← Back to home

Privacy Policy

Last updated: August 7, 2026

Draft — not legal advice.This is a plain-language template describing what ModDock actually collects and does, written to be a reasonable starting point for GDPR compliance. It isn't a substitute for review by a lawyer.

Data controller

ModDock is operated by an individual based in the Netherlands. For any privacy question or request, contact tjerkbakker@protonmail.com— that's also the fastest way to reach the person responsible for your data under GDPR.

Who this applies to

This policy covers two groups: server administrators who sign in to the ModDock web dashboard, and members of a Discord serverthat has added the ModDock bot. You don't need to sign in to the dashboard for the bot to process your data — using a server the bot is in is enough, the same way any other bot in that server works.

What we collect

If you sign in to the dashboard(via "Sign in with Discord"), we receive your Discord user ID, username, avatar, email address, and the list of servers you have the "Manage Server" permission in — Discord only shares what its own login screen shows you at the time.

If you use a server the bot is in, depending on which features that server's admins have turned on, we may store:

  • Your Discord user ID and username, wherever an action involves you (a case, a ticket, a report, etc.)
  • Message content, but only when a moderator or automod rule specifically flags it — a warning's evidence snapshot, an edited/deleted message log, a ticket transcript, or a message you reported
  • Moderation history: warnings, kicks, bans, timeouts, and mod notes, including the reason given
  • Join/leave timestamps, invite-tracking data (who invited whom), and voice-channel session times
  • Leveling/XP progress, giveaway entries, reaction-role selections, suggestions, and appeal messages
  • Aggregate message-activity counts per channel/hour (for the busiest-times dashboard chart) — this is a running count, not the messages themselves

We don't read messages in channels the bot isn't configured to act on, and we don't sell any of this data to anyone.

Why we collect it

To provide the moderation/utility features a server's admins have chosen to enable, and to let those admins review what actions were taken and why — that's the entire purpose of a moderation bot. Signing in to the dashboard is on the basis of your consent (you choose to sign in); data generated by using a server is processed on the basis of the server admins' legitimate interest in moderating their own community.

Who else sees it

Nobody outside the infrastructure needed to run the service. The database itself is hosted by Neon (Postgres) in AWS's London (UK) region. The dashboard runs on Vercel and the bot process on Railway, both of which may process data outside the EU/UK depending on where a request is served from. Where data leaves the EU/UK, we rely on those providers' own standard contractual clauses as the transfer safeguard. Discord itself, as the platform this all runs on top of, has its own separate Privacy Policy covering what it collects.

How long we keep it

Moderation history (cases, logs, etc.) is kept indefinitely by default, the same way Discord's own audit log or any other moderation bot's case history works — it's the record server admins rely on. If the bot is removed from a server, its data isn't automatically deleted. You can request deletion of your own data at any time (see below).

Your rights

Under GDPR (and similar laws elsewhere), you have the right to:

  • Delete your dashboard account yourself— Settings → Danger zone → Delete my account, no need to email anyone. This removes your login, profile, and any team access you've been granted on other servers.
  • Show you what data we hold about you
  • Correct inaccurate data
  • Delete data tied to your Discord ID in a specific server (subject to that server's admins' legitimate need to keep moderation records)
  • Restrict or object to certain processing
  • Export your data in a portable format

The self-service option above covers your dashboard account immediately. For anything else on this list, contact tjerkbakker@protonmail.com. You also have the right to complain to your local data protection authority at any time — in the Netherlands, that's the Autoriteit Persoonsgegevens(autoriteitpersoonsgegevens.nl); if you're elsewhere in the EU/EEA, your own country's authority.

Cookies

The dashboard sets a single session cookie to keep you signed in — nothing else, no advertising or tracking cookies. That cookie is strictly necessary for the login to function at all, so under GDPR/ ePrivacy rules it doesn't require a cookie-consent banner — there's nothing optional to consent to.

Data breaches

If a breach involving your personal data happens and poses a real risk to you, we'll notify the Dutch data protection authority within 72 hours as GDPR requires, and notify affected users directly where the risk is high enough to require it.

Children

ModDock follows Discord's own Terms of Service, which require users to be at least 13 (or older where local law requires it). We don't knowingly collect data from anyone younger.

Changes to this policy

If this policy changes materially, we'll update the date at the top. Continued use of the dashboard or a server running the bot after a change means you accept the update.

Contact

Questions about this policy or your data: tjerkbakker@protonmail.com.