Privacy Policy
Last updated: 2026-07-28
KyvoBot ("we", "us", "the Bot") is a Discord bot and companion web dashboard that provides server moderation, leveling and economy, party recruiting, AI-powered ticket support, and related community-management features. This policy explains what data we collect, how we use it, and how you can request it be deleted.
1. Who We Are
KyvoBot is a free, independently-operated Discord bot and is not a registered company. This policy covers data handled by the Bot itself and by its companion web dashboard.
2. Information We Collect
a. Discord account data (dashboard login)
When you log in to the dashboard with Discord, we receive your Discord user ID, username, and avatar via OAuth. We do not request or receive your email address. Your Discord access token and language preference are stored only in an encrypted session cookie in your own browser - never in our database. The list of servers you belong to is fetched from Discord's API each time you use the dashboard, and is cached for at most 60 seconds by our hosting infrastructure (a standard Next.js request cache) - it is not stored in our database or in Redis.
b. Data linked to your Discord account, per server
When you use the Bot's commands in a server, we may store the following, tied to your Discord user ID and that server's ID: • Economy/leveling data: points, XP, and level • League of Legends account link (/tier_verify): we send the Riot ID (game name + tag line) you provide to Riot Games' API and receive back your PUUID and ranked tier/rank/LP in response, which we store together with the Riot ID and a verification timestamp • Steam account link (/steam_link): the SteamID64 you provide (self-reported - we do not verify you own the account), plus a cached snapshot of your CS2 inventory analysis • Twitch live-role linkage: the Discord member ID an admin links to a tracked Twitch streamer • Your personal rank-card style preferences • Your saved favorite game preset • Party/scrim/quick-RSVP/giveaway participation history: which recruitment posts you joined or led, your self-reported tier, timestamps, and status • Anonymous reports: if you submit a report via /anonymous_report, the full report text and your Discord user ID are stored in our database for anti-abuse purposes, even though your identity is never shown to server admins in the dashboard or on Discord • If you are banned from the anonymous report system, that ban record (your Discord ID and the admin who applied it) • Automated moderation action logs: your Discord ID, the action taken, and a brief reason (which may include a short excerpt of the message that triggered it) - full message content is not stored • AI ticket support feedback: which knowledge-base entry answered your question and your 👍/👎 rating - not the conversation text itself (see Section 3 for how ticket conversations are actually processed)
c. Server (guild) configuration data
Server administrators can configure settings through the dashboard - automod thresholds, welcome/goodbye messages and channels, leveling/economy rules, custom command macros, ticket panel text and AI instructions, party presets, tier-to-role mappings, and the server's preferred bot language. This configuration data is not personal to any individual member.
3. Third-Party Services We Share Data With
• OpenAI: when a member asks the AI ticket support a question, that question is sent to OpenAI's API to generate an answer. When a ticket is closed, up to the last 150 messages in that ticket channel are sent to OpenAI's API to generate a short summary, which is then posted as a Discord message in the server's admin log channel - this summary is never saved in our database. • Riot Games: the Riot ID (game name + tag line) and region you provide are sent to Riot's API to look up your PUUID and ranked tier. • Valve (Steam): the SteamID64 you provide is sent to Steam's Web API to retrieve your public profile and CS2 inventory. • Twitch: broadcaster IDs and login names are sent to Twitch's API and EventSub webhook system to detect when a linked streamer goes live. • Discord: as a Discord bot and OAuth application, all of the above ultimately flows through Discord's platform, which has its own privacy policy.
4. Information We Do Not Collect
We do not collect your email address; real-time or precise location data (GPS or similar); payment or billing information; or voice/audio content - our "Join to Create" feature only detects when you join or leave a voice channel, it never records or processes audio. We do not use any third-party analytics or tracking scripts.
5. How We Use Your Information
We use the data described above solely to operate the features you or your server's administrators enable - for example, tracking XP for leveling, verifying a linked Riot/Steam account for the relevant commands, remembering your saved preferences, and applying automated moderation rules a server's admins configured.
6. Data Retention & Deletion
We do not currently have an automated process that deletes a server's data when the Bot is removed from that server - data tied to a server ID remains in our database indefinitely unless deleted manually. If you would like your personal data, or a server's data, deleted, please contact us at doyouknow4953@gmail.com and we will process your request manually.
7. Children's Privacy
Discord requires users to be at least 13 years old (or the minimum age required in your country). We do not knowingly collect data from anyone who does not meet Discord's own age requirements.
8. Changes to This Policy
We may update this policy as the Bot's features change. Significant changes will be reflected by updating the "last updated" date above.
9. Contact Us
Questions about this policy, or requests regarding your data, can be sent to doyouknow4953@gmail.com.