Privacy
Privacy policy
The short version: Bastion stores your server's settings and a record of what it did. It never stores what people write. Marketing email is off unless you turn it on.
Last updated
Who we are
Bastion is run by Xyliase Technologies LTD, trading as BASTION. In this policy, "we" and "us" mean that company.
- Company: Xyliase Technologies LTD, trading as BASTION, a company registered in Scotland.
- Company number: SC888385
- Registered office: Unit 29 Eliburn Industrial Park, Livingston, Scotland, EH54 6GQ
- ICO registration number: ZC246956
- Privacy contact: support@bastionbot.xyz
This policy covers the Bastion bot, the dashboard and this website. It follows the UK GDPR, the Data Protection Act 2018 and, for people in the European Union, the EU GDPR.
Our two roles
We handle personal data in two different ways, and the difference matters for who you ask about it.
- We are the controller for your dashboard account, billing and marketing email. We decide why and how that data is used, and this policy is our promise about it.
- We are a processor for what the bot handles inside a Discord server: moderation cases, message checks, message logs, verification, reports and appeals. The server's owner decides to use Bastion and how it is set up. We only follow those settings. The owner is the controller, and our data processing agreement sets out the rules we follow for them.
So if a server warned, banned or logged you, that server's staff are the people to ask first. We will help them answer you.
What we collect
When you sign in to the dashboard or to send an appeal, Discord gives us:
- Your Discord ID, display name and avatar.
- Your email address, only if Discord has verified it.
- The list of servers you are in. We read it to show the ones you can manage. We do not save the list.
- Access tokens for your Discord sign-in. We store them encrypted and use them only to read that server list.
When you use the dashboard, we keep a short settings history: which signed-in person changed which setting, or decided which appeal, and when. We also keep small counters that stop any one account sending too many requests. They hold our ID for your account and a number. On the web verification page, the counter holds a scrambled copy of the visitor's address instead, for a few minutes. We do not store your IP address in our database.
When you buy Bastion Pro, we keep which server it is for, the plan, its status and dates, and a Stripe customer ID. You pay on our checkout page, in a form that Stripe runs: your card details go from your browser straight to Stripe and we never see them. On that page Stripe's code runs in your browser and Stripe receives your IP address and details of your browser and device, which it uses to prevent fraud. See the cookies page for the cookies it sets.
If you turn on marketing email, we keep your choice, the address it applies to, the date, and the exact wording you agreed to.
If you vote for Bastion on top.gg, top.gg tells us the Discord ID of the account that voted. We keep that ID and the time of the vote so that votes can count towards free Pro time, and when you use a reward we keep which server you gave it to. Voting is optional. We send top.gg nothing: the vote button on our site is a plain link.
When Bastion is in a server, on behalf of that server we store:
- The server's name, icon, owner ID and member count, and its settings, including the IDs of the roles, channels and people the staff picked.
- Moderation cases: who did what to whom, their names and Discord IDs at the time, the reason and the date.
- Staff notes about members, quarantine records, appeal blocks and, on Pro, backups of roles and channels.
- Security events: a short summary each time Bastion acts.
- Appeals: what the person wrote, their Discord ID and display name, and the decision.
- Member reports: the IDs of the reported message, its channel and its author, who reported it and the reason they typed. Not the text of the message.
- Verification records and automod strike counts, for a short time.
- Raid reports and invite tracking. When a raid is detected, Bastion keeps a report for 30 days: the accounts that joined, with their Discord ID, name, the date the account was made, whether it had a picture, when it joined, which invite it used and what Bastion did. It also keeps the invites that were used, with who made each one. Outside a raid, which invite a new member used is worked out in memory and shown in the server's own join log. It is not saved.
- Test mode records. When staff put a part of Bastion in test mode, it keeps a line for each thing it would have done and to whom, for 30 days.
- Temporary bans, passes that let one account join once, and who anti-nuke is holding while the owner is asked what to do.
- Staff PINs and recovery keys, as salted hashes only. A PIN or a key is never stored, shown again or written to a log.
- Custom branding, on Pro: the name Bastion uses in that server, and a picture the owner uploaded for it. The picture is passed to Discord and then deleted from our database.
- Verification signals, only where a server uses the web check to look for second accounts or VPNs. See verification signals.
What we never store:
- Message content. The bot reads each message to check it for spam and holds a member's last few messages in memory for a short time to spot repeats. It does not save what people write.
- Message log text. If a server turns on message logs, the bot posts the text of a deleted or edited message in the Discord channel that server chose. The text is not written to our database.
- Passwords. You sign in through Discord. Bastion has no password of its own.
- Card details. They go straight to Stripe.
This website uses no advertising, loads no analytics company's code and does not follow you across websites. Our hosting provider's servers see your IP address when they deliver a page, as every website's do.
Referral links and our own counts. We like to know which links bring people to Bastion and which buttons lead to Bastion Pro. For that we keep daily totals: how many visits a referral link brought (a link that ends in ?r= and a label, such as ?r=top.gg), how many times Bastion was added to a server after one, and how often each "Get Pro" button was shown, pressed and paid through. The totals are numbers for a day. They hold no ID of any person, browser or server, and no IP address. They are kept for 25 months.
The label of the link you arrived through is the only part that is ever tied to you:
- Before you sign in, it is kept in one cookie, with the time. The cookie holds no ID. The cookie policy lists it.
- Once you are signed in, the label and the time are kept on your dashboard account.
- If you add Bastion to a server, the label is noted on that server's record with your Discord ID as the person who added it.
- If you buy Bastion Pro, the subscription record notes the label, and which "Get Pro" button you came through. The same three short values are attached to the subscription in Stripe.
If your browser sends Global Privacy Control or Do Not Track, the cookie is not set, one that is already there is removed, and no label is kept on your account. You can see all of this in your data download, and deleting your account removes the label from it and your ID from the servers you added Bastion to.
Verification signals
Some servers ask new members to verify on a page of this site instead of inside Discord. We call it the web check. The member opens a private link the bot showed them and presses one button. If the server looks for second accounts or checks for VPNs, the page first asks you to sign in with Discord, and the link only works for the Discord account it was made for. That stops someone passing their own link to you so that your device and connection are saved under their account. If you open a link made for someone else, nothing about your device or connection is saved. On a server that uses neither check, no sign-in is needed.
That sign-in asks for very little. It is separate from the dashboard's. We ask Discord only for your account's identity, not your email or your list of servers. We use your Discord ID once, to check the link is yours, and hand the access back to Discord straight away without storing it. It creates no Bastion account and no session. Two short cookies carry it for about ten minutes. The cookie policy lists them.
What the page uses:
- Your IP address. Every website sees it. We use it for a moment and then discard it. It is used to count requests so the page cannot be flooded, to compare it with public lists of VPN, datacentre and Tor addresses if the server asked for that, and to make the scrambled values described below if the server looks for second accounts. We never store the IP address itself.
- A device cookie. Only if the server looks for second accounts, and only once you press the button. It holds a random ID and nothing about you or your device. The cookie policy lists it.
What is stored, on behalf of that server:
- A scrambled copy of the link, with your Discord ID and your display name at the time, for about an hour.
- If the server looks for second accounts: your Discord ID, the server, the time, what happened, and three scrambled values. One is made from your connection (your IPv4 address, or the /64 network of your IPv6 address), one from its wider network (the /24 or the /48), and one from the random ID in the device cookie.
- If the server checks for VPNs: whether your address was on a list and which list, or that the check could not be run. Not the address.
- Daily counts for the server's dashboard, such as how many people passed. Numbers only, with nobody named.
On a server that has neither check switched on, nothing about your address or device is stored at all, no cookie is set, and the record of your check is deleted as soon as the bot has let you in.
Why. To stop someone who was banned from coming back on a new account, and to stop one person bringing many accounts into a server in a raid. The server's owner decides to use these checks and is the controller. We act as their processor. The lawful basis is usually the owner's legitimate interests in preventing ban evasion and raids. For the short request counters on the page, the basis is our own legitimate interests in keeping the page available.
How it is limited:
- A separate key for every server. The scrambled values are keyed hashes (HMAC-SHA256). Each server has its own key, made from a secret only we hold and that server's ID. The same connection gives a different value in every server.
- No matching across servers. A member is only ever compared with other members of the same server, and the values from two servers cannot be compared, by a server owner or by anyone reading our database.
- Staff never see an address or a scrambled value. They see which member matched and why, for example "same device".
- No fingerprinting. We do not read your screen, fonts, graphics or audio hardware, or anything else about your device, and no outside script does.
- 90 days. Each record is deleted automatically 90 days after the check. It also goes when you delete your account, and 30 days after Bastion leaves the server.
- Still personal data. A scrambled value is pseudonymous, not anonymous. We treat it as personal data.
Automated decisions. Depending on the server's settings, a match or a VPN can mean you are let in and staff are told, held until a moderator looks, kicked or banned, without a person deciding first. The page tells you what happened and that it was automatic. A shared connection is not proof: people who live together share one. If it was wrong, ask that server's staff. A moderator can let you in or undo it. If the server takes appeals, you can appeal a ban. If you cannot reach them, email support@bastionbot.xyz and we will pass your request to the server's owner.
Your choices. These records are in the data download on the account page, and deleting your account there erases them from every server. You do not need an account: email support@bastionbot.xyz with your Discord ID to see them, have them erased or object.
The shared raid list
Raids often hit many servers with the same accounts. A server can choose to join Bastion's shared raid list, so that servers warn each other. It is off unless the server's staff switch it on.
What goes on the list. Only an account that Bastion's automatic raid response kicked or banned in a server that has opted in, and only if the account is less than 90 days old. For each account we keep:
- The account's Discord ID.
- The date it was first seen in a raid, and the date it was last seen in one.
- A mark for each server that reported it. The mark is a keyed hash (HMAC-SHA256) made with a secret only we hold. It names no server and cannot be turned back into one. Its only use is to count how many different servers saw the account.
No name, no message, no reason and no server is kept.
How it is used. When an account joins a server that has opted in, Bastion checks whether two or more different servers reported it in the last 30 days. If so, that server's own setting decides what happens: by default staff are only told. A server that has not opted in adds nothing to the list and is told nothing from it.
How long. An entry is deleted automatically 30 days after the account was last seen in a raid.
Our role and lawful basis. We run the list across servers, so we are the controller for it. The basis is legitimate interests: ours and the servers', in stopping the same accounts raiding one community after another. We have weighed that against the effect on the people listed. That is why the list holds so little, needs two servers, takes only young accounts removed in a raid, and expires quickly.
How to opt out. A server's staff can switch the shared list off at any time on the dashboard, under Anti-Raid. If you think your account is on the list wrongly, you can see your entry in the data download on the account page, and you can object by emailing support@bastionbot.xyz with your Discord ID. We will look at it and remove the entry where the objection is fair.
The AI check for scam images
Scam adverts are often posted as a picture, so that a text filter cannot read them. On Pro, a server can switch on an AI check for them. It is off unless the server's staff switch it on, and it only exists on an installation of Bastion that has been set up for it.
This installation does not have it set up. No image is sent to anyone, whatever a server's settings say.
- What is sent. Only the image: the first picture a new member posts in a server that has the check on. It goes to Anthropic, the company that runs the AI model, with a fixed question asking whether it is a scam.
- What is not sent. No message text, no name, no Discord ID, no server, and not the address the image came from.
- What is stored. Not the image, not who posted it and not where. We keep a fingerprint of each image that was checked, with the answer, so that the same image is not checked twice and a known scam image is caught faster. A fingerprint is a short code worked out from the image. It cannot be turned back into the image. A scam fingerprint is kept for 180 days after the image was last seen, and a clean one for 30 days after it was last checked. If the answer leads Bastion to act, the usual security event and moderation case are recorded, as for any other automod action.
- Sharing, and how to opt out. Unless a server switches it off, its fingerprints go on a list used by every server that has the check on. Nothing on that list names a server or a person. A server's staff can switch this off on the dashboard, under Automod, in the AI check for scam images. That server then only uses its own results, and they are deleted when it stops using Bastion.
- Who decides. The server's owner chooses to use it and is the controller. We act as their processor and Anthropic as our sub-processor, for those servers only.
Why we use it, and our lawful basis
| What we do | Lawful basis |
|---|---|
| Sign you in, show you your servers and save the settings you choose | Contract. We need this to give you the service you asked for. |
| Take payment for Pro and switch Pro features on | Contract. |
| Keep subscription and payment records | Legal obligation. Tax and accounting law requires it. |
| Keep the service secure: sessions, rate limit counters, settings history, encrypted tokens | Legitimate interests. Our interest is keeping accounts and servers safe from abuse and being able to trace a harmful change. |
| Remember which referral link brought you, and count visits, invites and presses of each Get Pro button as daily totals | Legitimate interests. Our interest is knowing which links and buttons bring people to Bastion, using a label and totals in place of anything that follows a person around. You can object, and a browser that sends Global Privacy Control or Do Not Track is left out. |
| Send marketing email | Consent. It is off until you turn it on, and you can turn it off at any time. |
| Answer your questions and privacy requests | Legal obligation where the law requires an answer. Otherwise legitimate interests, the interest being to help the people who contact us. |
| Check for second accounts and VPNs on the web verification page, where a server has switched that on | We do this as a processor. The server owner's lawful basis is usually their legitimate interests in preventing ban evasion and raids. See verification signals above. |
| Run the shared raid list, for servers that have opted in | Legitimate interests: ours and the servers', in stopping the same accounts raiding one community after another. See the shared raid list above. |
| Send an image to the AI check for scam images, where a server has switched that on | We do this as a processor. The server owner's lawful basis is usually their legitimate interests in keeping scams out of their community. |
| Run the bot inside a server: moderation, message checks, logs, verification, raid reports, reports, appeals | We do this as a processor. The server owner chooses the lawful basis. It is usually their legitimate interest in keeping their community safe. |
Where we rely on legitimate interests, you can object. See your rights.
How long we keep it
| Data | Kept for |
|---|---|
| Your dashboard account: Discord ID, name, avatar, verified email address | Until you delete your account. If you do not sign in for 24 months and have no running subscription, we delete it for you. |
| Encrypted Discord sign-in tokens | Deleted with your account. |
| Sign-in sessions | 7 days at most. Removed at once when you sign out. |
| Your marketing email choice, with its date and wording | Deleted with your account. |
| Subscription records: server, plan, status, dates, Stripe customer ID | While the subscription runs, then 6 years after it ends, because tax and accounting law requires it. |
| The label of the referral link you arrived through, with the time | In a cookie for 90 days. On your account until you delete it. On a subscription record for as long as that record is kept. |
| Which referral link brought Bastion to a server, and the Discord ID of the person who added it | Erased 30 days after Bastion is removed from the server. The ID is removed when that person deletes their account. |
| Daily totals of visits by referral link, bot invites, and views and presses of each Get Pro button. Numbers only, with nobody named | 25 months. |
| Stripe event IDs, kept so a payment message is never handled twice | 30 days. |
| Rate limit counters: your account ID and a number. On the web verification page, a scrambled copy of your address and a number | Up to 2 days. Most last a few minutes. |
| Dashboard settings history: who changed which setting, and when | 90 days. |
| Server settings, moderation cases, staff notes, backups and appeal blocks | While Bastion is in the server. Erased 30 days after Bastion is removed, unless it is added back first. |
| Security events | 90 days. |
| Votes for Bastion on top.gg: your Discord ID and the time of each vote | 120 days. |
| Your vote count and unused voting rewards | Until 120 days after your last vote, or until you delete your account. |
| Pro time given to a server with a voting reward: the server, the dates and your Discord ID | 24 months after the Pro time ends. Your Discord ID is removed from it when you delete your account. |
| Appeals | 365 days from the day the appeal was sent. |
| Member reports | 30 days. |
| Requests the dashboard sends to the bot, such as starting a backup | 7 days. |
| Quarantine records | Until the member is released. |
| Lockdown records | Until every permission the lockdown changed has been put back. If Bastion is removed from the server first, 30 days after it leaves. |
| Verification records | Removed automatically when they expire. |
| Web verification links: a scrambled copy of the link, and who it was for | About 20 minutes. |
| Verification signals: scrambled copies of the connection, its network and the device cookie's ID, and whether the address was on a VPN list | 90 days. Only saved when the server has second account detection on. Without it, the record is deleted as soon as the bot has acted. |
| Verification counts for the dashboard: numbers only, with nobody named | 35 days. |
| Automod strike counts | 60 minutes after the member's last strike. |
| Fingerprints of images the AI check for scam images has looked at, with the answer: no image, and nobody and no server named | A scam image: 180 days after it was last seen. A clean image: 30 days after it was last checked. An answer in doubt: 30 days. |
| Daily counts of AI image checks for the dashboard: numbers only | 35 days. |
| Raid reports: the accounts that joined during a raid, the invite each one used, and what Bastion did | 30 days from the start of the raid. |
| Test mode records: what a part of Bastion in test mode would have done, and to whom | 30 days. |
| A pass that lets one account join once, given by staff | 24 hours. |
| The shared raid list: an account ID, the dates it was first and last seen in a raid, and marks that count servers without naming them | 30 days after the account was last seen in a raid. |
| Temporary bans: who is banned and when the ban ends | Until the ban ends. |
| Anti-nuke holds: who is being held while the owner is asked what to do | 2 days. |
| Staff PINs: a salted hash of each moderator's PIN. Never the PIN | Until the owner resets it or the moderator deletes their account. After that a "reset required" marker with no secret stays, so the PIN cannot be bypassed, until the owner resets it. Erased 30 days after Bastion is removed from the server. |
| Recovery keys: a salted hash of a server's recovery key, who made it and when. Never the key | Until it is used, cancelled or replaced. Erased 30 days after Bastion is removed from the server. |
| Custom branding: the name Bastion uses in a server, and a picture waiting to be applied | The picture is deleted from our database as soon as Discord has it. The rest is erased 30 days after Bastion is removed from the server. |
| Status page records: when the bot was last running and how many minutes it ran each day. Nothing about any person | 45 days. |
Removal is automatic and runs in the background, so a record can stay a few hours past its date.
Posts the bot makes in a server's own Discord channels, such as log entries, are ordinary Discord messages. They stay until the server or Discord deletes them.
Who receives it
We do not sell personal data. We share it only with the companies below, and only for the reason given.
| Company | Why | What they receive |
|---|---|---|
| MongoDB, Inc. (MongoDB Atlas) | Hosts our database. | Everything Bastion stores: accounts, encrypted tokens, server settings, moderation records, raid reports, appeals and subscription records. |
| Vercel Inc. | Runs the website and the dashboard. | Everything that passes through the website while it is being handled, such as your sign-in and the settings you save. |
| [Bot hosting provider] | Runs the bot. | Everything that passes through the bot while it is being handled, including message content in memory. |
| Discord Inc. | Sign-in, and the platform the bot works on. | Sign-in requests, and every action the bot takes in a server. When you are signed in, your browser also loads avatars and server icons from Discord's image servers. |
| Stripe | Takes payment for Bastion Pro and issues invoices and receipts. | Your display name, verified email address, Discord ID, our account ID, and the ID and name of the server you bought Pro for. Card details go straight from your browser to Stripe, through the payment form on our checkout page, and never reach us. On that page Stripe also receives your IP address and browser and device details, for fraud prevention. |
| Klaviyo, Inc. | Sends marketing email, only to people who have turned it on. | For people who opted in only: email address, Discord ID, and the fact that they started a checkout or subscribed, with the server ID. |
The sub-processors page has the same list with locations and roles.
top.gg, the bot listing site, is not in this list because it receives nothing from us. It sends us the Discord ID of each person who votes for Bastion there. top.gg handles its own visitors under its own privacy policy.
The bot also downloads a public list of known scam links from GitHub a few times a day. That request carries no personal data.
The website downloads public lists of Tor, VPN and datacentre addresses from the Tor Project and from GitHub a few times a day. Those requests carry no personal data either. Your address is compared with the lists on our side and is never sent to them.
We may disclose data if the law requires it, or if the company is sold or merged, in which case this policy continues to apply to it.
Transfers outside the UK and EEA
Some of the companies above are based in, or use servers in, the United States and other countries outside the UK and the European Economic Area.
Where personal data leaves the UK or the EEA, we rely on a legal safeguard for the transfer. Where applicable, that is a UK or EU adequacy decision (including the UK extension to the EU-US Data Privacy Framework for companies certified under it), the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses.
Email support@bastionbot.xyz if you would like to know which safeguard applies to a particular company.
How we protect it
- Encrypted tokens. Discord sign-in tokens are encrypted with AES-256-GCM before they are stored, and never leave our servers.
- Sessions held on our side. Your browser holds only a random session ID in a cookie that scripts cannot read. Signing out ends the session in our database.
- Access checked every time. Each time you open or save a server's settings, we check with Discord that you still manage that server.
- A strict Content-Security-Policy. The site runs only its own scripts and loads no outside scripts, fonts or frames.
- Limits on requests. Each account can only make so many requests in a given time.
- No secrets in logs. Our application logs are written to leave out message content, email addresses and tokens.
Your rights
Under UK and EU data protection law you have the right to:
- Access the personal data we hold about you.
- Correct data that is wrong.
- Erase your data.
- Restrict how we use it.
- Take it with you in a format a computer can read.
- Object to use that is based on legitimate interests, and to marketing at any time.
- Withdraw consent to marketing email at any time. It does not affect what happened before.
- Complain to a regulator.
How to use them:
- Yourself, in the dashboard. The account page lets you download your data, turn marketing email on or off, and delete your account.
- By email. Write to support@bastionbot.xyz. Include your Discord ID so we can find your data. We answer within one month.
- Your name, avatar or email is wrong. These come from Discord. Change them in Discord and sign in again.
- Records inside a server. Warnings, bans, notes and appeals belong to the server that made them. Ask that server's staff. If they do not answer, email us and we will pass your request to the server's owner.
Deleting your account erases your verification signals and any staff PIN you set, in every server. Where you had a PIN, a "reset required" marker with no secret in it stays, so deleting an account cannot be used to get round the PIN. The server owner clears it. Deleting your account also withdraws a server recovery you started that has not taken effect. It does not delete other records about you inside other people's servers, and it does not delete past payment records that the law makes us keep.
Complaints. In the UK, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. In the EU, you can complain to the data protection authority in the country where you live. We would like the chance to put things right first, so please email us.
Automated decisions
Inside a server, Bastion acts automatically. Automod, the join gate, anti-raid and anti-nuke can delete a message, time a member out, quarantine, kick or ban them without a person pressing a button. They work from what a member does in that server: how fast they post, what links they send, how new their account is, and the rules the server's staff chose.
These are the server's decisions, made with the server's settings. We do not decide who is punished. If Bastion acted against you and you think it was wrong:
- Ask the server's staff to look at it. A person there can undo any action.
- If the server has appeals switched on, use its appeal page. Bastion includes the link when it tells you about a ban or a timeout. A person on the server's staff decides every appeal.
The web verification page can also lead to an automatic decision, based on a match with another account or on a VPN. See verification signals.
We make no automated decisions about you for our own purposes.
Children
Discord requires its users to be at least 13, or older in some countries. Bastion is for people who are old enough to use Discord where they live. We do not knowingly collect data from anyone younger. If you believe a child below that age has an account with us, email support@bastionbot.xyz and we will delete it.
Changes to this policy
When we change this policy we update the date at the top and describe what changed on this page. We will not use data we already hold for a new purpose without telling you first.
Contact
Privacy questions and requests go to support@bastionbot.xyz, or by post to Xyliase Technologies LTD, trading as BASTION, Unit 29 Eliburn Industrial Park, Livingston, Scotland, EH54 6GQ.
See also the cookie policy, the data processing agreement and the terms of service.