Privacy Policy
Last updated: September 17, 2026
Who we are
The Roleplay Bot is operated by Offir Gutte, an individual based in Israel, trading as "The Roleplay Bot." This is not currently a registered business. For the data we decide the use of — accounts, billing, security and running the service — that operator is the controller. For the content and configuration inside your own Discord server, the picture is different and it matters: see "Our role, and yours" below.
For anything in this policy, or any privacy-related notice, contact support@theroleplaybot.site or see the Support page.
What personal data we collect
The short answer, for anyone deciding whether to add the bot to their server: we collect what your Discord account tells us when you sign in, what you and your staff configure and record through the features you switch on, and — only if you buy something — a record of that purchase. We do not ask for your email address, your real name, your phone number, your address or your date of birth, and nothing here is used for advertising or sold to anyone.
Discord account information
- Your Discord user ID — the numeric account ID, which is the only thing we use to identify you. It never changes, unlike a username.
- Your Discord username, display name and avatar, cached so the dashboard can show who is signed in without asking Discord on every page load. This is a copy of what Discord gives us for display; it is never used to decide what you are allowed to do.
- The list of Discord servers you are in, which Discord returns when you sign in so we can work out which of them you have permission to configure. It is held only in memory, for a few seconds at a time, and re-read from Discord rather than kept — we do not store a copy of which servers you belong to.
- Discord access and refresh tokens — issued by Discord when you approve the login, and stored encrypted so that your session survives a restart and can still check your permissions. They are never written in readable form, never logged, and never sent back to your browser. Logging out ends the session and the tokens with it.
- We do not receive your email address from Discord. We ask Discord only for your basic identity and your server list, so your Discord email is never sent to us. If you buy something, the payment provider collects an email address on its own systems for the receipt — see "Payments and billing" below.
Roblox identity (only if a server turns it on)
Some servers use a Roblox roleplay feature that links a member's Discord account to their Roblox account. This is off by default and only applies where a server's staff has switched it on.
- Your Roblox user ID, username and display name — the same kind of identifiers described for Discord above. Roblox usernames and display names can change, so we keep the name as it was at the time you linked, alongside the ID, which does not change.
- How the link is made — normally, you sign in directly with Roblox through Roblox's own sign-in page, using Roblox's official sign-in feature for outside apps (OAuth). We never see your Roblox password, and we do not read or scan your Roblox profile. Occasionally a server's staff record a link by hand instead — for someone whose Roblox profile is private, unreachable, or who otherwise cannot complete sign-in themselves — and when they do, we keep a note of who did it and why.
- It is reusable across servers — once linked, the same link is recognised by every server that uses this feature, so you are not asked to sign in with Roblox again for each one. Each server still separately decides what role or nickname, if any, to give you based on it.
- You can unlink it at any time from the page this feature links to. Unlinking removes the connection; it does not delete records a server's staff already created that mention your Roblox name, for the same reason described under "Content created through the features you turn on" below.
This is not a Roblox product and is not endorsed by, affiliated with, or supported by the Roblox Corporation. "Roblox" is a trademark of the Roblox Corporation. What travels between us and Roblox is exactly what Roblox's own sign-in feature sends when you choose to use it — we do not have any other access to your Roblox account.
Discord server and community information
- The server's ID and its name, recorded when a server is connected to an account so it can be identified afterwards even if it is later renamed.
- Role IDs, channel IDs and permission settings that a feature needs in order to work — which role a rank maps to, which channel a log or panel is posted in, which roles may review an application, and so on. These are settings your staff choose, stored so the bot behaves the way you configured it.
Content created through the features you turn on
This is the category most worth reading carefully, because what ends up here is decided by your server's staff, not by us — see "Our role, and yours".
- Applications — the questions your staff write, and the answers applicants submit, together with who applied, when, and what was decided.
- Tickets — the ticket's subject and metadata, who opened it and who handled it, and, where your staff generate a transcript, the messages in that ticket channel.
- CAD / dispatch records, on servers that turn this on — a unit's on-duty status and which department, dispatch calls (type, location, priority and a free-text description) and any notes added to one, each recorded against the Discord user ID of the member concerned and, where that member has linked one, their Roblox identity at the time. Your staff can also file incident reports against a call: a free-text account of what happened, written by a member of your staff, stored together with a frozen copy of that call's details, the units who were assigned to it and its notes as they stood when the report was filed. A report is kept as written — later edits to the call do not change it — and it is not deleted when it is withdrawn from the working list, only archived with a stated reason. Your staff can also file BOLOs ("be on the lookout"): a short record of a person or vehicle the server is looking for, with free-text descriptions your staff write and, optionally, the name of a member of your server — copied as it reads at that moment, together with their Roblox username where they have verified one. A BOLO stays until your staff mark it resolved or archived, with a stated reason in both cases, and is not deleted either. Finally, your staff can record in-character enforcement records — a warning, a citation or an arrest — against either a named member of your server (their name and, where verified, their Roblox username, copied as they read at that moment) or a name your staff type in, together with what it was for, where, and any details they write. These are roleplay records kept by your server's staff. They are not real legal enforcement, carry no fine or payment, and mean nothing outside your server. A record can be voided with a stated reason if it was made in error; it is never deleted. Your staff can also keep citizen and vehicle records — an in-character person's name, an optional in-character date of birth or age, notes, and optionally a link to a member of your server; and a vehicle's plate, make, model, colour and type, optionally registered to one of those citizens. These describe roleplay characters and roleplay vehicles, not real people or real vehicles. We do not ask for, and there is nowhere to store, a real address, phone number, email, licence number or any government identification number. A citizen or vehicle record is archived with a stated reason rather than deleted. Finally, your staff can issue warrants against one of those citizen records — what the warrant is for, any details they write, and optionally a vehicle, a call, a report, a BOLO or an enforcement record it relates to. The citizen's name at that moment, and where that citizen was linked to a member of your server their name and Roblox username too, are copied onto the warrant and never change afterwards. A warrant here is an in-character note that your staff are looking for somebody. It is not a real warrant, grants no authority of any kind, involves no court or judge, and means nothing outside your server. A warrant stays outstanding until your staff mark it served or voided, with a stated note in both cases, and is never deleted.
- CAD case files and evidence, on servers that turn CAD on — a case file is the record that ties one job together. It holds a short title, a summary and any notes your staff write, which department is leading it, which of your members are assigned to it, and links to the calls, reports, citizens, vehicles, BOLOs, warrants and enforcement records it involves. Notes can be marked internal, in which case they are only ever sent to staff who can manage that case — they are filtered out before the page is built, not hidden afterwards. A note is never edited: a correction is a new note saying what it should say and why, and the original is kept. Against a case your staff can record evidence items — what the item is, a description, where it came from, who collected it, and a chain of custody: every transfer, check-out, return, seal, release and disposal, each with who did it, when, and a stated reason. That history is never edited or deleted; a mistake is corrected by adding a correction entry.
Your members can attach image files to an evidence item, and those files are stored on our servers. Only PNG, JPEG, WEBP and GIF images are accepted, and each is checked against its own file signature rather than its name. A file is stored outside anything the public web can reach, under a randomly generated name that has nothing to do with the name it was uploaded with; the name it was uploaded with is kept only as a label to show your staff. It can only be downloaded by somebody who can read that case in that server, checked again on every single download. A file can be withdrawn with a stated reason, after which it stops being downloadable and the record keeps saying that it was added and later withdrawn. Whatever your members upload is decided entirely by your server's staff and members, not by us — see "Our role, and yours". A server's staff can turn evidence file uploads off entirely.
Case files and evidence are in-character roleplay records. They are not legal, law-enforcement or medical records, they carry no real-world authority, and nothing here is evidence of anything outside your roleplay. Closing, reopening, archiving or restoring a case all keep the whole file; nothing here is deleted. - Court records, on servers that turn Court on — an in-character roleplay court. A court case holds a short title, a summary, what kind of matter it is, and its place in that court's own lifecycle. Against it your staff can record participants — a judge, a clerk, counsel, a defendant, a plaintiff, a respondent, a witness or another role they label themselves — each either a name your staff type in, one of the citizen records described above, or a named member of your server, whose name is copied as it reads at that moment and never changes afterwards. They can file charges from a statute list your server writes for itself, each keeping its own copy of that statute's wording so editing or retiring it later never changes a charge already filed; schedule hearings with a date, a time, the timezone the court sits in, a location and a description; record decisions — an outcome, a summary and, optionally, a sentence or final order as free text; and mark evidence from a linked case file as an exhibit, recording whether the court admitted or excluded it and why. Hearings and case notes can both be marked internal, in which case they are only ever sent to court staff — filtered out before the page is built, not hidden afterwards. These are fictional roleplay records. This is not a real legal service and is not a real court: no finding here is a real allegation, a real criminal record or a real judgment, none of it carries authority of any kind, and it means nothing outside your server. A sentence or final order is free text only — nothing applies a punishment, moves money, issues a fine or changes anything in a game. There is nowhere to store a real address, phone number, email, licence number or any government identification number. A decision is never rewritten. Correcting one adds a correction beside it saying what it should have been and why, and the original stays on the record permanently. Nothing in a court record is deleted: a charge is withdrawn, an exhibit is withdrawn, a participant is removed, a hearing is cancelled and a case is closed, dismissed or archived — each with a stated reason, and each kept.
- Game session records, on servers that turn Game Sessions on — a live session your server runs, which members join while it is running. A session holds a title, a description, the joining details your staff type in (a link, a code, a server name, instructions), which state it is in, who is hosting it and who they named as a co-host for that session. Against it we record who joined and when, who is on the waiting list, everyone who took part at any point, and — where a host removes somebody — that removal and the reason they gave for it, recorded against the Discord user ID of the member concerned. When a session ends we keep a summary: how long it ran, how many took part, the most at once, who ended it, and any closing message. Joining a session is entirely the member's own choice — it is a button on a message in a channel your server chose, it needs no permission, and leaving removes you from the live list. Your server chooses whether the names of the people who have joined are shown publicly on that message or only a count. A server chooses how many finished sessions are kept (between five and one hundred); once that many have passed, the oldest is discarded. Finished sessions keep names as they read at the time, so the record still makes sense after somebody changes their name or leaves.
- Personnel and moderation records — ranks, promotions and demotions, infractions and their stated reasons, activity, events, training, certifications and rosters, each recorded against the Discord user ID of the member concerned.
- Configuration and audit history — a record of sensitive changes inside your server (promotions and demotions, infractions, changes to who can manage what), scoped to that server, so your staff can see what changed and by whom.
- Appeals, on servers that turn this on — a member can ask a server's staff to reconsider a punishment, a ban, a denied application, or the conduct of a staff member. An appeal holds what you write about it yourself: your explanation, what you are asking for, and your answers to any extra questions that server's staff have written. It also holds the conversation that follows — messages between you and the reviewers — and a record of every status it passed through, who moved it and why. Where you name a case, an infraction or an application, the appeal is linked to your own record of it; a reference to somebody else's record resolves to nothing at all. This is the one feature deliberately usable by somebody who is no longer in the server, because a person who has been banned is exactly who most needs it: the appeal page asks you to sign in with Discord and nothing else, so we hold and process appeals from people who have left or been removed. Reviewers can also attach notes that only they see — see the bullet below. An appeal is never deleted: withdrawing, denying or closing one keeps the whole record and its history.
- Staff notes attached to those records, where a feature provides for them.
Billing and purchase information
- Orders and subscriptions — which plan or add-on, the amounts, the currency, any discount or gift card applied, the status of a subscription and its billing period, and whether a payment succeeded, failed or was refunded.
- An opaque reference issued by the payment provider, so a payment can be matched back to an order for support and accounting.
- Card and payment method details are handled by Paddle and never reach us — see "Payments and billing" below, which sets out exactly what we do and do not keep.
Support, feedback and security communications
- Feedback and bug reports submitted via the /feedback and /bug-report Discord commands or the dashboard Feedback page, including an optional screenshot attachment.
- Published reviews — if you choose to publish a review, a limited snapshot (rating, title, message, and your server's name only if you explicitly opt in to attribution) may be shown publicly. Your Discord user ID and server ID are never included in that public snapshot.
- Anything you send us at support@theroleplaybot.site, including a security or vulnerability report, and whatever you chose to include in it.
- Internal notes about an account — where we are helping with a support or billing issue, or have had to act on a report, we may write a short note or a status marker against that account, with the reason. These are ours, for running the service; they are not shown to the account they are about, and they never change what that account is allowed to do.
- Partner Program applications — if you apply, we hold what you submit: the kind of partner you are, a display name, the links you provide, an optional note about your audience, and why you want to partner with us. If you're approved, we hold your referral code, aggregate click counts for it (a daily total only — never your visitors' IP addresses, browser fingerprints, or any other per-visitor record), and, where a server owner confirms a referral, which Discord server was confirmed and by whom. Internal review notes on an application are ours, for running the program, and are never shown to the applicant.
Technical and security data
- Session records — an identifier for your signed-in session, when it was created, when it expires or was revoked, and the IP address and browser user-agent string the session was created from, so a session can be recognised and, if needed, revoked. Sessions expire automatically and end immediately when you log out.
- A security token held with the session to protect against cross-site request forgery.
- Legal acceptance records — before you can check out, we record that you agreed to the current Terms of Service and Privacy Policy: which versions, when, and the IP address and browser user-agent string the request came from. This is kept for accountability if a purchase is ever disputed, and is never used to decide a price, an entitlement, or anything else about what you may do.
- Abuse protection — your IP address is counted in memory to rate-limit repeated requests. It is held only for that short window and is not written to our records or used for anything else.
- Records of a suspension or a block, if we ever have to stop a Discord account or a server from using the service: what was acted on, the reason, and when, including when it was lifted.
Our role, and yours
A fair question before adding any bot to a community is "who is actually deciding what happens to this data?" There are two answers, because there are two different kinds of data here.
For your account, billing, security, legal-acceptance and service-operation data, we decide. We determine what is collected and how it is used in order to run, secure and bill for the service, and everything above describes those decisions. Questions, corrections and deletion requests about that data come to us — see "Your rights and choices" below.
For what happens inside your Discord server, you decide, and we carry it out. The server's owner and staff choose which features to turn on, what questions an application asks, what a ticket is for, what is written in an infraction reason or a staff note, and who on the team can see any of it. We provide the tool and run the service that stores and displays it — we do not choose what your community asks its members for, and we do not use that content for our own purposes.
Practically, that means: if a member of your community wants to know why they were asked a particular question, wants their application answers or ticket removed, or disagrees with a moderation record, the server's own staff are the people who can act on that — they configured it and they can change or delete it. We will help where we reasonably can, and we will act on requests about the account and billing data we hold ourselves. Section 5 of the Terms of Service sets out that responsibility from the server owner's side.
We are not offering a formal data processing agreement, and this section is a plain-English description of how the service works rather than a substitute for one. If your organisation needs something more formal before using the bot, get in touch through the Support page and say so.
How it is stored
Configuration and records are stored in a data store operated to run the bot and dashboard — there is no separate analytics database and no third-party data broker. We use reasonable access controls to protect stored data, and certain sensitive values, such as an optional feedback webhook URL, are encrypted. No online service can guarantee perfect security, and we do not claim that every category of stored data is encrypted.
Payments and billing
We do not store your card details. Full card numbers, expiry dates, security codes and bank credentials are never received by our systems and are never written to our records. Payments are handled by Paddle.com Market Ltd ("Paddle"), our Merchant of Record and authorized reseller, and your payment details are entered on Paddle's systems, not ours. Before you can check out, we ask you to explicitly confirm you agree to our Terms of Service and this Privacy Policy, and we keep a record of when you did — see "What personal data we collect" above.
What we do keep is the record of the transaction itself:
- Orders and receipts — an order reference, what was bought, the quantity, the currency, the amounts (list price, any discount, the total), any discount code or gift card applied, and the timestamps for when it was placed, paid or refunded.
- Subscriptions — which plan an account is on, the status of its subscription (for example active, past due, or cancelled), the current billing period, any trial dates, and whether it is set to end at the end of the period.
- Payment status — whether a payment succeeded, failed, expired or was refunded, and the amount of any refund together with the reason recorded for it.
- An opaque provider reference — an identifier issued by the payment provider so that a payment can be matched to an order for support and accounting. It is meaningless outside their systems and carries nothing about a payment instrument.
We keep no cardholder name, no card brand, no last four digits of a card, no expiry, no payment token and no bank account details. If you need to change how you pay, that is done through the payment provider rather than through us.
Billing records are kept as long as we are required to keep them for accounting, tax and dispute purposes, which is generally longer than other records. A refund never rewrites the original order: what you were charged stays as it was, and the refund is recorded beside it, so that both sides have the same history.
Third-party payment providers
When you make a payment, Paddle acts as an independent controller of the information you give it directly — your payment details, your billing address and any tax identifiers it needs. Paddle's handling of that information is governed by Paddle's own Privacy Notice, which we do not control. Paddle may process the information in countries other than your own — see "International data transfers" below.
We share with Paddle only what is needed to take a payment and to match it back to the right account: the amount, the currency, what is being bought, and an account name and reference of our own. We do not send Paddle your Discord identifiers or any of your server's configuration or member records.
How it is used
Data is used to operate the service, to provide the features you or your server's staff configure, and to handle support requests, feedback, and bug reports you submit. We do not use your data for any other purpose.
Legal bases for processing
Where the law that applies to you requires a stated legal basis, this is the one we rely on for each kind of data above:
- Performance of a contract — Discord account information, session data, server configuration and records, and billing/payment/legal-acceptance records, because we cannot provide the dashboard, run a checkout, or honour a subscription without them.
- Legitimate interests — feedback and bug reports (improving the service), the legal-acceptance record described above (being able to show what you agreed to and when, if a purchase is ever disputed), and keeping the service secure and available: session records, abuse rate-limiting, internal support notes, and records of a suspension or block.
- Consent — a published review and any optional attribution on it, which you control and can withdraw as described under "Your rights" below.
- Legal obligation — billing records kept for accounting, tax and dispute-resolution purposes, for as long as those obligations require.
Selling and advertising
We do not sell personal information or use personal information for targeted advertising.
When data may be shared
If a server's Platform Owner configures an optional Discord webhook for feedback delivery, submitted feedback/bug report content (friendly names only — never your Discord ID or the webhook URL itself) may also be delivered to that Discord webhook, because they chose to configure it. Where you make a payment, information about that payment is shared with Paddle as described under "Third-party payment providers" above. Otherwise we do not share your data with third parties. Anything you do inside your own Discord server remains subject to Discord's own Terms of Service and Privacy Policy, which we do not control.
International data transfers
We operate from Israel, and the people who use The Roleplay Bot are spread across many countries, so data described in this policy is very likely to be processed somewhere other than where you live — including by us, by Paddle (see "Third-party payment providers" above), and by Discord. Where a transfer needs a specific legal safeguard under the law that applies to you, we and the processors we use rely on the mechanism each of their own privacy policies describes; we do not maintain a separate list of countries here because it would only duplicate, and risk drifting from, what those policies already say.
Retention
We retain data for as long as needed to provide the service, maintain accurate records, resolve issues, and operate the platform. Server configuration and records generally persist until removed by your server's staff or until a server is no longer part of the service. We do not commit to a fixed deletion timeline. Billing and payment records are an exception: they are kept for as long as accounting, tax and dispute-resolution obligations require, even after an account stops using the service.
Your rights and choices
You can log out at any time to end your dashboard session immediately. Depending on where you live, you may also have some or all of the following rights over data we hold about you: to access it, to correct it, to ask us to delete it, to restrict or object to how we use it, to receive a copy in a portable format, to withdraw a consent you gave us (such as review attribution) without affecting anything done before you withdrew it, and to complain to your local data protection authority. Billing and legal-acceptance records are the one exception we cannot delete on request while a legal obligation to keep them still applies — see "Retention" above. To exercise any of these, use the channels described on the Support page; we will ask enough to confirm it is really you asking before we act.
Age
The Roleplay Bot is not directed at, and must not be used by, anyone who is not old enough to use Discord in their own country — Discord sets and enforces that minimum age, not us, and we do not knowingly collect data from anyone below it. If we learn that we have, we will delete the account and the data associated with it.
To purchase a subscription, manage billing, or create or manage an organization account, you must be at least 18 years old, or the age of legal majority where you live — whichever is higher — the same rule our Terms of Service sets.
If you believe a minor has used the service, tell us through the Support page and we will look into it.
Changes
This policy may change as the product does. Check the "Last updated" date above.