Privacy Policy
Last updated: September 16, 2026
1. Introduction and Scope
This Privacy Policy describes how Chopstick308 ("we," "us," or "our"), the operator of Sentinel, collects, uses, stores, and shares information in connection with the Sentinel Discord bot and web dashboard (collectively, the "Service"). By using the Service, you agree to the practices described in this Policy.
This Policy applies to all users of the Service, including Discord server administrators, server members whose servers have Sentinel installed, and individuals who access the Sentinel web dashboard at sentinelbot.gg. It does not apply to third-party services that Sentinel integrates with — please review the privacy policies of Discord, Stripe, OpenAI, Anthropic, Twitch, YouTube/Google, top.gg, Discord Bot List, and feed publishers separately.
2. Discord Privileged Intents
To operate in Discord servers that invite Sentinel, the bot requests Discord’s privileged Gateway intents. These intents allow the bot to receive certain events from Discord. We use them only to provide features configured by server administrators:
- Message Content Intent: Required to read message text for keyword and AI auto-moderation, leveling/XP from chat, custom commands and automation triggers, sticky messages, prefix commands, and related text-based features.
- Server Members Intent: Required for join/leave and member-aware features such as welcome and goodbye messages, verification gates, moderation actions, role assignment (reaction roles, voice-linked roles, level rewards), giveaways, LFG, tickets, leaderboards, member pickers in the dashboard, antiraid join tracking, and server backup member lists.
- Presence Intent: Required for online/offline statistics such as live “online members” counters when Statistics Channels (or similar status features) are enabled.
Privileged intents are not used for advertising, selling data, scraping private DMs for marketing, or tracking users across unrelated servers for third-party purposes.
3. Information We Collect
We collect information only to the extent necessary to provide and improve the Service.
3.1 Information you provide directly
- Dashboard configuration: When you configure Sentinel through the web dashboard, we store your settings including channel IDs, role IDs, welcome message text, auto-moderation sensitivity levels, automation rule content, embed template content, custom command responses, sticky and reminder text, poll content, verification panel settings, and any other options you explicitly save. This is treated as server configuration data.
- Discord OAuth authentication: When you sign in to the dashboard using Discord, we receive your Discord user ID, display name (global name or username), and avatar URL from Discord's OAuth API (scopes: identify and guilds). We store these for the duration of your session to display your profile and verify your permissions, along with the list of Discord servers (guild IDs) you belong to and which servers you are permitted to manage. We also store Discord OAuth access and refresh tokens server-side for the session so the dashboard can refresh guild membership and permissions. We do not receive your email address, phone number, or Discord password.
- Voluntary feedback and suggestions: If you use
/feedback,/suggestion, or reply to a removal-feedback direct message, we receive the message content you submit (and any attachments you include) together with your Discord user ID, username, and related guild context so we can review it.
3.2 Message content — processing vs storage
- Processed in real time: In servers where Sentinel is present, message content may be processed (not necessarily stored) to power features such as keyword auto-moderation, leveling XP eligibility, custom commands, automations, sticky reposts, and prefix/slash command handling.
- Forwarded to AI providers: When AI Auto-Moderation, Full AI, or related AI features are enabled by a server administrator, message content (or extracted page text for AI Website Tracking / theme generation prompts) may be sent to OpenAI and/or Anthropic for analysis. Those providers process data under their own privacy policies.
- Stored by Sentinel in limited cases: We may store user-authored or message-derived text when needed for a feature, including sticky message text, reminder text, ticket transcript content (when transcripts are enabled), custom command and automation text, embed/panel content, and short command/dashboard action payloads used for operator debugging (see Section 3.6). We do not operate a general searchable archive of all server chat history.
3.3 Information collected automatically through use of the Service
- XP and leveling data: When the leveling system is enabled in a server, we record message activity to calculate experience points and assign levels. This data is associated with your Discord user ID and the server's guild ID.
- Infraction records: When a server moderator issues a warn, timeout, kick, or ban through Sentinel, we log the action, the target user's Discord ID, the moderator's Discord ID, and any reason provided. This data serves as the server's moderation history.
- Economy data: When economy features are enabled, we store Discord user IDs together with wallet and bank balances, inventory items, cooldowns, and related game, gambling-session, or shop state. Depending on server configuration, economy data may be scoped per server (local mode) or shared across participating servers (global mode). Global mode may be the default for servers that have not selected otherwise; local mode may require Premium where the dashboard so indicates.
- Giveaway and reaction role entries: We store user IDs in association with giveaway entries and reaction role assignments as needed to operate those features.
- Server analytics (when enabled): We may store per-user activity aggregates such as message counts and join/leave events associated with Discord user IDs and guild IDs to power the analytics dashboard. Older analytics rows are archived or purged on a rolling schedule (typically about ninety (90) days).
- AI Website Tracking: When AI Website Tracking is enabled, we store the configured URL, tracking description, check interval, alert channel ID, and the latest extracted value, summary, content hash, and check status for each tracker. To perform checks, Sentinel fetches the public webpage and sends extracted page text to OpenAI and/or Anthropic for analysis. We do not retain full page archives of every check — only the data needed to operate the tracker and detect changes.
- Community and server feature data: Depending on which features are enabled, we may store Discord user IDs together with related server data such as: birthday month/day and optional birth year; ticket thread metadata, opener user IDs, and transcript content when transcripts are used; invite counts and inviter associations; LFG post host IDs and descriptions; giveaway and reaction-role participation; voice-linked role assignments; antiraid join-event timestamps; poll and reminder content; and custom command or automation configuration you save.
- Guild and server metadata: When Sentinel joins or rejoins a Discord server, we record the guild ID, guild name, guild owner Discord user ID, and join timestamps (initial join and most recent rejoin). If Sentinel is removed from a server, we retain this metadata together with removal timestamps and tenure information for operational, analytics, and service-improvement purposes even after the bot no longer has access to the server.
- Direct messages to server owners: When Sentinel joins a server, we may post a welcome message in a server channel and/or send an optional onboarding direct message to the server owner with setup links and feature information. We may also send occasional product or patch-note direct messages to server owners. When Sentinel is removed from a server, we may send an optional direct message to the server owner soliciting voluntary feedback. If the owner replies within the active reply window (currently twenty-four (24) hours from the outreach message), we forward the reply content — and any attachment filenames or files the owner included — to our internal operator support channel. We record outreach metadata (owner user ID, guild ID, guild name, tenure, send time, and whether a reply was received) to route replies correctly and prevent duplicate forwarding.
- Growth and churn analytics (operator-only): We maintain aggregated bot-wide metrics such as server join and leave counts, member join and leave events, and periodic snapshots of total servers and members. For servers from which Sentinel was removed, we retain guild ID, guild name, owner Discord user ID (where available), join and removal dates, and tenure. These records are used exclusively for internal operational analytics and are not sold or used for advertising.
- Welcome verification gate (Premium): When enabled by a server administrator, new members may be required to complete a verification interaction (for example, clicking a Verify button on a verification panel) before receiving full access. We store verification configuration (channel, role, and embed settings) and process verification interactions needed to assign or withhold roles. Temporary role restrictions applied during verification are configured by the server administrator.
- Server backups (Premium): When enabled, we create and store compressed snapshots of server structure — including roles, channels, permission overwrites, related Sentinel plugin configuration, and member roster metadata such as Discord user IDs, display names/nicknames, and role membership lists — to support restore operations initiated by server administrators. Snapshots are stored on our infrastructure and associated with the guild ID.
- MEE6 XP import: When a server administrator initiates a MEE6 import, we fetch publicly available leaderboard data from MEE6's API and/or process administrator-uploaded JSON or CSV export files. We store imported XP, level, and username mappings, and optional role-reward associations, solely to apply them to the server's leveling configuration. We do not guarantee the accuracy or completeness of imported data.
- RSS and news feed polling: When the news feed feature is enabled, we store configured feed URLs, display labels, target channel IDs, polling schedule metadata, and the identifiers of the most recently seen items. On a recurring schedule, Sentinel fetches those publicly accessible third-party RSS or Atom feeds to detect and post new entries.
- Twitch and YouTube alerts: For stream or upload alerts, we store alert configuration (channel/broadcaster identifiers, target Discord channel, message template, and polling state) and may call Twitch or YouTube/Google APIs to detect new content. If a server enables Twitch subscriber role linking, members who authorize access through Twitch OAuth provide OAuth tokens that we store (access token, refresh token, and expiry) together with their Discord user ID, Twitch user ID, Twitch login, guild ID, and subscription-check status. Short-lived OAuth state tokens used during the authorization handshake are discarded after use or expiry (currently ten (10) minutes). Removing the bot from a server does not always instantly wipe all alert or link records; deletion follows unlink, admin action, verified request, or our retention practices below.
- Bot-list votes and rewards: If you vote for Sentinel on listings such as top.gg, we may receive a webhook notifying us of your Discord user ID and store vote timestamps, streaks, and related reward state (including optional DM preferences) to grant configured rewards.
3.4 Payment and billing information
- If you purchase a Premium subscription, we store your Stripe Customer ID, Stripe subscription ID, subscription status (active, cancelled, past-due), and the Discord user ID of the Premium purchaser (premium buyer) to verify and manage billing access. If Premium or Fast Tracking is activated through a License Key, we store key expiry information and redemption metadata associated with the server. Full payment card details are collected, processed, and stored exclusively by Stripe — we never receive, see, or store your card number, CVV, or bank account details.
- If you purchase Full AI credit packs, we store the pack purchased, credit amount, Stripe payment identifiers, guild ID, purchaser Discord user ID, and resulting credit balance and transaction history for that server. Stripe processes the payment; we do not store card details.
- If you use Premium transfer, we log your Discord user ID, source guild ID, destination guild ID, and transfer timestamp to enforce monthly transfer limits. If you submit a subscription cancellation reason through the billing dashboard, we store that reason together with your Discord user ID and guild ID.
3.5 Full AI usage statistics
- On Premium servers with Full AI enabled, we store credit balance, credit purchase and consumption records, scans used in the current billing period (where applicable), and optional scan-limit settings configured by server administrators. These statistics are used to operate billing, enforce limits, and display usage in the dashboard.
3.6 Operator action and error logs
- To keep the Service reliable, we may record command and dashboard action events — including guild name/ID, user name/ID, action or command name, non-secret argument/payload summaries, success or failure status, and error traces — and forward them to our internal operator Discord channels (for example activity and error log channels). These logs are used for debugging, abuse investigation, and operational monitoring. They are retained for a limited period (currently about thirty (30) days) and then deleted.
3.7 Technical and session data
- The web dashboard uses a first-party session cookie that stores an opaque session identifier. The corresponding server-side session record may include your Discord user ID, display name, avatar URL, OAuth access and refresh tokens, and guild permission lists for the duration of the login. Short-lived cookies may also be used during the OAuth login handshake. Session data is discarded when you log out or the session expires.
- We may also receive aggregate listing statistics requests from bot lists (for example approximate server or user counts) as part of normal bot-list integrations.
4. How We Use Your Information
We use the information we collect only for the following purposes:
- Service delivery: To operate and deliver the features you and your server administrators configure, including moderation, welcome and verification, leveling, economy, giveaways, tickets, alerts, backups, and all other Sentinel features.
- Authentication and authorization: To verify your identity and permissions when you access the web dashboard, and to determine which servers and settings you are permitted to manage.
- Billing and subscription management: To process and manage Premium subscription payments through Stripe, verify active subscriptions, and handle billing inquiries.
- Service improvement and debugging: To diagnose errors, investigate abuse or policy violations, and improve the reliability and security of the Service — including reviewing operator action/error logs, voluntary feedback, and aggregated growth/churn metrics.
- Legal compliance: To comply with applicable laws, respond to lawful requests from authorities, and enforce our Terms of Service.
We do not use your data for advertising, behavioral profiling, or any sale to third parties.
5. How We Share Your Information
We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:
- AI providers (OpenAI / Anthropic): Message content, tracking page text, or admin-provided theme prompts may be forwarded to these providers when AI features are enabled in a server. Each provider processes this data under their own privacy policy and data processing terms.
- Stripe: Billing information necessary to process Premium subscriptions and credit packs is shared with Stripe, Inc. Stripe may collect additional information from you directly during checkout.
- Discord: Sentinel interacts with Discord's API to function. Discord's privacy policy governs their collection and use of data arising from those interactions.
- Twitch and YouTube/Google: Stream and upload alert polling and Twitch OAuth token exchange occur with those providers under their respective privacy policies. We store resulting tokens and alert state solely to operate the configured features.
- Bot listing sites (for example top.gg): We may send aggregate statistics (such as server counts) and receive vote webhooks. Those sites are subject to their own privacy policies.
- Operator support channels: Action/error logs, voluntary
/feedbackor/suggestionsubmissions, and replies to removal-feedback DMs may be visible to the Service operator in our internal Discord support channels. They are not sold or shared with unrelated third parties. - Legal requirements: We may disclose your information if required to do so by applicable law, regulation, legal process, or a valid governmental or law enforcement request. Where permitted, we will attempt to notify you of such requests.
- Protection of rights: We may disclose information where we believe disclosure is necessary to protect the rights, property, or safety of us, our users, or others, or to detect, prevent, or address fraud, security, or technical issues.
- Business transfers: If the Service is acquired by or merged with another entity, your information may be transferred as part of that transaction. We will notify you of any such change and any changes to this Privacy Policy.
6. Data Retention
We retain data for as long as necessary to operate the Service and fulfill the purposes described in this Policy, subject to the following:
- Server configuration data is retained for as long as Sentinel remains in your server, and for a reasonable period thereafter in case of re-addition. When we permanently delete server data (including after verified deletion requests), we aim to complete removal within about ninety (90) days where practicable; removing the bot from a server does not by itself guarantee immediate wipe of all stored records.
- XP and leveling data is retained until a server administrator resets it or you submit a deletion request.
- Economy balances and inventory are retained until reset by a server administrator, economy features are cleared, or you submit a deletion request.
- Infraction records are retained as part of server moderation history until a server administrator deletes them or you submit a deletion request.
- Server analytics aggregates are retained on a rolling basis (typically about ninety (90) days) and then archived or deleted.
- Operator action and error logs are retained for about thirty (30) days and then deleted.
- Session data (including profile fields and OAuth tokens held server-side) is stored only for the duration of your active login session and is discarded when your session expires or you log out.
- Billing data (Stripe Customer ID, subscription status, premium buyer ID, credit balances, credit transaction history, and key expiry dates) is retained for as long as your subscription or credit balance is active and for a reasonable period afterward to handle billing inquiries or disputes.
- Full AI usage statistics are retained while Sentinel remains in the server and for up to 90 days after removal or credit exhaustion, unless a server administrator requests earlier deletion.
- AI Website Tracking data is retained until a server administrator deletes the tracker or removes Sentinel from the server.
- Premium transfer and cancellation logs are retained as long as needed to enforce transfer limits, investigate abuse, and resolve billing disputes.
- Guild metadata after removal (guild ID, guild name, owner Discord user ID, join and removal timestamps, and tenure) is retained for operational analytics and service improvement. We aim to limit individually identifiable removal records to about ninety (90) days where practicable, or longer only in aggregated or operator-analytics form needed to run the Service; you may request deletion as described in Section 11.
- Removal feedback outreach records and voluntary reply content are retained for the reply window and thereafter only as long as needed to review feedback and improve the Service (typically not exceeding ninety (90) days), unless needed to resolve an active support inquiry.
- Growth and churn analytics (aggregated join/leave counters and related operational records) are retained for internal operational purposes.
- Server backup snapshots (Premium) are retained until a server administrator deletes them or they are rotated out by the snapshot limit (currently five per server). After deletion or rotation, we aim to remove snapshot files within about ninety (90) days where practicable. Removing the bot from a server does not always instantly delete existing snapshots; contact us or delete snapshots from the dashboard when available.
- MEE6 import data is retained as part of the server's leveling configuration until reset by a server administrator or deleted pursuant to a server data deletion request.
- News feed configuration and last-seen item IDs are retained while the feature remains enabled and for up to ninety (90) days after the feed is disabled or Sentinel is removed.
- Twitch OAuth tokens and link records are retained while subscriber role linking remains enabled for the member and server. Tokens are deleted when a member unlinks their account, an administrator disables the feature, a verified deletion request is fulfilled, or we purge records under our retention practices after the Service is no longer used for that server.
- Vote reward records are retained while needed to grant streaks/rewards and for a reasonable period afterward for abuse prevention.
7. Data Security
We implement reasonable technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include opaque or encrypted session credentials, private server infrastructure, and access controls limiting who can interact with stored data.
However, no method of electronic storage or internet transmission is 100% secure. We cannot guarantee absolute security of your data. In the event of a data breach that affects your personal information, we will notify affected users through the dashboard or Discord as soon as reasonably practicable and as required by applicable law.
8. Cookies and Tracking
The Sentinel web dashboard uses first-party cookies to maintain your authenticated state after you log in with Discord and to complete the OAuth handshake. The primary session cookie:
- Contains an opaque session identifier — profile and token data are stored server-side, not embedded in the cookie;
- Is deleted when you log out or your session expires;
- Is required for the dashboard to function; it cannot be disabled while using the authenticated portions of the site.
We do not use advertising cookies, third-party tracking cookies, analytics pixels, or fingerprinting technologies. Marketing pages may load fonts or similar static assets from third-party CDNs (for example Google Fonts); that is not advertising or cross-site behavioral tracking. We do not respond to "Do Not Track" (DNT) browser signals at this time because we do not engage in the cross-site tracking that such signals are designed to prevent.
9. Children's Privacy
The Service is not directed to children under 13 years of age, and we do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe that a child under 13 has provided personal information to us, please contact us through our support server immediately and we will take steps to delete that information promptly.
Server Administrators are responsible for ensuring their use of Sentinel complies with the Children's Online Privacy Protection Act (COPPA) and any other applicable laws regarding minors.
10. Your Rights and Choices
Depending on where you are located, you may have the following rights with respect to your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data. Note that your username and avatar URL are sourced from Discord and must be updated there.
- Deletion: Request deletion of your personal data. See Section 11 for details.
- Restriction: Request that we restrict processing of your data in certain circumstances.
- Portability: Request a copy of your data in a structured, machine-readable format.
- Objection: Object to our processing of your data in certain circumstances.
To exercise any of these rights, please contact us through our Discord support server. We will respond to verified requests within 30 days. We may need to verify your identity before fulfilling a request.
11. Data Deletion Requests
You may request deletion of specific personal data associated with your Discord user ID at any time:
- XP and level data: Can be reset by a server administrator through the dashboard, or by contacting us.
- Economy balances and inventory: Can be reset by a server administrator where tools exist, or by contacting us.
- Infraction records: Can be deleted by a server administrator through the dashboard, or by contacting us.
- Twitch links, vote records, analytics rows, and action-log entries: Can be removed upon verified request where still retained in our systems.
- All personal data: To request full deletion of all data associated with your Discord user ID across all servers, contact us through our support server. We will fulfill verified requests within 30 days where practicable. Note that we cannot delete data that server administrators are required to retain for their own legal compliance purposes, or data that has already been purged from our systems.
12. California Residents — CCPA Rights
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with the following additional rights:
- Right to Know: You have the right to request information about the categories and specific pieces of personal information we have collected about you in the past 12 months, the sources of that information, the purposes for which it was collected, and the categories of third parties with whom it was shared.
- Right to Delete: You have the right to request deletion of personal information we have collected from you, subject to certain exceptions.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights. We will not deny you the Service, charge you different prices, or provide a different quality of service because you exercised your privacy rights.
- Right to Opt-Out of Sale: We do not sell personal information. You do not need to opt out.
To exercise your California privacy rights, contact us through our Discord support server. We will verify your identity before fulfilling any request.
13. International Users
The Service is operated from the State of Florida, United States. If you are accessing the Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States. By using the Service, you consent to the transfer and processing of your information in the United States, which may have data protection laws that differ from those in your country.
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you may have additional rights under the General Data Protection Regulation (GDPR) and similar laws, including the right to access, correct, delete, or restrict processing of your personal data, and the right to lodge a complaint with your local supervisory authority. We process personal data as necessary to provide the Service (contract), to secure and improve the Service (legitimate interests), and, where Server Administrators enable AI or monitoring features, based on their configuration of the Service for their community. To exercise GDPR-related rights, contact us through our support server.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes — particularly those that affect how we use your personal data or your rights — we will make reasonable efforts to notify active users through the dashboard or Discord before the changes take effect. Your continued use of the Service after changes are posted constitutes your acceptance of the revised Policy.
15. Contact
For privacy-related inquiries, data access requests, data deletion requests, or to report a potential privacy issue, please contact us through our Discord support server or via the /support command in any server with Sentinel. We aim to respond to all privacy inquiries within 30 days.