Effective date: September 6, 2026
1. Who We Are
Sauna ("Sauna", "we", "us", or "our") provides a Discord bot and accompanying web dashboard (together, the "Service") for ticketing, moderation, leveling, roles, community engagement, analytics, and related server-management features. This Policy applies to the Sauna bot, the dashboard at saunabot.rest, and the API at status.saunabot.rest. Discord separately governs your Discord account under its own privacy policy.
2. Information We Collect
Dashboard sign-in. When you sign in through Discord OAuth, Discord gives us your user ID, username, a short-lived access token, and the servers you own or administer. We use the identify and guilds scopes. We do not request your email, direct messages, friends list, or account password.
Server configuration. We store settings selected by administrators, including channel, message, and role IDs; ticket and Mod Mail configuration, optional ticket questions, Mod Mail block lists and retention choices; automod rules and acknowledgements; auto-role, reaction-role, role-picker, welcome, leave, verification, and leveling settings; custom command programs and drafts (including block contents and workspace layout); canned responses; onboarding progress and feature choices; and dismissed health-check recommendations. Values members enter while running a custom slash command are processed to generate its response and are not stored by the command builder. Answers submitted while opening a ticket are posted inside that private ticket channel and become part of its transcript if the ticket is closed. Server Health reads live server permissions and the saved configuration to produce its checks; the diagnostic snapshot is not sent to a third party or stored separately.
Moderation records. For warnings, timeouts, removed timeouts, kicks, and bans, we store the action, target and moderator Discord IDs, supplied reason where applicable, and timestamp. Cases are capped at the 500 most recent records per server.
Leveling. When enabled, we store accumulated XP and the time of a member's last counted message, keyed by Discord user ID. We do not store message content to calculate XP.
Audit log. We store up to 500 recent server audit entries. These may include message edits or deletions with content truncated to 300 characters, joins, leaves, and role changes, together with relevant Discord IDs and timestamps.
Ticket transcripts. When a ticket closes, Sauna creates a transcript containing the ticket conversation and participant Discord IDs. It may be delivered to a configured Discord channel or to the ticket opener and is also retained for administrator review. Transcripts are capped at the 200 most recent per server.
Mod Mail. When you use Sauna's DMs to contact a server, we send your username, Discord user ID, messages, and attachments to that server's private staff channel. We store the conversation and channel IDs so your conversation still works after a bot restart. Staff replies are sent back to your DMs. The server administrator chooses whether closed conversations are deleted immediately or saved for 7, 30, or 90 days. A saved copy contains the full conversation, attachments, user IDs, and staff-only messages. If a server blocks you from Mod Mail, it stores your Discord user ID until an administrator unblocks you.
Analytics. Sauna keeps day-level server counts such as messages, members, and command usage. These aggregate figures are not tied to individual members and are retained for 90 days.
Member lookup. Administrators can request basic member details already visible to server staff, including username, nickname, avatar, join and account creation dates, and roles. Results are requested live from Discord and are not separately stored by the lookup feature.
Dashboard feedback. A signed-in administrator may send a private star rating and note to Sauna's developer. We include their Discord username and user ID, the selected server's name and ID, the feedback, and its submission time. The current submission is stored in Sauna's database and a private Discord channel. Sending again updates it.
Cookies, sessions, and local storage. oauth_state and oauth_redirect last up to five minutes and secure the login flow. pirtis.sid identifies a dashboard session for up to seven days. Session data, including the Discord access token needed to refresh administrator permissions, is stored in a server-side SQLite database. Cookies are marked httpOnly and secure. The site also uses browser local storage for display preferences, dismissed maintenance announcements, and feedback reminder choices. Feedback reminder data includes the save count, postponement time, dismissal choice, and signed-in Discord user ID. We do not use advertising or third-party analytics cookies.
Technical logs. Hosting and network systems may record IP addresses, request times, errors, and similar technical data for security, abuse prevention, and debugging. We do not use these logs for advertising or profiling.
3. How We Use Information
We use this information to operate configured features, authenticate administrators, enforce server-specific permissions, receive optional dashboard feedback, maintain moderation accountability, provide analytics and transcripts, prevent abuse, and diagnose technical problems.
4. Server Administrators
For server settings and records generated by features an administrator enables, that administrator determines how Sauna is used in their community and is responsible for notices or consents required by applicable law. We process that data to provide the Service. We control dashboard authentication and operational data.
5. Sharing
We do not sell personal data or share it for advertising. We disclose information only to Discord as required to operate a Discord bot; to hosting and infrastructure providers that run the Service; where required by law or necessary to protect users and the Service; or to a successor in a merger, acquisition, or asset sale subject to this Policy.
6. Retention and Deletion
- Moderation cases and audit entries: the 500 most recent per server.
- Ticket transcripts: the 200 most recent per server.
- Mod Mail transcripts: none, or up to 7, 30, or 90 days as selected by the server administrator, with a 200-transcript cap per server.
- Aggregate analytics: 90 days.
- Dashboard sessions: up to seven days, deleted on logout or expiry.
- Server configuration and leveling data: retained until changed or deleted by an administrator or Service operator.
- Dashboard feedback: retained until you update it or ask us to delete it.
- Production backups: retained for up to 14 days; deleted data may remain in a backup until that backup expires.
Removing Sauna from a Discord server does not by itself guarantee immediate deletion of stored server data. A server administrator can request deletion using the contact address below.
7. Security
We use HTTPS/TLS, secure and HTTP-only session cookies, access controls, rate limiting, restricted production access, and routine backups. No transmission or storage system is completely secure, so absolute security cannot be guaranteed.
8. International Transfers
Infrastructure providers may process data outside your country. Where applicable, we take steps intended to provide protections required for transfers from the EEA or UK.
9. Your Rights
Depending on where you live, you may have rights to access, correct, delete, export, object to, or restrict processing of personal data. For server-specific records, contact the relevant server administrators first or contact us for assistance. You can clear your dashboard session by logging out. EEA and UK residents may also complain to their local data-protection authority.
10. Children's Privacy
Discord requires users to be at least 13 or the minimum age required in their country. We do not knowingly collect data from children below the applicable age.
11. Changes
We may revise this Policy as the Service changes. Material updates will be reflected by changing the effective date and, where appropriate, providing additional notice.
12. Contact
Questions and data requests can be sent to privacy@saunabot.rest.
