Privacy policy
What SecureBoot stores,
and why.
This Policy explains what SecureBoot processes, why it is needed, how long it is retained and how to request access or deletion.
SecureBoot does not ask for or store your Discord password. Dashboard login happens on Discord through OAuth2. We use Discord data only to provide the bot and dashboard features described here.
Scope and roles
This Policy applies to the SecureBoot Discord bot, the dashboard at swcode.xyz/secureboot and related support.
For dashboard account and service-operation data, SecureBoot / SWcode acts as data controller. For server-specific moderation records and configurations, the Discord server owner or operator also determines why and how the features are used and may act as an independent controller.
Data we process
Depending on enabled features, SecureBoot may process:
- Discord account and OAuth data: Discord user ID, display name, manageable server IDs, names and permission flags. OAuth access tokens are used to fetch this information and discarded immediately after login; they are not stored in the dashboard session.
- Server configuration: server, channel, message and role IDs; command prefix; enabled modules; configured thresholds, templates and permission policies.
- Moderation records: user and moderator IDs, action type, warning reason, source, status and timestamp.
- Giveaways and role systems: prize, host, creator, participant and winner IDs; reaction-role mappings; booster-role metadata.
- Anti-abuse events: short-lived join scores/signals and short-lived hashes of message content used to detect spam or repeated messages.
- Operational data: timestamps, processing status and limited error information needed to deliver jobs and keep features reliable.
Message content
When AutoMod or media-link detection is enabled, SecureBoot reads messages that Discord makes available to the bot so it can apply the configured rule. The full text is not written to the persistent database for spam detection; SecureBoot stores a one-way SHA-256 content hash for the short configured detection window.
Warning reasons, giveaway prizes, welcome messages, notification templates and other text deliberately submitted through commands or the dashboard are stored because they are part of the configured service.
Purposes and legal bases
We process data to:
- authenticate dashboard users and show servers they are authorised to manage;
- execute requested commands and configured server features;
- maintain moderation history, security controls and giveaway integrity;
- prevent abuse, protect the service and diagnose failures;
- meet legal and Discord platform obligations.
Depending on the context, processing is based on performance of the requested service, consent or authorisation through Discord OAuth and bot installation, legitimate interests in operating and securing the service, and compliance with legal obligations.
Automated moderation
AutoMod and Anti-Raid use rule-based thresholds chosen by authorised server administrators. Automated consequences can include message deletion, a warning, timeout, kick, ban or temporary lockdown.
SecureBoot does not use AI profiling to make these decisions. Questions or appeals about a server action should first be directed to that server's administrators, who control the rules and can reverse an action where Discord permits.
Who receives data
Data is not sold, licensed to data brokers or used for behavioural advertising. It may be processed by:
- Discord Inc., as the platform and API provider;
- our hosting and infrastructure providers, only as needed to run the bot, database and website;
- authorised server administrators, through logs and dashboard features configured for their server;
- public authorities, only when disclosure is legally required.
Discord and infrastructure providers may process data outside Poland or the European Economic Area under their own legal safeguards and privacy terms.
How long data is retained
- Dashboard sessions: expire after 15 minutes of inactivity and are reset after a maximum of 4 hours.
- Spam and raid detection events: are automatically removed after the short operational window for which they are needed.
- Configuration, moderation and giveaway records: remain while needed to provide the configured feature, maintain requested history or resolve abuse and reliability issues.
- Server or user deletion requests: are handled after authority and identity are reasonably verified, unless retention is required by law or necessary to establish, exercise or defend legal claims.
Removing the bot stops new server events from being processed. Because administrators may need moderation history, existing records are removed on a verified request rather than automatically at the instant the bot is removed.
Security measures
SecureBoot uses HTTPS, HttpOnly and Secure session cookies, OAuth state validation, CSRF protection, rate limiting, permission and role-hierarchy checks, restricted server-side storage, signed bot-dashboard requests and database-backed processing controls.
No online service can guarantee absolute security. If we identify a material incident affecting Discord API data, we will take reasonable containment steps and provide required notifications.
Your privacy rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or object to certain processing. You may also withdraw consent where consent is the basis, without affecting earlier lawful processing.
Email kontakt@swcode.xyz with your Discord user ID, relevant server ID and the request. Do not send your Discord password or token. We may request proof that you control the account or server before disclosing or deleting records.
You may lodge a complaint with your local data-protection authority. In Poland, the supervisory authority is the President of the Personal Data Protection Office (UODO).
Children
SecureBoot is not directed to anyone below Discord's minimum age or the minimum age of digital consent that applies in their country. We do not knowingly request sensitive information from children. If you believe prohibited data has been processed, contact us for review and removal.
Policy changes
We may update this Policy when features, laws or Discord requirements change. The effective date identifies the current version. Material changes will be communicated through the website, dashboard or bot where practical.
Contact and requests
Data controller: SecureBoot / SWcode, operated by Zvssv in Poland.
For privacy requests, security reports or questions, email kontakt@swcode.xyz. Include enough information to identify the relevant account or server, but never include your Discord password, bot token or OAuth token.
Rules for using the service are available in the SecureBoot Terms of Service.
