Legal

Privacy

What data Skord processes, why, and how to ask for deletion. Plain language; not legal advice.

Effective September 2026 · Operated by Devscor

Who

Controller

Skord is a Discord bot and web dashboard operated by Devscor (“we”). This policy describes what information we process when you use the bot on a server or sign in to the dashboard.

If you have privacy questions, write to [email protected] and, when possible, include the Discord server ID.

Scope

This policy applies to use of Skord (the Discord application) and the related site / web dashboard. It does not govern Discord’s own processing as an independent platform: when you use Discord, their policies also apply.

What data

Data we process

We only process data needed to provide and improve the service. Depending on how you configure Skord, that may include:

  • Discord identifiers: user, server (guild), channel, role and message IDs when a feature needs them.
  • Server metadata: guild name, approximate member count, bot presence and configuration you save in the dashboard.
  • Moderation: cases, warns, actions (kick, ban, timeout, etc.), optional reasons and who ran the action.
  • Auto-mod: the rule that fired, strikes, escalation and, on a hit, a snippet of the message (about 500 characters) tied to the case.
  • Audit / logs: when you enable log categories, the bot may post events to a channel on your server (edited/deleted messages, role changes, voice, etc.). That content is sent to Discord; we do not keep it as our own long-term store.
  • Levels and economy: XP, level, role rewards, balances and activity for those features.
  • Community: autoroles, starboard, tickets (created channels, support role, open/close logs), tags, giveaways and panels/messages you publish.
  • Community events and analytics: event type, IDs, date and shape metadata (for example message length, whether it had attachments, counts). Never the message text, usernames or URLs.
  • Workflows and integrations: the definition you build, runs, and webhook fields you allowed. Raw webhook bodies are not stored as community history.
  • Organizations: membership, dashboard roles and invites, so several admins can share config.
  • Web dashboard: Discord OAuth session (via Supabase Auth), including access tokens needed to list servers you can manage, and account preferences tied to that session.

Message content (Message Content)

Skord requests Discord’s Message Content privilege for the features that need it. We do not read every message on the server “just in case”: the bot looks at text when an active module requires it.

That includes, depending on what you enable:

  • Auto-mod: to detect invites, spam, mentions or domains you configured, and to leave a snippet on the case if there is a hit.
  • Message logs: to post before/after an edit or a delete in your audit channel. That lives in Discord, in the channel you chose.
  • Starboard: to repost in the starboard channel the text of a message that passed the ⭐ threshold (we do not repost NSFW channel content).
  • Commands and tickets: when a slash or a ticket needs to quote or copy what someone just wrote.
  • Templates you save in the dashboard: welcome, tags, embeds and panels. That is content you publish, not general chat.

What is not stored as chat

Event history, analytics and workflow triggers do not store message bodies: only IDs and shape (length, attachments, mentions). We do not index the server to search conversations. We do not use chat to train models or for ads.

YouTube and other third-party services

Skord does not connect to YouTube accounts, does not play or download videos and does not process YouTube data as a platform. Bot music was removed because YouTube does not allow that use.

If in auto-mod you add a domain (for example youtube.com) as a link filter, the bot only looks for that string in the message text, same as any other site. There is no YouTube API integration.

Data we do not seek

We do not ask for Discord passwords. We do not read DMs. We do not sell personal data or use it for third-party advertising.

Why and where

Purposes and basis

We use the data to:

  • Provide the service you configure (moderation, auto-mod, levels, welcome, economy, tickets, panels, workflows, analytics, etc.).
  • Show and save configuration in the dashboard.
  • Keep the service secure (abuse, rate limits, authentication).
  • Meet legal obligations when they apply.
  • Improve stability and technical support (system error logs, not used for advertising).

Where it is stored and providers

Bot configuration and records are stored in PostgreSQL databases run on cloud infrastructure (for example Supabase / API hosting).

Dashboard authentication is handled by Supabase Auth with Discord as the identity provider. The bot and API may run on compute providers (for example Railway) and the front on web hosting platforms (for example Vercel).

These providers act as processors or technical services needed to run Skord. Their own terms and security measures apply to them.

Sharing and transfers

We do not sell or rent personal data. We only share information with technical providers essential to the service, or when the law requires it (a valid authority request).

When you use Discord, part of the processing happens on Discord’s infrastructure (messages posted to log channels, interactions, OAuth). That is inherent to the product.

Time and security

Retention

We keep guild configuration while Skord is installed or while we keep a server record for the service.

Cases, warns and module data (levels, economy, etc.) are kept according to product logic and what you configure; you can ask for deletion of data tied to a server by writing to [email protected].

Live audit logging is published as messages in the channel you choose: retention depends on how you manage that channel in Discord.

Dashboard sessions last while the OAuth session / auth cookies remain valid or until you sign out.

Security

We apply reasonable measures: internal API access with keys, OAuth for the dashboard, secrets in environment variables and granular bot permissions (Administrator is not required by default).

No system is 100% secure. If you detect an incident that affects Skord data, tell us as soon as you can.

Your control

Your rights and control

You can:

  • Kick Skord from the server at any time (it will stop processing new events there).
  • Turn off modules or log channels from the dashboard.
  • Sign out of the dashboard.
  • Request access, correction or deletion of data tied to your guild by writing to [email protected] and including the server ID.

Minors

Skord is meant for Discord communities. Whoever invites the bot or administers the dashboard must have legal capacity and sufficient permissions on the server. If you run a server with minors, you are responsible for configuring the bot appropriately and for complying with applicable law.

Cookies and similar technologies

The dashboard uses cookies or similar storage needed for the auth session (Supabase) and basic UI preferences (for example theme). We do not use third-party advertising cookies in the sense of remarketing.

Term

Changes to this policy

We may update this page. The effective date is shown above. If the change is material, we will aim to publish the updated version here. Continued use after publication means you are aware of the current version.

Contact

Controller: Devscor, operator of Skord.

For privacy or deletion requests, write to [email protected] and include the Discord server ID when it applies.

You can also read the terms of use.