Data protection
Privacy Policy
What ZeroBot and its dashboard store, why, how long it is kept, and how to have it removed. Written to describe what the bot actually does.
Last updated 1 October 2026 · Mirko Goldschmidt, Oeversee, Germany
Who is responsible
ZeroBot is run by an individual, not a company:
Mirko Goldschmidt
Langacker 16, 24988 Oeversee, Germany
mirkogoldschmidt@outlook.de
The bot, its data and the dashboard run on a server in Germany. Everything runs on Discord as well, and Discord's own privacy policy covers what Discord does with it.
Which ZeroBot features run on a server is decided by that server's staff. For questions about why a feature is on in a particular server, ask its staff; for anything about what ZeroBot itself stores, use the address above.
What it stores about a server
The settings staff make on the dashboard or with commands: which modules are on, which channels and roles they use, panels, messages, word lists, ticket categories, staff teams, the bot's profile on that server, and similar configuration. These are stored against the server's ID and hold channel and role IDs rather than anyone's personal data.
What it stores about members
Depending on which features a server has switched on, ZeroBot stores the following against your Discord user ID:
| What | Why |
|---|---|
| Discord user ID, and your username where a log or case shows it | To know who an entry is about, and so staff can read it. |
| Levels: XP, level and when you last earned XP | Leveling, when the server uses it. |
| Warnings, timeouts, kicks, bans and punishment cases, with reason, staff member and time | Moderation, and so an appeal can be judged on the record. |
| Auto moderation strikes, with the rule that matched and the text or name that triggered it | Escalating responses to repeated spam or filtered content. Kept 30 days. |
| Tickets you open, their state, and whether you are blocked from opening tickets | Running tickets. When a ticket closes, a closing note goes to the server's own log channel. |
| Staff applications: your answers and the decision | So staff can review them. |
| Giveaway entries | Drawing a winner. |
| Reaction and self-role choices | Handing out the roles you picked. |
| On tier-list servers: queue entries, test results and tiers | Running tier tests. |
| Premium servers with Server Backups: the server's roles, channels and permission settings, including permissions set for single members, and who made each backup | Restoring the server after damage. The last 7 daily and 10 manual backups are kept. |
| On the operator's own server only: the Minecraft account you linked with /sync | Connecting your Discord and in-game ranks. Optional and can be undone. |
| On the operator's own server only, for its staff: tickets claimed and closed and warnings given (35 days), activity strikes and absence notices | That server's own staff activity checks. |
| On the operator's own server only: partnership requests, with the advert text, invite and proof screenshot | Reviewing partnerships. |
What it reads but does not keep
Messages. ZeroBot reads messages in channels it can see, to run filters, count XP and answer commands. It does not keep them in a database. Recent messages are held in memory for about a day (at most 25 hours) so that, if a server has message logs on, a deleted or edited message can be shown in that server's log channel. Restarting the bot clears that memory.
Names and profiles. Screening, when a server has switched it on, looks at usernames, display names, avatars, banners and account age when someone joins or changes them. Nothing is stored unless a check flags the account, in which case the report is posted to that server's staff log.
Images. On servers that use the strict chat filter or profile screening (Premium features), images posted in chat, and the avatars and banners of members who join or change them, are sent to Anthropic (Anthropic, PBC, San Francisco, USA) to be checked for sexual content, gore and hate symbols. ZeroBot keeps only the result. Anthropic acts as a processor under its data processing terms, which include the EU standard contractual clauses for the transfer to the USA; under its current terms it does not train on this data and deletes it within 30 days. On the operator's own server, partnership proof screenshots are checked the same way.
Support questions. On servers that switch on AI answers for a ticket panel (a Premium feature), the question you type, and your in-game name if you give one, are sent to Mistral AI (Mistral AI SAS, Paris, France) together with that server's own support text, so that an answer can be shown to you. Training on this data is switched off in ZeroBot's Mistral account. The answer is shown only to you; the question and the answer are also posted to that server's ticket log channel for its staff, and copied into the ticket if you choose to open one. ZeroBot keeps only a daily count.
Web verification. When a server verifies members through a web page, that page is served by the dashboard (on the operator's own server, by its website), whose web server sees your IP address like any website does. It is not linked to your Discord account and not kept beyond the ordinary access logs.
What a log channel or case forum shows is stored by Discord, in that server, and managed by that server's staff.
The dashboard
Signing in uses Discord. You allow ZeroBot to read your Discord ID, username and avatar, and the list of servers you are in. The server list is used to show which of your servers you can manage; it is read when you sign in and when you open the server list, held in memory for up to a minute so the page does not ask Discord twice, and not stored. ZeroBot does not ask for your email address.
Signing in sets one session cookie. It is encrypted and holds your Discord ID, name and avatar link, the server you are managing, and the Discord access token that lets the dashboard read your server list. It lasts until you sign out, or 30 days after you last used the dashboard.
The dashboard has no analytics, no advertising and no tracking. The web server keeps ordinary access logs, including IP addresses, for security and fault finding, and rotates them away after a short time.
Premium payments
Premium bought on the dashboard is paid through Stripe (Stripe Payments Europe, Ltd., Dublin, Ireland). Your card or other payment details are entered on Stripe's page and are never seen by ZeroBot. Stripe's privacy policy covers the payment itself.
ZeroBot receives and keeps: which server the subscription is for, the Discord ID of the person who paid, Stripe's IDs for the customer and the subscription, its status, and when the paid period ends. That is what switches Premium on and lets only the payer open the billing page.
Premium bought inside Discord is handled by Discord, and ZeroBot only learns which server has it.
Automatic decisions
Some features act on their own once a server's staff switch them on: auto moderation can delete a message and time out or ban a member after repeated hits, and screening can ban an account whose name, avatar or banner is clearly sexual, advertising or hateful. Borderline cases are flagged to staff instead of being acted on.
Every automatic action is recorded with the reason. The person affected sees a short notice in the channel, and ZeroBot never sends direct messages nobody asked for. You can ask for a human review at any time: ask the server's staff (for a ban, on the server's ban appeal page when it has one, or by contacting a staff member or the owner), or email mirkogoldschmidt@outlook.de. Staff can undo any of these actions in one click.
Legal bases
- Running the features a server has switched on, the dashboard sign-in, and Premium: performance of a contract (Art. 6(1)(b) GDPR).
- Moderation records, logs, screening and security logs: legitimate interest in keeping servers and the service free of abuse (Art. 6(1)(f) GDPR).
- Linking a Minecraft account with /sync: your consent, which you can withdraw by unlinking (Art. 6(1)(a) GDPR).
- Keeping payment records for as long as tax law requires: legal obligation (Art. 6(1)(c) GDPR).
How long it is kept
- Server settings stay after the bot is removed, so adding it back restores the setup. A server owner can ask for them to be deleted at any time.
- Member records stay until staff clear them (warnings, for example, can be removed on the dashboard) or until deletion is requested.
- Messages in memory for at most 25 hours.
- Auto moderation strikes for 30 days.
- Backups until they are replaced by newer ones, deleted on the dashboard, or deletion is requested.
- Session cookie until sign-out, or 30 days after the last visit.
- Payment records for as long as German tax law requires, up to ten years.
Your rights
Under the GDPR you can ask for a copy of what is stored about you, have it corrected or deleted, object to processing based on legitimate interest, and get it in a portable form. Email mirkogoldschmidt@outlook.de with your Discord user ID and, if it is about one server, that server's name.
One honest limit: a ban or case record can be kept after a deletion request where a server needs it to keep a banned person out. You can object to that, and it is then weighed case by case.
You can complain to a supervisory authority. For this controller that is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein.
Changes
If this policy changes, the date at the top changes with it. A change to what is collected or why is announced on the dashboard before it applies. The Terms of Service cover everything else about using ZeroBot.
