Last updated 24 September 2026 · Effective 24 September 2026
Threelines operates the Discord bot Choc and its dashboard. For the purposes of the GDPR and similar laws, we are the data controller for the data described below. Discord Inc. is a separate controller for your Discord account itself — see Discord’s Privacy Policy.
The Bot stores only what its features need. Everything below is keyed to a Discord user ID or server ID — we never ask for your name, email or any other off-Discord identifier.
| Data | When it is stored | Feature it serves |
|---|---|---|
| Server ID, server name, and the settings an admin configures | When the Bot joins a server | All configuration |
| User ID, XP, level, message count, voice seconds | When you send a message or sit in a voice channel, if leveling is on | Levels, ranks, leaderboards |
| Wallet and bank balance, streaks, inventory, claim timestamps | When you use an economy command, if economy is on | Currency and shop |
| Profile fields you choose to set: bio, birthday (day and month only), colour, marriage | Only when you set them yourself | Profiles, birthday announcements |
| Moderation cases: your user ID, the moderator’s ID, action type, reason text, duration | When a moderator warns, mutes, kicks or bans you | Moderation history and audit |
| Reminder text you write, and where to deliver it | When you run /remind |
Reminders |
| Giveaway entries, suggestion text and votes, ticket metadata | When you enter, suggest or open a ticket | Those features |
| Ticket transcripts — the full message history of a ticket channel | When a ticket is closed, if the server enabled transcripts | Support record for staff |
| Aggregate counts: messages per day, per channel and per hour; joins; leaves; command usage | Continuously, if the Bot is in the server | Dashboard statistics |
| Saved music playlists you create | When you save one | Music |
Aggregate statistics are counters only. They record that a message was sent in a channel at a given hour, never who sent it or what it said.
We process this data to provide features you or your server administrators asked for. Under the GDPR our lawful basis is legitimate interest in operating the service you chose to use, and consent for optional fields you volunteer, such as your birthday or bio. We do not use your data for automated decisions with legal effects.
This is the part most worth reading carefully.
If a server enables automod, the Bot inspects message content in memory against that server’s rules — invites, links, banned words, spam patterns and so on. Content is not written to the database by this check. If a message violates a rule, a case record is created containing the rule name and the action taken, and a summary including an excerpt of the message may be posted to the server’s log channel.
If a server administrator enables message logging, the Bot posts deleted and edited message content to a log channel that administrator chose. That content lives in Discord, in that server’s channel, under that server’s control — not in our database. Ask your server’s administrators who can see that channel.
/snipe)The most recently deleted message in a channel is held in memory only so it can be shown by the snipe command. It is never written to disk and is lost whenever the Bot restarts.
If a server enables transcripts, closing a ticket saves that channel’s full message history to our database and to the server’s ticket log. This is the only feature that persists message content to our storage. If you do not want a conversation recorded, ask staff to close the ticket without a transcript, or do not use tickets in that server.
Signing in uses Discord OAuth2 with the identify and guilds scopes. We
receive your user ID, username, avatar, and the list of servers you are in — enough to show you
only the servers you can actually manage.
We do not sell your data. It is shared only in these cases:
The Bot and its database are hosted on [your hosting provider and region]. Update this line with your actual arrangement, as it determines where data is processed.
Depending on where you live, you may have the right to access, correct, export, restrict or delete your data, and to object to its processing. We honour these requests regardless of whether the law where you live requires it.
Two honest limits. First, moderation cases and ticket transcripts belong to the server’s audit record; a request to erase those is passed to that server’s administrators, and we may decline where retention is necessary for the server’s legitimate interest in moderation. Second, we cannot delete content already posted by the Bot into a server’s channels — that is under the server’s control, so contact its administrators.
We respond within 30 days. If you are in the EEA or UK and are unhappy with our response, you may complain to your local data protection authority.
Data is stored in a SQLite database on the host, restricted to the Bot process. Dashboard access is gated by Discord OAuth2, and server configuration pages require the Manage Server permission on the relevant server.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your data and creates a real risk to you, we will notify affected servers and, where required, the relevant authority.
The Bot is not directed at children under 13, or under the higher minimum age that applies in your country. We do not knowingly collect data from them. If you believe a child has provided data, contact us and we will delete it.
We may update this policy. The date at the top will change, and material changes will be announced through the Bot’s support server where one exists.
Privacy questions, access requests and deletion requests: [email protected]. Please include your Discord user ID so we can find your records.