stingsbyv0.7.0 beta
Home Docs
Early access
Legal · Effective 30 September 2026

Privacy Policy

This policy explains what data the stingsby Discord bot and this website handle, why, how long it is kept, and what you can do about it. The short version: stingsby keeps only what it needs to protect servers and show staff what happened, it deletes it automatically, and it never sells or shares it.

1. Who is responsible

Stingsby is run by an individual maintainer, reachable as wfabio on Discord. The maintainer decides how the bot's data is handled and is responsible for it under this policy.

2. What the bot stores

Server settings

For each server that sets stingsby up: the server ID, the trap, log and join log channel IDs, how many hours of messages to delete on a ban, whether the trap is on, the chosen language, the chosen action and its timeout lengths, the new-account limit, the incident settings (a role ID to ping, pause lengths and alert thresholds), and the IDs of exempt roles. When stingsby is removed from a server, it also records the server ID and the date, so it knows when to delete the rest (see section 6).

Experimental features

For servers that ask for an experimental feature: the server ID, the feature, whether it was requested, approved or declined, the user ID of whoever decided, and when. The request itself (server name, member count, who asked) is posted in the bot owner's private support channel.

Strikes

Only for servers that use the escalating action: for each account the trap caught, the server ID, the account's user ID, how many times it was caught, and when it was last caught. This is what decides the next step. Strikes are deleted once they expire (after 90 days without being caught, unless the server chose another period), or earlier when staff press Forgive.

Event log

Each server has a security event log. Every entry records the server ID, the time and the kind of event, plus:

EventAlso stored
BanThe banned user's ID and username, and the text of the message that set off the trap, up to 1000 characters. Attachments are only counted, never stored.
Failed banThe same, with the reason the ban failed.
Setting changeThe ID and username of the staff member, and what they changed, e.g. a channel or role name.
Message clean-upThe ID and username of the staff member who ran /clear, how many messages were deleted and where, and whose messages they were. The deleted messages themselves are not stored.
Softban / timeoutThe same as a ban.
Unban, timeout removed, strikes clearedThe ID and username of the staff member, and the username and ID of the person concerned.
WarningThe name of a stingsby channel that was deleted.
IncidentWhat was detected (a raid, DM spam, or how many members joined in how long). No member IDs or names. When staff resume DMs or invites, their ID and username.
Join (only in servers that turn on the join log)The ID and username of the member who joined, and, when stingsby can tell, the ID and username of whoever created the invite they used, with the invite code.
Leave (only in servers that turn on the join log)The ID and username of the member who left, and when they had joined (or that stingsby removed them).

3. What the bot sees but doesn't keep

  • Messages: Discord sends stingsby the messages in channels it can see. Normally stingsby ignores all of them except messages in the trap channel. Nothing else is read, logged or stored.
  • Duplicate detection (experimental, only in servers that turned it on): stingsby also compares messages in other channels, to catch an account posting the same message in several channels at once. It keeps only short fingerprints (hashes, not the text), in memory, for 30 seconds. Nothing about those messages is saved, unless the account is caught; then the message that triggered it is stored, like a trap hit.
  • /clear: reads recent message history to find the messages to delete. Only the counts in the table above are kept.
  • Direct messages: Stingsby sends one DM to each account it bans, explaining why. Messages sent to the bot in DMs are ignored and not stored.
  • Member information in reports: ban reports show the account's creation date, join date and avatar. These are read from Discord when the report is made and are not saved in the database.
  • Members joining: for the join-spike alert, stingsby notes when each member joins and whether the account is less than a day old. This is kept in memory for 10 minutes only, never saved, and holds no IDs or names.
  • Invites (only in servers that turn on the join log): to tell which invite a new member used, stingsby keeps each of the server's invites in memory: its code, how many times it was used, who created it and its channel. This is never saved, and it's forgotten when the join log is turned off or stingsby leaves the server. The join itself is saved to the event log, as described above. Ban reports also show how the banned account joined.

4. Why the data is used

Only to run stingsby: banning compromised accounts, showing staff what happened through ban reports, /honeypot logs and /security report, and keeping the bot working. Where the GDPR or similar laws apply, the legal basis is legitimate interest: protecting Discord communities from spam and scams and giving their staff an audit trail. Stingsby does no profiling, advertising or tracking, and data is never used to train AI models.

5. Who can see it

  • The server's staff: event logs and reports are only shown inside the server they belong to, to members with the right permissions. Ban reports are posted in the log channel the staff chose, so whoever can see that channel can read them.
  • Discord: Stingsby works through Discord's platform, so Discord processes this data under its own Privacy Policy.
  • Hosting: the database lives on a rented virtual private server (VPS) managed by the maintainer. The hosting provider stores it but has no right to use it.
  • No one else. Data is never sold, rented or shared for any other purpose, unless the law requires it.

6. How long it is kept

  • Event log entries are deleted automatically after 90 days.
  • Strikes are deleted once they expire (90 days without being caught, by default), or when staff press Forgive.
  • When stingsby is removed from a server, its settings, event log entries and strikes are kept for 30 days, so nothing is lost if it was removed by mistake and added back. After that they are deleted automatically. If the server is deleted or never adds stingsby back, the same 30-day limit applies.
  • Delete all data in /config deletes all of a server's settings, event log entries and strikes straight away.
  • Reset in /config deletes a server's settings but keeps its event log, which then expires after 90 days as usual.
  • Backups: the maintainer may keep up to 14 recent backup copies of the database, to recover from failures. Older copies are deleted as new ones are made.
  • Technical logs: the bot's console log (server names and IDs, the usernames and IDs of banned accounts, errors) is capped at about 30 MB and overwritten as it fills, usually within days to weeks.

7. Security

The bot runs in a locked-down container on a server that only the maintainer can reach, with the database and the bot's secret token kept private. No system is perfectly secure, but access is kept to the minimum needed to run stingsby.

8. Your rights

Depending on where you live, including under the GDPR in the EU and UK, you may have the right to access the data held about you, have it corrected or deleted, object to or restrict its use, and receive a copy of it. To use any of these rights, send a direct message to wfabio on Discord with your Discord user ID. We'll reply within 30 days.

  • Server staff can delete everything stingsby holds about their server at any time with Reset or delete data → Delete all data in /config. Removing the bot also deletes it, 30 days later.
  • If you were banned by stingsby and want to return, contact that server's staff. Only they can unban you.
  • You can also complain to the data protection authority in your country.

9. Children

Stingsby is meant for people who meet Discord's minimum age, which is at least 13 and higher in some countries. It does not knowingly collect data from anyone younger.

10. This website

This site has no analytics, advertising or tracking cookies. It remembers your light or dark theme choice in your own browser only. Everything it shows, fonts included, is served from stingsby.com itself: no third-party services are contacted while you browse it. The site is delivered through Cloudflare, and the service hosting it may keep standard access logs.

11. Changes to this policy

We may update this policy as stingsby changes. The date at the top shows when it last changed. Significant changes will be noted on this site.

12. Contact

Privacy questions or requests: send a direct message to wfabio on Discord.

🐝 stingsby v0.7.0 (beta) · maintained by wfabio Home Docs Terms Privacy Support server Not affiliated with Discord Inc.