Effective date: August 11, 2026
1. Who We Are
Sauna ("Sauna", "we", "us", or "our") provides a Discord bot and accompanying web dashboard (together, the "Service") for ticketing, moderation, leveling, roles, community engagement, analytics, and related server-management features. This Policy applies to the Sauna bot, the dashboard at saunabot.rest, and the API at status.saunabot.rest. Discord separately governs your Discord account under its own privacy policy.
2. Information We Collect
Dashboard sign-in. When you sign in through Discord OAuth, Discord gives us your user ID, username, a short-lived access token, and the servers you own or administer. We use the identify and guilds scopes. We do not request your email, direct messages, friends list, or account password.
Server configuration. We store settings selected by administrators, including channel and role IDs, ticket configuration, automod rules, autoroles, reaction-role and role-picker panels, welcome and leave messages, verification settings, leveling configuration, custom commands, and canned responses.
Moderation records. For warnings, timeouts, kicks, and bans, we store the action, target and moderator Discord IDs, supplied reason, and timestamp. Cases are capped at the 500 most recent records per server.
Leveling. When enabled, we store accumulated XP and the time of a member's last counted message, keyed by Discord user ID. We do not store message content to calculate XP.
Audit log. We store up to 500 recent server audit entries. These may include message edits or deletions with content truncated to 300 characters, joins, leaves, and role changes, together with relevant Discord IDs and timestamps.
Ticket transcripts. When a ticket closes, Sauna creates a transcript containing the ticket conversation and participant Discord IDs. It may be delivered to a configured Discord channel or to the ticket opener and is also retained for administrator review. Transcripts are capped at the 200 most recent per server.
Analytics. Sauna keeps day-level server counts such as messages, members, and command usage. These aggregate figures are not tied to individual members and are retained for 90 days.
Member lookup. Administrators can request basic member details already visible to server staff, including username, nickname, avatar, join and account creation dates, and roles. Results are requested live from Discord and are not separately stored by the lookup feature.
Optional server analysis. When an administrator runs /analyze-server, Sauna creates a structural snapshot containing server counts, channel and category names, role names and selected permissions, Discord safety settings, bot permissions, and enabled Sauna features. That snapshot and deterministic findings are sent to Google's Gemini API to generate recommendations. Message content and member lists are not included. Google's processing is governed by its applicable service terms and privacy documentation.
Cookies and sessions. oauth_state and oauth_redirect last up to five minutes and secure the login flow. pirtis.sid identifies a dashboard session for up to seven days. Session data, including the Discord access token needed to refresh administrator permissions, is stored in a server-side SQLite database. Cookies are marked httpOnly and secure. We do not use advertising or third-party analytics cookies.
Technical logs. Hosting and network systems may record IP addresses, request times, errors, and similar technical data for security, abuse prevention, and debugging. We do not use these logs for advertising or profiling.
3. How We Use Information
We use this information to operate configured features, authenticate administrators, enforce server-specific permissions, maintain moderation accountability, provide analytics and transcripts, prevent abuse, and diagnose technical problems.
4. Server Administrators
For server settings and records generated by features an administrator enables, that administrator determines how Sauna is used in their community and is responsible for notices or consents required by applicable law. We process that data to provide the Service. We control dashboard authentication and operational data.
5. Sharing
We do not sell personal data or share it for advertising. We disclose information only to Discord as required to operate a Discord bot; to hosting and infrastructure providers that run the Service; to Google when an administrator explicitly invokes AI server analysis; where required by law or necessary to protect users and the Service; or to a successor in a merger, acquisition, or asset sale subject to this Policy.
6. Retention and Deletion
- Moderation cases and audit entries: the 500 most recent per server.
- Ticket transcripts: the 200 most recent per server.
- Aggregate analytics: 90 days.
- Dashboard sessions: up to seven days, deleted on logout or expiry.
- Server configuration and leveling data: retained until changed or deleted by an administrator or Service operator.
- Production backups: retained for up to 14 days; deleted data may remain in a backup until that backup expires.
Removing Sauna from a Discord server does not by itself guarantee immediate deletion of stored server data. A server administrator may request deletion using the contact address below.
7. Security
We use HTTPS/TLS, secure and HTTP-only session cookies, access controls, rate limiting, restricted production access, and routine backups. No transmission or storage system is completely secure, so absolute security cannot be guaranteed.
8. International Transfers
Infrastructure providers may process data outside your country. Where applicable, we take steps intended to provide protections required for transfers from the EEA or UK.
9. Your Rights
Depending on where you live, you may have rights to access, correct, delete, export, object to, or restrict processing of personal data. For server-specific records, contact the relevant server administrators first or contact us for assistance. You can clear your dashboard session by logging out. EEA and UK residents may also complain to their local data-protection authority.
10. Children's Privacy
Discord requires users to be at least 13 or the minimum age required in their country. We do not knowingly collect data from children below the applicable age.
11. Changes
We may revise this Policy as the Service changes. Material updates will be reflected by changing the effective date and, where appropriate, providing additional notice.
12. Contact
Questions and data requests can be sent to privacy@saunabot.rest.
