Privacy Policy

Last updated July 19, 2026

This Privacy Policy explains what information HarborBot ("HarborBot," "we," "us," or "our") collects through the Discord bot and the web dashboard (together, the "Service"), how we use it, and the choices available to you. It should be read alongside our Terms of Service.

1. Information We Collect

We collect only what the Service needs to do its job — moderation case management — and nothing beyond that:

  • Discord identifiers. Discord user IDs and server (guild) IDs for anyone who files a report, is reported, claims or flags a case, or configures the bot. We store these as opaque IDs, not as a profile of who you are outside Discord.
  • Report and case content. The reason text a reporter types into /report or /flag, and the resulting case's status history.
  • Evidence snapshots.When a report or flag is filed, HarborBot captures the last 20 messages in that channel (author, message content, timestamp, and attachment URLs) into the case record. This is the Service's core function — preserving context before a message can be deleted — and only happens when a report or flag actually fires, not continuously.
  • Server configuration. Settings an admin configures, such as which channel case alerts are posted to.
  • Dashboard login and permission data.When you sign in to the web dashboard with Discord OAuth, we receive your Discord identity and, to determine which servers you're authorized to view, a live list of the servers you belong to and your permission level in each. That guild list is checked against Discord's API in real time each time it's needed and is not separately stored by us.

We do not collect payment card information — Premium billing is handled entirely by Discord's own subscription system, and we never see or store your payment details.

2. How We Use Information

We use the information above solely to:

  • Create, merge, and display moderation cases to a server's authorized moderators;
  • Route case alerts to the channel a server's admin has configured;
  • Determine which servers' data a dashboard user is authorized to see; and
  • Operate, secure, and improve the Service.

We do not use your data to train AI models, sell it, or share it with advertisers. HarborBot is explicitly not AI-powered — no part of your data is fed into a machine-learning system to make judgment calls about you.

3. Who Can See This Data

Case data for a server is visible only to Discord users who currently hold the "Manage Server" permission (or equivalent) on that specific server, whether through the bot's commands or the web dashboard. HarborBot does not expose one server's case data to another server, and members without moderation permissions cannot view case details, only file reports.

4. Third-Party Service Providers

The Service is built on top of a small number of infrastructure providers, each of which processes data on our behalf under its own terms:

  • Discord — the platform HarborBot operates on; all message and identity data originates from Discord's API.
  • Supabase (hosted on AWS, us-east-1) — our database and authentication provider; case data and dashboard login sessions are stored here.
  • Vercel — hosts the web dashboard and marketing site.
  • Linode (Akamai) — hosts the always-on bot process that connects to Discord.

We do not sell personal data, and we do not share it with third parties for their own marketing purposes.

5. Data Retention and Deletion

Today, case data persists until it is deleted — there is not yet an automated retention window in place, regardless of tier. (Tiered automatic retention, with a shorter window on the free tier and extended retention on Premium, is a planned feature described in our product roadmap, but is not yet active; this policy will be updated when it ships.) A server admin can request deletion of that server's case data at any time by contacting us, or by removing HarborBot from the server, which stops any further data collection going forward. Removing the bot does not automatically delete already-stored case history — a separate deletion request is required for that.

6. Data Security

Data is stored with our database provider using industry-standard encryption in transit (TLS) and at rest. Access to the underlying database is restricted to the bot process and the web dashboard's server-side code, both of which authenticate using credentials that are never exposed to end users or stored in client-side code. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. Cookies

The web dashboard sets a session cookie through Discord OAuth login (via our authentication provider, Supabase) so you stay signed in. We do not use advertising, tracking, or analytics cookies.

8. Your Rights and Choices

Depending on where you live, you may have rights to access, correct, or delete personal data we hold about you, or to object to certain processing. You can exercise these rights by contacting us at the address below. If you are a member of a server (rather than that server's admin), the fastest way to stop HarborBot from processing data about you is to ask that server's admin to remove the bot, or to avoid triggering the Service (for example, by not being the subject of a report) — case data about you is created by other members' reports, not something you directly control.

9. Children's Privacy

The Service is not directed at children under 13, consistent with Discord's own minimum age requirement, and we do not knowingly collect data from anyone under that age beyond what Discord itself already provides as part of normal platform operation.

10. International Data Transfers

Our infrastructure is currently hosted in the United States. If you use the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your home country.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

12. Contact

Questions about this Privacy Policy, or requests to access or delete your data, can be sent to contact@harborbot.cc.