1. Overview
This Privacy Policy explains how Stratus ("we", "us") collects, uses, and shares information when you use the Stratus Discord bot and the Stratus web dashboard (together, the "Service"). By using the Service, you agree to the practices described here.
2. Information we collect
Discord account information. When you log into the dashboard, we use Discord OAuth. We receive basic profile information Discord provides, such as your user ID, username, display name, and avatar. We use this to identify your session and show servers you can manage.
Server configuration. When you change settings in the dashboard, we store configuration for Discord servers you manage, such as command prefix, bot personality, embed styling, anti-raid and anti-scam options, module toggles, and log channel preferences.
Discord server data via the bot. When Stratus is in a server, it processes Discord events needed for its features—for example messages (including for AI commands and message logs), member joins and leaves, moderation actions, and channel or role changes when logging is enabled. What is processed depends on how server staff configure the bot.
Session data. The dashboard stores a signed session identifier in your browser so you stay signed in. Discord OAuth access tokens are kept on our servers and are not embedded in that browser token. Sessions expire after a limited period.
Technical data. Hosting providers may automatically collect standard logs (such as IP address, request time, and user agent) for security and reliability.
3. How we use information
- Authenticate you and provide the dashboard
- Save and apply server settings to the bot
- Operate moderation, protection, logging, and AI features you enable
- Maintain, secure, and improve the Service
- Comply with law and enforce our Terms of Service
4. How we share information
We do not sell your personal information. We share data only as needed to run the Service:
- Discord — the bot and dashboard interact with Discord's API according to your actions and server configuration.
- AI providers — if AI commands are used, message content needed to generate a reply may be sent to our configured AI provider (for example, Mistral). Do not submit sensitive personal data in AI prompts.
- Infrastructure providers — the Service is hosted on third-party platforms (such as Vercel for the website and Railway for the API and bot). They process data on our behalf to deliver the Service.
- Legal requirements — we may disclose information if required by law or to protect rights, safety, and security.
5. Data retention
Server configuration is kept while the bot remains in use or until settings are reset or removed. Dashboard sessions expire automatically. Discord-related logs and bot data retention depend on server configuration and operational needs. We may delete or anonymize data when it is no longer needed.
6. Security
We use reasonable measures to protect stored configuration and sessions, including signed session tokens and access controls on dashboard routes. No method of transmission or storage is completely secure; use the Service at your own risk.
7. Your choices
- Sign out of the dashboard or clear site data in your browser to remove the local session token
- Remove Stratus from a server to stop bot-side processing for that server
- Adjust or disable logging, AI, and other modules in the dashboard
- Contact us to request information about data we hold about you, where applicable by law
8. Children
The Service is not directed at children under 13. Discord requires users to meet its minimum age requirements. If you believe a child has provided personal information through the Service, contact us so we can take appropriate steps.
9. International users
The Service may be operated from and processed on servers in various locations. By using the Service, you understand that information may be transferred to and processed in jurisdictions that may have different data protection laws than your own.
10. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top will reflect changes. Continued use after an update means you accept the revised policy.
11. Contact
For privacy questions or requests, contact the Stratus project maintainers through the Discord channels or support paths associated with the bot.