Last updated · July 2026
Privacy Policy
Your privacy matters to us. This page explains how we handle, protect, and respect your data while you use Crystal.
Our Commitment
At Crystal, we prioritize the protection of your privacy and personal information. This policy outlines our practices for collecting, using, and safeguarding your data while using our Discord bot and associated web dashboard.
Information We Collect
We collect and process the following data to provide our services:
- Discord profile information (user ID, username, avatar, and server roles when needed)
- Server (guild) configuration and feature preferences set by administrators
- Bot interaction data needed for features you enable (for example command usage, moderation records such as warns, leveling/XP, tickets, applications, counting, and welcome settings)
- Dashboard sign-in data via Discord OAuth (session tokens managed by our authentication provider so you can manage servers you have permission to administer)
- Message content only when required for enabled features (such as XP, counting, prefix commands, or logging you configure) — not for advertising or unrelated scraping
How We Use Your Data
Your data helps us deliver and enhance our services:
- Providing core bot functionality and dashboard settings
- Maintaining your preferences and per-server configuration
- Ensuring platform security and preventing abuse
- Communicating important updates when you contact support or join our support channels
Data Security
We implement reasonable security measures to protect your information:
- Encrypted connections (HTTPS/TLS) where the dashboard is served over the public internet
- Shared-secret authentication between the dashboard and the bot API
- Access controls so guild settings are limited to authorized Discord users
- Alignment with Discord's developer and security requirements
While we take care to protect data, no online service can guarantee 100% security.
Data Storage
Bot and guild data are stored in the service operator's database used by Crystal (for example local or hosted SQLite managed with the bot process). Dashboard sessions are stored according to our authentication setup. We retain data only as long as necessary to provide the service, honor your configuration, and meet legal obligations. You may request data deletion at any time through our support channels.
Your Rights
You have several rights regarding your personal data:
- Access your stored data
- Request corrections to inaccurate information
- Request deletion of your data
Contact us through the channels below to exercise these rights. We aim to respond within 30 days.
Third-Party Services
We use select third-party services to run Crystal:
- Discord API — core bot features, OAuth login, and guild membership
- Hosting or infrastructure providers chosen by the service operator (when deployed)
Each third-party service maintains its own privacy policy and data-handling practices. Discord's policy is available at discord.com/privacy.
Policy Updates
We may update this privacy policy periodically to reflect changes in our practices or legal requirements. Significant changes may be announced through our support Discord server or on this page. The "Last updated" date at the top will change when we revise the policy.
Contact Us
For questions or concerns about your privacy and data protection:
- Discord support — use the Support Server link on our website when available
- Or contact the server administrator who invited Crystal, if you are asking about data stored for a specific Discord community