Legal
Privacy Policy
Last updated 2026-09-08
This website
Everything else on this page is about what Righteous, the Discord bot, stores about you. This section is about the website you’re reading right now, which is a separate, much smaller thing.
This site is hosted on Vercel. Like any web host, Vercel necessarily processes some information for every request just to deliver the page: your IP address, browser user agent, the path you requested, and when you requested it. That’s ordinary infrastructure-level logging used to serve the page and guard against abuse, not something we query, export, or analyze ourselves.
We use Vercel Analytics to count page views in aggregate. It sets no cookie and writes nothing to your browser’s storage. Vercel identifies a “unique visitor” with a hash computed from the request that resets every 24 hours, so it can’t link your visits together across days, and it isn’t a personal identifier tied to you. What we see back is aggregate: the page, the referrer, and rough location and device type. We don’t receive raw IP addresses from it.
One page on this site can trigger a request to a third party on its own: the embed builder in the docs. If you type a complete custom Discord emoji code into one of its button fields, your browser fetches that emoji’s image directly from Discord’s CDN to preview it, the same as pasting that code into Discord itself would. Discord then sees your IP address, browser user agent, and this page as the referring URL for that one request. It only happens if you type a complete emoji code yourself; nothing on this site loads an outside image on its own.
This site doesn’t use cookies for any of the above, or for anything else. The cookie policy covers that in full, including why there is no consent banner.
1. What Righteous stores
What gets stored depends on which features a server or a member actually uses. In broad categories:
- Server configuration: settings for the features a server has turned on, logging preferences, moderation setup, ticket presets, custom embed codes, and similar.
- Whitelist and entitlement records: whether a server currently has access to Righteous, and the record of any Premium purchase behind it.
- Moderation history: a log of punishments (mutes, bans, warns, etc.) issued through the bot in a server: who issued it, the reason given, and when.
- Leveling XP: a running message-activity total per member per server, if a server has leveling turned on.
- Ticket records: the questions and answers from a ticket’s opening form, if a server uses the ticket system. A closed ticket’s transcript is posted as a file to the server’s own configured ticket-log channel. It isn’t held anywhere else by us.
- Last.fm account links: your Last.fm username, plus a cache of your top albums/tracks/artists and, for bought Premium members who’ve run a history sync, your full scrobble (listening) history, if you’ve linked an account.
- Letterboxd account links: your Letterboxd username and Letterboxd’s own public id for it, if you’ve linked an account — plus, if you run
,letterboxd update, a stored copy of the films you have logged and the films on your watchlist, with your rating for each. That copy is what lets the server-wide commands answer instantly instead of re-reading your profile every time. - Spotify account links: an OAuth token pair, if you’ve connected Spotify for the bot’s playback commands.
- Payment records: for anyone who has bought Premium or a Bot Purchase, a record of what was paid and when (not full card details, which are held by Stripe, never by us).
2. How long data is kept
A few specific things expire automatically, on a fixed schedule:
- A snapshot of a deleted or edited message, kept only so a server’s logging channel can show what changed: 24 hours.
- The cache that restores a member’s roles if they rejoin quickly after leaving: 12 hours by default. Configuring the window is free on every tier; Server Premium raises the ceiling to 48 hours.
- Internal Stripe webhook delivery receipts, used only to stop a retried payment event from being double-applied (not your payment history itself): 30 days.
- A finished giveaway’s list of entrants: kept for 14 days after the giveaway ends (so a reroll can still draw from it), then removed while the giveaway’s own record (prize, winners, dates) stays; that record is deleted at 90 days.
Everything else in Section 1 — server configuration, moderation history, ticket records, leveling XP, custom embed codes, your cached Last.fm library, your Spotify token pair, and whitelist and entitlement records — has no automatic expiry today. It’s kept until it’s deleted through one of the paths in Section 3, or by request.
Payment records are the one exception, and it is worth saying so plainly rather than leaving it to be inferred: they are kept as a permanent record. The collection behind them is append-only by design — a refund or a reversal is written as a new negative row rather than an edit to the row it reverses, so the history stays correct — and a business needs its own transaction records for accounting and tax purposes regardless. They are not deleted on request.
3. Deleting your data
Run ,lf reset confirm to unlink your Last.fm account and delete everything tied to it: your account link, your cached albums/tracks/artists, and your full synced scrobble history. It’s free and works for everyone, not just Premium members. It also answers to logout, delete, remove, forgetme, forget, wipe, deletedata, and unlinkme in place of reset, so however you think to ask for it works.
If you’ve connected Spotify, ,spotify logout deletes the stored token pair yourself (Self Premium, since that is what the whole ,spotify family is gated behind).
If you’ve linked Letterboxd, ,letterboxd reset unlinks the account and deletes the stored copy of your logged films and watchlist along with it. It’s free, and it also answers to unlink and logout.
For anything else in Section 1 — server configuration, moderation history, ticket records, leveling XP, custom embed codes, and whitelist and entitlement records — there is no self-serve deletion command yet. Ask in the support server or email righteouscord@gmail.com, and we’ll remove it by hand. Payment records are the exception, for the reason given in Section 2.
4. Third parties Righteous sends data to
- Discord: the platform Righteous runs on. Every message, member and server it can see, it sees the same way Discord shows it to any other bot.
- Last.fm: your linked username and, to build your stats, requests to Last.fm’s own API. Righteous only reads from Last.fm; it never posts, scrobbles, or writes anything back to your account.
- Spotify: if you connect an account, an OAuth token used to read what you’re playing and control playback (play, pause, skip) on your behalf.
- Letterboxd: your linked username, and requests to Letterboxd’s public website to read your diary, watchlist, favourites, follow list and logged films. Letterboxd has no public API, so this reads the same pages any signed-out visitor can see — nothing private, and nothing from an account set to private. Righteous only reads; it never posts, rates, logs a film, or changes anything on your Letterboxd account.
- TMDB: a film title you search for, sent to The Movie Database to work out which film you meant. Nothing about you goes with it — just the words you typed.
- Hugging Face: image or text content passed to their inference API when you use
/ocror/translate. - Groq: audio passed to their Whisper API when you use
/transcribe. - FlareSolverr: a Cloudflare-solving proxy we run ourselves, used only by the comics command to fetch a comic page’s URL. It’s our own infrastructure, not a third-party service, but it’s still a real network hop worth naming.
- Stripe: payment details for anyone who buys Premium. Stripe is the merchant of record for that transaction; see Terms for what that means.
5. Message content and logging
Righteous reads message content live to run the features a server has turned on (word filters, anti-nuke protection, autoresponders and the like), but doesn’t keep that content by default.
If a server has delete or edit logging turned on, the content of a deleted or edited message is kept for 24 hours (see Section 2) so the log entry can show what changed, then it’s removed automatically. A moderation action itself only stores the punishment type and the reason your staff typed, not the message content that may have prompted it.
6. Children
Discord’s own Terms of Service set the minimum age to use Discord at 13. Righteous is a general-audience bot, not directed at children, and doesn’t ask for or knowingly collect anyone’s age or birthdate; we rely on Discord’s own age floor rather than running a second one of our own.
If we ever learn, through a support conversation or otherwise, that we’ve collected data from someone under 13, we’ll delete it rather than keep it.
7. Your choices
A few things you can do yourself, right now:
- Run
,lf reset confirm(Section 3) to unlink and delete your Last.fm data. It’s free and self-serve, and since Last.fm data makes up the large majority of what Righteous stores overall, this one command covers most of what most people would ask to have deleted. - If you’ve connected Spotify (a Self Premium feature), run
,spotify logoutto delete your stored Spotify token pair. Also free-to-run and self-serve, for anyone who has a Spotify connection to begin with. - Leave a server. That stops any of its moderation, leveling, or logging features from applying to you going forward, though it doesn’t retroactively delete records that server already has stored (Section 1).
- For anything else, server configuration, moderation history, ticket records, leveling XP, or custom embed codes, there’s still no self-serve command (Section 3). Ask in the support server or email righteouscord@gmail.com, and we’ll handle it by hand.
Most U.S. state privacy laws — Texas’s and California’s included — that give you a formal right to access, correct, or delete your data are written with size thresholds well past a one-person operation like this one. So they don’t legally apply here today. That doesn’t change what we’ll actually do if you ask: reach out in the support server for a copy of what we have on you, a correction, or removal, and someone looks at it by hand.
One thing to state rather than leave unsaid: data may also be disclosed where the law requires it — a valid subpoena, court order, or equivalent legal process — or where it is necessary to investigate abuse of the bot. Nothing here has been asked for to date.
8. Do Not Track
Some browsers can send a “Do Not Track” signal when you visit a site. This website doesn’t set cookies or run any cross-site tracking script (see “This website” above), so there’s nothing here for that signal to turn off. We don’t currently respond to it differently, because doing so wouldn’t change anything we collect.
9. How this is protected
This site is served entirely over HTTPS: Vercel automatically issues and renews the certificate for it, and the static test mirror at test.righteousbot.dev does the same on its own through Caddy and Let’s Encrypt.
The database Righteous stores your data in runs on a private server and is reachable only from that same server, not from the internet. If you buy Premium, we never see your full card details; Stripe holds those (Section 1).
This is a small, one-person operation. We don’t have a security certification or a bug bounty program to point to. If you find a real problem, the support server is the fastest way to reach us.
10. Changes to this policy
We’ll update this page as Righteous or this site changes, and we’ll update the date at the top when we do. There isn’t a separate changelog for policy edits; the “Last updated” date is the marker of what’s current.
11. Contact
Righteous is run by one person, a sole proprietor based in Texas. There’s no company behind it, and there’s no published legal name or postal address for it. There is an email address: righteouscord@gmail.com, which is the right route for anything formal — a privacy request, a copyright notice, or a legal notice of any kind — because it doesn’t depend on an invite link staying valid. For everything else the support server is faster, and it’s where a person actually answers.
Questions about this page go to the support server, where a person answers them. For anything formal — a privacy request, a copyright notice, a legal notice — righteouscord@gmail.com reaches us without depending on an invite link staying valid.