Privacy Policy
effective August 11, 2026 · supersedes the version dated August 25, 2022
1. Introduction and scope
This Privacy Policy describes how Custom Commands (“we”, “us”, “our”) collects, uses, stores and shares personal data when you use the ccbot.app website and dashboard (the “Site”) and the Custom Commands Discord bot (the “Bot”, together the “Service”). By using the Service you agree to the practices described here. If you do not agree, do not use the Service.
2. Information we collect
Account information. When you sign in with Discord, we receive and store your Discord user ID, username, avatar and email address, together with the session data needed to keep you signed in. We never see your Discord password.
Content you create. Commands, embeds, events, scripts, variables, database contents, welcome and leave configurations, reaction-role setups, message templates and files you upload are stored so the Service can operate them for your server. This content belongs to you and can be edited or deleted from the dashboard at any time.
Operational records.To run and secure the Service we keep: audit logs of dashboard actions (which user changed what, and when); command execution logs on servers with a paid plan (command name, the invoking user's ID and name, the channel, and the option values submitted with the command); script error logs; usage counters (for example daily command and AI usage); vote records from top.gg; and, where a server enables the role-retention feature, a snapshot of a departing member's role IDs so they can be restored if that member returns.
Payment information. Payments are processed by Stripe. We store subscription status and Stripe identifiers, never your card number or other sensitive payment credentials. Stripe acts as an independent controller of the payment data it processes; see the Stripe Privacy Policy.
3. Message content
The Bot can read messages in channels it has permission to view. It uses this access solely to detect and run the text commands and event handlers your server has configured. The Bot does not build a store of your server's message history. Where execution logging applies (paid plans), the inputs a member deliberately submits to a command are recorded as described above.
4. How we use information
- To provide, operate and maintain the Service;
- To authenticate you and secure your account;
- To process subscriptions and prevent billing abuse;
- To enforce plan limits and protect the Service against misuse;
- To provide support and investigate errors you report to us;
- To comply with legal obligations.
Where the GDPR or similar law applies, our legal bases are the performance of our contract with you, our legitimate interests in operating and securing the Service, and your consent where required. We do not sell personal data and we do not use it for third-party advertising.
5. Sharing and processors
We share personal data only with the service providers needed to run the Service, each bound by its own privacy terms:
- Discord — the platform the Service operates on;
- Stripe — payment processing;
- Cloudflare — file storage (R2) and network infrastructure;
- UploadThing — file storage, only where your server has connected its own UploadThing account;
- top.gg — vote events, where your server uses vote rewards;
- AI model providers — where your server uses AI features, the prompt content needed to fulfil the request is passed to the model provider and is not used by us to train models;
- Hosting providers — the infrastructure our databases and services run on.
The Site and messages sent by the Bot may contain links to third-party websites. We are not responsible for the privacy practices of those websites, and this Policy does not cover them.
6. Data retention
- Content you create is kept until you delete it or your server data is purged;
- Command execution and audit logs are retained according to your server's plan (from 1 up to 30 days) and are purged after that window;
- If the Bot is removed from a server, that server's data enters a 7-day grace period; re-invite the Bot within that window and nothing is lost, otherwise the server's data — including its databases — is permanently deleted;
- Retained role snapshots are deleted as soon as the member rejoins and the roles are restored, or with the server's data as above;
- Account data is kept while your account exists and removed on verified deletion requests.
7. Your rights
Depending on where you live, you may have rights to access, correct, export, restrict or delete your personal data. Server administrators can delete server content directly from the dashboard, and removing the Bot triggers the purge described above. For account-level requests, contact us using the details below; we will verify the request and respond within the timeframe required by applicable law.
8. Security
Data is encrypted in transit, access to production systems is restricted, server data is isolated per Discord server, and dashboard actions are permission-gated and audit-logged. No system is perfectly secure; if we become aware of a breach affecting your personal data we will notify affected users as required by law.
9. Children
The Service is not directed at children. In line with Discord's Terms of Service, you must be at least 13 years old (or the higher minimum digital-consent age in your country) to use the Service.
10. International transfers
Our providers may process data in countries other than your own. Where required, transfers rely on appropriate safeguards such as standard contractual clauses maintained by the relevant provider.
11. Changes to this policy
We may update this Policy from time to time. Material changes will be reflected by a new effective date at the top of this page, and continued use of the Service after a change constitutes acceptance of the updated Policy.
12. Contact
Questions or requests about this Policy: email [email protected] or reach us in our Discord support server.