EFFECTIVE 24 SEPTEMBER 2026
Privacy Policy
This policy describes how Kami (the “bot”), operated by nen-exploit, handles information when it is installed in a Discord server or used through Discord commands.
1. Information the bot receives
Discord provides the bot with information needed for enabled features. This can include server, channel, role, message, and user IDs; usernames and display names; roles and permissions; member join and account creation times; voice channel changes; reactions; and audit log events. In servers where message features are enabled, the bot reads message content to apply configured automod rules and handle voice ping messages. It does not keep a copy of every message or store deleted or edited message content in its server logs.
Users or server staff may also submit ticket reasons, reported message links and author IDs, warning reasons, reminders, timezones, builds, music searches, No Hesi profile names or links, suggestions, giveaway entries, squad names and membership, event plan details and votes, and configuration choices. The bot automatically saves daily recovery snapshots containing role and channel names, topics, settings, permission overwrites, and associated member IDs. A server owner can also save a snapshot manually. These snapshots do not contain message history.
2. How information is used
We use this information to respond to commands, run server features selected by administrators, deliver reminders, provide support tickets and giveaways, maintain configuration and recovery snapshots, diagnose failures, and protect servers from spam or destructive activity. Where applicable, processing is based on providing requested features, the legitimate interest in operating and securing the bot, and legal obligations. Server staff decide which optional server features to enable. Users choose whether to supply information for optional personal commands.
3. Information stored and retention
- Preferences and records: saved timezones, builds, No Hesi profile mappings, warnings, server settings, and reaction role settings remain until changed, removed, or deleted on a verified request. They do not have an automatic expiry.
- Tickets: ticket metadata, including the opener ID and reason, remains while open. Closed ticket metadata is removed after about 30 days when the bot next updates its local store. Ticket messages and archived channels remain on Discord until server staff remove them.
- Reminders: reminder text and user ID are removed after successful delivery or cancellation. A failed reminder stays available for the user to review or cancel.
- Suggestions and giveaways: suggestion voter IDs are removed when staff close a suggestion or after about 90 days on the next store update. Active giveaway entrant IDs are removed when the draw finishes. Suggestion text and giveaway posts remain in Discord until removed there.
- Insights and activity: optional insights use daily aggregate counts without message text or member IDs. Buckets older than 35 days are pruned when a new metric is recorded; an inactive server’s older buckets may remain until then or until a deletion request is handled. Recent command outcomes are kept only in memory until the bot restarts.
- Recovery snapshots: the latest 14 encrypted snapshots per server are retained. Older snapshots are replaced as new ones are saved.
- Squads and event plans: squad records include member IDs and expire from local storage about seven days after the squad ends. Event plans include voter IDs and choices; they are removed about 30 days after their latest proposed time. Cleanup runs when the operations store is next updated. Posts and scheduled events on Discord follow the server's own retention rules.
- Incident timeline: security alerts, bot moderation actions, ticket escalations, and snapshot activity can be retained locally for up to 30 days, capped at 200 records per server. Entries may include user IDs and moderation reasons. Staff can view warnings and open ticket counts through the member context action; the owner can view the incident timeline in the local dashboard.
4. Sharing and external services
Bot messages, ticket channels, and other posts are sent to Discord and are visible according to the server’s permissions. No Hesi lookups send the supplied player name, Steam ID, profile link, or a Discord username used as a fallback search to LittleMan Stats. Music features can send a track or playlist URL to Spotify and a search or video URL to YouTube. Those services handle requests under their own policies. We do not sell user data or use it for targeted advertising.
5. Security and access
Local bot settings and records are encrypted at rest with AES-256-GCM. The local owner dashboard is password protected and bound to the host computer. Access to server records is limited to the operator and features or staff views described above. No system is perfectly secure. Discord and external services maintain their own storage and security controls.
6. Access, correction, and deletion requests
To request access to, correction of, or deletion of data held by the bot, open a data request issue in the public legal repository or use the contact options on nen-exploit’s GitHub profile. Say which data or feature your request concerns. You may include a Discord user or server ID if you are comfortable posting it publicly; otherwise, ask the operator for a private way to provide it. Do not publish private message content, passwords, or tokens in a public issue. We may need to verify that you control the account or server before acting. We will remove data that is no longer needed for the bot’s features, subject to applicable law. Server staff control messages and channels stored on Discord; contact them or Discord about content outside the bot’s local records.
7. This legal site
The public pages hosting this policy use GitHub Pages. The pages contain no bot-operated analytics, advertising scripts, or cookies. GitHub may process visitor information, including IP addresses, to host and secure the site under its own Privacy Statement.
8. Changes
We will update this page when our data practices materially change and revise the effective date above. Contact the operator through the GitHub profile linked above if you have questions.