Scope and responsibility
This policy describes processing by the Sentivy project and its operators. For privacy questions or requests, use the email in the Contact section below.
This policy covers people using the website, joining the waitlist, interacting with the bot, or posting in a server where monitoring has been enabled. Bot data comes from Discord and administrator settings; waitlist and support data come from you.
The operator determines the purposes of website signup, service security, and support processing. Server administrators determine their server rules and how they use moderation results. Where the operator processes member data solely on a server operator’s behalf, that relationship requires appropriate documented instructions and, where applicable, a data-processing agreement. This notice is not itself that agreement.
Data the bot and website process
We process data relevant to the requested functionality, including the following categories.
| Category | Examples and purpose |
|---|---|
| Message content and context | Eligible new or edited server messages, limited nearby text, timestamps, and message references to assess possible rule violations. Rules-channel text is read to build the policy snapshot. |
| Discord identifiers and access | Server, channel, message, user, and moderator IDs; displayed names; channel names; role or permission information needed to route reviews and check actions; and the time the bot joined each server, used to keep a new installation separate from an earlier one’s data. |
| Configuration and decisions | Selected channels, saved rules, thresholds, monitoring settings, model outputs, matched rules, review status, moderator reasons, sanctions and action-confirmation sessions. |
| Reliability and diagnostics | Queue records, message revision hashes, token counts, latency, error codes, and operational events. Decision logs are designed not to contain message bodies, but identifiers are still personal data. |
| Waitlist | Email address, signup time, consent time and version, source, expiry, a hash of the secret management token, and, if selected, the approval time and invitation reference. |
| Early-access invitations and grants | A hash of the single-use invitation code (not the plaintext code), its linked waitlist record, issuing operator ID, creation and expiry times, redemption or revocation times, and the redeeming Discord user ID. An access grant links that Discord ID to the invitation and records when access was granted. |
| Website security and support | Request metadata processed by hosting infrastructure; short-lived rate-limit counters and, when a trusted proxy is configured, a keyed daily hash of the client address. Support messages include the information you choose to send. |
Discord sign-in and dashboard sessions
The optional dashboard uses Discord OAuth with the identify and guilds scopes to read your basic profile and server list. It does not request your Discord password, email address, direct messages, or permission to join servers on your behalf. Adding the bot is a separate authorization on Discord.
Dashboard access depends on the mode in effect. In invitation-only mode, Discord sign-in alone does not grant dashboard access to ordinary users. A Sentivy operator manually approves selected waitlist requests and emails a single-use, expiring invitation code. Allowlisted Sentivy operators do not need a code; access to a server’s data still requires current permissions and bot installation. In broader-access mode, eligible server managers do not need a code; Discord sign-in, current server permissions, and bot installation are still checked. Redeeming a code binds the resulting invitation grant to the Discord user ID used at sign-in; we do not use a Discord email address to match it to the waitlist signup. Withdrawing the email signup cancels an unused code, but does not revoke a grant already redeemed by a Discord account. The signed-in account or a Sentivy operator can revoke that invitation grant; in broader-access mode, revoking it does not by itself remove eligibility under that mode.
We store your Discord user ID, display name and avatar reference, an encrypted access token, a hashed session identifier, a CSRF token, and session timestamps in the website database. Access to each server is checked against current Discord permissions and the bot installation. The website communicates with the bot over an authenticated private control connection; browser clients do not receive the bot token or moderation-database credentials.
Sign-in sets essential, first-party HTTP-only cookies for a browser-bound OAuth attempt (up to ten minutes) and your login session (up to eight hours, limited by the Discord token lifetime). HTTPS deployments use Secure, SameSite=Lax cookies. Sessions become unusable after one hour of inactivity, expiry, sign-out, or detected authorization revocation. Database expiry cleanup is asynchronous. Refresh tokens are not stored.
These cookies are used for authentication and security, not advertising. Signing out removes the current Sentivy session; it does not remove the bot, erase moderation records, or revoke every Discord authorization. You can revoke the Discord OAuth authorization in Discord’s Authorized Apps settings; that is separate from an invitation grant stored by Sentivy. Up to five active sessions are retained per account. Contact legal@sentivy.xyz for account-data requests.
Configuration changes and moderator decisions made in the dashboard are recorded in the bot’s audit history with the acting Discord user ID, under the moderation retention rules below. Rate limiting uses short-lived database counters. A recent OAuth sign-in is required before issuing a moderation decision; it is not a separate identity or multi-factor verification service.
What monitoring does and does not cover
Monitoring must be enabled for a configured server. The current bot skips its rules and review channels for ordinary message classification, bot and webhook messages, and content it cannot access. It does not analyse direct messages, audio, video, or image contents. Text can still contain links, personal information, or sensitive statements.
The bot uses up to six previous messages from its limited in-memory channel buffer for context. It is not a full archive of the conversation and does not continuously backfill all server history. Copies of relevant context can also be stored with a queued message or a review case.
Do not submit passwords, authentication codes, payment details, or unnecessary sensitive information to the bot, the rules channel, or support. Administrators should not enable monitoring in spaces containing information they are not authorised to process.
Purposes and legal bases
We use data to provide requested moderation, deliver review cards, verify permissions, record moderator actions, prevent duplicate actions, diagnose failures, and respond to requests. We do not use the data to build advertising profiles or sell personal information.
Where EU or UK data protection law applies, the proposed bases for the operator’s own processing are: consent for optional early-access emails, including an invitation code if selected; performance of a contract for requested service, configuration and dashboard access; legitimate interests in providing proportionate community-safety tools, preventing invitation abuse, securing the service, and handling support, where those interests are not overridden by people’s rights; and legal obligations where a specific law requires processing. Contract is not assumed to cover every server member.
For moderation carried out on a server operator’s behalf, the server operator must establish its own valid basis and provide the necessary notice. Merely joining a Discord server or acknowledging this policy is not treated as universal consent. Any special-category data requires an additional lawful condition where applicable; these terms do not create one.
You do not need to join the waitlist to read the website. Without an email address and affirmative signup consent, we cannot consider your early-access request or email you an invitation. You can withdraw that consent without affecting the lawfulness of earlier processing.
TypeSafe AI processing
The bot sends the target message text, selected server-rule passages, the channel name, and limited prior conversation to TypeSafe AI over its HTTPS API. It replaces author IDs in the model payload with temporary speaker labels; it does not send separate Discord ID or display-name fields to the model. This is not full anonymisation: the text or channel name can itself identify people.
TypeSafe returns structured assessments, such as a violation score, a selected rule, and a review-priority category. We store relevant results to support review and operation. A score can be wrong and should not be treated as a factual finding about a person.
Sentivy does not train or fine-tune models using Discord message content. TypeSafe’s published privacy policy also states that it does not train or fine-tune models on API input. This is a provider statement, not a claim of zero retention; its public policy does not specify a fixed API-input deletion period. Its processing and applicable service-provider agreement must be considered separately from Sentivy’s database cleanup.
Who can receive data
Discord provides message and interaction data and receives bot responses and requested moderation actions. Review cards and their context are posted in the configured private review channel; people who can access that channel can read them. Administrators control those permissions.
Railway hosts the application and storage infrastructure. The website’s MongoDB waitlist uses separate credentials and a separate database from bot moderation data. TypeSafe receives the moderation input described above, not your waitlist email as a separate signup record.
Authorised operators review waitlist requests and, if selected, use the applicant’s address to send an invitation code manually by email. The operator’s and recipient’s email services process that message under their own arrangements; the website has no automated mailing provider or payment checkout. Operators may also access records when necessary for support, maintenance, security, or a privacy request. Data may be disclosed where required by law. We do not sell personal data or share it for behavioural advertising. Any later automated mailing provider must be disclosed before use.
International processing
The inspected deployment uses Railway infrastructure in the United States, and TypeSafe states that its services are hosted in the United States. Your data may therefore be processed outside your country, including outside the EEA or UK.
The applicable service-provider agreements and international-transfer safeguards have not yet been confirmed in this notice. Publication does not establish that a particular safeguards agreement or adequacy mechanism is in place. Contact Sentivy for current information about those arrangements.
Where required, a valid transfer mechanism and appropriate safeguards must be established before the processing begins. Consent to early-access emails is not blanket consent to international transfers. Contact the operator for information about the arrangements that apply and how to obtain a copy of relevant safeguards.
Retention and cleanup
The following describes the current application’s default retention behaviour, not a guarantee that every external copy disappears at the same instant. Cleanup runs periodically and may be delayed while the service is offline. The bot retention window is configurable; an operator must review this notice if the deployed setting differs.
| Record | Current default behaviour |
|---|---|
| Queued messages | Message and context payloads remain while pending or processing. Completing or skipping a job clears its payload. A job not completed within about 10 minutes, for example during an outage, is dropped and its payload cleared, unless it is still being processed. Completed job metadata is eligible for deletion after one day. |
| Review cases, audit records, revision hashes | Eligible for cleanup after the configured window, seven days by default. A case whose sanction outcome is uncertain or still being applied is kept after the window, to prevent a second sanction, until moderators reconcile it. When the window ends, its message text, nearby context, displayed names, rule text and moderator-entered reason are removed; identifiers, revision hashes, the assessment result, the action state and the moderator’s ID may remain until reconciliation. |
| Rules and server configuration | The active rules snapshot and configuration remain while needed for the installation. Older snapshots are removed after the window only when no configuration, pending job, or case still references them. |
| AI diagnostics and usage | Up to 20 recent diagnostic entries per server, cleaned after 24 hours; daily usage counters are kept for approximately 31 days. |
| Action sessions and memory buffer | Confirmation sessions are cleaned after expiry. The small context buffer is replaced as messages arrive, drops a channel’s entries after about 10 minutes without activity, and is cleared on process restart or server removal; it is not a permanent history archive. |
| Waitlist | Signup records expire 365 days after registration unless removed earlier. MongoDB expiry cleanup is asynchronous. Repeating a signup does not extend the original record. |
| Early-access invitations | An unused code expires no later than the linked signup and its database record becomes eligible for deletion 30 days after expiry. The application retains only a code hash, not the plaintext code. A redeemed invitation record can remain while the associated dashboard grant is active, including after the one-year signup record expires. Once revoked, the invitation record becomes eligible for deletion after 30 days. MongoDB expiry cleanup is asynchronous. |
| Dashboard access grants | An invitation grant links a redeemed code to a Discord user ID and remains while that grant is active, even if the original waitlist signup expires or is withdrawn. The signed-in Discord account or a Sentivy operator can revoke the grant; withdrawing the email signup and signing out do not end it. In broader-access mode, eligible server managers may use the dashboard without an invitation grant; revoking a grant does not by itself remove eligibility under that mode. Contact Sentivy to request removal of an invitation grant if you cannot sign in. |
| Rate-limit records | Short-window counters expire within approximately 20 minutes. The daily signup cap counter expires shortly after the next UTC day begins. MongoDB cleanup is asynchronous. Raw IP addresses are not stored in the application’s rate-limit records. |
Hosting logs, backups, and Discord copies
Hosting-log retention and any backup schedule depend on the active infrastructure settings and provider arrangements. A fixed deletion period for these external records has not been confirmed in this notice. They do not automatically follow the application database’s retention window; contact Sentivy for current retention information.
A manually sent invitation email can remain in the operator’s sent mailbox and the recipient’s mailbox after the application invitation or waitlist record is removed. Those copies follow the respective email services’ and mailbox owners’ retention settings; a fixed deletion period for them is not confirmed here.
Deleting an application record does not automatically remove Discord review cards, original messages, Discord audit records, or copies retained by server moderators. Contact the relevant server administrators or Discord about data under their control. Provider-held API data is subject to the applicable provider arrangements, not the application database timer.
Any retention beyond ordinary operation must be justified, restricted to its purpose, and ended when no longer necessary, subject to legal requirements and platform obligations. Backup restoration procedures must account for deletion requests rather than silently restoring deleted personal data to use.
Access, correction, deletion, and objections
Contact Sentivy using the email below to request access, correction, deletion, restriction, or, where applicable, portability of your data. You can object to processing based on legitimate interests and withdraw consent where consent is the basis. These rights have legal conditions and exceptions.
For bot records, provide your Discord user ID and, if known, the server ID, message link, or case reference. You can contact us even after leaving or being banned from a server. We may need proportionate verification to prevent disclosure or deletion of someone else’s data; do not send credentials or identity documents unless specifically needed and safely arranged.
To remove a waitlist signup, use its current secret management link. The link shown after an initial signup works while the signup is active and unapproved. If an operator approves it, that link stops working: the operator receives a replacement link to include with the invitation code in a manually sent email. A repeated signup also shows a link of the same form, but it does not remove the existing record; only the first working link or the emailed replacement does. To protect signup privacy, the removal page does not confirm whether a link matched a record. If you lose the current link or need confirmation, contact Sentivy from the registered email address. Anyone who obtains a working link can remove the signup and cancel an unused invitation code. Removing the signup does not revoke an invitation grant already redeemed by a Discord account; sign in to revoke that grant or contact Sentivy. In broader-access mode, removing the signup or invitation grant does not by itself remove eligibility under that mode. A cancelled invitation record becomes eligible for deletion 30 days after revocation; actual database cleanup may lag. Removing the signup does not delete unrelated bot records or copies of an invitation email in mailboxes.
Pausing monitoring stops new analyses through the configured installation. Removing the bot from a server ends its access and deletes that server’s stored bot records; if the bot is offline at that moment, this happens when it next connects and Discord confirms the removal. If the bot is later added again, data from the earlier installation is not reused. A deletion request is separate from a moderation appeal: ask the server’s moderators to review a ban or timeout. We will respond to privacy requests within applicable legal time limits and explain any permitted limitation or extension.
You may complain to the supervisory authority competent for your location. In Poland this is the President of the Personal Data Protection Office (UODO). You do not have to contact us first to exercise that right.
Human review and automated assessments
AI is used to flag possible violations, not to impose an independent automated punishment. In the current bot a moderator must choose a ban, timeout, or no action. The model’s scores and suggested rule are review aids, not a reliable measure of a person’s character or intent.
A server sanction can affect participation in that server. Request a human review from the server’s moderation team. This policy does not authorise adding solely automated sanctions without a fresh assessment of notice, safeguards, and applicable legal obligations.
Security, cookies, and tracking
The application uses restricted access, permission checks, authenticated database connections, HTTPS to external APIs, bounded requests, and hashed waitlist management tokens. Security is not absolute; infrastructure settings and operational procedures also matter. A management link is a secret, so do not share it.
The current website does not include advertising cookies, tracking pixels, browser fingerprinting, or third-party analytics scripts. Hosting and network providers can still process technical request information. Visiting a linked provider’s website is governed by that provider’s policy, not this one.
Young users
Sentivy is not directed at children below the minimum age required by Discord or applicable law. The bot does not reliably know the ages of server members. Administrators must consider member ages and applicable service-provider restrictions before enabling external AI processing.
If you believe data about a child has been processed improperly, contact Sentivy so that processing and deletion can be reviewed. Providing this policy does not itself establish any parental consent or override a provider’s age restrictions.
Policy updates
We will update this page when our practices change and identify the updated date. Material new purposes or recipients will be disclosed before that processing begins, with any additional consent or other steps required by law. A new policy cannot retroactively create consent for past processing.
Contact
For support, privacy requests, or questions about these documents, contact Sentivy using the email below. Include only the information needed to locate your request. Never send your password, authentication code, or Discord token.