SecretverseLegal
WebsiteTerms of ServiceDashboard

Privacy Policy

Last updated: 22 September 2026

This policy explains what personal data SecretVerse Studio ("we", "us") processes when you use the SecretVerse Discord server, the SecretVerse Discord bot (the "Bot"), the staff dashboard at dashboard.secretverse-studio.com (the "Dashboard") and the content creator verification flow. It also explains why we process it, how long we keep it and the rights you have.

SecretVerse Studio is the data controller for this processing. You can reach us at contact@secretverse-studio.com or by opening a support ticket in the SecretVerse Discord server.

1. Who this applies to

  • Members of the SecretVerse Discord server, whose messages and activity the Bot moderates and logs.
  • Applicants to the content creator program, who choose to verify their accounts.
  • Staff members who sign in to the Dashboard.

The Bot runs in the SecretVerse Discord server only. It is not a public bot and it does not collect data from other servers.

2. Data we process and why

2.1 Discord account and membership data

When you are a member of the server, the Bot receives from Discord your user id, username, display name, avatar, roles, and the timestamps of your joins, leaves, nickname changes and role changes. It also receives voice channel join, leave and move events.

We use this data to run the server: apply automatic roles, welcome and goodbye messages, level rewards, ticket permissions and moderation. Legal basis: our legitimate interest in operating and securing the community.

2.2 Messages

The Bot reads messages posted in the server in order to:

  • Apply automatic moderation: filtered words, spam and duplicate detection, mass mentions, unauthorized invites, phishing links and scam patterns. Images attached to messages may be downloaded, fingerprinted and, when the optional text recognition is enabled, read by an on-server text recognition engine to detect scam screenshots. Fingerprints of images identified as scams are kept; the images themselves are not stored.
  • Award experience points for activity.
  • Keep a short-lived archive of recent messages (author, channel, content, attachment links) so that a deleted or edited message can still be shown to the moderation team and so that ticket transcripts can be produced. This archive is deleted after 14 days, except for messages posted inside a support ticket, which are kept until the ticket is closed and archived.
  • Record moderation-relevant events (deleted and edited messages with their content, joins and leaves, nickname and role changes, voice activity, channel and role changes, moderation actions) in a searchable log used by the moderation team. These events are kept for 90 days by default. The server administrators can set a shorter or longer retention.

Legal basis: our legitimate interest in keeping the community safe and in enforcing the server rules and the Discord Community Guidelines.

2.3 Moderation records

Warnings, timeouts, kicks, bans, temporary bans and ban requests are stored with the reason given, the moderator who acted, the affected member and the date. These records are kept for as long as they are relevant to the moderation of the community, so that repeat behaviour can be identified. A moderator can delete a warning. You can ask us to review or delete a record (see section 7).

Legal basis: our legitimate interest in moderating the community fairly and consistently.

2.4 Support tickets

When you open a ticket, the Bot stores the ticket category, the answers you give in the form (Roblox username, description, links), the private channel it creates, the staff member who handled it and its status. When the ticket is closed, a transcript of the conversation is posted to the staff log channel and sent to you by direct message. Ticket records are kept as part of the moderation history.

Legal basis: performance of the service you request (your ticket) and our legitimate interest in keeping a record of support and reports.

2.5 Levels, giveaways and voice channels

  • Experience points and level per member are kept for as long as you are a member and the Bot runs in the server.
  • Giveaway entries (your user id) are kept until 30 days after the giveaway ends, so that winners can be redrawn if needed. A giveaway exclusion list holds the user id, the reason and the staff member who added it.
  • Temporary voice channels created through the voice hub are tracked by channel id and owner id only while the channel exists.

Legal basis: performance of the features you take part in.

2.6 Content creator verification (optional)

Verification runs only if you apply to the content creator program and explicitly authorize it. Depending on the platform you pick:

  • Discord connections: through Discord's OAuth2 "connections" scope we read the accounts linked to your Discord profile (platform, account name, account id, Discord's verified flag and, when Discord provides it, the follower count). Only YouTube, TikTok, Twitch, Instagram and X connections are kept.
  • TikTok: through TikTok Login Kit we read your open id, display name, follower count, video count, verified badge, profile link and the view counts of your recent public videos, from which we compute an average. The numbers are stored as a snapshot taken at verification time.
  • YouTube: through the YouTube Data API we read the public statistics of the channel linked to your Discord (subscribers and the view counts of recent public videos).
  • Twitch: through the public TwitchTracker API we read the public follower count and average viewer count of the channel linked to your Discord.

Access tokens are used once to read this data and are discarded. Verification data is stored with your Discord user id and is used only to check your application against the published creator requirements and to help staff review it. A verification is considered current for 30 days; after that you are asked to verify again. You can request deletion at any time.

Legal basis: your consent, which you give when you authorize the access and which you can withdraw at any time in your Discord settings (Authorized Apps) and TikTok settings (Manage app permissions).

2.7 The Dashboard (staff only)

Staff members sign in to the Dashboard with Discord OAuth2 using the "identify" and "guilds" scopes. We read your user id, username and avatar and check your permissions and roles on the server. The Dashboard sets one essential session cookie, signed and valid for 7 days, and a short-lived cookie during the sign-in redirect. No analytics or advertising cookies are used.

Every settings change and every action run from the Dashboard is recorded in an audit log (who, what, when, on which member or item). Audit entries are kept for 12 months.

Legal basis: our legitimate interest in giving the moderation team a secure tool and in keeping staff actions accountable.

2.8 Technical logs

The server that runs the Bot writes technical logs (errors, rate limits, start and stop events) which may contain Discord ids. They are kept for a short period for troubleshooting.

3. Data we do not collect

We do not collect your email address, phone number, payment details or precise location. We do not read your direct messages with other users. We do not use your data for advertising or profiling beyond the moderation and level features described above. We do not sell personal data.

4. Where the data is stored and who can see it

Data is stored in a database on a server hosted by OVHcloud in France (European Union). Access is restricted to the SecretVerse Studio team and to staff members who hold the corresponding permissions or roles on the Discord server. Staff see moderation records, tickets, logs and creator verification results through Discord and the Dashboard.

Nightly encrypted backups of the database are kept for 30 days. Data deleted from the live database can remain in a backup for up to 30 days before it is overwritten.

5. Third parties

The Bot relies on the following services, each processing data under its own terms and privacy policy:

ServicePurposeData involved
Discord Inc.The platform the Bot and the Dashboard run onAll Discord data described above
OVHcloudHosting of the Bot, the Dashboard and the databaseAll stored data (hosting only)
Google (YouTube Data API)Creator verification, only if you pick YouTubePublic channel statistics
TikTok (Login Kit)Creator verification, only if you sign in with TikTokYour TikTok profile and public video statistics
TwitchTrackerCreator verification, only if you pick TwitchPublic channel statistics
RobloxGroup announcements relayed to the server; Roblox profile links in ticketsPublic group posts; the Roblox username you type in a ticket
RSSHub and RSS feedsRelaying the studio's public social posts to the serverNo member data

Discord Inc. is based in the United States. Transfers of data to Discord are covered by Discord's own safeguards under its privacy policy.

6. Retention summary

DataRetention
Recent message archive14 days (until closure for ticket channels)
Searchable activity log90 days by default, configurable by the administrators
Warnings and moderation actionsWhile relevant to moderation; deletable on request
Tickets and transcriptsWhile relevant to moderation; deletable on request
Experience points and levelsWhile you are a member and the Bot runs in the server
Giveaway entries30 days after the giveaway ends
Temporary voice channelsWhile the channel exists
Creator verification dataWhile your application is relevant; current for 30 days; deletable on request
Scam image fingerprintsIndefinitely (they identify no person)
Dashboard session cookie7 days
Dashboard audit log12 months
Database backups30 days

7. Your rights

Under the General Data Protection Regulation (GDPR) and similar laws, you have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to its processing, and to receive a copy of the data you provided. Where processing is based on consent, you can withdraw it at any time; this does not affect processing that already took place.

To exercise these rights, write to contact@secretverse-studio.com from an address you control, or open a support ticket in the server, and tell us your Discord user id. We answer within 30 days. Some moderation records may be kept where we have an overriding legitimate interest, for example to prevent a banned user from returning; we will tell you if that is the case.

If you are in the European Union you can also lodge a complaint with your data protection authority. In France this is the CNIL (cnil.fr).

8. Children

Discord requires its users to be at least 13 years old, or older where local law sets a higher age. We do not knowingly collect data from children below that age. If you believe a child is using the server, contact us and we will act on it.

9. Security

The Dashboard is served over HTTPS only. Sessions are signed and bound to your Discord permissions, which are re-checked continuously. The database is not exposed to the internet. Bot credentials are kept on the server only and are rotated if a leak is suspected. No system is perfectly secure; if a breach affecting your data occurs, we will notify you and the competent authority as the law requires.

10. Changes

We may update this policy when the Bot's features change. The date at the top tells you when it was last revised. Significant changes are announced in the SecretVerse Discord server.

11. Contact

SecretVerse Studio Email: contact@secretverse-studio.com Website: https://secretverse-studio.com Discord: https://discord.gg/secretverse

Contents
  1. 1. Who this applies to
  2. 2. Data we process and why
  3. 3. Data we do not collect
  4. 4. Where the data is stored and who can see it
  5. 5. Third parties
  6. 6. Retention summary
  7. 7. Your rights
  8. 8. Children
  9. 9. Security
  10. 10. Changes
  11. 11. Contact
SecretverseCanonical version Terms of Service