Xiribot is committed to protecting your privacy. This policy outlines how the Bot collects, processes, and stores data in Discord servers.
1. Data We Collect & Store
- Moderator Log Cache: For servers using audit features, the bot temporarily caches messages sent by moderators (users with the "Manage Messages" permission) in order to log self-edits and deletions.
- Resolution Room Transcripts: In servers utilizing the "Resolution Room" or temporary support ticket channel system, the bot logs all message content, attachments, and user IDs sent in active resolution channels. This data is stored to allow server administrators and members with access to view chat transcripts after a ticket is closed.
- Server Configuration Data: We store server IDs, channel IDs, configuration settings, and authorized role IDs to perform requested operations.
2. Message Content & AI Translation Data Usage
Our auto-translation feature inspects message content containing foreign languages to translate them into English. This processing is performed using Google's Gemini models via the official GenAI API.
AI Model Training & Privacy Failsafe: Depending on the server's billing configuration, API prompts are processed on either Google's paid or free tier. While the paid tier guarantees data privacy, the free tier may involve Google using prompt data for model training. For complete details, see the Google Gemini API Terms of Service & Data Usage Policy. To strictly enforce user privacy, free-tier translation is only permitted on development servers with fewer than 20 members. If a server exceeds 20 members, the translation pipeline is completely severed—no message content is captured, processed, or transmitted to the GenAI API—until a verified, paid-tier API key is configured by an administrator.
3. Data Retention
- Server Configuration Data: Stored indefinitely to maintain bot functionality, but is permanently purged within 30 days if the Bot is kicked from a server.
- Moderator Log Cache: Temporary message caches used to track edits and deletions are automatically and permanently deleted from our database every 14 days.
- Resolution Room Transcripts: Logged ticket transcripts are retained to allow server administrators and authorized members to review historical records. These are stored until either the server administrator explicitly deletes the transcript via the control panel, or for a maximum hard cap of 365 days, after which they are permanently purged.
To exclude yourself from Xiribot replies/transcripts and request deletion of all your stored data, please log in with your Discord account to verify your identity.
4. Data Security & Encryption
We prioritize the security of your stored data. To prevent unauthorized access, data leaks, or ciphertext tampering, all sensitive information stored in our databases is protected using authenticated encryption:
- Transcripts & Caches: Stored message content, attachment metadata, and message edit histories are encrypted at rest using secure AES-256-GCM encryption.
- API Credentials: Custom Gemini API keys provided by server administrators are encrypted using AES-256-GCM before being written to disk, ensuring both confidentiality and data integrity.
5. Your Rights (Right to be Forgotten)
If you choose to opt out, you have the right to request deletion of all historical logs and cached messages containing your user identification. Using the control panel above triggers a 30-day grace period deletion schedule, after which all database records containing your message logs will be permanently deleted.
6. Contact Us
For any inquiries regarding this Privacy Policy, to submit a manual data deletion request, or to appeal data handling practices, please contact us directly at [email protected].