Skip to content
Home Privacy Policy
LEGAL DISCLOSURE & KVKK / GDPR

Privacy Policy (Privacy Policy)

Last Updated: 1 October 2026

This policy explains what data VeyroBot collects, how it is used and stored, and your rights under KVKK (Turkish Personal Data Protection Law) and the GDPR.

1. Data Collected and Purposes

In line with Discord's Developer Terms of Service, the bot processes the data its features need to work. When you turn a feature off, it stops collecting new data. Server statistics (daily message and join counts) are not tied to any module and are always kept. Data processed:

  • Server (Guild) ID: To store guild-specific language, log channels, AutoMod, and music settings. The language chosen when the bot was added is also stored, for the channel and role names of setup templates; it is deleted 30 days after the bot is removed from the server.
  • User ID and Username: For moderation logs (Ban, Kick, Timeout, Warning, Case history) and Level (XP) systems.
  • Channel and Role IDs: For audit notifications, welcome greetings, and automated role assignments.
  • Staff Protection: While Staff Protection is on, we store which member holds which role; this index is deleted when protection is turned off. When a channel or role is deleted, its state at that moment (settings, permissions and role members) is recorded so it can be rebuilt. If that record is not tied to a protection incident, it is deleted within one hour. If it is, it is kept for 90 days together with the incident record (the ID of the member who acted and a summary of the actions). If a server admin reverts the bans from a Staff Protection incident, the Discord ID of each member being unbanned and the status of each step are kept with the incident record for up to 90 days, and deleted 30 days after the bot is removed from the server.
  • Server Backup: When an admin takes a backup or turns on the daily automatic backup, the server's name, roles (name, color, permissions, position), categories, channels, channel permissions and VeyroBot settings are recorded. If channel permissions are granted to specific members, those members' Discord IDs are included. Messages and who holds which role are not backed up. The latest 7 backups are kept for each server; the oldest is deleted when a new one is taken. Admins can delete backups from the panel at any time.
  • Feature data: Levels/XP, achievements, ticket and moderation records, suggestion texts sent to the suggestion system, and birthdays members enter themselves. Answers you give to application forms are also stored; they are visible only to that server's staff, in its review channel and dashboard. Feedback messages you send with /feedback are also stored; they are visible only to the bot developer, together with your username and server information.
  • Message content: Message text is processed only for these features, when they are turned on: deleted and edited message logs, ticket transcripts, the caps, emoji, line, repeat and spam filters, and Starboard. The blocked word, regex, invite, link and mass mention filters run on Discord's side as Discord's own AutoMod rules; VeyroBot only receives the violation notice Discord sends, to apply the punishment and record the case. AI chat only runs when you mention the bot or reply to one of its messages.
  • AI chat: AI chat is available only on Premium servers. When you mention the bot or reply to one of its messages, your message, your server display name, the server and channel name and your last 6 exchanges with the bot are sent to Google Gemini to generate a reply. Your Discord ID is not sent. Conversation context is stored, capped at the latest 500 messages per server; messages older than 90 days are deleted. For cost tracking we keep only per-server, per-day usage counts for 400 days; these records contain no message content or user identity. Server admins can turn the feature off.
  • Payments: Premium purchases are processed by Polar.sh; your card details never reach us. We only store subscription status, order number, product, validity period, billing country (to determine the refund period; the address is not stored) and which Discord account and server the subscription belongs to.
  • Ban appeals: If you appeal a server's ban, we store your Discord ID, your appeal text, the appeal status and, if given, the staff member's reason for rejecting it. If the server owner has enabled this setting, the reason for your ban is also shown to you on the appeal page. The record is deleted 180 days after the decision (or after submission if no decision is made), or 30 days after the bot is removed from the server. While the bot remains in the server, the appeal text and rejection reason are also removed from the notification sent to staff at the end of the same 180 days; if the bot is removed earlier, that message stays in Discord and only the server's staff can delete it. The appeal text is shown only to that server's staff.
  • Ban appeal index: If a server has turned on ban appeals, we keep only the server ID, your Discord ID and the date we noticed the ban so that your bans there can be shown to you on the appeal page; the ban reason is not stored in this index. The record is deleted immediately when the ban is lifted or the server turns appeals off, and within 30 days after the bot is removed from the server.
Strictly Non-Collected Data: Our bot does not monitor or log direct messages (DMs), never asks for passwords, and never sells or rents your data.

2. Data Retention and Security

All data is stored in a local SQLite database on the server where the bot runs. The database is backed up automatically every day and is never pushed to the code repository. Backups on the server are kept for at most 14 days, and encrypted backups stored off the server for at most 30 days. So that data can be restored even if the server is lost, a copy is transferred every day to the bot developer's computer, where only the most recent copy is kept. A record deleted from the database is removed from all backups within 30 days at the latest. The database and backups on the server are kept on an encrypted volume on disk. Only people who sign in with Discord and whose permissions on that server are verified can access the dashboard. Moderation and role actions taken from the dashboard are limited by your real Discord permissions; no one, including the bot developer, can bypass your server's role hierarchy through the dashboard.

We keep your purchase consent, the version of the documents shown at the moment of consent, the Premium activation record, and your refund or cancellation requests together with our reply for 3 years, as required by Article 20 of the Turkish Distance Contracts Regulation; these records are not deleted before that period ends and are deleted automatically once it does.

The web dashboard session is tied to a secure HTTP cookie and expires automatically after 7 days. The session is stored on our server and also contains an access token that Discord issues at login. The token carries only two scopes: "identify" (your Discord account details: ID, username, display name, avatar, profile banner and color, language preference, two-factor authentication status and account badges; your email address is not included) and "guilds" (the ID, name, icon and banner of the servers you are in, whether you own them, your permissions there and the server features). VeyroBot uses this token only to re-read your server list. The token is never sent to the browser, is not included in backups and is revoked with Discord when you log out.

No third-party analytics tool is used; page views are counted on our own server without cookies or identifiers. For security and debugging, the web server writes each request's IP address, browser information and referrer to a technical log, which is deleted automatically after about 15 days.

The site only uses functional storage: your language preference (the bot_dashboard_lang cookie, 1 year, also kept in browser storage), your theme (veyrobot_theme), the colors you recently used in the dashboard (veyro:embed-color-history) and a session-only entry (vbBlogTab) so the blog read counter does not count the same tab twice. Browser storage also remembers that the dashboard's one-time sign-in note was shown (veyro:liste-yeniden-giris-notu) and that you closed the setup wizard for a server so it does not open on its own again (veyro:sihirbaz-kapatildi, per server). The site itself uses no advertising or tracking cookies; if you play a YouTube video in a blog post, YouTube may set its own cookies.

To improve the product, we also keep aggregated server-level usage counts: when the bot was added to or removed from a server, how many times commands and modules were used, which setup wizard steps were completed, and which setup template was chosen in the wizard and how many settings were applied. These records contain no user IDs or message content and are deleted automatically after 90 days.

Permission-checked dashboard
Automatic Backup

3. Data Deletion Requests (Right to Be Forgotten)

Server admins or users can request permanent deletion of data about themselves or their server (warnings, logs, level records, AI chat history, etc.) via the contact form or the support server. Requests are handled within 30 days at the latest.

Data for a server is deleted automatically 30 days after the bot is removed from it; if the bot is added back within that time, nothing is deleted. You can request earlier deletion. Payment records and the server's Premium entitlement are not part of this deletion. Deletions cannot be undone.

4. Third-Party Services

VeyroBot utilizes the following third-party APIs:

  • Discord API: Core bot functionalities and OAuth2 authentication.
  • YouTube / yt-dlp: yt-dlp is used for music streaming. YouTube alerts use the YouTube API Services when needed. No user data is sent to YouTube. Google Privacy Policy: policies.google.com/privacy
  • Google Gemini AI: AI chat on Premium servers. In addition, the English jokes, advice and synopses returned by /joke, /advice, /anime and /manga are sent to Gemini's free tier to be translated into the server's language. These texts are third-party content and carry no user data; Google may use them to improve its products. Content sent is governed by Google's Privacy Policy.
  • Polar.sh: Processing Premium payments. Payment details go directly to Polar.sh.
  • Content and search services: Creator alerts (Twitch, Kick, YouTube, Reddit, Bluesky, RSS), search commands (Kitsu, JokeAPI, Advice Slip, PokéAPI, Dog CEO, GIPHY, TMDB, OpenWeather) and the emoji gallery's public emote catalog (7TV). Only alert and search queries are sent to these services; no user identity is shared.
  • Hosting and site services: The bot and database run on a Keyubu server in Turkey. The site serves its fonts, icons and libraries from its own server. In the dashboard and on leaderboards, avatars and server icons load from Discord, music covers in the dashboard load from YouTube and emoji gallery images load from 7TV; YouTube videos in blog posts do not load until you choose to play them; when played, they load from YouTube's privacy-enhanced mode (youtube-nocookie.com) and YouTube may set cookies. In these cases the service concerned can see your IP address. Email sent to support@veyrobot.xyz is forwarded through ImprovMX.

5. Your Rights and Contact

Under KVKK and GDPR you have the right to access, rectify and delete your personal data and to object to its processing. To exercise these rights, write to support@veyrobot.xyz or reach us on our support server.