Legal
Privacy Policy
What Aegis stores, why it stores it, where it lives, and how to get rid of it. Written to describe what the bot actually does rather than what a template says.
Last updated: September 2026
1. Who this covers
Aegis is a Discord bot, together with its web dashboard at aegisdashboard.xyz and the casino activity that runs inside Discord. This policy covers all three.
Aegis is self-hosted and run by an individual operator, not a company. It is not affiliated with Discord Inc.
Two different people are involved in any server using Aegis. Server administrators decide which features are switched on and how they are configured. Members of those servers have data stored as a result of those choices. Administrators control what is collected in their own server; the operator controls how it is stored and secured.
2. What Aegis stores
Aegis only stores what a feature needs in order to work. If a feature is switched off in your server, it stores nothing. Everything below is keyed to a Discord server ID, a Discord user ID, or both.
| Data | Stored because |
| Discord IDs | User, server, channel, role and message IDs are the keys everything else hangs off. Aegis works from IDs rather than names, and where a name is kept as well, the row for it below says so. |
| Server configuration | Every setting made through the dashboard or slash commands — which channels features use, which roles they grant, thresholds, toggles, custom text. |
| Moderation records | Warnings, notes staff write about a member, mutes, and a log of moderation actions with the name of the moderator who performed them and any reason given. Each entry records the punished member's Discord user ID as well as the username they had at the time, so a strike record still points at the same person after they change their name. |
| Member reports | Where message reporting is enabled: who reported, who was reported, the channel and message, a copy of the reported message's text, whatever the reporter typed, and which moderator handled it and how. See message content below. |
| Ban appeals | Where ban appeals are enabled: the appealing person's user ID and the username on their account, the reason recorded against their ban, what they wrote in the appeal, the replies moderators sent them, and the decision with who made it. A server's list of people blocked from appealing again is kept until staff undo it. |
| Levels & XP | Message and voice XP, level, and level card preferences, where leveling is enabled. |
| Economy & games | Wallet and bank balances, inventory, shop and auction activity, and per-game statistics, where the economy is enabled. |
| Fishing | Catches, collection progress, bait, and profile, where fishing is enabled. |
| Achievements | Which badges a member has earned in a server and when, and whether they have turned off being pinged by the announcement. Most badges read counts Aegis already keeps for other features; the hidden ones hinge on moments nothing else records, so a small per-member tally of those is kept too. |
| Tickets | Open tickets, and closed-ticket transcripts — see message content below. |
| Birthdays | Day and month, and year only if a member chooses to give one. |
| Invite tracking | Which invite a joining member used and who created it. |
| Role persistence | A member's roles, kept so they can be restored if they rejoin, where this is enabled. |
| Verification | When a member verified, and — where raid defense is enabled — a risk score with the reasons behind it, which can include signals suggesting an account may be an alternate of another. |
| Activity counts | Per member, counts of messages sent, reactions added and seconds spent in voice, for the activity leaderboards — counts only, with no channel and no timestamps. Per channel, a message count and when that channel was last used, for the analytics page. No message content either way. |
| Last known name | The display name a member last used in a server, so leaderboards can still label their entry after they leave. A name and nothing else. |
| Starboard, counting, reminders, temp voice, and similar | The small amount of state each of those features needs, such as which message was starred or the current count. |
One thing is published rather than merely stored. A server can apply to be listed on the Aegis homepage, and if the application is approved its name, icon and member count appear on a public page. It is off unless a server owner or administrator applies, reviewed by hand before anything shows, and no invite is ever published, so being listed gives nobody a route into the server. Members are never named on it.
Aegis does not store real names, email addresses, phone numbers, IP addresses, payment details, or anything about you from outside Discord. It does not build advertising profiles and has no analytics or tracking of that kind.
3. Message content
This deserves its own section, because it is the part people most want a straight answer on.
Read but not kept
Several features have to look at messages as they arrive: AutoMod filtering, scam and phishing link detection, the counting game, sticky messages, and XP. In every one of those cases the message is examined in memory as it arrives and then discarded. Nothing is written down.
Kept, where the feature is one that inherently keeps it
- Ticket transcripts. When a ticket is closed, Aegis saves a transcript of that ticket conversation so staff can refer back to it. This is the most sensitive thing Aegis stores. It exists only if ticketing is enabled, and only for messages sent inside a ticket channel. Files posted in the ticket are recorded by filename; the file itself is not kept, with one exception: on premium servers a copy of any image posted in the ticket is saved alongside the transcript, up to 8MB per ticket and 250MB per server, because Discord's own link to it stops working once the ticket channel is deleted. Those copies are ordinary files on the server, are shown only to the same server administrators who can already read the transcript, and are deleted whenever the transcript is — including when it ages out of the archive, when the server runs out of image storage and the oldest are dropped, when a member's ticket data is erased, and when Aegis is removed from the server. Non-image files are never kept, on any tier. A server keeps its newest 1,000 transcripts (5,000 on premium); once that is reached, closing a ticket permanently deletes the oldest one. Staff can also delete transcripts deliberately, one at a time or in bulk, and download any transcript as a file to keep outside Aegis.
- Staff notes. Notes are written by your server's staff about a member and are stored as written.
- Moderation reasons. The reason text a moderator types when warning, muting or banning someone.
- Reported messages. Where message reporting is enabled, reporting a message saves a copy of that message's text with the report, up to 1,000 characters, because the message itself can be deleted before a moderator reads it. Anything the reporter typed is saved with it. The reporter is named to the server's moderators. A report that has been dismissed or actioned is deleted 90 days after it was filed; one still open is kept until staff deal with it.
- Ban appeal text. Where ban appeals are enabled, what somebody writes on the appeal page is stored, along with the replies moderators send back to them and the reason recorded against the ban. An appeal that has been approved or denied is deleted, with its messages, 90 days after it was filed; one still open is kept until it is decided.
- Message logs. If message logging is enabled, edited and deleted messages are posted to a log channel in your own Discord server. Those logs live in Discord, under your server's control — Aegis does not keep a separate copy in its database.
Aegis never reads direct messages, and never reads messages in servers it has not been added to. It cannot see anything a Discord user with the bot's permissions could not also see.
4. How it is used
Stored data is used for one purpose: making the features you switched on work inside your own server. That is the whole list.
It is never sold, rented, shared with advertisers, used for profiling across servers, or used to train anything. Nobody buys access to it.
Moving your own progress between servers
There is one way data crosses from one server to another, and only a member can start it: the /transfer command moves your own fishing progress and achievement badges out of a server you are in and into another one you are also in. Nothing moves unless you run it yourself and confirm it, it is limited to once every 24 hours, and the receiving server has to have allowed incoming fishing progress at all.
Currency, bank balances, XP, levels, warnings, notes and message history never move. Nobody but you can trigger it, an admin cannot run it on your behalf, and it is not a route for one server to read another's data — it only ever carries your own records, to a server you are already a member of.
The operator can access the database, because it runs on their server — that is unavoidable for anyone self-hosting software. In practice this access is used for fixing bugs and answering support requests, not for reading through server data.
5. Where it is stored
- Everything lives in a single encrypted SQLite database on the server that runs Aegis. The database is encrypted at rest with SQLCipher, so the file cannot be read without the key — a stolen copy of the file on its own is not readable.
- The server is a private virtual server rented from a hosting provider. The provider has physical access to the machine, as any host does, but the database itself is encrypted.
- Data is not copied to any third-party service, analytics platform, or data broker.
- Backups, where taken, are of the same encrypted file and are held under the same conditions.
No system is perfectly secure, and Aegis is run by one person rather than a company with a security team. The measures above are real, but they are described so you can judge them, not as a guarantee.
6. Dashboard & sign-in
Signing in to the dashboard uses Discord OAuth2. Aegis requests two scopes: identify and guilds. That gives it your user ID, username, avatar, and the list of servers you are in — enough to show you the servers you can manage. It does not request your email address, your messages, or the ability to act as you.
When you sign in, a session is created on the server and a cookie holding only a session identifier is set in your browser. The session record itself is kept in the same encrypted database and holds your Discord access and refresh tokens so the dashboard can keep talking to Discord on your behalf while you are signed in.
The session cookie is httpOnly, is marked Secure over HTTPS, and uses SameSite=Lax. It is a rolling one-year session, refreshed on each visit — so in practice you stay signed in until you log out, stay away for a year, or revoke Aegis from your Discord account settings.
Logging out deletes the session record and the tokens in it. Revoking Aegis in Discord's authorized-apps settings invalidates the tokens immediately.
The ban appeal page on this site uses that same sign-in and the same session, which is how an appeal can be tied to the account that filed it. Signing in there does not put anyone back into the server they are appealing to, and it does not give them anything on the dashboard they could not already reach.
The dashboard uses no analytics, no advertising cookies, and no tracking pixels. The only cookie it sets is the session one.
7. The casino activity
The casino runs as a Discord activity — a page Discord displays inside its own client. It signs you in with Discord OAuth2 using only the identify scope, and it checks that you are a member of the server whose casino you are opening.
Games played there use the same wallet and the same records as the equivalent slash commands; nothing extra is stored because you played in the activity rather than in chat. The page keeps a short list of your recent results in your browser for the duration of the session, and forgets it when you close the activity.
There is also a public demo of the casino, linked from the Aegis listing on top.gg and playable without adding Aegis to a server. It has no sign-in and no Discord account behind it, hands every visitor their own private tables and play chips, and runs against a separate scratch database that is deleted every time it restarts. Nothing played there touches the main database or any server's currency, and the only thing kept is a count of how many games have been started at each table.
8. Third parties
Aegis talks to a small number of outside services. What each one receives:
Webfonts are served from this site rather than from Google Fonts, so loading a page here sends nothing to Google — no IP address, no user agent, no request at all.
| Service | What it receives |
| Discord | Everything Aegis does happens through Discord's API. Discord's own Privacy Policy governs that. |
| Top.gg | Only if your server uses vote rewards. Top.gg tells Aegis that a given Discord user voted; nothing is sent the other way. |
| Twitch & YouTube | Where social notifications are configured, Aegis polls their public feeds for the channels your server chose. This is outbound only — no member data is sent. |
| Hosting provider | Runs the server. Sees network traffic and holds the machine, as any host does. |
9. Retention & deletion
When Aegis is removed from a server
By default, removing Aegis from a server immediately and permanently deletes everything stored for that server — configuration, levels, warnings, notes, moderation logs, birthdays, economy balances, fishing progress, badges earned, tickets and their transcripts, member reports, ban appeals and the messages in them, saved roles, and analytics counts. This happens automatically at the moment of removal and is not recoverable.
There is one exception, and it is one a server administrator has to switch on deliberately: a "keep data if Aegis is removed" setting exists in the dashboard so a server can re-add the bot without losing its setup. When that setting is on, data is kept instead of deleted. It is off unless someone turns it on.
While Aegis is in your server
- If a member leaves and the server has turned off "keep XP, currency & fishing data", those are deleted for that server at once, along with the badges they earned, their counter tallies and game statistics, their birthday, and the last display name held for them. Nothing is retained and nothing is merely hidden. The same goes for their tickets and transcripts under the separate ticket setting. Both settings are on by default.
- While that setting is on, Aegis keeps the last display name it saw for a member so leaderboards can still label their entry after they leave. It holds a name and nothing else, it is deleted with the rest of their data, and it goes when Aegis is removed from the server.
- Aegis keeps a running count per member per server of messages sent, reactions added and seconds spent in voice channels, for the activity leaderboards. These are counts only — no message content, no channel, no timestamps — and they are deleted alongside XP and currency under the same setting.
- A server owner or administrator can erase an individual member's data for their server at any time, choosing what goes: XP, level card and swear jar; currency, bank and items; fishing progress; badges, counters, game statistics and birthday; tickets and transcripts; or warnings and notes. Erasing warnings and notes also removes reports filed about that member and any appeals they made, and strips their name from reports and appeal replies they wrote about somebody else. Warnings and notes are never erased by a member simply leaving.
- Expired dashboard sessions are cleared automatically.
- Records tied to something that no longer exists — a deleted ticket panel, a removed reaction role — are cleaned up with it.
- Ticket transcripts have a ceiling. Each server keeps its newest 1,000 (5,000 on premium). Closing a ticket once the archive is full permanently deletes the oldest transcript. Staff can delete transcripts sooner, and can download any of them beforehand if a copy needs keeping.
- Member reports and ban appeals age out. A report that has been dismissed or actioned is deleted 90 days after it was filed, and an appeal that has been approved or denied is deleted 90 days after it was filed, taking the messages in it with it. Anything still open is kept until staff deal with it, because an unanswered report or appeal is still somebody's job.
- Other data is kept for as long as the feature that created it is in use, because that is what makes it useful. Warnings do not silently expire; staff clear them.
Anything downloaded out of the dashboard — a ticket transcript saved as a file, for instance — leaves Aegis entirely at that point and becomes the responsibility of whoever downloaded it.
10. Your choices
- See what is held about you. Ask through the support server and the operator will tell you what is stored against your user ID.
- Have it deleted. You can ask a server administrator to remove your records for their server, or ask the operator directly. Requests are honored.
- Stop it being collected at all. Leaving a server, or that server removing Aegis, ends collection. Features can also be switched off individually by an administrator.
- Have a server erase you specifically. A server owner or administrator can erase one member's data for their server from the dashboard, choosing exactly what goes: XP, level card and swear jar; currency, bank and items; fishing progress; badges, counters, game statistics and birthday; tickets and transcripts; or warnings and notes.
- Sign out everywhere. The dashboard settings menu has a Sign Out Everywhere button that ends every session on your account across every device, and deletes the Discord tokens held in them. Useful if you have signed in on a machine you no longer control.
- Disconnect the dashboard. Revoke Aegis under Discord's Authorized Apps settings at any time.
Depending on where you live you may have statutory rights over your data — for example under the UK GDPR, the EU GDPR, or the CCPA — including access, correction, deletion, and objection. Aegis honors these requests regardless of where you live, because it is the same small amount of data either way.
11. Age
Discord requires users to be at least 13, and older in some countries. Aegis is not directed at children and does not knowingly store data for anyone below the minimum age for their country. If you believe a child's data is held, contact the operator and it will be removed.
12. Changes
This policy will be updated when what Aegis does with data changes. The date at the top always reflects the current version. Material changes will be announced in the support server rather than made quietly.