Privacy Policy
Last updated 2026-09-11
Summary
Echo stores the minimum needed to provide its features. It does not store message content in bulk, does not sell data, and does not share data with third parties.
What is stored
- Server IDs, and per-server configuration set by administrators (channels, roles, thresholds, message templates, auto-response triggers and replies).
- User IDs and the username shown at the time of the action, for moderation cases and auto-moderation infractions.
- Moderation records: the action taken, the moderator, the reason supplied, duration, and timestamps.
- Auto-moderation infractions: which rule was triggered and a short detail such as the matched word or link host, plus a timestamp.
- Leveling data: XP total, level, message count, and the time XP was last granted.
- Economy data: wallet and bank balances, daily streak, cooldown timestamps, and items owned.
- Dashboard sessions: your Discord user ID, username, avatar hash, and OAuth access and refresh tokens, held server-side.
What is not stored
- Message content is not written to the database. Where logging is enabled, message text is posted to a log channel inside your own Discord server and is held by Discord, not by this bot.
- Voice audio, video, and screen shares are never recorded. Voice logging records only that a state changed and who changed it.
- Email addresses, passwords, payment details, and IP addresses are not collected.
- Direct messages are not read or stored.
Why it is stored
Purely to provide the features you have enabled: to keep a moderation history, to award and display levels, to run the economy, to apply configured rules, and to sign you in to the dashboard.
Retention and deletion
Configuration and user data for a server are retained while the bot remains in that server. Removing the bot leaves stored data in place unless deletion is requested.
Administrators can clear data themselves at any time: `/levels reset` clears XP, `/eco reset` clears a member's balance and inventory, `/infractions clear` clears auto-mod strikes, and `/case reason` amends a case record.
To have all data for a server or for an individual user deleted, contact [email protected]. Dashboard sessions expire automatically after seven days, and signing out deletes the session immediately.
Access and security
Data is stored on infrastructure controlled by the bot operator. Dashboard access requires signing in with Discord, and each request re-checks with Discord that you still hold Manage Server in the server you are viewing.
OAuth tokens are stored server-side only and are never placed in a browser cookie. No security measure is perfect, and no guarantee of absolute security is given.
Children
The service is not directed at anyone below the minimum age required by the Discord Terms of Service in their country.
Changes
This policy may be updated as the bot changes. The date at the top reflects the most recent revision.
Contact
Privacy questions or deletion requests: [email protected].