Privacy Policy

Who we are

The Roleplay Bot is operated by Offir Gutte, an individual based in Israel, trading as "The Roleplay Bot." This is not currently a registered business. For the data we decide the use of — accounts, billing, security and running the service — that operator is the controller. For the content and configuration inside your own Discord server, the picture is different and it matters: see "Our role, and yours" below.

For anything in this policy, or any privacy-related notice, contact support@theroleplaybot.site or see the Support page.

What personal data we collect

The short answer, for anyone deciding whether to add the bot to their server: we collect what your Discord account tells us when you sign in, what you and your staff configure and record through the features you switch on, and — only if you buy something — a record of that purchase. We do not ask for your email address, your real name, your phone number, your address or your date of birth, and nothing here is used for advertising or sold to anyone.

Discord account information

Roblox identity (only if a server turns it on)

Some servers use a Roblox roleplay feature that links a member's Discord account to their Roblox account. This is off by default and only applies where a server's staff has switched it on.

This is not a Roblox product and is not endorsed by, affiliated with, or supported by the Roblox Corporation. "Roblox" is a trademark of the Roblox Corporation. What travels between us and Roblox is exactly what Roblox's own sign-in feature sends when you choose to use it — we do not have any other access to your Roblox account.

Discord server and community information

Content created through the features you turn on

This is the category most worth reading carefully, because what ends up here is decided by your server's staff, not by us — see "Our role, and yours".

Billing and purchase information

Support, feedback and security communications

Technical and security data

Our role, and yours

A fair question before adding any bot to a community is "who is actually deciding what happens to this data?" There are two answers, because there are two different kinds of data here.

For your account, billing, security, legal-acceptance and service-operation data, we decide. We determine what is collected and how it is used in order to run, secure and bill for the service, and everything above describes those decisions. Questions, corrections and deletion requests about that data come to us — see "Your rights and choices" below.

For what happens inside your Discord server, you decide, and we carry it out. The server's owner and staff choose which features to turn on, what questions an application asks, what a ticket is for, what is written in an infraction reason or a staff note, and who on the team can see any of it. We provide the tool and run the service that stores and displays it — we do not choose what your community asks its members for, and we do not use that content for our own purposes.

Practically, that means: if a member of your community wants to know why they were asked a particular question, wants their application answers or ticket removed, or disagrees with a moderation record, the server's own staff are the people who can act on that — they configured it and they can change or delete it. We will help where we reasonably can, and we will act on requests about the account and billing data we hold ourselves. Section 5 of the Terms of Service sets out that responsibility from the server owner's side.

We are not offering a formal data processing agreement, and this section is a plain-English description of how the service works rather than a substitute for one. If your organisation needs something more formal before using the bot, get in touch through the Support page and say so.

How it is stored

Configuration and records are stored in a data store operated to run the bot and dashboard — there is no separate analytics database and no third-party data broker. We use reasonable access controls to protect stored data, and certain sensitive values, such as an optional feedback webhook URL, are encrypted. No online service can guarantee perfect security, and we do not claim that every category of stored data is encrypted.

Payments and billing

We do not store your card details. Full card numbers, expiry dates, security codes and bank credentials are never received by our systems and are never written to our records. Payments are handled by Paddle.com Market Ltd ("Paddle"), our Merchant of Record and authorized reseller, and your payment details are entered on Paddle's systems, not ours. Before you can check out, we ask you to explicitly confirm you agree to our Terms of Service and this Privacy Policy, and we keep a record of when you did — see "What personal data we collect" above.

What we do keep is the record of the transaction itself:

We keep no cardholder name, no card brand, no last four digits of a card, no expiry, no payment token and no bank account details. If you need to change how you pay, that is done through the payment provider rather than through us.

Billing records are kept as long as we are required to keep them for accounting, tax and dispute purposes, which is generally longer than other records. A refund never rewrites the original order: what you were charged stays as it was, and the refund is recorded beside it, so that both sides have the same history.

Third-party payment providers

When you make a payment, Paddle acts as an independent controller of the information you give it directly — your payment details, your billing address and any tax identifiers it needs. Paddle's handling of that information is governed by Paddle's own Privacy Notice, which we do not control. Paddle may process the information in countries other than your own — see "International data transfers" below.

We share with Paddle only what is needed to take a payment and to match it back to the right account: the amount, the currency, what is being bought, and an account name and reference of our own. We do not send Paddle your Discord identifiers or any of your server's configuration or member records.

How it is used

Data is used to operate the service, to provide the features you or your server's staff configure, and to handle support requests, feedback, and bug reports you submit. We do not use your data for any other purpose.

Legal bases for processing

Where the law that applies to you requires a stated legal basis, this is the one we rely on for each kind of data above:

Selling and advertising

We do not sell personal information or use personal information for targeted advertising.

When data may be shared

If a server's Platform Owner configures an optional Discord webhook for feedback delivery, submitted feedback/bug report content (friendly names only — never your Discord ID or the webhook URL itself) may also be delivered to that Discord webhook, because they chose to configure it. Where you make a payment, information about that payment is shared with Paddle as described under "Third-party payment providers" above. Otherwise we do not share your data with third parties. Anything you do inside your own Discord server remains subject to Discord's own Terms of Service and Privacy Policy, which we do not control.

International data transfers

We operate from Israel, and the people who use The Roleplay Bot are spread across many countries, so data described in this policy is very likely to be processed somewhere other than where you live — including by us, by Paddle (see "Third-party payment providers" above), and by Discord. Where a transfer needs a specific legal safeguard under the law that applies to you, we and the processors we use rely on the mechanism each of their own privacy policies describes; we do not maintain a separate list of countries here because it would only duplicate, and risk drifting from, what those policies already say.

Retention

We retain data for as long as needed to provide the service, maintain accurate records, resolve issues, and operate the platform. Server configuration and records generally persist until removed by your server's staff or until a server is no longer part of the service. We do not commit to a fixed deletion timeline. Billing and payment records are an exception: they are kept for as long as accounting, tax and dispute-resolution obligations require, even after an account stops using the service.

Your rights and choices

You can log out at any time to end your dashboard session immediately. Depending on where you live, you may also have some or all of the following rights over data we hold about you: to access it, to correct it, to ask us to delete it, to restrict or object to how we use it, to receive a copy in a portable format, to withdraw a consent you gave us (such as review attribution) without affecting anything done before you withdrew it, and to complain to your local data protection authority. Billing and legal-acceptance records are the one exception we cannot delete on request while a legal obligation to keep them still applies — see "Retention" above. To exercise any of these, use the channels described on the Support page; we will ask enough to confirm it is really you asking before we act.

Age

The Roleplay Bot is not directed at, and must not be used by, anyone who is not old enough to use Discord in their own country — Discord sets and enforces that minimum age, not us, and we do not knowingly collect data from anyone below it. If we learn that we have, we will delete the account and the data associated with it.

To purchase a subscription, manage billing, or create or manage an organization account, you must be at least 18 years old, or the age of legal majority where you live — whichever is higher — the same rule our Terms of Service sets.

If you believe a minor has used the service, tell us through the Support page and we will look into it.

Changes

This policy may change as the product does. Check the "Last updated" date above.