🏳️‍🌈
Pride Doesn't End Here

Privacy Policy🔒

By authorizing or interacting with Kuma Bot, you agree to the data practices outlined in this policy. Aki Works aims to be straightforward about what Kuma Bot processes and to store only what its features need to work. We never sell your data or use it for advertising.

See, export & delete your own data →

It's your right to know. Verify it's you and view exactly what Kuma Bot holds about your account, then download it or request its deletion.

The Data We Collect, By Tier

Not all data is equal. We group everything Kuma Bot collects into three tiers, from the bare essentials it can't run without, to data we only ever touch when you switch on the feature that needs it. The sections below break each of these down in full.

Tier 1 · Essential

Minimal Necessity Data

The essentials Kuma can't operate without. Collected for every server so core moderation and safety work, and so we can keep the bot running and diagnose crashes.

  • Identifiers (user & role IDs)
  • Moderation records
  • Server settings
  • Crash events
  • Debug snapshots
Tier 2 · Operational

Additional Collected Data

Data that helps us run, fix, and improve Kuma, like knowing which communities it's active in and catching errors in our logs before you ever have to report them.

  • Server join / leave events
  • Error & log files
  • Command usage
  • Uptime history
Tier 3 · Optional

Extra / Feature Data

Only collected when you opt in by enabling the feature that uses it. Turn the feature off and Kuma stops collecting it, none of this is gathered by default.

  • Leveling & XP
  • Economy balances
  • Image content scanning
  • Gacha, AniList & Letterboxd links
  • Reaction roles
  • Feeds & giveaways
  • Roadmap posts

1. What We Process & Store

Kuma Bot is a moderation and community bot, so it processes some of your server's activity to do its job. Here's what that involves, and what we keep:

  • Identifiers: Your user ID on the platform you use us on (Stoat, Discord or Fluxer), username, server nickname, avatar, and role IDs. We keep a small cache of usernames, avatars, and role names so past actions still show a real name instead of a raw ID, even after someone leaves or a role is deleted.
  • Message processing: To provide AutoMod, the content filter, leveling/XP, keyword alerts, counting, ghost-ping detection, and (where a server has connected a channel to a bridge) relaying your messages to the linked channels on other platforms, Kuma Bot reads messages in real time in channels it can see. This processing (including use of Discord's Message Content intent) is required for those features; it is never used for advertising, profiling, or sale.
  • Stored message content: Kuma Bot does not keep a copy of your messages. When server logging is enabled, the content of edited and deleted messages, messages that trigger an automatic moderation action, and the transcript of a purge are written to your server’s own log channel on the platform, where your moderators already control them. Kuma Bot stores only a pointer to that log post, and reads the text back from it when a moderator views the dashboard. If the log post is deleted, or logging was never switched on, the text is gone and the dashboard says so rather than producing a copy.
  • Chat Snapshots: When a report is filed or a punishment happens, Kuma Bot records which messages were in that channel, storing their IDs and nothing else. We do not keep a copy of the messages. When a staff member opens a snapshot on the dashboard, the text is fetched live from the platform at that moment. A snapshot reports what was said at the time of the event: if a message was edited or deleted afterwards, Kuma Bot reads what it originally said out of your server’s own log channel, and an edited message is shown as it stood at the time and labelled as edited. A message that is gone from both the channel and your logs is simply reported as unavailable. Snapshots are a moderation record, kept for the server, and the stored IDs are automatically deleted after 60 days. Server owners can delete any individual snapshot from the dashboard at any time, or turn snapshots off entirely with !snapshots off or from the dashboard.
  • Verification: If a server turns on web verification, new members complete a captcha (Cloudflare Turnstile) on our verify page. Cloudflare receives your IP address to run that check, and their privacy policy applies to it. Kuma Bot itself stores only that you verified and when (so you aren't asked again), and we do not store your IP address. With smart routing on, a join is scored from signals already visible to the server (account age, whether you have an avatar, name/raid flags, prior cases here); if you're held for review, that score and the reasons are shown to the server's staff and kept with the server's moderation records until resolved. Where a server enables the anti-VPN option, when you complete the captcha your IP is checked against a reputation service (proxycheck.io) for VPN/proxy use, and Kuma Bot keeps a one-way, per-server hash of your IP (never the address itself) solely to spot multiple accounts joining from the same network. These hashes cannot be reversed to an IP and are automatically deleted after 30 days.
  • Moderation records: Cases, warnings, mutes, bans, the reasons and appeal text attached to them, and private moderator notes about members.
  • Engagement & configuration: Leveling XP, economy balances and purchases, message counts, command usage, channel IDs, timestamps, and your server's settings, toggles, reaction roles, custom commands, keyword lists, giveaways, and feeds.
  • Community roadmap: If you post on the public roadmap, we store what you write (your idea or comment, plus the display name, emoji avatar and colour you chose) and a random identifier your browser keeps so your votes only count once and your own posts are marked as yours. There is no account, email or password; the name is whatever you type, so it need not be your real one. Please treat anything you post there as public: ideas and comments are visible to everyone, and new ideas are read by staff before they appear. Clearing your browser storage loses the link to your past posts (they stay up under the name you used). To have a post removed, ask us (see your rights below).
  • Website & dashboard: Support tickets (their subject, messages, the contact you provide, and any files you upload), dashboard and staff login sessions, a record of dashboard actions, diagnostic snapshots from the !debug command, and careers applications submitted on the site.
  • Cross-platform bridging: If a server admin connects a channel to a bridge, Kuma Bot copies new messages in that channel (their text, attachments, and your username and avatar) to the linked channels on the other platforms (Stoat, Discord, Fluxer), where they are re-posted through a webhook or masquerade so they appear under your name. To keep the copies in sync, Kuma Bot stores a short mapping of the original and relayed message IDs, so an edit or deletion on one side is mirrored on the others. Bridging is off until an admin sets it up, and webhooks are only created in the channels they authorize for it.
  • Cross-platform punishments & account linking: If linked communities enable cross-platform punishments, a moderation action (such as a ban) in one community can be applied to the others; to do this, your user ID and the action are shared with the linked servers' Kuma Bot instance. Separately, if you choose to link your own accounts with the !link command, Kuma Bot stores the mapping between your Stoat, Discord, and Fluxer user IDs so your profile and settings follow you across platforms. You can unlink at any time, and this mapping is included in the data you can view and erase from the privacy hub.
  • What we don't do: Kuma Bot only reads DMs to handle commands you send it (such as a game's private actions), never your personal conversations, and DM content isn't stored. We don't read channels Kuma Bot isn't in, collect off-platform data or credentials, or use any of the above to build advertising profiles.

2. Why We Process It

  • To run the features you enabled: Moderation and anti-raid, content filtering, leveling, economy, welcomes, tickets, and the rest of Kuma Bot's toolkit only work by processing the relevant activity in your server.
  • To give moderators the tools they need: The dashboard and Staff Hub surface health metrics, the activity feed, cases and appeals, and audit history so your team can manage the community.
  • To support you: Tickets, the debug command, and careers applications exist so you can reach us and so we can diagnose problems you report.
  • Not for advertising or sale: We do not profile users, run ads, or monetize your data in any way.

3. Where We Store It & How Long

  • Infrastructure: Data is held in a database on a private, persistent volume hosted on Railway, with uploaded ticket files stored on the same protected disk. Access is restricted by secret tokens kept in environment variables and is not exposed publicly.
  • Kept until you remove it: Most data (server settings, moderation history, levels, economy, notes, and logs) is retained for as long as Kuma Bot is in your server (so history and configuration persist), or until you or a moderator deletes it.
  • Automatically expired: Some data is short-lived by design: dashboard and staff login sessions and one-time login codes expire within minutes, and uptime history rolls off after about 90 days.
  • When Kuma Bot leaves: If Kuma Bot is removed from your server, its associated data can be deleted on request (see your rights below).

4. When We Access or Share Your Data

  • Technical maintenance: Aki Works staff may access the database strictly to fix bugs, investigate crashes, or respond to abuse and security issues.
  • No monetization: We never sell, rent, or trade your data to third parties.
  • Service providers: Data is hosted on Railway, and messages are delivered through the platform your server is on (Stoat, Discord or Fluxer). A few optional features send specific data to a third party only when you use them: image content scanning sends posted images to Google's Vision API to check for gore/explicit content, AniList profile linking sends the AniList username a member provides to AniList, and Letterboxd profile linking sends the Letterboxd username a member provides to Letterboxd to check the profile and link to it. We don't share your data with anyone else.
  • Linked communities you connect: Where a server enables bridging or cross-platform punishments, the specific data those features need (relayed message content and your name/avatar for bridging; user IDs and moderation actions for punishments) is shared with the other communities that server has linked to on Stoat, Discord, and Fluxer. This only happens between communities an admin has explicitly connected, and never with anyone else.
  • Legal & safety: We may disclose data only where required to comply with a valid legal request, or to report serious abuse to the relevant platform's staff (Stoat, Discord or Fluxer) or the relevant authorities.

5. Your Rights & The Right to Be Forgotten

Under international frameworks (including GDPR and APPI), you have rights over your data:

  • Erasure: Server owners can wipe their community's configuration and history at any time, and individual members can request that their records be permanently removed from our database.
  • Access: You can request a copy of the data Kuma Bot holds that is associated with your account.
  • How to exercise your rights: Email us at legal@kumabot.xyz. We'll verify and action requests within 30 days.

6. Governing Law, Jurisdiction & Global Compliance

  • Current framework: Kuma Bot and Aki Works operate out of Japan. By using our services, you agree that any disputes or privacy evaluations are governed by the laws of Japan.
  • Sub-processors & international transfers: To run the service we rely on a small set of third-party processors: Railway (database and file hosting) and the Stoat, Discord & Fluxer platforms (message delivery), plus (for opt-in features only) Google Cloud (Vision API) for image content scanning and AniList and Letterboxd for profile linking. Some of these process data on servers outside your country (including the United States); where applicable, such transfers rely on those providers' own data-processing terms and standard contractual clauses. We use them solely to deliver Kuma Bot's features, and never to sell or otherwise monetize your data.

International Compliance (GDPR & APPI):

For EU Citizens

Aki Works acts as the Data Controller for bot operations. Processing is carried out under the lawful basis of Legitimate Interest (to secure and moderate communities) and, where you enable optional features, on the basis of consent.

For Japanese Residents

In accordance with the APPI, we maintain internal controls against unauthorized data handling and will notify both affected users and the Personal Information Protection Commission (PPC) in the unlikely event of a significant data breach.

Last updated July 2026