HarborBot is in active development, so bugs are expected. Check the status page for known issues, or report one.

Privacy Policy

Last updated July 23, 2026

This Privacy Policy explains what information HarborBot ("HarborBot," "we," "us," or "our") collects through the Discord bot and the web dashboard (together, the "Service"), how we use it, and the choices available to you. It should be read alongside our Terms of Service.

1. Information We Collect

We collect only what the Service needs to do its job (moderation case management) and nothing beyond that:

  • Discord identifiers. Discord user IDs and server (guild) IDs for anyone who files a report, is reported, claims or flags a case, or configures the bot. We store these as opaque IDs, not as a profile of who you are outside Discord.
  • Report and case content. The reason text a reporter types into /report or /flag, and the resulting case's status history.
  • Evidence snapshots.When a report or flag is filed, HarborBot captures the last 20 messages in that channel (author, message content, timestamp, and attachment URLs) into the case record. This is the Service's core function (preserving context before a message can be deleted) and only happens when a report or flag actually fires, not continuously.
  • Server configuration. Settings an admin configures, such as which channel case alerts are posted to.
  • Dashboard login and permission data.When you sign in to the web dashboard with Discord OAuth, we receive your Discord identity and, to determine which servers you're authorized to view, a live list of the servers you belong to and your permission level in each. That guild list is checked against Discord's API in real time each time it's needed and is not separately stored by us.
  • Email address. Discord OAuth login also provides us with the email address associated with your Discord account, which we store. We may use it to contact you about the Service, for example product updates or matters affecting your account, and will never share it with third parties for their own marketing purposes.

We do not collect payment card information. Premium billing is handled entirely by Discord's own subscription system, and we never see or store your payment details.

2. How We Use Information

We use the information above solely to:

  • Create, merge, and display moderation cases to a server's authorized moderators;
  • Route case alerts to the channel a server's admin has configured;
  • Determine which servers' data a dashboard user is authorized to see; and
  • Operate, secure, and improve the Service.

We do not use your data to train AI models, sell it, or share it with advertisers. HarborBot is explicitly not AI-powered. No part of your data is fed into a machine-learning system to make judgment calls about you.

3. Who Can See This Data

Case data for a server is visible only to Discord users who currently hold the "Manage Server" permission (or equivalent) on that specific server, whether through the bot's commands or the web dashboard. HarborBot does not expose one server's case data to another server, and members without moderation permissions cannot view case details, only file reports.

4. Third-Party Service Providers

The Service is built on top of a small number of infrastructure providers, each of which processes data on our behalf under its own terms:

  • Discord: the platform HarborBot operates on; all message and identity data originates from Discord's API.
  • Supabase: our database and authentication provider; case data and dashboard login sessions are stored here.
  • Vercel: hosts the web dashboard and marketing site.
  • Linode (Akamai): hosts the always-on bot process that connects to Discord.

We do not sell personal data, and we do not share it with third parties for their own marketing purposes.

5. Data Retention and Deletion

A case persists indefinitely while it is open or claimed; nothing auto-deletes it. Once a case is closed, if auto-delete is enabled for the server (Settings page), it is removed after that server's retention window: a fixed 14 days on the free tier, or a choice of 7, 14, 21, or 30 days on Premium. A server admin can also delete an individual case manually from the dashboard at any time.

Removing HarborBot from a server, whether by kicking the bot or deleting the server itself, immediately and permanently deletes everything for that server: cases, evidence, case notes, Crewmates, and invite codes. There is no grace period, so make sure any open cases are resolved first if you want to keep a record of them. A server admin can also request deletion of that server's data at any time before removal by contacting us at the address below.

6. Data Security

Data is stored with our database provider using industry-standard encryption in transit (TLS) and at rest. Access to the underlying database is restricted to the bot process and the web dashboard's server-side code, both of which authenticate using credentials that are never exposed to end users or stored in client-side code. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. Cookies

The web dashboard sets a session cookie through Discord OAuth login (via our authentication provider, Supabase) so you stay signed in. We do not use advertising, tracking, or analytics cookies.

8. Your Rights and Choices

Depending on where you live, you may have rights to access, correct, or delete personal data we hold about you, or to object to certain processing. You can exercise these rights by contacting us at the address below. If you are a member of a server (rather than that server's admin), the fastest way to stop HarborBot from processing data about you is to ask that server's admin to remove the bot, or to avoid triggering the Service (for example, by not being the subject of a report). Case data about you is created by other members' reports, not something you directly control.

9. Children's Privacy

The Service is not directed at children under 13, consistent with Discord's own minimum age requirement, and we do not knowingly collect data from anyone under that age beyond what Discord itself already provides as part of normal platform operation.

10. International Data Transfers

Our infrastructure is currently hosted in the United States. If you use the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your home country.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

12. Contact

Questions about this Privacy Policy, or requests to access or delete your data, can be sent to contact@harborbot.cc.