Privacy Policy
What the bot keeps, why, for how long, and how to have it all erased.
Last updated: 29 July 2026
1. Data controller
The data controller is EchoBit, reachable at omniazesupport@gmail.com. Any request concerning your data may be sent to this contact.
2. What the bot does not keep
The content of your messages is never recorded. When logging is active, the bot posts a summary embed in the channel you designated, then keeps no trace of it in the database. No attachment, no voice message, no audio content is stored.
3. Data processed by the bot
The data below is recorded per Discord server, only for the modules you have enabled. A disabled module writes nothing.
Server configuration
- Server ID, chosen language, active modules.
- IDs of the channels and roles you designate in the settings.
- Text you enter: welcome and goodbye messages, ticket labels and forms, role panels.
Moderation
- History of sanctions issued through the bot: ID of the sanctioned member, ID of the moderator, sanction type, reason entered, duration, public code, date.
- Internal notes attached to a sanction: author's ID and note text.
- Temporary bans awaiting lifting: member ID, expiry, reason.
Community modules
- Levels: member ID, experience points, number of messages counted, date of last activity. The message count is a counter: their content is neither read for this purpose nor kept.
- Tickets: ID of the member who opened the ticket and IDs of the associated channels.
- Giveaways: IDs of the entrants in a draw.
- Captcha: IDs of members awaiting verification, erased once verification has passed or lapsed.
- Temporary voice: IDs of the channels created and of members excluded from a channel.
- Backups: the server's structure (roles, channels, permissions). A backup contains no messages.
Apart from the text you enter yourself, the personal data processed is therefore limited to Discord numeric IDs. The bot collects no email address, no IP address and no payment data.
4. Data processed by the site
Signing in to the dashboard goes through Discord (OAuth2). The site requests two authorisations: your profile (identify) and the list of your servers (guilds). You never type a password on this site.
- A session is created in the server's memory: Discord ID, display name, avatar, and the Discord access token.
- The Discord token never leaves the server: the cookie placed in your browser contains only a random, signed session identifier.
- As this storage is in memory, restarting the site erases all sessions and signs you out.
- This cookie is strictly necessary for the dashboard to work. The site uses no advertising or analytics cookie.
The site loads no external script, no remote font and no tracker: its content security policy forbids it. The only resources loaded from a third-party domain are avatars and server icons, served by Discord's CDN.
5. Purposes and legal bases
- Performance of the service: applying to your server the settings you chose, keeping a moderation history, running the enabled modules.
- Legitimate interest: protecting servers against raids and abuse, diagnosing technical incidents.
No data is used for advertising purposes, resold, or transferred to third parties.
6. Recipients and processors
- Discord, the platform the bot operates on, subject to its own privacy policy.
- Host: OVH SAS, 2 rue Kellermann, 59100 Roubaix, France, which hosts the bot, the site and the database. The servers are located in France, so your data does not leave the European Union.
- Audio infrastructure: if the music module is enabled, a relay plays back the requested sound. It does not listen in on voice channels, records nothing, and no personal data is passed to it.
7. Retention period
- A server's data is kept for as long as the bot is present there.
- When the bot leaves a server (or is removed from it), a 7-day grace period applies: an accidental removal or a short outage does not erase your configuration. If the bot is re-invited within that period, everything is found as it was.
- After those 7 days, an automatic sweep run every 6 hours permanently deletes all of the server's data: configuration, sanctions, notes, levels, tickets, giveaways and backups.
- Dashboard sessions expire by themselves and are lost whenever the site restarts.
8. Your rights
In accordance with the GDPR, you have a right of access, rectification, erasure, restriction and objection regarding data concerning you.
- Erasing an entire server: remove the bot from the server. The data will be deleted automatically after the 7-day grace period.
- Immediate or partial erasure: write to omniazesupport@gmail.com stating the ID of the server concerned. A request targeting a server can only be handled if it comes from someone holding the “Manage Server” permission there.
- Resetting levels: available directly from the dashboard, for one member or for the whole server.
You may also lodge a complaint with the supervisory authority of your country of residence: in France the CNIL, in the United Kingdom the ICO, and in the other countries of the European Economic Area the equivalent national authority. The list is maintained by the EDPB.
9. Security
- Authorisation to access a server is re-checked with Discord on every request: it is never inferred from what your browser claims.
- The Discord access token stays server-side and is never exposed to the browser.
- The session cookie is signed; any tampering makes it invalid.
As no system is infallible, we cannot guarantee absolute security; we undertake to handle any incident diligently.
10. Minors
The Service is aimed at Discord users and follows the platform's age conditions. We do not knowingly collect data concerning people who do not meet the required age in their country of residence.
11. Changes
This policy may evolve alongside the Service. The applicable version is the one published on this page, dated at the top of the document.
12. Contact
For any question or request regarding your data: omniazesupport@gmail.com.