Skip to content
Docs menu: Privacy and data

Account

Privacy and data

In short

Bastion stores your server's settings, its case history and 90 days of security events, plus your Discord ID, name, avatar and email address if you log in to the dashboard. It never stores what people write in messages, though it does keep the text of appeals. Remove the bot and your server's data is erased 30 days later. You can download or delete your own account on the account page.

What's stored

DataWhat it isWhy
Server settingsEvery choice you make in the dashboard, plus IDs of the roles, channels and trusted people you pick.So the bot knows what to do.
Basic server detailsServer name, icon, owner ID, member count, when Bastion joined, and the result of its last role and permission check.To show your server in the dashboard.
Case historyEach moderation action: who did it, who it was done to, their usernames and IDs, the reason and the date.So you can look up what happened. See moderation.
Staff notesNotes added with /note add, with who wrote them.So your staff can read them later.
Security eventsA short summary each time Bastion acts, such as a raid starting. A new report or appeal, and each appeal decision, is also recorded as one line naming the people involved. Kept for 90 days.To show recent activity on the dashboard.
AppealsWhat the person wrote, their Discord ID and display name, whether it was about a ban or a timeout, the decision, who decided and when, and which staff post belongs to it. Deleted 365 days after it was sent.So staff can read and decide it, and the person can see the answer. See appeals.
Appeal blocksThe server ID, the blocked person's Discord ID, who blocked them and when.So a blocked person can't send another appeal to that server.
Member reportsThe IDs of the reported message and its channel, the author's ID, the IDs of the people who reported it, the reason they typed, and who dealt with it. Not the text of the message. Each report is deleted after 30 days.So a message is only reported once and two moderators can't both act on it. See member reports.
Quarantine recordsThe list of roles a quarantined member had, the reason and who did it. Removed when the member is released.So the roles can be given back. See quarantine.
Lockdown recordsThe channel and role permissions Bastion changed during a lockdown. Removed when the lockdown ends.So they can be put back.
Verification recordsA scrambled copy of the captcha answer, the number of wrong tries, and when an unverified member is due to be removed. Each record deletes itself, within about a day at most.To run verification.
Verification signals (Pro, web check only)Only if you switch on second account detection: a scrambled copy of each verifying member's connection, of its wider network and of a random ID from a cookie on the verify page, with their Discord ID, the time and what happened. With the VPN check on, also whether the address was on a public VPN list. Never the IP address itself. The scrambled values only work inside your server. Kept for 90 days.To spot second accounts and ban evasion. See web check, alts and VPNs.
Web check linksA scrambled copy of each private verify link, with who it was for and their display name. Removed after about 20 minutes.So the link works once, for the right person.
Verification countsHow many people were asked, passed and failed each day, and how many were flagged. Numbers only. Kept for 35 days.For the numbers on the Verification page.
Automod strikesThe server ID, the member's user ID and how many strikes they have. Nothing about what they wrote. Each record deletes itself 60 minutes after the member's last strike.So a repeat spammer doesn't get a clean slate if Bastion restarts. See Automod.
Raid reportsFor each raid: the accounts that joined, with their ID, name, when the account was made, whether it had a picture, when it joined, which invite it used and what Bastion did. Also the invites used and who made each one. Kept for 30 days.So you can see who came in and act on all of them at once. See raid reports.
Invite trackingWhich invite each new member used is worked out in memory and posted in your join log. It's only saved as part of a raid report.So you can see where a raid came from.
Test mode recordsA line for each thing a part of Bastion in test mode would have done, and to whom. Kept for 30 days.So you can check Bastion's judgement before switching it on for real.
Shared raid list (only if you opt in)The ID of an account Bastion removed in a raid, the dates it was first and last seen in a raid, and a mark for each server that reported it. The mark is scrambled with a secret only Bastion holds and names no server. Removed 30 days after the account was last seen in a raid.So servers that opt in can warn each other about the same raid accounts.
Temporary bansWho is banned, their name at the time, who banned them and when it ends. Removed when the ban ends.So the ban can be lifted on time.
Join passesThe ID of an account staff said may join once, and who said so. Removed after 24 hours.So one person can be let past the join gate.
Anti-nuke holdsWho is being held while the owner is asked what to do, what they did and what the owner chose. Removed after 2 days.So the owner's answer reaches the right person.
Staff PINs (Pro)A scrambled copy of each moderator's PIN, the number of wrong tries and any lockout. Never the PIN itself.To run the staff PIN.
Recovery keyA scrambled copy of your server's recovery key, who made it and when, and anyone waiting to use it. Never the key itself.To run the recovery key.
Custom branding (Pro)The name Bastion uses in your server. A picture you upload is passed to Discord and then deleted from Bastion's database.So Bastion can wear your name and picture.
Settings historyWhich dashboard user changed which setting, or decided which appeal, and when. Kept for 90 days.So changes can be traced.
Backups (Pro)Roles, channels, permissions and a few basic server settings.So they can be restored. See backups.
Login detailsYour Discord ID, display name, avatar and verified email address. Discord's access tokens for your login are stored encrypted. A dashboard session lasts 7 days at most.So you can log in to the dashboard and see your servers.
Marketing email choiceOnly if you answer the question on the account page: on or off, the address, the date and the wording you saw.So we email only people who asked.
Subscription details (Pro)Which server is on Pro, who bought it, its status and renewal date, and a Stripe customer ID.To switch Pro features on.

What's never stored

  • Message content. Bastion reads each message to score it for heat. It holds a member's last few messages in memory for a short time, so it can spot repeats and delete spam. What people write is never saved to the database.
  • Message text in message logs. With message logs on (Pro), Bastion copies the text of a deleted or edited message into a post in the log channel you chose. That post lives in your Discord server, like any other message. The text is read from memory, posted and forgotten. It's never written to Bastion's database, and Bastion keeps no copy once it's posted. Messages sent before Bastion started can't show their text at all.
  • The text of a reported message. When a member reports a message, its text is quoted in the staff post in your Discord channel. Only the message's ID is saved, never its text. The reason the reporter types is saved, for 30 days.
  • Server change posts. The server changes log is posted in the Discord channel you chose and nowhere else. Bastion keeps no copy.
  • Images. With the AI check for scam images on (Pro), the first picture a new member posts is sent to Anthropic to be looked at. Only the picture is sent: no message text, name, ID or server. Bastion doesn't keep the picture. It keeps a fingerprint of it with the answer, so the same picture isn't checked twice and a known scam image is caught faster. The fingerprint can't be turned back into the picture and says nothing about who posted it. You can switch off sharing it. With the check off, or on an installation where it isn't set up, no image is sent to anyone.
  • PINs and recovery keys. Only a scrambled copy is kept. Nobody, including the owner and Bastion's own team, can read one back.
  • IP addresses. The web check uses a member's address for a moment and throws it away. Only a scrambled copy is ever saved, and only if you switch on second account detection.
  • Device fingerprints. Bastion doesn't read anything about a member's screen, fonts or hardware. The only lasting thing the verify page saves in a browser is one cookie with a random ID, when second account detection is on. Signing in on that page asks Discord only who the member is, creates no Bastion account, and uses two cookies that last 10 minutes.
  • Your Discord password. You log in through Discord itself. Bastion never sees it.
  • Card details. Payments are handled by Stripe. Bastion doesn't see or keep your card number.
  • A list of your members. Bastion keeps records about a member only when something happens to them, such as a warning.

Case reasons and staff notes are typed by your moderators, so they contain whatever your moderators write. Ask staff not to paste private information into them. In the same way, an appeal holds whatever the person chose to write, and a report holds the reason the reporter typed.

Who else receives data

  • Discord. Bastion works through Discord, and you log in with Discord. Login asks Discord for your identity, your email address and your server list.
  • Stripe. If you start a Pro checkout, Stripe receives your name and email address so it can take payment. The card form on the checkout page is Stripe's, so your card details go straight to Stripe, and Stripe sees your address and browser details there to prevent fraud.
  • Anthropic, only if you switch on the AI check for scam images. It receives the picture a new member posted and nothing else.
  • Cloudflare, only if the human check is switched on. If the web check page shows a Cloudflare human check, the member's browser sends Cloudflare its address and browser details. When it is off, the page loads nothing from any other company.
  • Nobody, for the VPN lists. Bastion downloads public lists of VPN, datacentre and Tor addresses from the Tor Project and GitHub and checks them itself. A member's address is never sent to them.
  • Klaviyo. Our email provider receives nothing unless you turn on marketing email on the account page. It is off by default, and logging in sends nothing. If you turn it on, Klaviyo receives your email address and Discord ID, and a note if you start a checkout or subscribe.
  • The sub-processors page lists every company and what it receives.

How long data is kept

  • Security events are removed after 90 days.
  • Automod strike records are removed 60 minutes after the member's last strike.
  • Member reports are removed after 30 days.
  • Verification signals are removed after 90 days. Without second account detection, the record of a web check is deleted as soon as Bastion has acted on it. Web check links go after about 20 minutes, and verification counts after 35 days.
  • Raid reports and test mode records are removed after 30 days. A shared raid list entry is removed 30 days after the account was last seen in a raid.
  • A join pass is removed after 24 hours, an anti-nuke hold after 2 days, and a temporary ban record when the ban ends.
  • Staff PINs and the recovery key are kept until they're reset or replaced. If a moderator deletes their Bastion account, their PIN is erased and a "reset required" marker with no secret stays, so the PIN can't be bypassed. They go with everything else 30 days after Bastion leaves.
  • Appeals are removed 365 days after they were sent. An appeal block stays until staff undo it with /appeals unblock.
  • Settings history is removed after 90 days.
  • Message log posts and server change posts are ordinary Discord messages in your own channel. Bastion doesn't keep them. They stay until you or Discord delete them. The same goes for the staff posts for reports and appeals.
  • Settings, cases, notes, backups and appeal blocks are kept while Bastion is in your server. When it leaves, everything held for the server is erased automatically 30 days later. Add Bastion back within those 30 days and nothing is erased.
  • A dashboard account nobody has logged in to for 24 months is deleted, unless it pays for a running subscription.
  • Subscription records are kept for 6 years after a subscription ends, because tax law requires it.
  • Backups are also limited by number. Bastion keeps your newest automatic backups, 5 by default, and up to 10 manual ones.

Who can see it

The dashboard shows your server's data only to people who can manage that server: the owner and anyone with Administrator or Manage Server. Of those, only the owner and trusted people can change the protection settings. See the dashboard. Message logs can be read by anyone who can see the channel you chose, so keep it private. Staff who can use moderation commands can also read cases and notes inside Discord. Appeals are shown on the Activity page to everyone who can open the dashboard, and in the staff channel you chose, along with reports. Keep that channel private. A person who appeals can see their own appeals on the appeal page after signing in, and nobody else's.

How to remove your data

  1. Cancel Pro if you have it

    Removing the bot doesn't cancel a subscription. Cancel from your Billing page, in the menu under your name, which still works after the bot is gone. See Pro.

  2. Remove the bot

    In Discord, open Server Settings, then Integrations or the member list, and kick Bastion. It stops collecting anything the moment it leaves.

  3. Wait 30 days, or ask for sooner

    Everything held for the server is erased automatically 30 days after Bastion leaves. Adding it back in that time cancels this. To have it erased sooner, the server owner can email support@bastionbot.xyz with the server ID.

  4. Your own account

    Open Account and privacy in the dashboard. You can download everything linked to your Discord ID, or delete your account, without emailing anyone. A running subscription must be cancelled first.

TipTo find a server ID, switch on Developer Mode in Discord's Advanced settings, then right-click the server icon and choose Copy Server ID.

If you're a member, not an owner

If a server using Bastion holds a case about you and you want it looked at, speak to that server's staff first. They control the record. If they don't answer, email support@bastionbot.xyz with your Discord user ID and we'll pass your request to the server's owner.

If you sent an appeal, Bastion holds what you wrote, your Discord ID and display name, and the decision. Signing in to appeal also creates the login record described above. You can download a copy of all of it, or delete your login record, at Account and privacy. The appeals themselves belong to the server you sent them to and are removed after 365 days.

If you verified on a server's web check page, Bastion may hold scrambled copies of your connection and of a cookie's random ID for that server, for 90 days. Staff there can see that your account matched another one, never your address. You can download these records or erase them from every server at Account and privacy, or email support@bastionbot.xyz with your Discord user ID if you have no account. If the check kept you out and you think it was wrong, ask that server's staff: a moderator can let you in.

The privacy policy is the full legal version of this page. See also the cookie policy and, for server owners, the data processing agreement.

Does Bastion read my messages?

It checks each message as it arrives so it can spot spam. It doesn't save them. If the server has message logs on, the text of a deleted or edited message is posted in that server's log channel, and still not saved by Bastion.

Is my appeal stored?

Yes. The text, your Discord ID and display name, and the decision are kept for 365 days, then deleted.

Is a reported message stored?

No. Bastion saves the message's ID, who reported it and the reason they gave, for 30 days. The text of the message only appears in the staff post in that server's Discord channel.

Does Bastion store my IP address?

No. If a server uses the web check with second account detection, Bastion keeps a scrambled copy that only works inside that server, for 90 days. The address itself is never saved.

What is the shared raid list, and am I on it?

It's a list of accounts that were removed in raids, shared between servers that opt in. It holds an account ID and two dates, and names no server. An entry goes 30 days after the account was last seen in a raid. If you have a dashboard account, your data download says whether you're on it. To object, email support@bastionbot.xyz with your Discord user ID.

Does Bastion send my pictures to an AI?

Only if the server switched on the AI check for scam images, and then only the first picture a new member posts. The picture goes to Anthropic with no message text, name or ID. The picture isn't kept, only a fingerprint of it that can't be turned back into the picture.

Does it read private messages?

No. A bot can only see channels in servers it has been added to.

I removed the bot. Is my data gone?

Not yet. It is kept for 30 days in case you add Bastion back, then erased automatically. Email support if you want it gone sooner.

Can I get a copy of my data?

Yes. Sign in and open Account and privacy to download everything linked to your Discord ID. For a copy of a whole server's records, the owner can email support@bastionbot.xyz with the server ID.

Last updated