Voice audio
- Email addresses, real names, IP addresses, or payment information
- Anything about users in servers where Suzune is not installed
Why we store it
Solely to make the bot work. Configuration has to persist across restarts; case history has to persist to be queryable; invite and XP counts have to persist to be counts; anti-nuke snapshots have to persist for long enough to restore what was deleted.
We do not sell, rent, or share your data with third parties. We do not use it for advertising or profiling. We do not train machine learning models on it.
Where it's stored
Data is held in a PostgreSQL database. Access is restricted to the bot operator and used only for operating and debugging the service.
We keep aggregate, non-identifying counters (for example, the total number of anti-nuke events across all servers) for operational statistics. These cannot be traced back to individuals.
How long we keep it
- While Suzune is in your server — retained so the bot functions.
- Short-lived caches — anti-nuke restore snapshots and deleted-image caches expire automatically (minutes, not days) and are never written to the database.
- After Suzune is removed — data associated with that server is no longer used, and is deleted on request (see below) or during periodic cleanup of inactive servers.
- On request — deleted promptly, see below.
Your rights
You may request access to, correction of, or deletion of your data at any time. If you are in the EU or UK, these rights are granted to you under the GDPR, and this section is how you exercise them.
Server owners can request deletion of all data for a server they own. Individual users can request deletion of their personal records (case history, XP, invite attribution, ticket records) from a given server.
Contact: contact@suzunebot.site, or the support server at discord.gg/kBtwmBsr6B.
Please include the relevant server ID and your Discord user ID so we can locate the records. We respond within 30 days. We may need to verify you control the account or server in question.
One limitation, stated plainly: deleting a moderation case removes our copy, but if your server has mod-log channels enabled, a copy of that action may already exist as a message in your own Discord channels. We cannot delete messages sitting in your server's history — that's yours to manage.
Children
Discord requires users to be at least 13, or older where local law sets a higher age. Suzune is not directed at children under 13 and we do not knowingly store their data. If you believe we have, contact us and we'll delete it.
Security
Access to the database is restricted and credentials are never committed to source control. That said, no system is perfectly secure. If a breach affects your data, we will notify affected server owners through the support server and, where legally required, the relevant supervisory authority.
Changes
We may update this policy. Material changes will be announced in the support server, and the "last updated" date above will change. Continued use after a change means you accept it.
Contact
Email: contact@suzunebot.site
Support server: discord.gg/kBtwmBsr6B