DATA PRIVACY // DOC_ID: P-9041

Privacy Policy

Data protection architecture, Discord OAuth telemetry scope, information retention schedules, and user privacy rights governing the Discord Server Management System (DSMS) infrastructure.

EFFECTIVE: AUGUST 14, 2026
POLICY REVISION: v2.4.0
COMPLIANCE: GDPR & CCPA READY
TELEMETRY ENCRYPTION VERIFIED
01

Information We Collect

DSMS collects data strictly required to authorize access, process moderation telemetry, and maintain server management operations:

  • Discord Authentication (OAuth2): User IDs, Discord usernames, avatars, email address (if authorized), and server permission bitmasks.
  • Guild Telemetry: Server IDs, channel IDs, role hierarchies, bot permissions, and aggregated message frequency metrics.
  • Sentinel Audit Logs: Moderation action logs, toxicity scores, warning history, ban/kick records, and incident reports.
  • Form Submissions: User-submitted public appeal forms, support tickets, and associated contact fields.
02

How We Use Your Telemetry

Collected data is processed exclusively for the following administrative purposes:

  • Validating administrative clearance for access to guild management panels.
  • Running real-time automated moderation heuristics via Sentinel Shield.
  • Rendering live War Room feeds, analytics graphs, and server activity leaderboards.
  • Sending automated alert notifications and webhooks configured by guild administrators.
NO DATA COMMERCIALIZATION
DSMS never sells, monetizes, or shares server telemetry or member identities with data brokers or advertising networks.
03

Data Storage & Retention Schedules

We enforce strict data minimization and automatic log rotation schedules across all storage engine instances:

  • Active Sessions: Stored in encrypted SQLite session stores; automatically expire after 7 days of inactivity.
  • Audit Logs & Metrics: Preserved for up to 90 days for server historical reporting, unless manually cleared by a Guild Owner.
  • Sentinel Trigger Cache: Transient message analysis caches are purged within 24 hours of event evaluation.
04

Third-Party Service Providers

DSMS integrates with trusted third-party APIs solely to deliver core services:

  • Discord Developer API: Authenticates users and fetches real-time guild member state.
  • CDN Providers (JsDelivr, FontAwesome, Google Fonts): Serves static assets, iconography, and UI typography.

Each third-party provider operates under their respective privacy policies and data protection standards.

05

Cookies & Local Storage

We use essential cookies and browser LocalStorage strictly for technical functionality:

  • Session Cookie (express:sess): Maintains encrypted session state for authenticated administrators.
  • Theme Preference (dsms_theme): Remembers your Light Mode / Tactical Dark Mode selection in LocalStorage.

We do not use tracking pixels, fingerprinting scripts, or third-party marketing cookies.

06

User Rights & Control

Under GDPR, CCPA, and global privacy frameworks, users interacting with DSMS possess the following rights:

  • Right to Access: Inspect stored telemetry, moderation records, and server settings associated with your Discord ID.
  • Right to Revoke Access: Instantly de-authorize DSMS at any time via Discord's Authorized Apps settings (`User Settings > Authorized Apps`).
  • Right to Data Erasure: Request permanent removal of audit logs and profile records.
07

Data Erasure & Deletion Requests

Server owners or individual Discord users may request complete data erasure at any time:

  • Guild De-Authorization: Removing the DSMS bot client from a Discord server flags all associated guild settings for purge after 14 days.
  • Direct Deletion Request: Users can submit a data deletion ticket via the administrative panel or official support channel. All matching database entries will be permanently removed within 7 business days.
08

Security Protocols

We implement multi-layered defense mechanisms to safeguard stored telemetry against unauthorized access:

  • Encrypted Transport: All web traffic is transmitted over enforced TLS/HTTPS protocols.
  • Security Headers: Helmet middleware enforces strict Content Security Policies (CSP), anti-clickjacking, and XSS mitigations.
  • Rate Limiting: Protection against brute-force authentication and API flooding.
09

Protection of Minors

DSMS services are designed in compliance with Discord's Terms of Service and minimum age requirements (13+ globally, 16+ in specific European jurisdictions). We do not knowingly collect personal information from children under minimum legal age thresholds.

10

DPO Contact & Inquiries

If you have questions, compliance requests, or data deletion inquiries regarding this Privacy Policy, please contact our Data Protection Command Team:

  • Email: privacy@dsms.protocol
  • Discord Command: Contact server administrators or submit a ticket in the official DSMS support server.