Privacy Policy

Effective and last updated: August 5, 2026

1. Scope

This Privacy Policy explains what data ChatSift collects, why, and how you can reach us about it, for our bots and the ChatSift dashboard.

2. Information we collect

We only collect what the Service needs to do the thing you're using it for:

  • Discord identifiers. User IDs, guild (server) IDs, channel/message IDs — the raw identifiers Discord itself uses. We don't separately store your username, avatar, or discriminator; those are fetched live from Discord whenever the dashboard displays them, not kept in our database.
  • AMA content. Questions submitted through an AMA session, tied to the submitting user's ID.
  • ModMail content. Ticket messages are only stored beyond the lifetime of the Discord conversation itself if a server's staff explicitly turn on transcript recording for that server — it's opt-in per server, off by default. Server config (snippets, greeting messages, category setup) is always stored, since it's how the bot is configured.
  • Dashboard session data. When you log in via Discord OAuth, we request the identify, guilds, and guilds.members.read scopes — enough to know who you are and which servers you can manage — and hold a Discord access/refresh token in an encrypted session cookie so you stay logged in. We don't request or store your email address.

We don't collect your IP address, and we don't run any analytics or tracking scripts on the dashboard.

3. How we use it

Solely to operate the Service: routing AMA questions through the queues you've configured, relaying ModMail tickets between a user and server staff, remembering your server's bot configuration, and keeping you logged into the dashboard. We don't use your data for advertising, profiling, or anything unrelated to the feature you're actually using.

4. How long we keep it

Server configuration, AMA questions, and (where a server has opted in) ModMail transcripts are kept indefinitely — this is what powers the dashboard's historical views (past AMA sessions, ticket history, snippet usage), which server staff rely on as an ongoing record, not just a live queue. If a feature is discontinued, we will purge all data associated with it.

Dashboard session cookies expire after 30 days of inactivity. If you'd like something deleted sooner, see Section 7 below.

5. Who we share it with

We don't sell, rent, or share your data with third parties. The only place your data goes is Discord's own API, because that's how the Service works in the first place. We don't use any third-party analytics, advertising, or error-tracking services that your data would pass through.

6. Security

We take reasonable technical measures to protect your data, including:

  • Your Discord OAuth tokens are encrypted, not just signed, wherever they're embedded in your session. The longer-lived one is only ever transmitted over an httpOnly, secure cookie, never accessible to client-side JavaScript; a short-lived (5-minute) one is held in memory by the dashboard itself so it can attach it to your requests, and is refreshed automatically.
  • API credentials stored in the database (such as branded ModMail deployments) are encrypted (AES-256-GCM).
  • Access to production systems is restricted to the ChatSift team.

In the event of a data breach affecting your information, we will notify Discord as required by their Developer Terms of Service and post an announcement on our support server.

7. Your rights & how to reach us

If you'd like to know what data we hold about you, or want it deleted, reach out to a ChatSift Team member on our support server — we'll handle it directly.

8. Children's privacy

The Service is only for people who meet Discord's own minimum age requirement (13, or older where local law requires it) — we don't knowingly collect data from anyone younger, and access is gated entirely through your Discord account.

9. Changes to this policy

We may update this Privacy Policy from time to time. If we make a material change, we'll update the "last updated" date above. Continuing to use the Service after a change means you accept the updated policy.