Privacy Policy
Last updated: 10/3/26
This policy describes what data BILBI processes, why, and for how long. It covers the BILBI Discord bot, its web dashboard and the public website.
Data controller
Sacha Pastor EI, 42 rue Proudhon, 63000 Clermont-Ferrand, France — SIREN 109 069 948, APE 5829C. TVA non applicable, art. 293 B du CGI decides why and how the data described below is processed.
Data collected
- Discord account : identifier, username, display name, avatar.
- OAuth tokens : kept encrypted, to maintain your session.
- Server configuration : the module settings you define.
- Audit log : actions taken in the dashboard, kept for 90 days.
- Billing : Stripe identifiers (customer and subscription). No bank details.
- Custom bot : token encrypted with AES-256-GCM, if you supply one.
- Member data : what the modules a server enables record about its members, by Discord identifier: levels and balances, birthdays (day and month only), suggestions, application and ticket answers, moderation cases and notes, invitations and votes. Kept for that server, under its retention.
Purposes
This data serves only to provide the service: signing you in, applying your configuration on Discord, managing the subscription and offering support. No data is resold or used for advertising.
Legal bases
Every processing operation rests on a stated legal basis. Performance of the contract covers authentication, applying your configuration and managing the subscription. Legitimate interest covers the audit log and the security of the service, strictly to the extent needed to keep it working. Legal obligation covers the retention of accounting records tied to payments.
Message content
The bot does not keep the content of your server's messages. Ticket transcripts are generated on demand, at closing time, then sent to the channel you designated — they are not stored on our side.
One narrow exception: when a member reports a message, the lines around it are copied into the report, so your moderators can still read them after the author deletes it. That excerpt is erased automatically after 30 days — the report itself stays in your registry. A moderation case records what triggered the rule, such as a banned word or the domain of a link, never the message.
TikTok connection
If you link a TikTok account to BILBI, TikTok gives us your account identifier, your display name and the list of the videos you published yourself: title, description, cover image, publication date and link. Your profile picture is not requested. This is used only to announce your new videos in the Discord server you chose. It is never sold, never used for advertising, and never handed to a third party.
The authorisation requested is read-only and limited to the user.info.basic and video.list scopes. BILBI can read only the account that granted it: following someone else’s account is impossible by design. BILBI never posts anything on TikTok on your behalf.
TikTok access tokens are encrypted at rest with AES-256-GCM. You can unlink the account at any time from the dashboard: the link and its tokens are then deleted for good, and the alerts that relied on it stop. You can also revoke the authorisation from the security settings of your TikTok account.
Processors
- Discord — authentication and operation of the bot.
- Stripe — payment processing.
- TikTok — linking creator accounts and reading their own videos.
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Allemagne, +49 9831 505-0 — données hébergées au centre de Helsinki (Finlande) — infrastructure hosting.
Transfers outside the European Union
Two of our processors are established in the United States: Discord, without which the service would not exist, and Stripe for payments. These transfers are framed by the European Commission's standard contractual clauses and, where applicable, by certification under the EU–US Data Privacy Framework. No other data leaves the European Union: the infrastructure is hosted inside the Union.
Retention
Configurations and what the modules record are kept as long as the bot is present on the server, and for 90 days after it is removed — a server that brings the bot back finds everything as it left it. Past that, they are deleted automatically. The audit log is purged after 90 days. Sessions expire after 7 days of inactivity.
Your rights
You have the right to access, correct, erase and port your data. A server administrator deletes their server's data by removing the bot: it is erased 90 days later, or sooner on request. A member can ask for what a server holds about them to be erased, at the address below. Send your request to: [email protected]
Complaint
If a request goes unanswered or the answer does not satisfy you, you may lodge a complaint with the supervisory authority of the country you live in. In France that is the CNIL (cnil.fr). We would obviously rather settle it directly, and we answer within 30 days.
Cookies
A single cookie is set (bilbi.sid), strictly necessary to keep you signed in. No analytics or advertising cookie is used.