Privacy Policy

Last updated: July 2026

1. Who is responsible for your data

Wody is developed and operated by an individual (a natural person), not a registered company, acting as the data controller for this Service. Reach us at wodyteams@gmail.com. This Privacy Policy explains what data Wody (the Discord bot and this dashboard) collects, why, and what rights you have over it. It should be read together with our Terms of Service and Cookie Policy.

2. Data we collect when you log in

When you log in with Discord OAuth2, Discord shares with us:

  • Your Discord user ID, username, global display name, and avatar hash;
  • The list of servers you belong to and, for each, whether you're the owner;
  • An OAuth access token and refresh token, used only to fetch the information above and to act on your behalf inside the dashboard (for example, listing servers you can manage).

We never see your Discord password, and we don't request scopes beyond what the dashboard needs to function. None of this is stored inside your browser cookie itself: the cookie only holds a random, signed session identifier, while your cached profile, access token and refresh token are kept server-side, in a  sessions record tied to that identifier and deleted on logout or after 7 days, whichever comes first.

3. Data collected through using the bot

Depending on which modules a server owner enables, Wody stores, per server:

  • Configuration you set through the dashboard (welcome/goodbye text, automod rules, ticket settings, custom commands, auto responses, reaction roles, and similar);
  • Moderation history: bans, kicks, timeouts, warnings, and who issued them;
  • Leveling/XP data and leaderboard positions per member;
  • Suggestions submitted and their approve/deny status;
  • Ticket transcripts, so a closed ticket can be reviewed later;
  • Giveaway entries and results;
  • Scheduled message content and recurrence settings;
  • Server configuration backups (premium servers), i.e. periodic snapshots of the settings above so they can be restored;
  • Your lifetime /vote total, tied to your Discord account, used solely to determine whether you've reached the 100-vote threshold for an automatic Premium key;
  • Premium key and activation records: which key was issued (and to whom, if issued manually), which server it was activated on, and by whom.

This data is tied to Discord IDs (server, channel, user), not to any information Discord doesn't already expose. We don't read or store the general chat history of your server; only the specific content described above.

4. Why we process this data

We process this data to operate the service you or your server owner asked for: authenticating you, applying the configuration you set, running moderation and automod, and keeping the features listed above working. Where EU/Romanian data protection law requires a legal basis, this is either performance of the arrangement you enter into by using the service, or our legitimate interest in running a functioning, secure bot and dashboard, whichever applies to the specific data involved.

5. Where data is stored and how it's protected

Configuration and bot data live in MongoDB Atlas. Your session is kept in a signed, HttpOnly, Secure, SameSite cookie described in detail in our Cookie Policy; it is not encrypted, but it is cryptographically signed so it can't be tampered with. The dashboard runs on Vercel, and all traffic is encrypted with HTTPS. Server-side checks make sure only an actual server owner or authorized staff can change that server's settings.

No system is perfectly secure, and this is a free service run by one person rather than a company. We take reasonable, genuine steps to protect your data, but we can't guarantee it will never be breached, and to the extent Romanian and EU law allows it, we're not liable for losses arising from a breach where the security measures described above were actually in place.

6. Who else sees this data

We don't sell your data, and we don't share it with advertisers. The only parties involved are:

  • Discord Inc., which provides the identity and OAuth data described above, under its own privacy policy;
  • MongoDB Atlas, which hosts our database;
  • Vercel, which hosts the dashboard.

Both MongoDB Atlas and Vercel act as processors on our behalf and run their own independent security programs; they don't use your data for their own purposes.

7. How long we keep it

Your session cookie, and the server-side session record it points to, expire after 7 days at most, or immediately on logout. Server configuration and history (moderation logs, levels, tickets, suggestions, scheduled messages, config backups) are kept for as long as Wody remains in that server, since removing the bot is how a server owner signals they no longer want that data retained. Your lifetime vote total and any premium key/activation records are kept for as long as they remain relevant to your account or server (for example, to prevent re-unlocking a revoked key). If you'd like specific records deleted sooner, contact us and we'll handle it manually.

8. Your rights

If you're in the EU/EEA, or wherever else applicable data protection law grants you these rights, you can:

  • Ask what data we hold about you and get a copy of it (access);
  • Ask us to correct inaccurate data (rectification);
  • Ask us to delete your data (erasure), subject to what a server owner needs kept for moderation records;
  • Ask us to restrict or object to certain processing;
  • Request your data in a portable format;
  • Lodge a complaint with your local data protection authority — in Romania, ANSPDCP.

To exercise any of these, email wodyteams@gmail.com. We'll respond within a reasonable time and may need to verify your Discord identity first.

9. Data about other server members

If you're a server owner or staff member configuring Wody, you may see data about other members of your server (their warnings, levels, ticket transcripts, and similar). You're responsible for using that data only for legitimate moderation purposes and in line with Discord's own rules and applicable law.

10. Children

The service follows Discord's own minimum age requirement (13, or higher where local law requires it). We don't knowingly collect data from anyone below that age beyond what Discord itself already provides through normal use.

11. International transfers

Our infrastructure providers (MongoDB Atlas, Vercel) may process data outside Romania, including outside the EU/EEA. Where that happens, we rely on the safeguards those providers make available, such as standard contractual clauses, to keep your data protected to a comparable standard.

12. Changes to this Policy

We can update this Privacy Policy whenever needed. The date at the top always shows the last revision, and meaningful changes will be announced on our community server where practical. Continued use of the service after the effective date of a revised Policy constitutes acceptance of it.

13. Contact

For any privacy, legal, or data related question, contact us at wodyteams@gmail.com.

Privacy Policy — Wody