Privacy policy
Last updated:
1. What roly is
roly is a Discord bot that audits the role-based permissions in a server and produces a report describing which roles hold dangerous or overpowered access. roly operates on a trust-first basis: it reads only the metadata needed to perform the audit, and it never modifies roles on its own.
2. Information we collect
To deliver the service, roly collects the following data:
- Server metadata: server ID, server name, the role list (name, ID, color, hoist status), and each role's permission flags.
- Command invocation data: the user ID of the operator who runs a scan, the channel ID where the command was issued, and the timestamp of the command.
- Account data: the Discord user ID of anyone who links a dashboard account (email is optional).
We do not collect messages, voice, attachments, member lists beyond role memberships, or channel content.
3. What we do with it
- Generate the audit report you requested.
- Rate-limit abusive usage and prevent abuse of the Discord API.
- Send operational responses back to the server where the command was run.
- Improve rule definitions for the permission classifier (aggregated, non-identifying).
We do not sell, rent, or lease this data. We do not use it to train third-party models.
4. Discord permissions requested
When you invite roly, we request the minimum scopes required to read role and permission data: typically View Audit Log, Manage Roles (read-only use), and Send Messages to deliver the report. roly never asks for or uses Embed Links.
5. Data retention
- Audit reports: 30 days, then automatically purged. You can request the deletion of all the data from your server by contacting us via e-mail or a ticket on our Discord server.
- Operator command history: 14 days, for abuse investigation only.
- Linked dashboard accounts: retained until you unlink or delete the account.
6. Cookies and the dashboard
If you use the web dashboard at roly.space, we use a first-party session cookie to keep you signed in via Discord OAuth. No third-party analytics, no advertising cookies, no fingerprinting.
7. Sharing and disclosure
We share information only with the subprocessors required to run the service (hosting, error monitoring, Discord itself). We will disclose information only when required by valid legal process, and where permitted we will notify you before any disclosure.
8. Your rights
You can request to:
- Export all data we hold associated with your Discord guild or user ID.
- Delete all data associated with your Discord guild or user ID.
- Revoke roly's access to your server at any time by removing the bot from the server.
To exercise these rights, email [email protected].
9. Security
roly is built on a least-privilege model: scoped bot tokens, scoped database credentials, encrypted at rest, no human access to live server data by default. We publish a status page at roly.space and disclose material incidents within 72 hours of confirmation.
10. Changes to this policy
If we make material changes, we'll post a notice in the roly support server and update the date above. Continued use of roly after the effective date constitutes acceptance of the updated policy.
11. Contact
Questions, complaints, or data requests: [email protected].