SlinkyBot
Privacy Policy
Effective date: 1 August 2026. SlinkyBot is operated by Conarx, Ltd. Questions and rights requests can be sent to contact@conarx.tech or by post to Conarx, Ltd, 27 Old Gloucester Street, London, WC1N 3AX. See the Privacy Policy, GDPR Privacy Notice, and Terms of Service.
Scope and controller
Effective date: 1 August 2026. SlinkyBot is a service family that includes a Discord bot and a browser-based WebUI. The bot operates within participating Discord servers, while the WebUI supports account authentication, server management, and ban appeals. This policy covers those interfaces, related databases and caches, bot-generated content, and integrations used to provide them (together, the “Services”). Discord is a separate service with its own terms and privacy policy.
Conarx, Ltd is the primary controller for SlinkyBot's own processing. Participating servers remain responsible for their configuration, moderation, content, permissions, and decisions, and can have separate responsibilities for personal data they direct or control. This policy applies worldwide, subject to any mandatory consumer, privacy, and other rights that apply where you live.
Information the Services handle
- Discord identity and server data: the bot uses broad Discord gateway intents and can receive guild and member IDs and names, usernames, display names, nicknames, roles, avatars, activities, join and leave timestamps, memberships, permissions, and invite attribution.
- Messages and other content: author IDs and display names; guild, channel, and message IDs; channel metadata; message content and timestamps; reply context; and edit or deletion status. The message-processing Redis cache is configured with a 24-hour expiry, but related data can persist in database records, moderation records, ticket transcripts, and logs.
- Moderation and appeals: infractions, moderator IDs, reasons, durations, referenced message IDs, staff notes, moderation actions, appeal text, appeal status, and decision history.
- Tickets and transcripts: creator and user IDs; guild, channel, and message IDs; ticket configuration, timestamps, and status; and closed-ticket transcripts containing message content, authors, timestamps, attachments, embed summaries, and reactions.
- Leveling and participation: per-server user and channel XP activity, message counts, voice and streaming minutes, likes, timestamps, roles, channels, level configuration, and calculated level summaries.
- Giveaways and invites: creator and host data, invite codes, prizes, entrant and member IDs, entry and message counts, winners, rerolls, timestamps, and logs.
- Administrator configuration: embeds, URLs, descriptions, rules, staff manuals, automod patterns, ticket text, role and channel settings, and other custom server content.
- OAuth and session data: Discord identity and guild data obtained with the
identifyandguildsscopes; server-side access and refresh tokens; CSRF tokens; and an expiring opaque session ID stored in a signed browser cookie. The WebUI does not request your Discord email address. - Security and operational data: request timing, network address information, authentication events, errors, rate-limit identifiers, and other application, proxy, infrastructure, or security logs used by the deployment.
- Premium subscription data: subscription, payment, billing, tax, transaction, and entitlement information needed for the $49.95 USD monthly recurring Premium subscription. Stripe Checkout processes the payment flow and determines and displays applicable taxes. SlinkyBot receives the account, transaction, subscription-status, and entitlement information made available by Stripe; payment details are subject to Stripe's policies and terms.
Why information is used
Information is used to connect the bot to Discord servers; authenticate WebUI users; determine server-specific access; attribute invites; process commands and configured automod rules; operate tickets, moderation, appeals, leveling, giveaways, and administrator features; generate requested bot output; prevent abuse; protect sessions and forms; diagnose faults; and maintain the Services.
Subscription information is used to provide Premium entitlements, process and reconcile payments, calculate or communicate applicable taxes through Stripe Checkout, prevent fraud and abuse, handle chargebacks, keep accounting records, and communicate about the subscription.
Visibility and recipients
Information can be shown through Discord or the WebUI according to server configuration and access controls. This can include bot responses, server names and icons, level and giveaway information, ticket content, appeal history and text, and staff decision notes. Server owners, administrators, moderators, ticket staff, or other authorized members can see information needed for their configured duties. Other server members can see information posted in channels available to them.
Information is processed by Discord when the Services receive Discord events, use Discord APIs, or display content in Discord. It can also be available to Conarx and authorized operators and processed by hosting, database, cache, logging, security, or network providers supporting the deployment. SlinkyBot infrastructure is hosted in the USA. That infrastructure location does not determine the processing location of Discord, OpenAI, Stripe, or another provider, which can process information in the USA or other countries under their own policies, terms, and contractual arrangements. The Services do not make Discord responsible for SlinkyBot's practices, or SlinkyBot responsible for Discord's practices.
AI automod and OpenAI
When a server enables AI-assisted automod, the bot can send relevant message content and context, user IDs and display names, timestamps, channel context, infractions, staff notes, configured rules, and moderation instructions to the official OpenAI API. The output can support the server's moderation workflow, but it can be inaccurate and does not replace human judgment.
Zero data retention is verified for the relevant OpenAI API project, and API content is not used for model training under the applicable configuration and terms. These statements do not describe every OpenAI product or account, and OpenAI's terms, policies, security practices, processing locations, and other provider conditions continue to apply.
Payments and Stripe
Stripe is the payment provider for the $49.95 USD monthly recurring Premium subscription. Stripe Checkout determines and displays applicable taxes at checkout. Stripe can process payment details, billing information, subscription and transaction data, and fraud or chargeback information under its own terms and privacy policy. Conarx uses information made available by Stripe to provide and manage Premium access, reconcile payments, support accounting, and respond to disputes.
For provider information, see Stripe's Privacy Policy and Stripe's Services Agreement. Conarx does not control Stripe's processing.
Cookies and browser sessions
The WebUI uses a signed cookie containing an opaque session identifier. Discord access and refresh tokens, identity data, and CSRF security data are stored server-side rather than in that cookie. Sessions expire according to deployment configuration. Disabling cookies can prevent sign-in and form submissions from working, and signing out ends the active browser session.
Retention
We generally seek to retain operational data for no longer than 7 days where feasible, but that target does not mean that every record is deleted after 7 days. Feature records are deleted after 12 months with no bot-observed membership or activity in any participating server, where feasible and subject to the exceptions below. Different records can have different lifecycles, and the message-processing cache can expire sooner.
We can retain or restrict access to information for legal obligations, legal claims or disputes, security, fraud or abuse prevention, accounting, chargebacks, and controlled backups. We minimize the retained information, restrict access, and delete it when the relevant exception ends where feasible. Discord and independent participating servers can retain information under their own practices.
Your choices and requests
You can choose not to sign in, submit an appeal, enter a giveaway, or use optional commands. Messages and activity in a participating server can still be processed when needed for enabled server features. Server owners and administrators choose whether to add the bot, grant permissions, and configure features, channels, roles, moderation rules, ticket access, and AI automod; removing permissions or the bot can stop features but does not by itself confirm deletion of stored records.
Requests for access, correction, deletion, restriction, objection, portability, or other rights that apply can be sent to contact@conarx.tech or by post to Conarx, Ltd, 27 Old Gloucester Street, London, WC1N 3AX. A server administrator can also be an appropriate first contact for server-controlled content or settings. We may request proportionate information to verify identity and authority. We respond within applicable statutory timelines, subject to lawful extensions, exceptions, and limits; not every request can be fulfilled in every circumstance.
Security
The Services use access controls, server-side sessions, CSRF protection, and other operational safeguards intended to reduce risk. No online service can guarantee absolute security. Users should protect their Discord accounts and sessions, and server administrators should grant only permissions needed for configured features. Where required by applicable law, Conarx will handle security incidents and notifications through the required processes.
Age and children
The Services do not set a separate universal minimum age. Users must meet Discord's minimum age requirements and any additional age, consent, or access requirements imposed by applicable law or a participating server.
External links and policy changes
Bot messages, administrator content, tickets, or the WebUI can contain links to external sites. Those sites are controlled by others and have their own practices; a link does not mean the project owner endorses or guarantees them.
This policy can change when the bot, WebUI, integrations, providers, or applicable requirements change. The effective date shown in the shared legal header identifies the current version. We will provide notice of material changes where required by applicable law.
Related notices
If the GDPR, UK GDPR, or similar data-protection law applies to you, read the GDPR Privacy Notice for additional information about lawful bases, rights, international transfers, and regulatory complaints. The Terms of Service describe the conditions for using the Services.