This Privacy Policy explains how Momentum Bot (“Momentum”, “we”, “us”, “our”) collects, uses, and protects information when you use our Discord bot, website at momentumbot.gg, and related services (collectively, the “Service”). We are committed to transparency and to complying with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), and other applicable privacy laws.
1. Who We Are
Momentum Bot is operated as a Discord application. For data-protection inquiries, contact our Data Protection Officer at legal@momentumbot.gg.
We act as a data controller for information we collect directly (e.g. website analytics, support emails) and as a data processor on behalf of server administrators for moderation data generated inside their Discord servers.
2. What Data We Collect
2.1 Account & Server Data
When Momentum is added to a Discord server, we receive via the Discord API:
- Server ID, server name, and member count
- IDs of administrators who add or configure the bot
- Channel IDs where the bot is permitted to operate
2.2 Moderation Data
When the bot takes or logs a moderation action, we store:
- The Discord ID of the affected user
- The reason, timestamp, and type of action (timeout, kick, ban, etc.)
- The moderator ID who triggered or approved the action
- Case file content and audit-trail entries
2.3 Threat-Intel Data
To detect repeat offenders across servers, we store:
- Discord IDs of users flagged as scammers, spammers, or severe violators
- A category label and a confidence score
- The originating server ID and timestamp
We do not store message content beyond what is needed to log a moderation reason. We do not store profile pictures, friend lists, or DM content.
2.4 Billing Data
Premium subscribers’ payments are handled by Stripe. We receive your email address and subscription tier; Stripe holds your card details. See Stripe’s Privacy Policy.
2.5 Website & Support Data
- Cookies & analytics: see Section 4 below.
- Support emails: the content of your message and your email address, retained until the issue is resolved plus 90 days.
2.6 Lawful Basis (GDPR)
We process personal data under the following lawful bases:
| Purpose | Lawful basis |
|---|---|
| Providing the moderation Service | Performance of a contract (Art. 6(1)(b)) |
| Threat-intel sharing across servers | Legitimate interests (Art. 6(1)(f)) |
| Billing & subscription management | Performance of a contract |
| Website analytics | Consent (Art. 6(1)(a)) |
| Legal record-keeping | Legal obligation (Art. 6(1)(c)) |
3. How We Use Data
- To operate, log, and audit moderation actions in your server
- To detect and prevent abuse, scams, and spam across participating servers
- To process Premium subscriptions and prevent fraud
- To improve the Service’s accuracy and reliability
- To respond to support requests and legal inquiries
We do not sell personal data. We do not use personal data to train external AI models.
4. Cookies
Our website uses cookies and similar technologies for the limited purposes below. We follow ePrivacy Directive (EU) and PECR (UK) requirements: non-essential cookies are only set after you consent via the cookie banner.
4.1 Essential Cookies
These are required for the site to function and are set without consent:
| Cookie | Purpose | Duration |
|---|---|---|
cookie_consent |
Stores your cookie preference | 12 months |
cookie_consent_at |
Timestamp of your choice | 12 months |
4.2 Analytics Cookies (optional)
If you consent, we may load analytics to understand aggregate traffic. These are blocked until you accept.
4.3 Managing Cookies
You can withdraw consent at any time by clicking “Cookie settings” in the footer or by clearing your browser cookies. Essential cookies remain active.
5. Data Sharing
We share data only in these circumstances:
- Discord Inc. — to operate the bot via their API. See Discord’s Privacy Policy.
- Stripe — to process payments.
- Hosting & infrastructure providers — under data-processing agreements.
- Server administrators — they can access and export moderation data for their own server.
- Legal authorities — where required by law or to protect rights, safety, or property.
We never sell data to third parties or share it for cross-context behavioral advertising.
6. International Transfers
Momentum is hosted in the European Union. Where data is transferred outside the EU/EEA (e.g. to Discord or Stripe in the US), we rely on Standard Contractual Clauses (SCCs) and the safeguards those providers have in place under EU law.
7. Data Retention
| Data type | Retention period |
|---|---|
| Active moderation case files | While the bot is in your server + 90 days |
| Banned-user records | Duration of the ban + 90 days |
| Threat-intel records | 24 months from last confirmed incident, then anonymized |
| Billing records | 7 years (legal/tax obligation) |
| Website analytics | 14 months |
| Support emails | Until resolution + 90 days |
You can request earlier deletion where legally permitted (see Section 8).
8. Your Rights
Depending on where you live, you may have the following rights:
- Access — request a copy of your data
- Rectification — correct inaccurate data
- Erasure — request deletion (“right to be forgotten”)
- Restriction — limit processing in certain cases
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
- Withdraw consent — for consent-based processing (e.g. analytics cookies)
- No retaliation — we will not degrade your Service for exercising rights
California residents additionally have rights under the CCPA/CPRA to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information as defined by California law.
To exercise any right, email legal@momentumbot.gg from the email associated with your Discord account and include your Discord user ID. We respond within 30 days, extending to 90 days for complex requests with notice.
9. Children’s Privacy
Momentum is not directed at children under 13 (or the minimum Discord age in your country). We do not knowingly collect data from anyone below that age. If you believe we have, contact us and we will delete it.
10. Security
We use industry-standard measures including TLS encryption in transit, encrypted storage at rest, scoped access controls, and regular security review. No method is 100% secure; we will notify affected users and regulators of any breach within 72 hours as required by GDPR Art. 33.
11. Changes to This Policy
We may update this Privacy Policy. Material changes will be announced via our support Discord or by email. The “Last updated” date above reflects the latest revision.
12. Contact & Supervisory Authority
Questions or requests? Email legal@momentumbot.gg.
EU/UK residents have the right to lodge a complaint with their local data-protection supervisory authority. You can find your authority via the European Data Protection Board or the UK ICO.