Draft: placeholder legal text, pending review. Not legal advice.

Privacy Policy

Last updated: June 30, 2026

Staffd is an AI employee that works inside your Discord server. This policy explains what we process, what we keep, why, and the control you have over it. The short version: we hold a record of moderation history so the service can do its job. We do not build a profile of your members, and we never train AI on your content.

Who we are

Staffd (“we,” “us”) provides an AI moderation employee for Discord communities. We operate the service from the United States. For any question or request about this policy or your data, contact us at support@staffd.gg.

How Staffd is split

Staffd has two sides, and they handle different data. The bot lives in Discord and does the moderation work. The account (this website) is where an owner signs in, manages connected servers, and pays. The sections below cover each.

What the bot reads and stores in Discord

  • Messages, read in the moment. To moderate, Staffd reads messages as they are posted and sends their content to our AI provider for a judgment. The large majority are evaluated and immediately discarded. We do not keep a copy of your server's conversations.
  • Flagged incidents.When something is flagged, we store an evidence snapshot tied to that incident: the flagged message, the author's Discord identifier, and a small amount of surrounding conversation for context. We snapshot it because the original on Discord can be edited or deleted.
  • Moderation actions. When your team acts on a flag (a warning, deletion, timeout, removal, or dismissal), we store that action and who took it, as an immutable record.
  • Your server's understanding. We store the distilled rules, lore, norms, and vibe read that Staffd learns about your server, along with basic server identifiers and the name you give your employee.
  • Member identifiers. Where a person is part of an incident or an action, we store their Discord ID so enforcement stays fair over time (knowing who has already been warned). This is moderation history, not a profile.

What the account and website handle

  • Sign-in. Signing in uses Discord (OAuth). Discord tells us your user ID and the list of servers you belong to, which we use to show the ones you administer where Staffd is installed. We store your Discord user ID as your account key. We do not collect or store passwords, and we do not request your email through sign-in.
  • Display. Your Discord username and avatar are shown in the dashboard from your Discord profile.
  • Billing. When you subscribe, payments are handled by Stripe. Stripe holds your payment details and billing email. We store your subscription status per server so the service knows what is active. We never see or store full card numbers.
  • Session. We keep you signed in with a single secure, httpOnly session cookie. We do not use advertising or cross-site tracking cookies.

How we use data

We use the data above to:

  • moderate your server and surface flags to your team;
  • keep enforcement consistent over time (the memory that makes fair escalation possible);
  • answer members when they summon Staffd, and help owners run their server;
  • provide and manage accounts and billing;
  • operate, secure, debug, and improve the service.

We do not sell or rent your data, and we do not use it for advertising.

Legal bases (EEA and UK)

Where the GDPR or UK GDPR applies, we process data on these bases:

  • Contract: to provide the service and handle billing.
  • Legitimate interests: to moderate effectively, keep enforcement fair, and keep the service secure, balanced against your rights.
  • Legal obligations: where the law requires us to retain or disclose data.
  • Consent: where we ask for it specifically.

Inference yes, training no

We use AI inference to read context and propose moderation judgments. We do not train AI models on your content, and neither do our providers. Your community's conversations are never used as training data. Message content is sent to our AI provider only to reach a judgment in the moment.

Moderation history, not user profiling

Everything we keep is oriented around moderation events: what was flagged, what was decided, what was agreed. The purpose is enforcement continuity, not tracking people. We do not build advertising or behavioral profiles, and we do not infer or record sensitive characteristics about your members.

Service providers

We rely on a small set of trusted providers to run Staffd. Each may process data only to provide its service to us, and is bound to protect it:

  • Discord: the platform Staffd operates on, and the source of the data it acts on.
  • Anthropic: AI inference for moderation judgments. Content sent for inference is not used to train models.
  • Google Cloud: hosting and our database. Data is stored in the United States.
  • Stripe: billing and subscription payments.

We do not sell or broker your data to anyone.

Where your data is processed

Staffd is operated and hosted in the United States. If you use Staffd from outside the United States, including from the EEA or UK, your data will be processed in the United States. We rely on appropriate safeguards for such transfers where the law requires them.

Security

We protect your data with encryption in transit and at rest, server-side handling of secrets, and access limited to what is needed to run and support the service. No system is perfectly secure, but we work to keep your data safe and to limit what we hold in the first place.

Data retention

We keep a server's moderation history while Staffd is active in that server, because that history is what lets it moderate fairly over time. You can delete it sooner at any time (see Your rights and choices). When Staffd is removed from a server, we retain that server's data for a 30-day grace period and then permanently delete it. The grace period means an accidental removal does not erase your history, while a deliberate one is honored.

Your rights and choices

You can access, correct, or delete the data we hold about you:

  • Server ownerscan delete an individual server's moderation history, or their entire account and all associated data, from the dashboard.
  • Memberscan request deletion of what we hold about them by emailing support@staffd.gg. Because a member's moderation history lives inside a server the owner controls, we may verify your request or coordinate with the server's owner before acting.

Depending on where you live (for example the EEA, the UK, or California), you may have additional rights, including to access a copy of your data, to port it, to object to or restrict certain processing, and to not be discriminated against for exercising your rights. To make any request, contact support@staffd.gg, and we will respond within the time the law requires.

Children

Staffd is not directed to children. You must meet Discord's minimum age (at least 13, or older where your country requires) to use Discord, and therefore Staffd. We do not knowingly collect data from anyone below that age. If you believe a child has provided us data, contact support@staffd.gg and we will remove it.

Changes to this policy

We may update this policy as the service evolves. When we make material changes, we will update the date above and, where appropriate, provide notice. Continued use of Staffd after changes take effect means you accept the updated policy.

Contact

For any question or request about this policy or your data, reach us at support@staffd.gg.