Privacy Policy
Vortigern is a Discord bot and web dashboard for Roblox roleplay communities, operated by an individual developer under the name Vortigern Industries. This policy describes exactly what information it handles, why, who else sees it, how long it is kept, and how to get it back or have it deleted. It is written to be checked against the software, not to be reassuring.
1. What We Collect
What we hold depends on which features a server uses. Nothing in the table below is collected from you personally — it arrives because you used the bot, joined a server it is in, or signed into the dashboard.
From Discord
| Data | When | Stored? |
|---|---|---|
| User ID, username, avatar | You join or leave a server, or take an action the bot records | Yes |
| Account creation date | You join a server, for alt-account screening | Yes |
| Message content (first 500 characters), channel name | Only if the server owner has switched on message content logging, which is off by default | Yes, if enabled |
| Server name, icon, roles, channels, member counts | Rendering the dashboard | No — read live from Discord |
| Daily server statistics — how many joins, leaves and messages a server saw each day, and how many distinct people posted | The Analytics page a server's managers see | Yes, as counts only, for 400 days. No message text and no usernames. Who posted is recorded as a one-way code rather than your ID, and that code is dropped after 100 days, leaving only the number |
| Your list of Discord servers | You sign into the dashboard, to show which servers you can manage | In your session only, deleted after 12 hours |
| Discord OAuth access token | You sign into the dashboard | In your session only, deleted at logout or after 12 hours |
Message content is off by default. Vortigern does not store the text of your messages unless a server owner has explicitly enabled it for that server, in Settings → Data & Privacy. When it is off, message text is never written to disk. When it is on, only the most recent 300 messages per server are kept and each is truncated to 500 characters.
From Roblox
If a server links a Roblox game, that game's scripts send us gameplay events. If staff look up a player, we query Roblox's public APIs.
- Stored: Roblox username, Roblox user ID, account age in days, in-game chat messages (500 characters), place name, and the moderation action taken.
- Not stored: profile description, badges, friend and follower counts, avatar images. These are fetched live when staff open a lookup and are never written to disk.
From the dashboard
- A session cookie — one cookie, strictly to keep you signed in. No advertising, analytics or tracking cookies are set, and there are no third-party scripts on the site.
- Your IP address is used in memory to rate-limit requests and prevent abuse. It is not written to any file, log or database, and is discarded within about a minute.
- Your account settings — the handful of display preferences on your Account page, stored against your user ID. They are deleted the moment you set them all back to their defaults, and they are included in both the download and the erasure.
What we never collect
We do not collect your email address, real name, phone number, payment details, or location. We do not read your direct messages — the bot ignores DMs entirely. We use no third-party analytics, telemetry, advertising or tracking services, and we do not profile you or follow you across the web. The only statistics we keep are the daily per-server counts described above, which are aggregates: they record that a server was busy, not who you are or what you said.
2. Why We Use It
Each thing we hold exists for a specific feature. We do not collect data speculatively.
| Purpose | What it uses |
|---|---|
| Showing join/leave history and screening alt accounts | User ID, username, avatar, account creation date |
| Chat logs for moderation review | Message content, where a server has enabled it |
| Faction rosters, applications and punishments | User ID, display name, application answers, punishment reasons |
| Shift tracking | User ID, username, shift start time |
| Showing who changed a server setting | User ID, username in the audit trail |
| Linking a Discord account to a Roblox account | Discord user ID sent to Bloxlink, if the server configured it |
| Keeping you signed in | Session cookie, Discord profile, OAuth token |
| Preventing abuse of the dashboard | IP address, in memory only |
We never sell your data, share it for advertising, or use it to train machine-learning models.
3. Who Else Sees It
Data leaves our system in exactly four directions, all of them necessary to make a feature work.
| Recipient | What is sent | Why |
|---|---|---|
| Discord | Your OAuth token, to read your profile and server list | Signing you in and operating the bot |
| Bloxlink | Your Discord user ID and the server ID | Finding your linked Roblox account, only in servers that configured it, only when staff run a lookup |
| Roblox | A Roblox username or user ID | Fetching public profile and avatar information for staff lookups |
| Your own server's Discord channels | Faction notifications: applicant name, roster changes, punishment reasons | Posting updates where the server asked for them |
Server staff can see your data. Moderators and faction leaders in a server can view that server's logs, rosters, applications and punishments through the dashboard. We control what the software does; we do not control what a server's own staff do with what they see. Treat anything you post in a server as visible to that server's staff.
We will disclose information if legally required to, and to investigate abuse of the service — but there is no other circumstance in which it is shared.
4. How Long We Keep It
Most stores are capped by count rather than age: once the cap is reached, the oldest entry is dropped as a new one arrives.
| Data | Retention |
|---|---|
| Join, leave and chat logs | Most recent 300 per type, per server |
| Settings audit trail | Most recent 300 per server |
| Dashboard session and OAuth token | 12 hours, or immediately on logout |
| Active shift records | Cleared when the shift ends, or automatically after 24 hours |
| Queued in-game moderation commands | 60 seconds |
| Faction applications / posts / activity | Most recent 300 / 200 / 400 per faction |
| Faction punishments | Minor expire after 30 days, moderate after 90 days, severe remain on record |
| Faction rosters and profiles | Until the faction or the server's data is deleted |
| IP addresses | In memory only, discarded within about a minute |
When the bot is removed from a server, that server's data is deleted automatically — logs, audit trail, factions, rosters, applications, settings and uploaded images. This happens as soon as the removal is processed, without anyone needing to ask.
5. Your Rights and Controls
You do not need to email anyone or wait for a reply to exercise these. They are built into the dashboard and take effect immediately.
Anyone with a Discord account
- See what we hold — your Account page lists every record we have of you, counted store by store, across every server.
- Download your data — Download my data on that page. You get a JSON file of everything we hold about you across every server.
- Erase your data — use Request erasure on the same page. The request is reviewed by our team in our support server, and we act on it within 30 days. Your messages, applications, posts, roster entries, cases, shift records and access overrides are then deleted.
Two limits on erasure, stated plainly. First, moderation and audit records of actions you took against other people are not deleted — they are stripped of anything identifying you and kept as anonymous entries, so erasure cannot be used to wipe the record of your own moderation actions. Second, if you are under an active punishment when we erase you, we keep one minimal note of that punishment alone — what it was, which server, and when — because otherwise erasure would be a way to clear a ban. That note holds no reason text and nothing else about you, it is deleted when the punishment ends or the server parts ways with us, and you are told exactly what was kept. Everything that exists only to describe you is deleted outright.
Server owners
- Export your server's data — Settings → Data & Privacy → Export Server Data.
- Erase your server's data — the same panel. Removes everything for that server immediately.
- Control message logging — the same panel. Off by default; you decide whether it is ever on.
- Remove the bot — kicking Vortigern deletes the server's data automatically.
Depending on where you live you may also have rights under laws such as the GDPR or CCPA — including access, correction, deletion, and objecting to processing. The controls above satisfy access and deletion directly. For anything else, or if a control does not work for you, contact us using the details in section 9 and we will respond within 30 days.
6. How It Is Protected
- All traffic to the dashboard is encrypted with HTTPS.
- Sessions are stored server-side; the cookie is
httpOnlyand cannot be read by scripts. - Dashboard features are gated on your real Discord permissions in the relevant server, re-checked on every request.
- Access to management functions is limited to server owners and roles the owner has explicitly granted.
- In-game data ingestion is authenticated with a per-server key, compared in constant time.
No system is perfectly secure. Vortigern is a hobby project run by one person on self-hosted infrastructure, not an enterprise service with a dedicated security team. Please weigh that when deciding what to entrust to it. If you believe you have found a vulnerability, report it via the support server rather than disclosing it publicly.
7. Children
Discord requires users to be at least 13, or older where local law sets a higher minimum. Vortigern is not directed at children under 13 and we do not knowingly collect their information. If you believe a child under 13 has used the service and we hold their data, contact us and we will delete it. A parent or guardian can make that request on the child's behalf.
8. Changes to This Policy
We may update this policy as the software changes. The effective date at the top always reflects the current version. Material changes — particularly any change to what we collect or who we share it with — will be announced in the support server before they take effect. Continuing to use Vortigern after a change means you accept the updated policy.
9. Contact
For privacy questions, data requests, or anything else about this policy, reach us in the support server. We aim to respond within a few days, and within 30 days at the outside.
See also our Terms of Service and the Your Data & Privacy Controls guide, which walks through the export and erasure tools step by step.