Introduction
The below privacy policy describes how the Lead Developer (@rocktheeee) of the Discord bot 'Trace' ("Trace") collects, uses, and discloses from users ("User" or "You") of the bot. By inviting Trace to your guild ("server"), or using its commands and/or features, you agree to the practices outlined in the Trace Privacy Policy ("Privacy Policy"). Your privacy and data is critically important to the Trace Development Team ("we", "us"), and we are committed to protecting the data you entrust to us.
The Trace Mission
Trace is designed to be used in a roleplay context, especially for games such as Emergency Response: Liberty County, Maple County, or Flashing Lights. The content of any logged events is entirely generated by the user, and is not endorsed or created by Trace. Trace is simply a tool to store the information and send it to the correct locations. For further information, refer to our Trace Terms of Service.
Information We Collect
In order for Trace to function as intended, a minimal amount of data must be collected. While we only collect the minimum amount of data required to allow commands to work, that data may include:
User IDs/Nicknames (For command execution, logging who performed an action, logging which action was executed with association to this ID, in addition to preventing overload by exccessive commands)
Server IDs (To store and access server-specific preferences and configurations)
Channel IDs (To send embeds and messages to specific channels in response to commands.)
Preferences (Provided by users during setup to allow Trace to work as they need it to)
Timestamps and Command Usage data (Allows guild owners to see who is running which commands, also allows us to flag unusual or suspicious behavior and/or potential Terms of Service violations)
Log Inputs (Temporarily stored during processing, encrypted and stored upon approval or deleted upon denial. If a log is reported as being in violation of our TOS, data including a User ID, Guild ID, and log contents will be collected and sent to our support server for review for potential TOS violations. Upon review, this data is deleted unless a violation can be proven. For more information about reporting, please refer to the "Reporting Policy" below.)
"Infraction" Details (Provided by users, stored for users to access and reference later. Trace staff do not access this data.)
Terms of Service Violation Details (See the "TOS Enforcement" section below for more details)
Trace does not collect/store the following data:
Sensitive Account Information (Trace only collects Discord User IDs!)
Email addresses
Payment information
Any form of sensitive personally identifiable information (SPII)
We only interact with and handle information available to all bots via Discord API, and data explicitly provided by the user who uses the command. Never input sensitive personal information or passwords into any bot or application command or prompt!
How We Use This Information
We use the collected information for the following purposes:
Provide and maintain the bot's functionality and purpose (Refer to "The Trace Mission" above).
To ensure compliance to our Terms of Service, Discord Terms of Service, and Discord Community Guidelines.
To return accurate data, settings, and preferences upon request.
To respond to user support requests.
Data Security and Retention
All stored data is securely stored, and access to it is restricted to you (the user) and authorized Trace Staff (for troubleshooting or safety purposes only). Trace developers and representatives will only access or alter your data with your permission. Archived data (including but not limited to preferences, command logs, infraction history, and log databases) is stored using industry standard encryption/hashing methods, ensuring data cannot be read or altered by unauthorized individuals. (See "Data Storage Security") below.
It is our mission to be as transparent with the small amount of data as we can be. In accordance with that mission, we have provided the following list which describes each type of data, when it is collected, what specifically is collected, how long it is retained, and when it is deleted. (Hashed data: #, Encrypted Data: *, User-provided Data: "")
Config Settings: Collected Data: Guild ID (#), Guild Preferences (*) // Retention Duration: Indefinite // Automatically Removed upon Trace leaving the server
Logged Events: Collected Data: Case ID, Guild ID (#), "Primary identifier", User ID (*), Format ID, Timestamp, Log Details (*) // Retention Duration: Indefinite // Automatically Removed upon Trace leaving the server
Pending Requests: Collected Data: Message ID (#), Timestamp, Request-specific data (*) // Retention Duration: 2 Weeks // Automatically removed when an entry has been pending for more than two weeks
Command History: Collected Data: Event ID, User ID (*), Guild ID (#), Command ID, Allowed/Denied // Retention Duration: 1 Week // Automatically removed when a history entry is older than one week
Shifts: Collected Data: Shift ID, Guild ID (#), User ID (*), Timestamps // Retention Duration: Indefinite // Removal: Run /shift wipe to delete all entries for the server // Automatically Removed upon Trace leaving the server
Leaves: Collected Data: Leave ID, User ID (*), Guild ID (#), Timestamps, Reason (*), Active/Inactive // Retention Duration: Indefinite // Automatically removed upon Trace leaving the server
Infractions: Collected Data: Case ID, User ID (*), Guild ID (#), Timestamp, Issuer ID (*), "Action" (*), "Reason" (*), "Notes" (*), Revoked, Message ID (*) // Retention Duration: 1 Year // Automatically removed when Trace leaves the server, or when an infraction case was issued more than 1 year ago.
Known Users: Collected Data: User ID (#), Various Status Flags, History (*) // Retention Duration: See "TOS Enforcement" below // History entries removed when they exceed one year old. User entries removed when they meet the following criteria: no status flags, not blocked, and no history entries within 1 year
Any data stored by Trace will be retained until Trace is removed from the guild. At that point the task is queued to (irreversibly) delete guild-related data. We reserve the right to delete/remove any data stored by Trace at any time for any reason. Upon leaving a guild, Trace automatically queues the deletion of all guild-specific data (as mentioned above as being deleted when Trace leaves the server). This task will be automatically completed within 24 hours of Trace leaving the guild. (Note: Data sweeps are conducted every 24 hours. If Trace goes offline, a new sweep is performed 5 minutes after coming back online, and then resumes a 24 hour cycle.)
Guild owners, or designated guild leaders may request that guild data be deleted. Note that continued use of Trace after removal of data will generate new data. In addition, individual users may request that their individual data be deleted, as outlined in the "Your Rights" section below.
Data Storage Security
We only collect and store a small amount of data. However, we strive to secure this small amount data to the best of our ability. There are three ways data is stored: Raw (Used for generic info like timestamps), Encrypted (Reversably scrabled, but unique every time. This means we cannot search by encrypted data, but we can reverse it again. This is used for more sensitive data like LOA or Infraction details), and Hashed (Scrambled using secure cryptographic hashing algorithms, but scrambled the same way every time. This is used for obfuscating data like Guild IDs. This can still be reversed, however it is much more difficult to reverse than just plain ids.). Using these methods, we strive to protect data beyond what is required.
TOS Enforcement
In order to ensure compliance to our Terms of Service, we must collect and store information related to Terms of Service violations. This data will not be stored unless a violation of our Terms of Service is proven. By using Trace commands/services (Similar to Discord's policies regarding safety and moderation), all users agree to allow violation-specific details and information to be processed and stored in order to protect other users. Again, this data will only be stored in the case of a proven violation. This data may include (but is not limited to): User ID & Nickname, Guild ID & Name where the violation took place, violation reason and details, timestamps, all ticket transcripts related to the offense, and any actions taken as a reaponse. This allows us to ensure that no one who is in violation of our Terms of Service is able to continue causing harm. (To avoid this data being collected, abide by our Terms of Service and we will not be forced to take actions against you)
When a Terms of Service Enforcement Action is taken, it may include a temporary/permanent suspension of Trace Services. (See "Privilege of Use" in our Terms of Service). Additionally, a KU entry is created in order to enforce the suspension and provide incident details to Trace Staff later on. All KU entries are stored with a hashed user ID as the key, meaning we cannot reverse entries to discover the user ID. Thus, entries can only be tied to a specific User ID if that exact ID is searched again later on. if For more information about the security details of hashing, see "Data Types" above)
If you do not wish to give this consent, immediately stop using Trace commands, and remove Trace from your server (if applicable). Usage of Trace services or commands implies consent to this basic enforcement principle which allows us to effectively mitigate breaches of our Terms of Service in such a way that does not disrupt service to other users.
(Not) Sharing Your Information
We do not sell, trade, store, or otherwise transfer any kind of guild or personal user data to third parties. Your data is safe with us!
Your Rights (GDPR // CCPA Compliance)
We believe privacy is a fundamental human right that is under attack every day. Thus, we seek to ensure that all Trace users have the following entitlements:
Right to Access: Users can request a copy of their data at any time. Sensitive guild-related data will not be included. Gathering this data may take up to 7 days under normal circumstances.
Right to Erasure: Users can request that their data be deleted. Deleting data for more than 1 server may take up to 7 days under normal circumstances.
Right to Object: Users must understand that certain data (such as the user id, guild id, and timestamp) must be processed every time a command is run. If you wish this data to not be collected, discontinue use of Trace, and remove Trace from the server (if applicable).
Right to Data Portability: Users can request their data in a transferable format. Collection and formatting of this data may take up to 14-30 days under normal circumstances, depending on the number of servers the user is within.
To exercise any of these rights, please reach out to us in our support server.
Children's Privacy
Trace is not intended for use by individuals under the age of 13. We do not knowingly or intentionally collect personal information from children under the age of 13. If we become aware that such information has been collected from a child under the age of 13, we will immediately take steps to remove all collected data from the child and access to Trace commands/services will be indefinitely suspended.
Changes to the Privacy Policy
This Privacy Policy may be updated at any time, without advanced notice. Notice will be given within the Trace Support Server. Continued use of the bot after such changes are announced constitutes acceptance of the new Privacy Policy.