جاري التحميلLoading

Privacy Policy

2026-09-10

This policy explains what we collect, where it is kept, who reaches it, and when it is deleted. It is part of the same agreement governed by the Terms of Service.

It covers two layers that differ entirely in responsibility: the data of your own account as a customer, and the data of the members of the server where you run your instance. Clause 1 separates them, and everything after it is read in that light.

1. Who is responsible for which data

1.1 For your own account data, we are the controller: we decide why it is collected and how it is processed.

1.2 For your server members' data, you are the controller and we are a processor acting on your behalf and on your instructions. You decide which system runs and what is logged, and the duty to inform your members and to answer their requests falls on you alone.

1.3 Using the bot inside Discord is also subject to Discord's privacy policy, since Discord is the platform the messages and events reach us from in the first place, and we do not control what Discord itself collects.

1.4 This policy does not govern any site, service or server you reach through a link from us. Those parties' policies are their own.

2. Your account data and sign in methods

2.1 Signing in with Discord gives us what Discord itself shares: the account id, the username, the display name and the avatar. Signing in with Google gives us the id, the name, the email address and the picture. You may link more than one identity to a single account.

2.2 If you choose a passkey, we store only the public key and the device id, and the private key never leaves your device. If you enable two step verification we store its secret encrypted. The emergency code is stored encrypted and hashed, and is never visible to us in plain text after it is created.

2.3 Accounts we create at your request, such as your team accounts, are stored with a login name and a hashed code, with no email address and no external account.

2.4 We also store your preferred language, a short support code that identifies your account when you write to us, and the time and method of your last sign in.

2.5 The legal basis for this processing is performance of the contract with you. Without this data no account can be created and no instance can run.

3. Subscription and payment

3.1 Every payment has an order record holding: the plan, the term, the amount, the status and the payment method, the payment address or the memo assigned to you, and the network transaction id once it completes.

3.2 The payment details themselves take place at the payment processor, and only the confirmation and the status reach us. We do not see your private keys, we do not inspect your wallet, and we hold no card data.

3.3 Order records are kept for the period accounting and tax duties require, which is longer than the general retention period in clause 13, and they remain after the account is closed.

3.4 The legal basis here is performance of the contract, and legal obligation as regards accounting records.

4. Technical data and cookies

4.1 On each request we log: the IP address, the browser and device type, the time of the request and the path requested. The purpose is protecting the service from abuse and diagnosing faults, and nothing else.

4.2 We use cookies necessary to run the service: the sign in session, an anti forgery token, and the language and theme preference. We use no advertising cookies and no cross site tracking, we do not sell your data, and we do not share it for marketing purposes.

4.3 We use a human verification service at sign in and registration to prevent automated accounts. It receives the IP address and browser data for that purpose alone.

4.4 An audit log records sensitive events: sign ins, changes to security methods, payment operations, and team changes. It holds the actor's identity, the time of the act, and the IP address.

4.5 The legal basis here is legitimate interest in protecting and securing the service, and performance of the contract as regards necessary cookies.

5. Support and tickets

5.1 Support tickets, their attachments and their messages are stored in our central database, not in your instance, and are read by the staff authorised to handle tickets.

5.2 What you write in a ticket remains stored after it is closed, for follow up, dispute resolution and improving support. Do not put in a ticket sensitive data we do not need to know.

5.3 The legal basis here is performance of the contract and legitimate interest in evidencing what passed between us.

6. Your server's data and its members

6.1 Everything concerning your server is stored in your instance's database alone: system settings, the text and replies you write, the event logs you enable, level and economy points, warnings and moderation records, tickets inside the server, and the media you upload.

6.2 What is stored follows what you enable. A disabled system writes nothing, and a log that is not enabled is never created.

6.3 AI memory, if you enable it, stores the text of the conversations the bot holds with members so that it can follow context. The server brain, by contrast, stores aggregate counts and not text.

6.4 Discord member ids are stored wherever a system requires it: the subject of a warning, the holder of points, whoever opened a ticket, and who joined and who left.

6.5 You decide how long this data stays inside your instance, you may delete it from the dashboard at any time, and all of it is permanently deleted when the instance is deleted under clause 13.

7. Isolation between customers

7.1 Each customer has an independent database and independent storage. No customer's data is mixed with another's, and no customer reaches another's data through any interface.

7.2 The services shared between us and all customers are confined to those that carry no content: routing, monitoring, billing and support.

8. Public media links

8.1 Media you upload for use in messages and announcements is published at public links by design, so that Discord and your members can display it.

8.2 These links require no authentication. Whoever holds the link can open the file. Do not upload to this space anything that must not be seen publicly.

9. Artificial intelligence and content processing

9.1 The artificial intelligence systems run on models belonging to us and operated by us, on compute capacity supplied by external infrastructure providers.

9.2 Those providers do not use your content or your members' content to train their own models, and they are contractually bound not to.

9.3 Enabling these systems means the text of the messages concerned and the media attached to them leave your instance for that processing, and the result returns to it. We use what is necessary from them to develop our own models and their dictionaries.

9.4 Control rests with you: you may disable these systems wholly or partly from the dashboard, and that outflow then stops entirely.

9.5 Output is generated automatically and may be inaccurate, and reviewing what the bot publishes in your server is your responsibility.

10. Helper bots

10.1 Helper bots are our own applications. We ask you for no token and we do not access any developer account of yours.

10.2 What helper bots collect is subject to this same policy, and is stored in your instance and not in any shared location.

11. Who can reach your data

11.1 Access is confined to whoever needs it to do their work: support sees your ticket and the account data needed to serve you, and operations reaches the infrastructure and not, as a rule, the content of your instance.

11.2 Access to the content of your instance occurs only at your request to resolve a problem, or where there is an unavoidable operational necessity, and it is written to the audit log.

11.3 We do not sell your data or your members' data, we do not rent it, we do not share it with advertisers, and we do not use it to build advertising profiles.

11.4 Our staff are bound by confidentiality, and their access lapses as soon as their need for it ends.

11.5 We may share aggregate data that identifies no person, such as the number of running instances or the usage rate of a feature, for measurement and development.

12. Sub processors

12.1 We rely on external providers to perform parts of the service, in defined categories: a compute capacity provider for running the models, hosting, network and data centre providers, an email delivery provider, a payment processor, a human verification provider to prevent automated accounts, and a certificate and anti abuse provider.

12.2 Every sub processor is bound by a contract confining its processing to what we ask, forbidding it from using the data for its own purposes, and requiring security measures equivalent to ours.

12.3 You may request a current list of the sub processors engaged at the time of your request, and it is sent to you at the address in clause 18 within thirty days.

12.4 We remain answerable to you for the acts of sub processors within the scope of what we entrust to them.

13. Retention periods and deletion

13.1 When your subscription ends without renewal your instance keeps running for 3 grace days, then it is stopped and its data remains stored for a further 60 days, during which you may renew and recover everything.

13.2 When that period expires the instance, its database and its files are deleted permanently and irreversibly, and we cannot restore them afterwards by any means.

13.3 Account and identity data is deleted when the account is closed, except what must remain for a legal or accounting duty, or to establish a right in a live dispute.

13.4 Audit logs and technical server logs are deleted after a defined period, shorter than the instance retention period.

13.5 Operational backups rotate on a short cycle and are replaced automatically, so a trace of deleted data may remain in them until their cycle completes.

14. Your rights and your members' rights

14.1 In your account data you have the right: to access it, to correct it, to request its deletion, to obtain a copy of it in a portable format, and to object to processing that rests on our legitimate interest.

14.2 We answer your request within thirty days of receiving it at the address in clause 18. If the request is complex we tell you the additional time needed and why.

14.3 Requests from your server members are addressed to you and not to us, because you are the controller of that layer. We assist you in meeting them through the deletion and export tools in the dashboard.

14.4 If you believe our processing of your data breaches the law, you may complain to the competent authority in your country, and we would prefer that you write to us first so that we can correct what can be corrected.

15. Children

15.1 The service is not directed at anyone under thirteen, and no one under eighteen may subscribe to it under clause 3 of the Terms of Service.

15.2 If we learn that we hold the data of a child below the permitted limit without a basis, we delete it as soon as it is verified. If you are a parent or guardian and believe this has occurred, write to us at the address in clause 18.

16. Where data is held and how it moves

16.1 Data is held on servers at hosting providers that may be located outside your country, and some of it moves between data centres for operational and recovery purposes.

16.2 For every transfer we apply contractual and technical safeguards that preserve the same level of protection, and we confine transfers to what delivering the service requires.

17. How we protect data and what happens in a breach

17.1 The connection between your browser and our servers is fully encrypted, sensitive secrets are stored encrypted, and passwords are stored hashed rather than in plain text.

17.2 Access rests on least privilege, every sensitive access is logged, and administrative accounts are protected by a second factor.

17.3 We separate the infrastructure so that a breach of one instance opens no door onto another, and we monitor the systems around the clock.

17.4 No system is a hundred per cent secure, and we cannot promise you that a breach will never occur. What we promise you is what follows it.

17.5 If a breach affects your data, we notify you without undue delay and at the latest within seventy two hours of becoming aware of it, telling you what happened, which data was affected, what we did, and what we advise you to do.

17.6 If the breach affects your server members' data, we notify you as the controller, and the duty to notify your members and the competent authority, where required, falls on you.

18. Authority requests, changes and contact

18.1 If a formal request from a competent authority reaches us seeking data, we examine its lawfulness and its basis before any response, and we disclose only the minimum expressly required.

18.2 We notify you of the request before disclosure so that you can object to it, unless the law forbids us from notifying you or notification would endanger life.

18.3 We grant no party direct or standing access to our systems or to our customers' data.

18.4 We may update this policy. Any material change is published here with an updated date and notified in the dashboard before it takes effect.

18.5 For anything concerning privacy and your rights in your data: support@simplock.net

18.6 For technical help and day to day questions, the support server on Discord: https://discord.gg/simplock