Legal
Privacy policy
Last updated 19 September 2026
This policy explains what Sweet (the Discord bot and this dashboard) stores, why, for how long, and how server administrators and members can control it. We collect the minimum needed to provide the features a server turns on.
01Who operates the service
Sweet is operated by the individual or team that runs this instance (the “operator”). The operator is the data controller for everything described here. The operator's contact is listed in the bot's Discord profile and in the support server.
02Data we process
- Identifiers. Discord user, server, channel, role and message IDs. These are needed to run every feature.
- Configuration. Settings chosen by server administrators (prefix, log channels, protections, feature toggles, panels).
- Activity counters. Aggregated message counts, voice minutes, reactions, joins and leaves used for analytics, leveling and leaderboards. Counters are stored per hour and per day, not per message.
- Moderation records. Warnings, cases, incidents, ban appeals, ticket metadata and ticket transcripts, created when staff use those features.
- Message logging. If a server enables message logging, message content and attachment links are stored encrypted so deleted and edited messages can be shown to that server's staff. Only servers that turn this on store content.
- Dashboard sign-in. When you sign in with Discord we receive your user ID, username, avatar and the list of servers you are in. The access token is kept in an encrypted cookie on your device and on our server only for the duration of your session.
03What we do not do
We do not sell data, show advertising, build profiles for third parties, or read direct messages. The bot only sees messages in servers it has been invited to and only stores content where a server administrator has enabled logging.
04Legal basis
Processing is based on the legitimate interest of server administrators in moderating and running their community, and on the consent given when an administrator invites the bot and enables features. Analytics can be disabled per server at any time.
05Retention
- Logged message content: the retention configured by the server (default 60 days), then deleted automatically.
- Analytics counters: 60 days on the free tier, up to 3 years for premium servers.
- Moderation cases, appeals and transcripts: until the server deletes them or removes the bot.
- Everything belonging to a server is deleted within 30 days after the bot is removed from that server.
06Your rights
You can ask the operator to show or erase data about you. Server administrators can erase a member's analytics with /analytics settings action:erase-user, exclude channels and roles from counting, and disable analytics or logging entirely. Residents of the EU, UK, California and similar jurisdictions have statutory rights of access, rectification, erasure and objection which we honour on request.
07Security
Data is stored in a PostgreSQL database with access limited to the operator. Sensitive fields such as logged message content and passwords for temporary voice channels are encrypted at rest. The dashboard talks to the bot over an authenticated API and never exposes tokens to the browser.
08Third parties
The service relies on Discord to operate at all. TypeSafe AI. Their own privacy policies apply to what they receive. No data is sold, and nothing is shared with anyone else.
09AI checks
Sweet uses TypeSafe AI to judge a small amount of text that the built-in rules cannot read on their own, such as a scam written in fresh wording or a slur spelled to dodge a word list. This is part of how the service works and is active in every server; there is no per-server switch.
Sweet sends the following, and receives back a category and a probability:
- AutoMod: the text of a message, but only when it already looks worth checking — it contains a link, several mentions, comes from a recently joined member, or is long. Short, ordinary chat is never sent.
- Autoresponders: the text of a message, only when the server has responders set to “intent” mode and nothing matched literally.
- Ban appeals: the answers written in an appeal form, so staff get a suggested reading. The decision stays with staff.
- Anti-raid: a joining account's username, display name, account age and whether it has an avatar.
- Cohort detection: the same four details for a group of accounts that joined within the last few hours, judged together to tell a coordinated group apart from real people arriving after a mention somewhere.
- Before a punishment: the messages that caused it, re-read so an automatic timeout, kick or ban that looks misjudged is held for staff instead of applied.
- Account takeover: for a long-standing member only, a sample of how they normally write here alongside the message in question, to notice when an account stops sounding like its owner.
- Administrative actions: the kind of action taken, what it was taken on, and how long the person or bot doing it has been in the server. No member data.
- Names: a nickname or a voice channel name, on its own.
- Tickets and answers: what somebody wrote when opening a ticket or asking a question, alongside your own written answers, so the matching one can be shown back unchanged.
- Help: a question typed at the help command, with the names and descriptions of the bot's own commands.
When a raid is confirmed, Sweet also stores a fingerprint of the attack's shape — the naming formula, the account-age band and whether avatars were set — and matches it against other servers that use Sweet, so an attack only has to be recognised once. The fingerprint is a one-way hash and contains no user IDs, no names and nothing identifying the server it came from; member lists are never shared between servers.
Discord user IDs, message IDs, channel names and server identifiers are not sent. Attachments, images and voice are never sent. Results are cached briefly so the same text is not sent twice, and Sweet stores only the verdict it acted on, not a copy of the text. If the service is slow or unavailable, the check is skipped and the ordinary rules apply, so nobody is punished because of it. TypeSafe receives the text only to return that judgement.
10Children
Discord requires users to be at least 13 years old (or older where local law requires). Sweet is not directed at children below Discord's minimum age and we do not knowingly store their data.
11Changes
We will update this page when the policy changes and adjust the “last updated” date. Material changes are announced in the support server.
Questions? Reach the operators of Sweet in the support server or through the contact listed in the bot's Discord profile.