Home / Privacy Policy

Privacy Policy

Last Updated: July 21, 2026

1. Introduction

Welcome to Krow Bot ("we," "our," or "us"). Your privacy is important to us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Discord bot and associated website services at krow.rip.

By accessing or using our services, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

Information You Provide

  • Account Information: Email address, username, and password when you register on our website.
  • Discord Data: Discord user ID, username, avatar, and server membership when you link your Discord account.
  • Third-Party Integrations: Spotify and Last.fm account tokens when you connect these services.
  • Communications: Messages and content you send through our chatbot or support channels.

Automatically Collected Information

  • Usage Data: Pages visited, features used, and interaction patterns.
  • Device Information: Browser type, operating system, and device identifiers for session management.
  • Log Data: IP addresses, access times, and referring URLs.

Discord Server Content (Bot Features)

  • Message Content: To provide moderation, auto-moderation, anti-nuke, AI chat, and logging features, the bot processes messages sent in servers where it is active and those features are enabled by a server administrator. Message content is used in real time to perform these functions. We do not sell message content or use it for advertising.
  • Server & Activity Data: Moderation actions, edited or deleted messages (only where a server admin enables logging), levels/XP, economy balances, tickets, and similar server configuration and activity data.
  • AI Processing: When AI chat or other AI features are used, the message content needed to generate a response is sent to our AI provider, Google Gemini, and is subject to Google's applicable terms. Presence data is never included in what is sent to any AI provider.

Presence Data (Online Status and Activities)

Where the Guild Presences intent is enabled, the bot can see a member's online status (online, idle, do not disturb, offline) and their current activities, including their custom status and Spotify listening activity. We use it only in the ways listed below, and only at the moment it is needed:

  • Status roles (vanity roles): Where a server administrator has configured one, the bot checks whether a member's custom status contains that server's chosen keyword (typically its vanity invite, for example .gg/krow) and grants or removes a reward role to match. Only the custom status is read for this; games and other activities are ignored.
  • Spotify features: Commands that show what a member is currently listening to, and that highlight others in the server listening to the same track or artist, read Spotify activity at the moment the command is run.
  • Online member counts: Counter channels and server statistics show how many members are currently online. This is an aggregate number only and is not linked to any individual.
  • On-demand lookups: Commands such as -userinfo display a member's current status and activity in the reply, at the moment the command is run.

We do not store presence data. It is read from Discord in memory, used to produce the response or role change described above, and discarded. It is never written to our database or logs, never sent to any third party, never used for advertising or profiling, and we do not build any history of when members are online.

Opting out. A member who does not want the status-role feature to act on them simply does not put the server's keyword in their custom status; the feature only responds to a keyword a member has deliberately chosen to display. Discord's own privacy settings also let a member appear offline or hide their activity, which removes the data from the bot entirely. Server administrators can remove the feature for everyone at once by deleting the configured status role.

3. How We Use Your Information

  • Provide, operate, and maintain our bot and website services.
  • Authenticate your identity and manage user sessions.
  • Process and fulfill bot commands and customization preferences.
  • Enable third-party integrations (Spotify, Last.fm, Discord).
  • Send notifications and updates you have opted into.
  • Monitor and analyze usage patterns to improve our services.
  • Detect, prevent, and address technical issues and abuse.

4. Data Sharing & Disclosure

We do not sell, trade, or otherwise transfer your personal information to third parties except in the following circumstances:

  • Third-Party Services: When you authorize connections to Spotify, Last.fm, or Discord, we share necessary tokens with those platforms to provide the requested functionality.
  • AI Providers: When you use AI features, the message content needed to generate a response is processed by Google Gemini.
  • Payment Processing: Payments and Social Pro subscriptions are processed by Stripe. We store Stripe customer/subscription references and billing status, but not full card details.
  • Public Social Data: For Social Pro, Apify processes configured public Instagram/TikTok usernames, posts, and public engagement metrics. See our Public Social Data Disclosure.
  • Error Monitoring: Sentry may receive technical error details and limited request context. Default personally identifiable information collection is disabled.
  • Legal Requirements: When required by law, subpoena, or governmental request.
  • Safety: To protect the rights, property, or safety of our users and the public.

5. Data Security

We implement industry-standard security measures to protect your information:

  • Passwords are hashed using bcrypt with salt rounds.
  • All data transmission is encrypted via HTTPS/TLS.
  • JWT tokens with CSRF protection for session management.
  • Rate limiting to prevent brute force attacks.
  • Security headers (HSTS, X-Frame-Options, CSP) on all responses.
  • Two-factor authentication (2FA) available for all accounts.

While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

6. Your Rights

You have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of any inaccurate data.
  • Deletion: Request deletion of your account and associated data.
  • Disconnect: Unlink third-party integrations (Spotify, Last.fm, Discord) at any time through your profile settings.
  • Opt Out: Disable notifications and data collection where applicable.

To exercise these rights, contact us at the email below or use the settings in your profile page.

7. Cookies & Local Storage

We use cookies for:

  • Authentication: JWT access and refresh tokens stored as secure, HTTP-only cookies.
  • CSRF Protection: CSRF tokens to prevent cross-site request forgery.
  • Preferences: Theme preference (light/dark mode) stored in localStorage.
  • Device Recognition: Device UUID for session management across devices.

You can manage cookie preferences through your browser settings. Disabling cookies may limit functionality.

8. Data Retention

We retain your personal data only as long as necessary to provide our services and fulfill the purposes described in this policy. Account data is retained until you request deletion. Activity logs and Social Pro aggregate delivery records may be retained for up to 90 days. Billing records may be retained longer where required for tax, accounting, fraud prevention, or legal compliance.

9. Children's Privacy

Our Services are not directed to anyone under the age of 13, or the minimum age required to use Discord in your country. We do not knowingly collect personal data from children under that age. If you believe a child has provided us with personal data, contact us and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Continued use of our services after changes constitutes acceptance of the revised policy.

11. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

  • Email: support@krow.rip
  • Discord: Join our support server
  • Website: krow.rip