SlinkyBot
GDPR Privacy Notice
Effective date: 1 August 2026. SlinkyBot is operated by Conarx, Ltd. Questions and rights requests can be sent to contact@conarx.tech or by post to Conarx, Ltd, 27 Old Gloucester Street, London, WC1N 3AX. See the Privacy Policy, GDPR Privacy Notice, and Terms of Service.
Scope, date, and relationship to the Privacy Policy
This notice supplements the Privacy Policy for SlinkyBot, a service family that includes a Discord bot and a browser-based WebUI (together with related systems and integrations, the “Services”). The bot operates within participating Discord servers, while the WebUI is a browser interface for authentication, server management, and ban appeals. This notice applies when the EU General Data Protection Regulation, the UK General Data Protection Regulation, or similar data-protection law applies to the handling of your personal data. It does not state that those laws apply to every user or every processing activity. Effective date: 1 August 2026.
Discord is a separate service with its own terms and privacy policy. This notice describes SlinkyBot's processing and does not replace information supplied by Discord or a participating Discord server.
Controller and contact details
For the processing described in this notice, the stated controller is:
Conarx, Ltd27 Old Gloucester Street
London, WC1N 3AX
contact@conarx.tech
Conarx is the primary controller for SlinkyBot's own processing. A participating server owner or administrator makes decisions about server rules, configuration, content, staff access, and moderation and remains responsible for those decisions and any separate data-protection duties that apply to the server's processing. No separate administrator DPA is intended by this notice; the roles are described directly here and in the Privacy Policy.
Personal data and sources
Depending on the features used, the Services can process the following categories from these sources:
- Data you submit directly: commands, messages, ticket content and transcripts, appeal text, attachments, giveaway entries, administrator configuration, rules, embeds, staff notes, and other content supplied through Discord or the WebUI.
- Discord identity and server data: the bot uses broad Discord gateway intents and can receive guild and member IDs and names, usernames, display names, nicknames, roles, avatars, activities, join and leave timestamps, memberships, permissions, and invite attribution from Discord APIs, events, interactions, and participating servers.
- WebUI OAuth and session data: Discord identity and guild information obtained through the
identifyandguildsscopes, server-side OAuth access and refresh tokens, CSRF data, and an opaque session identifier held in a signed browser cookie. The WebUI does not request your Discord email address. - Message processing and cache data: author IDs and display names; guild, channel, and message IDs; channel metadata; message content and timestamps; reply context; and edit or deletion status. The Redis message cache has a 24-hour expiry, but related data can persist in database records, moderation records, ticket transcripts, and logs.
- Moderation, appeals, tickets, and transcripts: infractions, moderator IDs, reasons, durations, referenced messages, staff notes, moderation actions, appeal text and decision history; ticket creator and user IDs; guild, channel, and message IDs; configuration, timestamps, and status; and closed transcripts with content, authors, timestamps, attachments, embed summaries, and reactions.
- Leveling, giveaways, and invites: per-guild, user, and channel XP activity; message counts; voice and streaming minutes; likes; timestamps; roles; channels; level configuration; giveaway creators and hosts; invite codes; prizes; entrant and member IDs; entries and counts; message tracking; winners; rerolls; and logs.
- Server configuration: feature settings, permissions, roles, channels, automod rules, ticket access, administrator content, and other instructions supplied by authorized server administrators.
- Automatic technical and security data: network address information, request timing, authentication activity, errors, rate-limit identifiers, abuse indicators, and application, proxy, infrastructure, cache, and security logs generated when the Services operate.
- AI-assisted automod data: relevant message content and context, user identifiers and display names, timestamps, channel context, infractions, staff notes, configured rules, and moderation instructions sent to the official OpenAI API when that feature is enabled.
- Premium subscription data: subscription, payment, billing, tax, transaction, chargeback, and entitlement information needed for the $49.95 USD monthly recurring Premium subscription. Stripe Checkout processes payments and determines and displays applicable taxes.
Purposes and lawful basis review
Personal data can be used to connect the bot to Discord; authenticate WebUI users; enforce server-specific access; process commands; provide moderation, appeals, tickets, transcripts, leveling, giveaways, invites, and administrator tools; apply configured rules; secure accounts and sessions; prevent abuse; investigate faults; maintain records; and comply with applicable requirements.
Depending on the purpose and circumstances, processing can be necessary for a contract or steps requested before a contract, based on legitimate interests, required by a legal obligation, or based on consent where consent is requested. The applicable basis depends on the purpose, the parties involved, and the deployment. Where a basis is not stated for a particular activity, this notice should not be read as selecting one.
Recipients and disclosures
Personal data can be disclosed or made available to:
- Discord when the Services receive Discord events, use Discord APIs, authenticate users, or display content through Discord.
- Authorized server owners, administrators, moderators, ticket staff, appeal reviewers, and other members according to server configuration, channel visibility, permissions, and assigned duties.
- Deployment-specific hosting, database, cache, network, logging, monitoring, and security providers that support operation of the Services. SlinkyBot infrastructure is hosted in the USA.
- OpenAI when AI-assisted automod is enabled. The relevant API project has verified zero data retention, and API content is not used for model training under the applicable configuration and terms. OpenAI's own terms, policies, locations, and provider conditions apply.
- Stripe for Premium payment processing, subscription status, applicable tax presentation, fraud prevention, accounting support, and chargebacks. Stripe's own terms, policies, locations, and provider conditions apply.
- Courts, regulators, law-enforcement bodies, or other authorities when disclosure is required by applicable law or a valid legal process.
International transfers
SlinkyBot infrastructure is hosted in the USA. Discord, OpenAI, Stripe, and other providers can process personal data in the USA or other countries outside the UK or EEA. Infrastructure location and provider processing location are separate matters. Transfer routes and any required safeguards depend on the provider and processing activity. Conarx will use a lawful transfer mechanism or other safeguard where applicable and can provide further information on request, subject to lawful restrictions. Provider policies and terms also apply.
Retention
We generally seek to retain operational data for no longer than 7 days where feasible. The Redis message-processing cache can expire sooner. Expiry from one cache or session does not establish deletion from moderation records, ticket transcripts, logs, backups, Discord, or another system.
Feature records are deleted after 12 months with no bot-observed membership or activity in any participating server, where feasible. Other retention periods vary by data category and deployment. We can retain or restrict access to information for legal obligations, legal claims or disputes, security, fraud or abuse prevention, accounting, chargebacks, and controlled backups. We minimize retained information, restrict access, and delete it when the exception ends where feasible. This does not claim that every record is deleted after 7 days or that every record can be deleted on request.
Security
The Services use measures intended to protect personal data, including access controls, server-side OAuth token storage, signed session cookies, CSRF protection, and operational security controls. Access within participating servers depends on configured roles, channels, and permissions. No online service can guarantee absolute security. Conarx will handle incidents and notifications through processes required by applicable law.
Your data-protection rights
Subject to applicable law and its conditions or exceptions, you may have rights to access your personal data; rectify inaccurate data; request erasure; restrict processing; object to processing; receive portable data; and withdraw consent where processing relies on consent. Withdrawal does not affect the lawfulness of processing completed before withdrawal.
Submit a request to contact@conarx.tech or by post to Conarx, Ltd, 27 Old Gloucester Street, London, WC1N 3AX. Describe the Discord account, server, and feature involved without sending passwords, tokens, or unnecessary sensitive information. Conarx may request proportionate information to verify your identity and authority before acting. A server administrator can also be an appropriate first contact for server-controlled content or settings. Conarx will respond within the time required by applicable law, subject to permitted extensions, exemptions, and limits.
AI assistance and automated processing
AI-assisted automod can analyze relevant messages and context and can produce classifications or recommendations for moderation workflows. AI output can be inaccurate and can create false positives or false negatives. Where the server's workflow provides human review or an appeal process, users can ask authorized staff to review the context and outcome. Server administrators and staff should not treat AI output as infallible or as a replacement for responsible human judgment.
Zero data retention is verified for the relevant OpenAI API project, and API content is not used for model training under the applicable configuration and terms. Those facts do not apply automatically to other OpenAI products or configurations. OpenAI's terms, policies, processing locations, and provider conditions continue to apply. Conarx will assess the actual deployment to determine whether any automated processing has legal or similarly significant effects and will provide notices or safeguards required by applicable law; this notice does not treat AI output as infallible or make that determination for every server.
Children and age requirements
The Services do not set a separate universal minimum age. Users must meet Discord's minimum age requirements and any additional age, consent, or access requirements imposed by applicable law or a participating server.
Complaints
Please contact contact@conarx.tech first so Conarx can try to address your concern. Where applicable, you also have the right to complain to the UK Information Commissioner's Office (ICO) or the data-protection supervisory authority responsible for your location or the relevant processing. Contacting Conarx first does not remove that right.
Changes and related information
This notice can change when the Services, server features, providers, deployment locations, or applicable requirements change. The effective date shown in the shared legal header identifies the current version. We will provide notice of material changes where required by applicable law. See the Privacy Policy for the general information handling notice, or contact contact@conarx.tech with questions.