← AEGIS

Privacy Policy

Last updated: 2026-08-05

1. Scope

This policy covers the AEGIS Discord bot and the AEGIS dashboard. It describes what data the Service processes, why, for how long, and what control server administrators and members have over it.

2. What we collect — bot

For servers where AEGIS is installed, the Service processes and stores:

  • Identifiers: Discord user IDs, usernames, server (guild) IDs, role IDs, channel IDs, and message IDs.
  • Security signals: normalized event metadata — e.g. join timing, account age, message counts, mention counts, and hostnames of links — with a severity and the deterministic risk factors derived from it.
  • Moderation records: cases (action, reason, moderator, timestamps), incidents, appeals, and staff notes created by your server's staff or by configured automation.
  • Audit events: an append-only, integrity-protected log of security and configuration actions.

3. What we deliberately do NOT collect

  • Message content is not stored by default. Spam detection uses transient in-memory analysis; stored signals carry metadata (counts, hostnames, rule names), not message text. The exceptions are deliberate and visible: when a staff member uses "Report Message", a short content preview (≤200 characters) is stored as evidence context, and servers can enable message-snapshot evidence under their retention policy.
  • No tracking pixels, advertising identifiers, or third-party analytics on this site.
  • No identity correlation beyond what Discord exposes; no collection of member IP addresses via the bot.
  • Server data is never sold and is not used to train machine-learning models.

4. What we collect — dashboard

  • Account: your Discord user ID, username, and avatar, obtained via Discord OAuth when you sign in. OAuth tokens are stored encrypted (AES-256-GCM) and are used only to verify your identity and server memberships.
  • Sessions: a session record including IP address and browser user-agent, kept for security auditing of logins. Session tokens are stored hashed.
  • Cookies: one essential cookie (aegis_session) that keeps you signed in. There are no advertising or cross-site cookies.

5. Retention and deletion

Each server selects a retention class; expired data is purged automatically on a scheduled job:

  • Security signals: 30 days (minimal) / 180 days (standard, default) / up to 1 year (extended).
  • Message-derived evidence: 30–90 days by class; deleted evidence is hard-purged 30 days after removal.
  • Moderation cases and audit events persist as the server's enforcement record; hourly analytics aggregates (counts only) outlive raw signals.
  • Dashboard sessions expire after 7 days and can be revoked everywhere at once.

Removing AEGIS from a server stops all collection for that server immediately; stored data then ages out under the rules above, and full deletion can be requested from the AEGIS operator via Discord.

6. Access controls on your data

Access to investigation data is permission-gated per server through AEGIS's role-based access control. Revealing stored evidence requires a dedicated permission, and every evidence access is itself logged (who, when, through which surface). Dashboard access to a server's data requires both current membership in that server and an assigned AEGIS role.

7. Where data lives and who touches it

Data is stored on infrastructure operated by the AEGIS operator (currently a European VPS hosted with OVH). Traffic may pass through Cloudflare where enabled for DDoS protection. If error monitoring (Sentry) is enabled, crash reports contain technical error details and correlation IDs — not message content or tokens. Discord itself processes all platform traffic under its own privacy policy. No other third parties receive server data.

8. Your rights

Depending on your jurisdiction you may have rights to access, correct, or erase personal data. Members should contact their server's administrators first, since moderation records belong to the server's legitimate operation; for anything unresolved, contact the AEGIS operator via Discord. We will respond to verifiable requests within a reasonable period.

9. Changes

Material changes to this policy will appear on this page with an updated date. The Terms of Service incorporate this policy.