Choc Pricing Privacy Terms
EN TH
Add to Discord Sign in with Discord

Privacy Policy

Last updated 24 September 2026 · Effective 24 September 2026

  1. Who we are
  2. What we collect
  3. What we do not collect
  4. Why we collect it
  5. Message content and logging
  6. The web dashboard
  7. Sharing and third parties
  8. How long we keep data
  9. Your rights and how to exercise them
  10. Security
  11. Children
  12. Changes to this policy
  13. Contact

1. Who we are

Threelines operates the Discord bot Choc and its dashboard. For the purposes of the GDPR and similar laws, we are the data controller for the data described below. Discord Inc. is a separate controller for your Discord account itself — see Discord’s Privacy Policy.

2. What we collect

The Bot stores only what its features need. Everything below is keyed to a Discord user ID or server ID — we never ask for your name, email or any other off-Discord identifier.

DataWhen it is storedFeature it serves
Server ID, server name, and the settings an admin configures When the Bot joins a server All configuration
User ID, XP, level, message count, voice seconds When you send a message or sit in a voice channel, if leveling is on Levels, ranks, leaderboards
Wallet and bank balance, streaks, inventory, claim timestamps When you use an economy command, if economy is on Currency and shop
Profile fields you choose to set: bio, birthday (day and month only), colour, marriage Only when you set them yourself Profiles, birthday announcements
Moderation cases: your user ID, the moderator’s ID, action type, reason text, duration When a moderator warns, mutes, kicks or bans you Moderation history and audit
Reminder text you write, and where to deliver it When you run /remind Reminders
Giveaway entries, suggestion text and votes, ticket metadata When you enter, suggest or open a ticket Those features
Ticket transcripts — the full message history of a ticket channel When a ticket is closed, if the server enabled transcripts Support record for staff
Aggregate counts: messages per day, per channel and per hour; joins; leaves; command usage Continuously, if the Bot is in the server Dashboard statistics
Saved music playlists you create When you save one Music

Aggregate statistics are counters only. They record that a message was sent in a channel at a given hour, never who sent it or what it said.

3. What we do not collect

  • We do not store your email address, phone number, IP address, or payment details.
  • We do not store your Discord password or token — sign-in goes through Discord’s own OAuth2.
  • We do not store a general archive of your messages. See section 5 for the narrow exceptions.
  • We do not read your direct messages with other people.
  • We do not sell, rent or share your data for advertising, and we do not profile you for it.

4. Why we collect it

We process this data to provide features you or your server administrators asked for. Under the GDPR our lawful basis is legitimate interest in operating the service you chose to use, and consent for optional fields you volunteer, such as your birthday or bio. We do not use your data for automated decisions with legal effects.

5. Message content and logging

This is the part most worth reading carefully.

Automated moderation

If a server enables automod, the Bot inspects message content in memory against that server’s rules — invites, links, banned words, spam patterns and so on. Content is not written to the database by this check. If a message violates a rule, a case record is created containing the rule name and the action taken, and a summary including an excerpt of the message may be posted to the server’s log channel.

Audit logging

If a server administrator enables message logging, the Bot posts deleted and edited message content to a log channel that administrator chose. That content lives in Discord, in that server’s channel, under that server’s control — not in our database. Ask your server’s administrators who can see that channel.

Deleted-message cache (/snipe)

The most recently deleted message in a channel is held in memory only so it can be shown by the snipe command. It is never written to disk and is lost whenever the Bot restarts.

Ticket transcripts

If a server enables transcripts, closing a ticket saves that channel’s full message history to our database and to the server’s ticket log. This is the only feature that persists message content to our storage. If you do not want a conversation recorded, ask staff to close the ticket without a transcript, or do not use tickets in that server.

6. The web dashboard

Signing in uses Discord OAuth2 with the identify and guilds scopes. We receive your user ID, username, avatar, and the list of servers you are in — enough to show you only the servers you can actually manage.

  • Your OAuth access token is held in a server-side session and is not written to our database.
  • A single session cookie is set. It is strictly necessary for login; we use no analytics, advertising or third-party tracking cookies.
  • Logging out, or leaving the session to expire, discards the token.

7. Sharing and third parties

We do not sell your data. It is shared only in these cases:

  • Discord — inherently, since the Bot operates on their platform.
  • Audio sources — when you use music commands, your search query is sent to the relevant third-party platform to resolve a track. Your Discord identity is not sent with it.
  • Other members of your server — leaderboards, profiles, level-up announcements and moderation logs are visible to people in that server by design.
  • Legal obligation — where we are required by valid legal process to disclose data.

The Bot and its database are hosted on [your hosting provider and region]. Update this line with your actual arrangement, as it determines where data is processed.

8. How long we keep data

  • While the Bot is in your server: as long as the feature needs it.
  • Reminders: deleted once delivered, unless you set them to repeat.
  • Deleted-message cache: until the next restart.
  • Moderation cases: retained as a server audit record, including after a warning is voided, until the server is deleted or an administrator requests removal.
  • If the Bot is removed from a server: the server is marked as departed. Its data is retained for 30 days so nothing is lost if the Bot is re-added by mistake, then deleted.
  • On request: deleted as described below.

9. Your rights and how to exercise them

Depending on where you live, you may have the right to access, correct, export, restrict or delete your data, and to object to its processing. We honour these requests regardless of whether the law where you live requires it.

  • Access or export — email us with your Discord user ID and we will send you everything stored about you, in JSON.
  • Deletion — email us with your Discord user ID. We will erase your member records, profile fields, reminders, playlists and inventory.
  • Correction — most profile fields can be changed yourself with the profile commands.

Two honest limits. First, moderation cases and ticket transcripts belong to the server’s audit record; a request to erase those is passed to that server’s administrators, and we may decline where retention is necessary for the server’s legitimate interest in moderation. Second, we cannot delete content already posted by the Bot into a server’s channels — that is under the server’s control, so contact its administrators.

We respond within 30 days. If you are in the EEA or UK and are unhappy with our response, you may complain to your local data protection authority.

10. Security

Data is stored in a SQLite database on the host, restricted to the Bot process. Dashboard access is gated by Discord OAuth2, and server configuration pages require the Manage Server permission on the relevant server.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your data and creates a real risk to you, we will notify affected servers and, where required, the relevant authority.

11. Children

The Bot is not directed at children under 13, or under the higher minimum age that applies in your country. We do not knowingly collect data from them. If you believe a child has provided data, contact us and we will delete it.

12. Changes to this policy

We may update this policy. The date at the top will change, and material changes will be announced through the Bot’s support server where one exists.

13. Contact

Privacy questions, access requests and deletion requests: [email protected]. Please include your Discord user ID so we can find your records.

Choc

The all-in-one Discord bot — levels, moderation, economy, music and a dashboard that shows you what is actually happening in your server.

Product
Features Pricing Add to Discord
Legal
Terms of Service Privacy Policy
Account
Sign in with Discord
© 2026 Choc. All rights reserved. Not affiliated with Discord Inc.