shrkbotshrkbotv3.5.2

Privacy policy

Last updated: July 23rd, 2026

This policy explains what the shrkbot Discord bot and its web dashboard (together, the "Service") store, why, and the choices you have. It's written to be readable rather than dense - if anything is unclear, contact us.

The Service is operated by Tim Engelhardt, the data controller under the EU General Data Protection Regulation (GDPR).

Who this applies to

  • Server members: people in a Discord server that shrkbot has been added to. shrkbot may process limited data about you because of features an admin has enabled.
  • Dashboard users: people (usually server admins) who sign in to this website with Discord to configure the bot.

What we store and why

We store only what the enabled features need:

  • Server configuration: the server's Discord ID, name, icon reference and approximate member count, plus a cached copy of its channels and roles (IDs, names, types, colours, positions, permission sets) and their permission overwrites (which can reference member Discord IDs) mirrored from Discord so the dashboard can display and apply your setup. Also which plugins are enabled, and the welcome, logging, role-menu and moderation settings admins configure - including any custom scam-keyword list.
  • Dashboard account: when you sign in with Discord we store your Discord ID, username, display name and avatar reference. We request only the identify and guilds OAuth scopes - we never receive your email, password or messages. Your Discord access token is held only in an encrypted session cookie in your browser (valid two weeks), never in our database, and is used solely to read which servers you manage.
  • Reminders: the reminder text you write, your Discord ID, the target channel and server, whether to deliver by DM, and the due time - kept until delivered or deleted by you with /unremind.
  • Welcome messages: on servers that use Discord's membership screening, a short-lived in-memory note that a member has joined but not yet finished onboarding - the server ID and their Discord ID, nothing else. It exists so the welcome can wait until they finish, which is what makes the greeting name them correctly. It is never written to disk.
  • Looking for Game: the roles you make pingable and the policy limits you set for each of them (which roles or channels may use them, minimum membership age, cooldowns and post lifetime). This is server configuration only. Who joins a post lives entirely in the Discord message, under Discord's retention — we never store joiners or post content. We keep only the non-personal message references needed to manage and clean up a post (channel and message IDs, and the IDs of the follow-up messages we post for it). A short-lived in-memory cooldown (minutes) throttles spam and is never written down.
  • Dashboard notifications: short activity entries (an event type plus details such as a plugin or channel name) so admins can see recent changes.
  • Operational data: background jobs briefly process the data above while running; a failed job may keep a short error record for up to 30 days. The web server keeps standard technical logs (IP address, timestamp, browser type) for security and troubleshooting.

Message content

shrkbot uses Discord's message-content intent so that servers can enable automated moderation. When an admin turns that feature on, shrkbot reads new messages, including, using optical character recognition (OCR), text contained in posted images, to check them against the server's rules. On servers that don't enable moderation, messages aren't processed at all.

This scanning happens in real time and in memory only: we do not store or retain message content, images, or text extracted from images. Once a message has been checked, its content is discarded. We keep no message history, no message logs, and no copies of your server's conversations.

If automated moderation acts on a message, shrkbot can post a moderation log entry to a channel your admins designate. That entry may include the offending message or the text extracted from an image so moderators can review it - it is delivered as an ordinary Discord message and is therefore stored by Discord in that channel, not retained by shrkbot. A short record that an action occurred (without the message content) may also appear in the dashboard.

The bot also receives member join and leave events to deliver welcome messages; the username shown there is rendered into the message and not stored.

To recognise repeat scam images, shrkbot stores a perceptual hash (a short numeric fingerprint that cannot be turned back into the image) of images a server's moderators explicitly confirm as scams, together with which servers confirmed them. These fingerprints are never linked to the user who posted the image, are deleted when every confirming server has removed the bot, and are pruned automatically after 180 days without a match. The bot owner may also mark images as global scams; their perceptual hashes are stored indefinitely as a cross-server blocklist and are treated the same as scams a server's own moderators confirmed, so a match can trigger that server's configured action (flagging, removal, and any punishment). These hashes are not linked to any user or server.

What we don't do

We don't sell data, we don't advertise, we don't profile you, we don't run analytics, and we don't store your servers' member lists or conversations.

Legal bases

Where the GDPR applies we rely on performance of the service (Art. 6(1)(b) - providing the features you or your admins enable) and legitimate interests (Art. 6(1)(f) - operating, securing and debugging the Service). You can object to processing based on legitimate interests; see "Your rights".

Who we share data with

Only the infrastructure that runs the Service: Discord itself, through its API (your use of Discord is governed by Discord's own privacy policy), and our hosting provider Hetzner (Helsinki, Finland, within the EEA), where the Service and its database run. We may disclose data where required by law.

How long we keep it

  • Server configuration: deleted automatically, in full, the moment the bot is removed from the server.
  • Reminders: deleted once delivered, or earlier if you delete them.
  • Pending-join notes: discarded the moment the welcome is sent or the member leaves, after 24 hours either way, and on every restart. They live in memory only and are never written down.
  • Looking for Game configuration: deleted automatically with the rest of the server's configuration the moment the bot is removed. A post's message references are deleted when the post is closed or expires, and otherwise removed with the server's configuration. Cooldowns live in memory only and vanish on restart; the posts themselves are ordinary Discord messages, kept by Discord until they expire or are deleted.
  • Confirmed scam-image fingerprints: pruned 180 days after they were last matched, and removed once every server that confirmed them has removed the bot. Global scam fingerprints set by the bot owner are retained indefinitely.
  • Dashboard account: kept until you delete it on your account page.
  • Caches, background-job records and logs are cleared automatically (at most 60 days, 30 days and briefly, respectively). Deleted data also drops out of database backups as they rotate.

Deleting your data

Erasure is self-service:

  • Remove the bot from a server to delete that server's configuration.
  • Delete individual reminders with /unremind.
  • Delete your dashboard account and your reminders with the "Delete my account" button on your account page.
  • Or contact us (see below) and we'll take care of it.

Your rights

Under the GDPR you have the right to access, correct, delete, restrict or object to our use of your personal data, and the right to data portability. You also have the right to complain to a supervisory authority - in Germany, your regional data protection authority. To exercise any of these, contact us (see below).

Security

Data travels over encrypted (HTTPS/TLS) connections and database access is restricted to the operator. No system is perfectly secure, so we can't guarantee absolute security, but we take reasonable measures and will notify affected users of a serious breach where the law requires it.

Cookies

We set two cookies: the essential encrypted session cookie described above, and a small flag (valid one year) remembering that you dismissed our cookie note. No tracking, no third-party cookies. Your browser also keeps a few purely local preferences in localStorage — your theme choice and collapsed-panel state. These never leave your device and we never read them server-side.

Children

shrkbot isn't directed at children. You must meet Discord's minimum age requirement (at least 13, or older where your country requires) to use Discord and the Service.

Changes

If this policy changes, the new version is published here with an updated date; for significant changes we'll try to give notice through the Service.

Contact

Tim Engelhardt - info@shrkbot.com / support server