Privacy Policy

2026-08-30

1. What this policy covers, and who is responsible

This policy explains what we collect, where it lives, who can reach it, and when it is deleted. It covers two very different layers: your own account data as our customer, and the data of the Discord server where your instance runs.

In the first layer, we are the controller. In the second, you are the controller of your members' data and we process it on your behalf and on your instructions: you decide which systems run and what gets recorded, and it is on you to tell your members about it.

Using the bot inside Discord is also subject to Discord's own privacy policy, since Discord is the platform the messages and events reach us through in the first place.

2. Account data and sign-in methods

Signing in with Discord gives us what Discord itself shares: account ID, username, display name, and avatar. Signing in with Google gives us the ID, name, email address, and picture. You can link more than one identity to the same account.

If you use a passkey, we store the public key and the device ID only, and the private key never leaves your device. If you enable two-step verification we store its secret encrypted. An emergency code is stored encrypted and hashed, and is never visible to us in plain text after it is generated.

Accounts we create at your request, such as accounts for your team, are stored with a login name and a hashed code, with no email and no external account.

We also store your preferred language, a short support code that identifies your account when you contact support, and the time and method of your last sign-in.

3. Subscription and payment

Every payment creates an order record holding the plan, duration, amount, status, payment method, the address or memo assigned to you, and the network transaction reference once it completes.

The payment details themselves happen at the payment processor, and all we receive back is the confirmation and status. We never see your private keys, never look into your wallet, and never hold card data.

Refunds go back to the same method you paid from, which is why we keep the transaction reference for as long as accounting and fraud prevention require.

4. Technical data and cookies

We store the IP address of your last sign-in, and we write sensitive operations to an audit log: sign-ins, subscription changes, team actions, and any support intervention, each with its timestamp and the IP it came from. The purpose is strictly security and accountability, and these entries are deleted automatically once their retention period is over.

We use strictly necessary cookies only: the session cookie, an anti-forgery cookie, and a random device ID used to spot suspicious sign-in attempts. We use no advertising cookies, and we place no third-party analytics on the site or the dashboard. The numbers we look at are computed from our own data.

The sign-in page uses an external human-verification service to keep bots out. It sees the IP address and browser at the moment of the check, and nothing else.

5. Support and tickets

Support ticket messages and their attachments are stored in our central system rather than inside your bot instance, because they are a conversation between you and our team, not server data. Only authorized support staff can read them.

We never ask for credentials, keys, or verification codes in a ticket, and our team will never ask for them on any channel.

6. Your server's data: what is stored, and where

Everything belonging to your server is stored in your own instance's database, on the host it runs on. It is not copied into any shared central database.

What gets stored follows the systems you switch on, and can include: member, role, and channel IDs; level, currency, and game points; warnings and moderation records; your server's tickets and their transcripts if you enable transcripts; invites and who invited whom; suggestions and votes; and every system's settings along with the text you write yourself.

The Server Brain system stores aggregated counts only: how many messages, in which hour, in which channel, and the most repeated words. It does not store message text.

The AI systems, if you enable them, do store the text of conversations held with the bot, their summaries, and a per-member memory that keeps context across sessions. That is real text data, and you can wipe it for one member or for the whole server from the dashboard.

The Discord logs the bot sends, such as a deleted or edited message or a member joining, are posted to a channel you choose and live inside Discord, so they are governed by the permissions you set on that channel.

7. Isolation between customers

Every customer gets a separate instance: its own database with a user scoped to that database alone, its own storage folder, and encryption secrets belonging to that instance only.

Reaching another customer's data is not merely blocked by a conditional check, it is not expressible in the code: every storage handle is bound to its tenant the moment it is created, and every query carries the tenant ID inside the filter itself. This is covered by automated tests that deliberately attempt the breach and fail.

8. Public media links

Images and files you upload for use in the bot's messages are published behind a public link carrying a long random token, because it is Discord itself that fetches them to display them to your members.

That means, plainly: anyone who has the link opens the file without signing in. The token is long enough that guessing it is not practical, but do not upload anything through this tool that you would not want reached.

9. AI and content processing

The AI systems operate only in the scope you define: the channels and systems you enable. While they are off, nothing is sent.

When they are on, what is needed to produce the reply is sent: the message text, the nearby context, and any attached media. Before sending, a sanitizing layer separates member data from instructions and blocks prompt injection into the model.

The models we offer are our own models, running on compute from accredited external providers, and your content is not used to train those providers' models. We may use what passes through these systems to develop our own models and dictionaries and to improve the quality of their replies, stripped of identifying details as far as possible. The list of providers may change as the service evolves.

Image and audio scanning for protection purposes runs on our own servers and never leaves the infrastructure your instance runs on.

10. Helper bots

Helper bots come from our own applications. You never enter a token and we never ask for one: all the dashboard sends when you add a helper bot is its name and its job. The token stays with us, sealed with a key belonging to your instance, and is never shown or exported to you.

Deleting a helper bot from your dashboard detaches it from your instance and returns it to our pool. Because the application is ours, nothing of yours remains in it.

11. Who can access your data

You first, and whoever you grant a permission to on your team, within exactly the bounds you granted.

Support staff do not enter your server's data unless you ask, or to fix a fault you reported, and then only within the scope of that fault, with every intervention written to the audit log.

Infrastructure providers, meaning hosting and network, payment processing, AI compute, and the human-verification service, process a defined portion on our behalf to run the service, and are bound to confidentiality and to using what reaches them for nothing else.

We do not sell your data or your members' data, we do not share it for advertising, and we do not use your account for marketing campaigns.

We may disclose specific data if compelled by a valid legal request, or to protect our rights or people's safety, and then only to the narrowest extent of that request.

12. Retention and deletion

Your instance data stays for as long as your subscription is active, then through the grace period of 3 days, then for 60 days after the instance is paused, during which you can renew and get everything back exactly as you left it.

Once that window passes, the instance, its database, and its files are deleted permanently and irreversibly.

Account data such as orders, invoices, and audit entries is kept afterwards for as long as accounting and fraud prevention require, then deleted automatically.

An account deletion request is carried out by erasing your identity and sign-in methods, while a financial record stripped of identity may remain where the law requires us to keep it.

13. Your rights, and your members' rights

You can access your data, correct it, and export it, since the dashboard's backup gives you your full configuration, and you can request deletion or object to a particular processing.

If a member of your server wants a copy of their data or its deletion, their request goes to you as the controller, and we give you the tools: wiping the AI memory for one member, deleting their data from the systems, resetting their points, and erasing the whole server's data.

You can also complain to the competent supervisory authority in your country if you believe we have not respected your rights.

14. Children

The service is not directed at anyone under thirteen, which is the minimum age Discord enforces and may be higher in some countries. We do not knowingly collect data from anyone below that age, and if such data reaches us it is deleted.

15. Where the data lives and how it moves

Your instance data lives on the host your instance runs on, which may be in a country other than yours. Your account, subscription, and ticket data lives in the central service database.

Running a service on the internet necessarily crosses borders, since Discord and our infrastructure providers operate in multiple locations. We contract them to confidentiality and limit what reaches them to what running the service requires.

16. How we protect the data

Sensitive secrets, meaning tokens, keys, and verification secrets, are stored encrypted, never in plain text.

Every uploaded file is checked by its actual content rather than its extension, and images are re-encoded to drop any hidden payload.

Your server's currency balances are protected by a cryptographic signature that prevents tampering outside the official code paths.

Sign-in is protected by rate limiting and standard security headers, sessions are invalidated on any significant account change, and every outbound request passes a check that blocks access to the internal network.

No system is completely secure. If a breach affecting your data occurs, we will tell you what we know and what we did, as soon as reasonably possible.

17. Changes and contact

We may update this policy whenever the service or the legal requirements change, and any material change is published here with the last-updated date at the top of the page.

For any question about your privacy or your data, contact support from your account page.

Who runs the service, and how to reach them

Simplock is run by an individual, not a registered company, and there is no corporate entity behind it. We say so plainly so you know who you are dealing with before you pay.

To see, correct or delete your data, and for anything about this policy, write to {supportEmail} and we answer within working days.

For faster technical help, the support server on Discord: {supportServer}