Privacy Policy
How Kaivor collects, uses, stores, and protects personal data.
Effective 4 September 20261. Scope
This Privacy Policy applies to the Kaivor Discord bot, documentation website, private beta, support, integrations, and related services. It explains how personal data is handled when Kaivor is installed, used, connected to an integration, or accessed through the website.
2. Data controller and contact
Kaivor is the service name used by a privately operated data controller based in Norway. The controller determines the purposes and means of the processing described in this policy.
The operator does not publish a private home address on this website. Necessary controller information will be provided to a verified data subject, Datatilsynet, or another competent authority through a secure channel where required. A public legal entity name and service address must be added before Kaivor expands beyond its current closed beta or begins accepting payment.
To make a privacy request, join Kaivor's official Discord support server and open a private ticket marked "Privacy Request." Include your Discord user ID, the relevant server ID, what you request, and enough information to verify that the request concerns you. Do not post personal information in a public channel.
A Discord server owner or administrator may separately control how Kaivor is configured and used in that server. Questions about a server's rules, logs, or moderation should normally be directed to that server first.
3. Data Kaivor may process
Depending on enabled features, Kaivor may process:
- Discord user, server, channel, role, message, webhook, application, and interaction identifiers.
- Public Discord profile data available through Discord's API, including usernames, display names, avatars, roles, membership, voice state, and presence.
- Custom-status text when Vanity Roles are enabled. Kaivor checks whether it contains administrator-configured text.
- Commands, arguments, settings, permission checks, cooldowns, and feature usage.
- Configuration snapshots created by administrators. These contain Kaivor settings and identifiers, not copies of Discord messages, channels, roles, member content, or moderation cases.
- Privacy requests and export-delivery records needed to verify, track, and answer a request.
- Weekly report settings and aggregate seven-day activity counts sent to a channel selected by an administrator.
- Moderation and security records, including cases, punishments, automod events, antinuke events, ignored targets, and audit identifiers.
- Message content and attachment links when required by an enabled feature, including snipes, ticket transcripts, logging, automod, starboard, reminders, tags, autoresponses, and scripts.
- Ticket openers, form answers, subjects, staff actions, timestamps, and transcripts.
- OAuth tokens, account identifiers, subscription settings, and information returned by integrations a user or administrator chooses to connect.
- Error logs, health information, latency, timestamps, shard information, rate-limit events, and security records.
- Website information processed by hosting and analytics providers, including IP address, browser and device information, referring page, and page activity where analytics are enabled.
Kaivor does not request Discord passwords, user tokens, payment-card details, government identifiers, health information, or other sensitive personal data. Do not submit such information through commands, tickets, forms, or support.
4. Sources
Kaivor receives data from Discord's API, server administrators, users who interact with Kaivor, connected services, the documentation website, and Kaivor's hosting and security systems.
5. Purposes and legal bases
Kaivor processes data:
- To provide requested bot, beta, support, integration, and website functions, based on an agreement or requested pre-contract steps.
- To provide moderation, security, abuse prevention, reliability, diagnostics, and service improvement, based on Kaivor's and server administrators' legitimate interests.
- To run an optional account connection or consent-based feature. Consent may be withdrawn by disconnecting the feature or submitting a request.
- To comply with legal duties, enforce rights, respond to lawful requests, and protect users or the service.
Kaivor does not sell personal data, use Discord API data for targeted advertising, disclose it to data brokers, or use message content to train artificial-intelligence models.
6. Administrator responsibilities
Server administrators choose which features to enable. They must use Kaivor lawfully, give members any required notice for logging, moderation, transcripts, deleted-message features, presence-based roles, and integrations, and restrict sensitive commands and outputs to authorized staff.
7. Retention
Retention depends on the feature:
- In-memory deleted-message, edited-message, and removed-reaction snipes are normally cached for two hours. No more than 20 entries of each snipe type are kept per channel.
- Persistent snipe archives and recent-join detection records use the server's temporary-data retention setting. The default is 30 days and administrators may choose 7 to 365 days.
- Configuration snapshots are limited to the newest 25 snapshots per server unless an administrator deletes them sooner.
- Privacy-request records remain while needed to verify, answer, and demonstrate handling of the request.
- Configuration, moderation, security, ticket, reminder, logging, role, level, giveaway, and integration records may remain while needed to provide the feature, maintain an audit history, resolve disputes, or protect the service.
- Ticket transcripts exported into Discord remain under the control of the receiving server and are also subject to Discord's practices.
- OAuth tokens remain until the integration is disconnected, the token expires or is revoked, or the related data is deleted.
- Operational logs and backups are kept only for a period appropriate to security, recovery, and troubleshooting.
- Removing Kaivor marks a server inactive but may not immediately erase every database record. A server owner may request deletion through the official support server.
Data is deleted or anonymized when no longer reasonably needed, subject to legal obligations, fraud prevention, security, backups, and legal claims.
8. Sharing and providers
Kaivor may disclose data only as needed to operate the service, comply with law, or protect rights. Providers may include Discord, Novonode or another disclosed bot host, Vercel, Supabase, selected integrations, future payment providers, professional advisers, and competent authorities.
Integration providers can include Spotify, Last.fm, YouTube, Twitch, Reddit, weather, translation, and audio services. Each provider has its own terms and privacy policy. Kaivor does not authorize providers to use Discord API data for unrelated advertising or data brokerage.
9. International transfers
Providers may process data outside Norway or the European Economic Area. Where required, Kaivor relies on an adequacy decision, approved contractual safeguards, or another lawful mechanism.
10. Security and incidents
Kaivor uses access controls, least-privilege permissions, encryption for supported credentials and tokens, restricted administration, validation, and logging. No online service can guarantee absolute security.
Kaivor will investigate security incidents and provide notifications required by law or Discord's rules to affected users, Discord, and competent authorities.
11. Your rights
Subject to law, you may request access, correction, deletion, restriction, objection, or portability. You may withdraw consent where processing relies on consent. You may complain to Datatilsynet, the Norwegian Data Protection Authority.
Requests may require verification through a Discord user ID, server ID, a direct-message confirmation, or confirmation from the relevant server owner. Kaivor aims to respond within one month where the GDPR applies, subject to lawful extensions for complex or numerous requests. Limited data may be retained where required by law or necessary for security, fraud prevention, or legal claims.
12. Children
Kaivor is not directed to anyone below Discord's minimum age in their country. Report suspected ineligible use privately through the official support server.
13. Platform rules
Use of Kaivor is also subject to Discord's Terms of Service, Privacy Policy, Community Guidelines, Developer Terms, and Developer Policy. Connected services have their own terms and policies.
14. Changes
This policy may change with Kaivor's features, providers, or legal duties. The current version and effective date will appear here. Material changes will be announced through an appropriate Kaivor channel where reasonably possible.