Privacy Policy

Privacy Policy

Last updated: 3 October 2026 · Version 3.4 (aligned with the Dutch version)

TL;DR

Note on legally binding version

This is the English translation. In case of any conflict or ambiguity, the Dutch version is the legally binding source under EU/NL law.

1. Who are we?

SlakBot is a free Discord bot developed and operated by the sole proprietorship of Luca (Netherlands), registered with the Dutch Chamber of Commerce (KvK) under number 42137410. This policy covers the SlakBot Discord bot and the website at slakbot.nl.

Under GDPR I am the data controller. SlakBot is run as a sole proprietorship. Under Dutch law that has no separate legal personality: the owner is personally responsible and answerable.

Contact for privacy requests (in order of preference):

2. What data do we collect?

2.1 Discord user data

When you use SlakBot in a server or log in to the web panel, we store:

2.2 Server-specific data

Per Discord server we store:

2.3 Security data (anti-scam)

For anti-scam protection we store:

Important: OCR scanning runs 100% locally on our server via Tesseract.js. Images are never sent to Google, OpenAI or any other external AI service. We only store a hash, not a copy of the image. This promise is about images; for message text, what follows below applies.

AI moderation on message text. If a server turns the AI moderator on, an AI model assesses the text of messages in the channels where it is active. There are two engines:

Those two engines are about what goes out. What goes into our own database is the same in both engines, and does not depend on the engine choice:

That log exists so a decision by the AI can be reviewed and reversed later, and it can be viewed by that server's admins (in the panel). There is no automatic clean-up on it: such a row stays — see §5. Messages the AI moderator does not flag leave no trace in the database: they are read, assessed and not recorded any further.

Correction: earlier versions of this policy said the message text ended up in our database in neither engine. That was not correct — the 200 characters above always did. That earlier text looked only at what leaves our server, and "not sent out" is not the same as "not stored".

Separately, the outcome (category, action, short reason) is recorded as a warning on the member. If the server has set up a report channel, SlakBot also posts the first 200 characters of the message there, so moderators can check whether the AI got it right. That channel lives in Discord.

2.4 Web panel data

When you use the web panel at slakbot.nl we store:

Support access. The owner of SlakBot and one designated support account can view the panel of every server that uses SlakBot, including what's in it, to help admins and check that things work. The support account is a second account of that same owner. In the panel it can only view: it cannot change anything there or send messages. The owner does use both accounts to manage the SlakBot ban list (see 2.9).

We use no tracking cookies, no Google Analytics, no ad networks and no third-party trackers.

2.5 Website analytics (cookieless)

To see which pages are visited, we count anonymous page views first-party on our own server — no Google Analytics, no external trackers. We only record the page name and (if you arrive from another website) the referring domain. We use no cookies for this, store no IP addresses, and respect Do Not Track. There is no way to identify you as a person.

When you click one of our /go/ marketing links we store a one-way hash of IP+browser (no readable IP address) — solely to count clicks and prevent double counting.

2.6 What we do NOT store

Note: if you write to us yourself through the contact form or the quote form, you do give us your name and email address — and we do keep those. See §2.8 for exactly what happens to them.

And note this too: in channels where the bot is active, the text of your message is read — by the word filter, and (if an admin turns them on) by the anti-scam system and the AI moderator. Reading is different from storing, and as a rule we do not keep that text. But not always. We no longer put a number on it — every figure we gave here before turned out to be incomplete when we checked it against the code — and instead we write out, per kind, what stays and why. The number of characters and the retention period differ per case:

Exactly how that works, and when text goes to Google, is in §2.3.

And the broader picture, honestly: SlakBot writes to a lot of tables, and a large share of them have no automatic clean-up routine — so they keep growing. Most of those hold server settings with no personal data in them, but not all: the activity log, the ticket transcripts, the scam signatures and the daily figures behind The Pass are part of the share that does say something about a person. The items with a period of their own are listed in §5; where there is no period, it stays until someone asks. You can: email privacy@slakbot.nl and we delete what is tied to your Discord ID (see §7 for the timeframe). This policy is not an exhaustive list of our database — but what it does say has to be correct.

2.7 Twitch link & chatbot data (optional)

Servers can link SlakBot to Twitch (sub roles, stream alerts and the Twitch chatbot). This link is fully optional: if you don't use it, nothing in this section is collected. If you do link, we process:

Rather not be tracked? Type !privacy in the Twitch chat of a channel where SlakBot is active. From then on we no longer count you for watch time, chat activity and the viewer list, in every channel with SlakBot, and we delete what we already had. Type !privacy aan to be counted again. We keep your Twitch ID for as long as you're opted out; otherwise we wouldn't know to skip you. We also keep in which channel (and which Discord server) you typed !privacy, only for counting: the streamer sees how many viewers opted out in their chat, but never who.

What !privacy does not reach. The command works on your Twitch account: it deletes your watch time, your chat activity and your rows in the viewer list. The daily figures from the list above are tied to your Discord ID and therefore stay — !privacy cannot reach them. The same goes for the rest of your Discord data (coins, XP, warnings). If you want those gone as well, email privacy@slakbot.nl: we carry out that request targeted at your Discord ID (see §7).

What we don't do: Twitch chat messages are not stored permanently (only a short-lived in-memory buffer of at most 5 minutes for moderation tools) and we never see your Twitch password. You can unlink at any time (!ontkoppel in Twitch chat or /ontkoppel-twitch in Discord) — this immediately deletes your link and tokens. The anti-scam promise above (OCR 100% local) is entirely separate from this data flow.

2.8 Contact form and quote requests

If you use the form at slakbot.nl/en/contact or request a quote for a custom bot, you send us the following yourself:

If you request a quote for a custom bot, that form also sends — where you fill those fields in — your Discord name, your server size and a budget indication. Those three are placed in the text of your request, so they travel along as part of your message.

If your message passes the spam checks, it does not go into a database: it is forwarded by email to the SlakBot mailbox, with your address as the reply-to. A mailbox is storage too — so your message stays there. If your submission is stopped by one of the honeypots or by the spam filter, something else happens: the server writes a short warning about it into the bot's error table, and that really is a database. Such a line contains the reason for the block and the IP address the submission came from; your name, your email address and the text of your message are not in it. At most ten of these are kept per hour, and they are deleted automatically after 30 days (see §5, the "Bot errors + crashes" item).

On top of that the server keeps a plain log file. Every submission immediately adds a line there with the sender's IP address, and a successful submission adds a second line with your email address and your name, so we can see that a message arrived.

What we use it for: only to answer your message or your quote request. Your address is not added to a mailing list, not sold on, and not used for advertising.

Legal basis: for a quote request we process your data to prepare a contract (GDPR article 6(1)(b)). For an ordinary question the basis is legitimate interest (6(1)(f)): without your address we cannot answer you.

How long: messages stay in the mailbox for as long as they are needed to handle your request and for our records — there is no fixed period. If you want your message gone sooner, ask us at privacy@slakbot.nl and we'll delete it (see §7).

Anti-spam checks: the form itself holds two hidden fields that only bots fill in (honeypots) and a timestamp of when you opened the page. The rest happens on the server the moment your submission arrives: it checks that timestamp, looks at whether your email address comes from a disposable mail domain, counts the links in your message (more than two links is refused) and scans the subject and the text of your message against a fixed list of blocked spam phrases (think "casino bonus" or "buy followers"). No human reads along for those two checks, but the content of your message is run past a filter. On top of that there is a limit of 30 submissions per 10 minutes and 200 per 24 hours. If one of these checks stops your submission, a line about it is kept along with your IP address — as described above.

2.9 SlakBot ban list

SlakBot keeps a small list of accounts that did raids, spam, hate or ban evasion. Servers with SlakBot ban those accounts, unless the server turns the list off. So this also concerns people who never used SlakBot themselves. The full explanation, and how to appeal, is at slakbot.nl/en/banlijst.

3. Why do we collect this data?

We use your data to run the bot and — if you write to us — to answer your message:

DataPurpose
User ID + nameDisplay in mod log, leaderboards, tickets
Server configBot knows which channels, roles, templates to use
Warnings + mod logMods can review history
Leveling XPCalculate levels, show /rank and /top
Economy balancePower /daily, /balance, /shop
Login logBot owner sees who logs into the panel (security)
Image hashesAnti-scam: scan same image only once
Message text the AI moderator flags (200 characters)Being able to review and reverse a decision by the AI later (§2.3)
Message text the anti-scam system flags (500 characters)Letting moderators check whether a removal was justified (§2.3)
Scam signatures (hash + 80 characters of normalised text, or a domain)Stopping a scam that appears on one server on every other server at once (§2.3)
Ticket transcript (the whole conversation, on closing)Letting admins review what was agreed in a handled ticket (§2.6)
Contact form (name, email, message)Answering your question or quote request (§2.8)
SlakBot ban list (ID + category)Protecting servers against raids, spam, hate and ban evasion (§2.9)

4. Who do we share data with? (Sub-processors)

We never share your personal data with third parties for commercial purposes.

The following external services (sub-processors) are used for specific features:

Sub-processorPurposeData sent
Discord Inc. (US)
Privacy
Bot platform — to execute commands and post messages User ID, server ID, message content (bot responses)
Pterodactyl host (EU) Server hosting — where the bot + database runs All data is stored on this EU server (encrypted disk)
Outgoing mail server (SMTP) Contact form and quote requests — delivering your message to the SlakBot mailbox Your name, your email address (also as reply-to) and the full text of your message
YouTube (Google, US) Video notifications — RSS feed + Data API No user data sent — only channel IDs (public)
Google Generative AI (Gemini) (Google, US)
Terms
AI moderation in the cloud engine (see §2.3) The message text and the sender's Discord username. Only if a server admin turns the cloud engine on themselves: the AI moderator is set to local by default and then sends nothing out. If that does not happen, no message goes to Google by this route.
Twitch (Amazon, US) Live alerts, clips and (optional) chatbot & account link — Helix API + EventSub Without the link: public channel names only. With the optional Twitch link (§2.7): Twitch user IDs, subscription status, bits/sub/gift/raid events and messages the bot posts in your Twitch chat. OAuth tokens are stored encrypted; the link can be cancelled per member
RapidAPI / TikTok scraper TikTok LIVE notifications — high-res avatars Only TikTok usernames (public)
Sinking Yachts API (NL)
phish.sinking.yachts
Anti-scam domain blacklist Only domain names from suspicious messages are checked — no user ID, no message content

Important: no separate data processing agreement (DPA) has been concluded with these parties; they process data under their own terms and privacy policies. We minimise the data we share.

5. How long do we keep your data?

Server admins can reset the economy (coins and watch time) at any time or on a schedule. Earned coins are not guaranteed and have no monetary value — see the terms.

What if SlakBot is removed from a server? The settings and the server-specific data are then kept, so you get them back when you add the bot again and don't have to set everything up from scratch. So there is no automatic clean-up after the bot is removed — earlier versions of this policy mentioned a 30-day period here, and that was not correct. If you do want your server's data gone, we do that on request: email privacy@slakbot.nl (see §7 for how long handling such a request takes). The exceptions are in the list above: the items with their own period — such as bot errors, login history, the post-stream viewer list and the ban list per server — are cleaned up automatically.

6. How do we secure your data?

7. Your rights (GDPR)

Under the General Data Protection Regulation you have the following rights:

For requests email privacy@slakbot.nl or send a DM via discord.gg/d9cpruNpyX (or use slakbot.nl/en/contact). Requests are handled manually — you'll get a response within the statutory 30 days; deletion or export is therefore not instant/self-service. For your Twitch watch time and the viewer list you can do it yourself right away: type !privacy in chat (see 2.7). Objecting to the SlakBot ban list? slakbot.nl/en/banlijst explains what to include (see 2.9).

8. Cookies

The website uses minimal cookies, only for essential functionality:

We use no tracking cookies, advertising cookies or third-party cookies.

9. Children

SlakBot is intended for users aged 16 and over. Under the Dutch implementation of the GDPR (article 8), children under 16 need consent from a parent or guardian for the processing of their data. Discord's own ToS requires 13+, but for our EU processing we apply the stricter GDPR threshold.

SlakBot includes games using a virtual, non-redeemable currency (e.g. /gamble, /blackjack and, in Twitch chat, !roulette/!duel). These are entertainment only: there is no real stake and no cash prize, so they don't qualify as gambling under Dutch law — but we advise server admins to disable these games for young audiences. See also the terms.

We don't knowingly collect data from people under 16 without consent. If you suspect we hold data of a minor without consent, contact us at privacy@slakbot.nl and we'll delete it right away.

No DPO (Data Protection Officer): we are not a public authority and we do not process special categories of personal data on a large scale, so the DPO obligation (GDPR article 37) does not apply. Privacy requests are handled by me personally, within the statutory 30 days.

10. Changes to this policy

We may update this privacy policy when that is needed (new features, changes in legislation, etc.). The date at the top of this page shows when the last change was made. For significant changes we send server owners a message by DM.

11. Complaints

Do you have a complaint about how we handle your data? Contact us first via discord.gg/d9cpruNpyX on Discord — we're happy to sort it out. You also always have the right to lodge a complaint with a supervisory authority. We fall under the Dutch DPA (Autoriteit Persoonsgegevens), but if you live or work in another EU country you may file your complaint there as well — article 77 GDPR gives you that right. If you live in the United Kingdom this runs under the UK GDPR instead, and you can go to the UK supervisory authority; see §12.

12. Users in the United Kingdom

Since Brexit the United Kingdom no longer falls under the European GDPR, but under the UK GDPR and the Data Protection Act 2018. Those laws grew out of the GDPR and give you largely the same rights; on some points they have diverged since 2025. Where that makes a difference for you, we apply whichever reading is the more generous.

If you live in the UK, we handle your data under the same rules as for users in the EU:

Where your data sits. The bot and the database run on a server in the EU (see §4), so data from UK users travels to the EU. That is allowed: the UK and the EU recognise each other’s level of protection, so data may move between the two without further measures.

Complaints. If something is wrong, contact us first through Discord. You can also complain directly to the UK supervisory authority, the Information Commissioner’s Office (ICO).

13. Contact

SlakBot Privacy Contact
Email: privacy@slakbot.nl
Security: security@slakbot.nl (see also /.well-known/security.txt)
Discord: discord.gg/d9cpruNpyX
Website: slakbot.nl
← Back to home · Terms · Nederlands