Jaeger’s Art Shack
Privacy Policy
This page explains what ShackBot collects, why it is needed, who can see it, and how long it is kept. It applies when you use https://shackbot.jaegerdraws.casa, https://join.jaegerdraws.casa, email verification, Discord authorization, moderation tools, or appeal forms.
1. Who runs ShackBot
ShackBot is operated for Jaeger’s Art Shack by the server owner and trusted administrators. Privacy questions, access requests, and correction requests can be sent to [email protected].
2. What ShackBot collects
Information you provide
- Your preferred or pseudonymous name.
- Your email address.
- Your acceptance of the current community rules.
- Anything you submit in an appeal or direct message to the server team.
Information received from Discord
- Your Discord user ID, username, and current display name.
- Whether you are already a member of the intended Discord server.
- Roles and related information needed for authorized moderation, safety checks, and role restoration.
ShackBot uses your Discord access token only for the brief time needed to identify your Discord account and add it to the server. It is handled only by a dedicated, isolated component; the rest of ShackBot never receives it. We never store the token in our database, files, backups, or logs. As soon as the Discord transaction finishes, the component securely overwrites the token memory it controls. We do not retain or reuse your token.
Moderation and operational records
- Reports, moderation cases, reasons, actions, notes, appeals, and outcomes.
- Role snapshots needed to restore eligible roles after a restriction.
- Email-delivery results and security audit events.
- A keyed, non-plain-text network identifier used for rate limiting and abuse prevention.
Essential cookies
ShackBot uses short-lived cookies to protect forms and carry limited onboarding state between steps. They are not used for advertising or behavioural tracking.
3. How the information is used
- To verify control of an email address.
- To confirm that join requests are made by people rather than automated abuse.
- To connect a verified application to an authorized Discord account.
- To add approved users to the community server and apply the correct starting role.
- To carry out moderation, appeals, restoration, and accountability processes.
- To diagnose failures, protect the service, and enforce reasonable rate limits.
4. Who can see the information
Ordinary application records are available only to people who operate the service and need them for that work. Private moderation cases, role snapshots, notes, and appeals are available to the server owner and authorized Constables.
ShackBot also relies on service providers such as Discord, an email provider, Cloudflare Turnstile, and Fly.io hosting. They receive only the information needed to provide their part of the service. Some providers may process information outside Canada.
Information may also be disclosed when required by law or when reasonably necessary to respond to a serious security or safety issue.
5. How information is protected
Email addresses are stored in encrypted form. Separate keyed values are used for email lookup and network rate limiting so those checks do not require plain-text values. Access to production systems and moderation records is limited to trusted operators.
No online service can promise perfect security. If a problem is discovered, the server team will work to contain it, understand what happened, and notify affected people when appropriate.
6. How long information is kept
- Unfinished applications: 7 days.
- Used or expired email-verification links: 30 days.
- Temporary Discord authorization state: 24 hours.
- Ordinary membership records: while membership is active, then 90 days.
- Moderation decisions and appeals: at least 365 days.
- Technical audit records: 90 days.
Routine cleanup does not remove records that are still connected to an active moderation case, appeal, security investigation, or legal requirement.
7. Access, correction, and deletion requests
You may ask what personal information ShackBot holds about you, ask for a factual correction, or ask whether information can be deleted. Send the request to [email protected] and include enough information to identify the relevant account.
The server team may need to verify your identity before responding. Some information may need to be kept for an active moderation matter, community safety, security, or a legal obligation. When a request cannot be completed fully, the reason will be explained plainly.
8. Changes to this policy
This page will be updated when ShackBot’s information-handling practices materially change. The effective date at the top shows when this version began.
9. Contact
Questions or concerns about this policy can be sent to [email protected].