1. Who are we?
SlakBot is a free Discord bot developed and operated by the sole proprietorship of Luca (Netherlands), registered with the Dutch Chamber of Commerce (KvK) under number 42137410. This policy covers the SlakBot Discord bot and the website at slakbot.nl.
Under GDPR I am the data controller. SlakBot is run as a sole proprietorship. Under Dutch law that has no separate legal personality: the owner is personally responsible and answerable.
Contact for privacy requests (in order of preference):
- Email:
privacy@slakbot.nl(formal channel, response within 30 days) - Discord:
discord.gg/d9cpruNpyX(faster, no guarantee during holidays) - Web: slakbot.nl/en/contact
2. What data do we collect?
2.1 Discord user data
When you use SlakBot in a server or log in to the web panel, we store:
- Discord user ID (numeric ID, no email or password)
- Username (to display in mod log, leveling, tickets, etc.)
- Avatar URL (for display in the web panel)
- Server IDs where you are an admin (for proper access)
2.2 Server-specific data
Per Discord server we store:
- Server ID and name
- Configuration settings (channel IDs, role IDs, embed colors, templates)
- Moderation history (warns, kicks, bans, mutes — including moderator + user)
- Message content the AI moderator has flagged — the first 200 characters of such a message, with the category, the reason and the confidence, in the activity log. Only on servers where an admin has turned the AI moderator on, and only for messages the AI flags (see §2.3 and §5)
- Message content the anti-scam system has flagged — the first 500 characters of such a message, with the scam type and the action taken, in the scam log. Only on servers where an admin has turned the anti-scam system on, and only for messages the anti-scam system flags; automatically deleted after 180 days (see §2.3 and §5)
- Leveling data (XP per user per server)
- Economy data (balance, daily streak)
- Tickets and suggestions — and, when a ticket is closed, the full transcript of that ticket channel, which is always saved, even if sending it is turned off (see §2.6 and §5)
- Custom commands
- Stream goal progress (aggregate) — and, if the optional Twitch link is used, watch time, chat activity and redemptions per linked viewer (see §2.7)
2.3 Security data (anti-scam)
For anti-scam protection we store:
- Hashes (SHA-256) of analysed images — to detect the same scam image without re-scanning
- Scam attempts — your Discord ID, your username, the timestamp, the scam type and the action taken, for mod-log purposes
- A signature of a flagged scam message — a hash, together with the first 80 characters of the normalised message text (or, for a link, the domain) as a comparison sample. It carries no Discord ID and no username, only which server saw it first. These signatures are shared with every server SlakBot runs in — that is what stops a scam appearing on one server from landing on the others — and they have no retention period (see §2.6 and §5)
- The first 500 characters of a flagged message — if the anti-scam system flags a message, that text goes into the same row, so a moderator can check later whether it was justified. Messages the anti-scam system lets through are not recorded. Such a row is automatically deleted after 180 days (see §5)
Important: OCR scanning runs 100% locally on our server via Tesseract.js. Images are never sent to Google, OpenAI or any other external AI service. We only store a hash, not a copy of the image. This promise is about images; for message text, what follows below applies.
AI moderation on message text. If a server turns the AI moderator on, an AI model assesses the text of messages in the channels where it is active. There are two engines:
- Local — this is the default. The model runs on our own EU server. The message text does not leave that server.
- Cloud — only if a server admin turns that engine on themselves. The message text (up to 1500 characters) and the sender's Discord username are then sent to Google Generative AI (Gemini) to be assessed (see §4). If an admin does not do that, this does not happen.
Those two engines are about what goes out. What goes into our own database is the same in both engines, and does not depend on the engine choice:
- Out to a third party — only in the cloud engine, and then only to Google. In the local engine the message text does not leave our server.
- Into our own database — in both engines. If the AI moderator flags a message, SlakBot writes a row in the activity log containing the first 200 characters of that message, the category, the reason, the confidence score and which engine assessed it, along with your Discord ID and your username. That row is written before the bot decides whether to act — but that does not mean the log is full of assessments nothing followed from. In the cloud engine, an assessment below 75% confidence is not recorded at all: there, every row has an action attached. In the local engine the bot acts from 65% up, and the threshold above which it flags a message at all depends on the sensitivity setting: 85% on "mild", 70% on "normal", 55% on "strict". On "strict" there can be a row in the log that no removal or warning followed from. That can happen in the other modes too: a server admin can switch off the automatic deleting and warning and let the moderator only watch along. The log row is still written.
That log exists so a decision by the AI can be reviewed and reversed later, and it can be viewed by that server's admins (in the panel). There is no automatic clean-up on it: such a row stays — see §5. Messages the AI moderator does not flag leave no trace in the database: they are read, assessed and not recorded any further.
Correction: earlier versions of this policy said the message text ended up in our database in neither engine. That was not correct — the 200 characters above always did. That earlier text looked only at what leaves our server, and "not sent out" is not the same as "not stored".
Separately, the outcome (category, action, short reason) is recorded as a warning on the member. If the server has set up a report channel, SlakBot also posts the first 200 characters of the message there, so moderators can check whether the AI got it right. That channel lives in Discord.
2.4 Web panel data
When you use the web panel at slakbot.nl we store:
- Login history (user, IP address, browser, timestamp) — for security monitoring
- Session cookies (to keep you logged in)
Support access. The owner of SlakBot and one designated support account can view the panel of every server that uses SlakBot, including what's in it, to help admins and check that things work. The support account is a second account of that same owner. In the panel it can only view: it cannot change anything there or send messages. The owner does use both accounts to manage the SlakBot ban list (see 2.9).
We use no tracking cookies, no Google Analytics, no ad networks and no third-party trackers.
2.5 Website analytics (cookieless)
To see which pages are visited, we count anonymous page views first-party on our own server — no Google Analytics, no external trackers. We only record the page name and (if you arrive from another website) the referring domain. We use no cookies for this, store no IP addresses, and respect Do Not Track. There is no way to identify you as a person.
When you click one of our /go/ marketing links we store a one-way hash
of IP+browser (no readable IP address) — solely to count clicks and prevent double counting.
2.6 What we do NOT store
- Content of private messages (DMs)
- Messages in channels where the bot isn't active
- Passwords (we use Discord OAuth — we never see your password)
- Phone numbers
- Payment card or bank details — the bot is free; billing for the paid Custom Bot service happens outside the bot. Note: with donation integrations (StreamElements/Streamlabs) we do process the donor name and amount as supplied by that service
Note: if you write to us yourself through the contact form or the quote form, you do give us your name and email address — and we do keep those. See §2.8 for exactly what happens to them.
And note this too: in channels where the bot is active, the text of your message is read — by the word filter, and (if an admin turns them on) by the anti-scam system and the AI moderator. Reading is different from storing, and as a rule we do not keep that text. But not always. We no longer put a number on it — every figure we gave here before turned out to be incomplete when we checked it against the code — and instead we write out, per kind, what stays and why. The number of characters and the retention period differ per case:
- If the AI moderator flags a message, we keep the first 200 characters of it in the activity log, with the category, the reason, the confidence and the engine — in the local engine just as much as in the cloud engine, and with no retention period (§2.3 and §5).
- If the anti-scam system flags a message, we keep the first 500 characters of it in the scam log, with the scam type and the action taken — 180 days, then automatically deleted (§2.3 and §5).
- For a message the anti-scam system flags, we additionally keep a signature: a hash with the first 80 characters of the normalised text (or the domain of a link) as a comparison sample, without a Discord ID or username. Those signatures are permanent and are shared with every server SlakBot runs in, so that a scam appearing on one server is stopped everywhere at once (§2.3 and §5).
- When a moderator — or the person who opened it — closes a ticket, the entire conversation from that ticket channel goes into the database as a transcript: every message (up to 5000 of them), with the participants' names, the timestamps and the links to any attachments. There is no character limit and no retention period here; the transcript can be viewed by that server's admins. That saving happens always on closing, even if the admin has turned off sending it to a log channel or to the person who opened the ticket: the ticket channel itself is deleted after closing, the transcript stays. This is by far the heaviest case on this list: whatever was said in a ticket is in there in full. So don't put anything in a ticket you would not want kept (§5).
Exactly how that works, and when text goes to Google, is in §2.3.
And the broader picture, honestly: SlakBot writes to a lot of tables, and a large
share of them have no automatic clean-up routine — so they keep growing. Most of
those hold server settings with no personal data in them, but not all: the activity log, the ticket
transcripts, the scam signatures and the daily figures behind The Pass are part of the share that
does say something about a person. The items with a period of their own are listed in §5; where
there is no period, it stays until someone asks. You can: email privacy@slakbot.nl and we delete what is
tied to your Discord ID (see §7 for the timeframe). This policy is not an exhaustive list of our
database — but what it does say has to be correct.
2.7 Twitch link & chatbot data (optional)
Servers can link SlakBot to Twitch (sub roles, stream alerts and the Twitch chatbot). This link is fully optional: if you don't use it, nothing in this section is collected. If you do link, we process:
- Twitch user ID + username, linked to your Discord ID — for coins, roles and perks across both platforms
- Encrypted Twitch OAuth tokens (of the streamer and of the bot account; AES-encrypted) — to read sub status, send chat messages and receive events
- Subscription status (sub tier) — cached and refreshed ~every 15 minutes, for sub→role sync
- Watch time and chat activity — minutes watched and message counts per Twitch account, including viewers who haven't linked yet (so that history can be claimed later); automatically deleted after 12 months
- Daily figures per linked Discord member — if you are linked, SlakBot records one row per day each night with your minutes watched, your number of chat messages, your coins, your XP and your score. That is the history behind The Pass ("member since", progress over time). These daily rows have no retention period: they stay, also after those 12 months and also after
!privacy— see the explanation below and §5 - Post-stream viewer list (on by default on servers with the new panel, in channels where watch time is on; the streamer can turn it off there) — per stream, who was in chat: the Twitch name and Twitch ID of everyone who said something in chat, with roughly how long and how many messages, and of everyone who only watched, with roughly how long. Watching here means: logged in to Twitch with chat open, the same way Twitch itself shows it to the streamer and the moderators. People who watch without an account aren't visible to us. The list is only visible to that Discord server's admins and that channel's Twitch moderators (in the panel), and is deleted automatically after 7 days. They can also download the list as a text file. Such a file is then kept by that admin or moderator, and they are responsible for it: someone who opts out with
!privacyafterwards is still in a file downloaded earlier. SlakBot does not post a notice about this in Twitch chat: this policy is that notice. - Bits, sub, gift and raid events — who, how much and when, for alerts and coin rewards
- Redemptions — a log of loyalty-shop purchases and Channel Points redemptions
- Link tokens — the one-time !koppel links are valid for 15 minutes and expire automatically
Rather not be tracked? Type !privacy in the Twitch chat of a channel where
SlakBot is active. From then on we no longer count you for watch time, chat activity and the viewer
list, in every channel with SlakBot, and we delete what we already had. Type !privacy aan
to be counted again. We keep your Twitch ID for as long as you're opted out; otherwise we wouldn't know
to skip you. We also keep in which channel (and which Discord server) you typed !privacy,
only for counting: the streamer sees how many viewers opted out in their chat, but never who.
What !privacy does not reach. The command works on your Twitch
account: it deletes your watch time, your chat activity and your rows in the viewer list. The daily
figures from the list above are tied to your Discord ID and therefore stay —
!privacy cannot reach them. The same goes for the rest of your Discord data (coins, XP,
warnings). If you want those gone as well, email privacy@slakbot.nl: we carry out that
request targeted at your Discord ID (see §7).
What we don't do: Twitch chat messages are not stored permanently
(only a short-lived in-memory buffer of at most 5 minutes for moderation tools) and we never see
your Twitch password. You can unlink at any time (!ontkoppel in Twitch chat or
/ontkoppel-twitch in Discord) — this immediately deletes your link and tokens.
The anti-scam promise above (OCR 100% local) is entirely separate from this data flow.
2.8 Contact form and quote requests
If you use the form at slakbot.nl/en/contact or request a quote for a custom bot, you send us the following yourself:
- Your name
- Your email address — needed to reply to you
- The subject (optional)
- The content of your message
If you request a quote for a custom bot, that form also sends — where you fill those fields in — your Discord name, your server size and a budget indication. Those three are placed in the text of your request, so they travel along as part of your message.
If your message passes the spam checks, it does not go into a database: it is forwarded by email to the SlakBot mailbox, with your address as the reply-to. A mailbox is storage too — so your message stays there. If your submission is stopped by one of the honeypots or by the spam filter, something else happens: the server writes a short warning about it into the bot's error table, and that really is a database. Such a line contains the reason for the block and the IP address the submission came from; your name, your email address and the text of your message are not in it. At most ten of these are kept per hour, and they are deleted automatically after 30 days (see §5, the "Bot errors + crashes" item).
On top of that the server keeps a plain log file. Every submission immediately adds a line there with the sender's IP address, and a successful submission adds a second line with your email address and your name, so we can see that a message arrived.
What we use it for: only to answer your message or your quote request. Your address is not added to a mailing list, not sold on, and not used for advertising.
Legal basis: for a quote request we process your data to prepare a contract (GDPR article 6(1)(b)). For an ordinary question the basis is legitimate interest (6(1)(f)): without your address we cannot answer you.
How long: messages stay in the mailbox for as long as they are needed to
handle your request and for our records — there is no fixed period. If you want your message
gone sooner, ask us at privacy@slakbot.nl and we'll delete it (see §7).
Anti-spam checks: the form itself holds two hidden fields that only bots fill in (honeypots) and a timestamp of when you opened the page. The rest happens on the server the moment your submission arrives: it checks that timestamp, looks at whether your email address comes from a disposable mail domain, counts the links in your message (more than two links is refused) and scans the subject and the text of your message against a fixed list of blocked spam phrases (think "casino bonus" or "buy followers"). No human reads along for those two checks, but the content of your message is run past a filter. On top of that there is a limit of 30 submissions per 10 minutes and 200 per 24 hours. If one of these checks stops your submission, a line about it is kept along with your IP address — as described above.
2.9 SlakBot ban list
SlakBot keeps a small list of accounts that did raids, spam, hate or ban evasion. Servers with SlakBot ban those accounts, unless the server turns the list off. So this also concerns people who never used SlakBot themselves. The full explanation, and how to appeal, is at slakbot.nl/en/banlijst.
- What data: your Discord ID and/or Twitch ID, one fixed category (raid, spam or scam, hate or harassment, ban evasion), the date and who decided. No name, no explanation in free text, no messages. On top of that, per server, what SlakBot did there (for example banned, or not because someone is staff) and whether the message to the banned person arrived.
- Per server we also keep whether the list is on or off there, who changed that, and when the message after the first ban there went to which owner (their Discord ID).
- Who decides: only the maker of SlakBot, by hand. No computer or AI puts anyone on the list, and servers can't put anyone on the list.
- Purpose: protecting communities against raids, spam, hate and ban evasion.
- Legal basis: legitimate interest (GDPR article 6(1)(f)). Servers and their members don't want to be bothered again and again by the same accounts. On the other side: the list only holds an ID and a category, lasts 12 months at most, never affects owners or staff, every server can turn it off, and you can appeal. Child safety and criminal offences are not put on this list: those belong with Discord, Twitch or the police.
- Who sees it: the maker of SlakBot sees the whole list. The admins of a server only see the bans in their server (in their mod log channel and under bans in Discord's server settings), with the number and the category. They don't see the rest of the list. Such a ban also goes into that server's moderation history, like a normal ban. The banned person gets a private message once, with the category and a link to the explanation page.
- Twitch: the list can also contain a Twitch account. Banning on Twitch is still off for now.
- How long: 12 months at most on the list, then off it automatically. When someone comes off the list (expired or lifted sooner), SlakBot lifts its own bans and, 30 days later, deletes the entry and what it did per server.
- Objection: you can always object (GDPR article 21). slakbot.nl/en/banlijst explains how, and what to include. If you file one, we keep your appeal: your Discord ID and name, the reason and date of the ban, the age you state yourself and the explanation you write. There is currently no retention period on that; ask us to delete it and we will.
3. Why do we collect this data?
We use your data to run the bot and — if you write to us — to answer your message:
| Data | Purpose |
|---|---|
| User ID + name | Display in mod log, leaderboards, tickets |
| Server config | Bot knows which channels, roles, templates to use |
| Warnings + mod log | Mods can review history |
| Leveling XP | Calculate levels, show /rank and /top |
| Economy balance | Power /daily, /balance, /shop |
| Login log | Bot owner sees who logs into the panel (security) |
| Image hashes | Anti-scam: scan same image only once |
| Message text the AI moderator flags (200 characters) | Being able to review and reverse a decision by the AI later (§2.3) |
| Message text the anti-scam system flags (500 characters) | Letting moderators check whether a removal was justified (§2.3) |
| Scam signatures (hash + 80 characters of normalised text, or a domain) | Stopping a scam that appears on one server on every other server at once (§2.3) |
| Ticket transcript (the whole conversation, on closing) | Letting admins review what was agreed in a handled ticket (§2.6) |
| Contact form (name, email, message) | Answering your question or quote request (§2.8) |
| SlakBot ban list (ID + category) | Protecting servers against raids, spam, hate and ban evasion (§2.9) |
4. Who do we share data with? (Sub-processors)
We never share your personal data with third parties for commercial purposes.
The following external services (sub-processors) are used for specific features:
| Sub-processor | Purpose | Data sent |
|---|---|---|
| Discord Inc. (US) Privacy |
Bot platform — to execute commands and post messages | User ID, server ID, message content (bot responses) |
| Pterodactyl host (EU) | Server hosting — where the bot + database runs | All data is stored on this EU server (encrypted disk) |
| Outgoing mail server (SMTP) | Contact form and quote requests — delivering your message to the SlakBot mailbox | Your name, your email address (also as reply-to) and the full text of your message |
| YouTube (Google, US) | Video notifications — RSS feed + Data API | No user data sent — only channel IDs (public) |
| Google Generative AI (Gemini) (Google, US) Terms |
AI moderation in the cloud engine (see §2.3) | The message text and the sender's Discord username. Only if a server admin turns the cloud engine on themselves: the AI moderator is set to local by default and then sends nothing out. If that does not happen, no message goes to Google by this route. |
| Twitch (Amazon, US) | Live alerts, clips and (optional) chatbot & account link — Helix API + EventSub | Without the link: public channel names only. With the optional Twitch link (§2.7): Twitch user IDs, subscription status, bits/sub/gift/raid events and messages the bot posts in your Twitch chat. OAuth tokens are stored encrypted; the link can be cancelled per member |
| RapidAPI / TikTok scraper | TikTok LIVE notifications — high-res avatars | Only TikTok usernames (public) |
| Sinking Yachts API (NL) phish.sinking.yachts |
Anti-scam domain blacklist | Only domain names from suspicious messages are checked — no user ID, no message content |
Important: no separate data processing agreement (DPA) has been concluded with these parties; they process data under their own terms and privacy policies. We minimise the data we share.
5. How long do we keep your data?
- Server config + leveling + economy — as long as the bot is in your server. If the bot is removed, this data stays — see the note below this list. Deletion is available on request via
privacy@slakbot.nl - Warns + mod log — as long as the server exists (for mod history)
- Login history (panel) — 12 months, then automatically deleted
- Anti-scam image hashes — indefinite (anonymised, no user link)
- Anti-scam attempts, including the first 500 characters of a flagged message (with your Discord ID, your username, the scam type and the action taken) — 180 days (just over 6 months), then automatically deleted
- Bot errors + crashes — 30 days, then automatically deleted
- Broadcast history — 12 months, then automatically deleted
- Tickets — as long as the server exists
- Twitch↔Discord link + tokens — until unlinked, at which point the link and the tokens are deleted immediately. If only the bot is removed from the server, the link stays; deletion is available on request via
privacy@slakbot.nl - Twitch watch time + chat activity (per Twitch account) — 12 months, then automatically deleted. Note: the daily figures in the next item are not covered by this
- Daily figures per Discord member (the history behind The Pass: minutes watched, number of chat messages, coins, XP and score per day) — kept indefinitely. There is no retention period on these rows and no automatic clean-up. This history is deliberately permanent: it is the basis for "member since" and for progress in The Pass, and a clean-up would remove that irreversibly.
!privacydoes not reach these rows (it works on your Twitch account, while this history is tied to your Discord ID). Deletion is possible, targeted at your Discord ID, on request viaprivacy@slakbot.nl - Activity log, including the AI moderator's rows (the first 200 characters of a flagged message, with category, reason, confidence, engine, your Discord ID and your username) — kept indefinitely. There is no retention period on this and no automatic clean-up. The log is the server's mod history: it shows who did what and makes it possible to reverse an action, even months later. This applies in both engines of the AI moderator, including the local one. Deletion is possible, targeted at your Discord ID, on request via
privacy@slakbot.nl - Scam signatures (a hash plus the first 80 characters of the normalised text, or the domain of a link; with no Discord ID or username) — kept indefinitely. There is no retention period on these and no automatic clean-up. This list is shared with every server SlakBot runs in: that is the whole point of it, a scam appearing anywhere is stopped everywhere. Removing a specific signature is available on request via
privacy@slakbot.nl - Ticket transcript: the entire conversation from a closed ticket channel (every message, up to 5000 of them, with the participants' names, the timestamps and the links to attachments) — kept indefinitely. There is no retention period on this and no automatic clean-up. The transcript exists so admins can review a handled ticket later, and it is always saved on closing: even if sending it to a log channel or to the person who opened the ticket is turned off, and even after the ticket channel itself has been deleted. Deletion is available on request via
privacy@slakbot.nl - Post-stream viewer list — 7 days per stream, for people who chatted and for people who only watched
- Opt-out via
!privacy— for as long as you're opted out (!privacy aanremoves it) - Redemptions (loyalty shop / Channel Points) — as long as the link/server exists. There is no automatic clean-up after the bot is removed; deletion is available on request via
privacy@slakbot.nl - Supporter history (donations: name + total) — as long as the server exists; deleted on request
- Link tokens (!koppel links) — 15 minutes — single-use, then gone automatically
- Coins / economy balance — until an economy reset by the server admin, or until deletion
- Contact and quote messages (in the mailbox) — as long as needed to handle the request and for our records; deleted on request
- SlakBot ban list (ID, category, date, who decided) — 12 months at most on the list. After that, or after being lifted sooner, another 30 days; then everything is deleted, including what SlakBot did per server
- Ban list per server (on/off, message to the owner) — until 30 days after SlakBot has left the server. If the list is off, we keep only that, as long as the server exists (without Discord IDs), so it stays off if SlakBot comes back
Server admins can reset the economy (coins and watch time) at any time or on a schedule. Earned coins are not guaranteed and have no monetary value — see the terms.
What if SlakBot is removed from a server? The settings and the server-specific
data are then kept, so you get them back when you add the bot again and don't
have to set everything up from scratch. So there is no automatic clean-up after the bot
is removed — earlier versions of this policy mentioned a 30-day period here, and that was not
correct. If you do want your server's data gone, we do that on request: email
privacy@slakbot.nl (see §7 for how long handling such a request takes). The
exceptions are in the list above: the items with their own period — such as bot errors, login
history, the post-stream viewer list and the ban list per server — are cleaned up automatically.
6. How do we secure your data?
- All data sits on a European server with an encrypted hard disk
- HTTPS everywhere — all communication between you and the web panel is encrypted
- The database is only reachable through authenticated connections
- All integration tokens — StreamElements/Streamlabs and Twitch OAuth tokens (streamer + bot account) — are stored AES-encrypted; without the encryption key the system refuses to run
- Login only via Discord OAuth — we never see your Discord password
- Permission checks on every API call (access only to servers where you are an admin)
7. Your rights (GDPR)
Under the General Data Protection Regulation you have the following rights:
- Access — you can request which data we hold about you
- Rectification — have incorrect data corrected
- Erasure ("right to be forgotten") — have all your data deleted. Besides your Discord data this covers your Twitch link, tokens, coins, watch time, redemptions, supporter history and the daily figures from §2.7 (those last ones we can only remove on request — no automatic period runs on them)
- Restriction — ask us to pause processing temporarily
- Object — object to specific processing
- Portability — export your data in a readable format
For requests email privacy@slakbot.nl or send a DM via
discord.gg/d9cpruNpyX (or use slakbot.nl/en/contact).
Requests are handled manually — you'll get a response within the statutory
30 days; deletion or export is therefore not instant/self-service. For your Twitch watch time
and the viewer list you can do it yourself right away: type !privacy in chat
(see 2.7). Objecting to the SlakBot ban list? slakbot.nl/en/banlijst
explains what to include (see 2.9).
8. Cookies
The website uses minimal cookies, only for essential functionality:
- Session cookie — to keep you logged in to the web panel (expires after 7 days of inactivity)
- CSRF token — protection against cross-site request forgery attacks
We use no tracking cookies, advertising cookies or third-party cookies.
9. Children
SlakBot is intended for users aged 16 and over. Under the Dutch implementation of the GDPR (article 8), children under 16 need consent from a parent or guardian for the processing of their data. Discord's own ToS requires 13+, but for our EU processing we apply the stricter GDPR threshold.
SlakBot includes games using a virtual, non-redeemable currency (e.g. /gamble,
/blackjack and, in Twitch chat, !roulette/!duel).
These are entertainment only: there is no real stake and no cash prize, so they don't qualify
as gambling under Dutch law — but we advise server admins to disable these games for young
audiences. See also the terms.
We don't knowingly collect data from people under 16 without consent. If you suspect we hold
data of a minor without consent, contact us at privacy@slakbot.nl and we'll
delete it right away.
No DPO (Data Protection Officer): we are not a public authority and we do not process special categories of personal data on a large scale, so the DPO obligation (GDPR article 37) does not apply. Privacy requests are handled by me personally, within the statutory 30 days.
10. Changes to this policy
We may update this privacy policy when that is needed (new features, changes in legislation, etc.). The date at the top of this page shows when the last change was made. For significant changes we send server owners a message by DM.
11. Complaints
Do you have a complaint about how we handle your data? Contact us first via
discord.gg/d9cpruNpyX on Discord — we're happy to sort it out.
You also always have the right to lodge a complaint with a supervisory authority. We fall under
the Dutch DPA (Autoriteit Persoonsgegevens),
but if you live or work in another EU country you may file your complaint there as well —
article 77 GDPR gives you that right. If you live in the United Kingdom this runs under the
UK GDPR instead, and you can go to the UK supervisory authority; see §12.
12. Users in the United Kingdom
Since Brexit the United Kingdom no longer falls under the European GDPR, but under the UK GDPR and the Data Protection Act 2018. Those laws grew out of the GDPR and give you largely the same rights; on some points they have diverged since 2025. Where that makes a difference for you, we apply whichever reading is the more generous.
If you live in the UK, we handle your data under the same rules as for users in the EU:
- Your rights are the same as in §7 — access, correction, erasure, objection, restriction and portability. You request them the same way.
- Retention periods are the same as in §5.
- Sub-processors are the same as in §4.
Where your data sits. The bot and the database run on a server in the EU (see §4), so data from UK users travels to the EU. That is allowed: the UK and the EU recognise each other’s level of protection, so data may move between the two without further measures.
Complaints. If something is wrong, contact us first through Discord. You can also complain directly to the UK supervisory authority, the Information Commissioner’s Office (ICO).
13. Contact
privacy@slakbot.nlsecurity@slakbot.nl (see also /.well-known/security.txt)discord.gg/d9cpruNpyX