Privacy Policy

Last updated: 19 July 2026

Who we are

Kaevo is a Discord bot and web dashboard. This policy covers data processed when you use the bot in a Discord server, or sign in to the dashboard.

What we store

Automatically, when the bot is used

  • Discord IDs — your user ID, and the IDs of servers, channels and roles. These are pseudonymous identifiers, not names.
  • Moderation records — warnings, mutes, bans, kicks and timeouts issued through the bot, including the reason a moderator typed and who issued it.
  • Ticket and mod mail content — the messages exchanged in a support ticket or mod mail thread, including transcripts kept after closing.
  • Feature data — levelling XP, economy balances, birthdays, applications, reviews, suggestions, bug reports, game state and prediction pools, where a server has enabled those features.
  • Linked accounts — if you use Roblox verification, the Roblox account you linked.

When you use the dashboard

  • Your Discord username, avatar and the servers you can manage, obtained via Discord OAuth2.
  • A session cookie so you stay signed in.
  • An audit log of configuration changes you make, including your user ID and username.

What we do not store

  • Your Discord password or email address. Sign-in goes through Discord; we never see your credentials.
  • Payment details.
  • Messages in channels the bot has not been asked to act on. The bot does not archive general server chat.

Why we store it

To provide the features a server administrator has switched on. A moderation log is useless without the records in it; an economy cannot work without balances. Where the GDPR applies, the lawful basis is legitimate interest in operating the service a server asked for, and consent where you volunteer information (a birthday, an application answer, a linked Roblox account).

How long we keep it

Data is currently kept until it is deleted by a server administrator or by request. There is no automatic expiry. We are being explicit about this rather than claiming a retention period the software does not yet enforce.

Removing the bot from a server does not automatically delete that server's data, so that re-inviting it does not wipe a moderation history. To have it deleted, use the contact route below.

Who can see it

  • Server staff — anyone a server has given dashboard access to can see that server's data. We cannot control how individual server owners manage their own staff.
  • Bot operators — a small number of Kaevo staff can access data for support and abuse investigation.
  • Nobody else. We do not sell data, and we do not share it with advertisers.

Your rights

Under the GDPR you can ask us to:

  • tell you what we hold about you
  • correct it
  • delete it
  • export it in a portable format
  • restrict or object to processing

Some requests interact awkwardly with moderation: deleting your warning history in a server would remove a record that server relies on to moderate. Where those conflict we will explain the position rather than silently refuse.

Security

Data is held in a MongoDB database on servers we control. Dashboard access requires Discord OAuth2, and administrative access additionally requires two-factor authentication. Two-factor secrets are stored encrypted.

Children

Discord requires users to be at least 13, or older where local law demands it. Kaevo is not intended for anyone below Discord's minimum age.

Contact

For any request about your data, join the support server and open a mod mail thread, or use the contact page.