Legal

Privacy policy

Last updated: 4 September 2026

1. Scope

This policy explains how Rallybit handles information when you use the Discord bot, dashboard, website, and related community-management features. A Discord server and its authorised staff may make their own decisions about how they use Rallybit, and may need to provide members with additional notices.

2. Information Rallybit processes

Rallybit may process Discord user, server, channel, role, message, invite, and application identifiers; usernames, display names, avatars, server names, and server structure; command inputs and interaction details; bot and dashboard configuration; role, moderation, warning, timeout, ticket, report, review, transcript, shift, level, invite, welcome, giveaway, and activity records; and technical information such as timestamps, errors, latency, security events, and IP-derived request data.

3. Message content

Rallybit processes message content only where a configured feature needs it—for example, command handling, channel transcripts, ticket transcripts, automoderation, reports, custom responses, or AI-assisted naming. A server’s administrators choose which optional features to enable and where they operate.

4. Dashboard authentication

The dashboard uses Discord OAuth to identify you and load servers you are allowed to manage. Rallybit does not receive your Discord password. Discord access and refresh tokens are kept in the protected server-side session and are not placed in browser-readable storage. Session cookies are secure, HTTP-only, and used to keep you signed in.

5. How information is used

Information is used to provide requested bot features; save server settings; enforce permissions; operate moderation, tickets, transcripts, roles, shifts, and activity tools; generate statistics and profiles; prevent abuse; maintain security; diagnose faults; restore interrupted operations; and improve reliability.

6. AI-assisted features

When an authorised administrator uses Prettfy, the design prompt and relevant channel or role naming information may be sent to the configured AI provider, currently OpenRouter, to produce suggestions. Permission overwrites and private credentials are not intentionally included. Administrators should avoid placing personal or confidential information in an AI prompt.

7. Service providers and sharing

Rallybit does not sell personal information. Information may be handled by essential providers that help operate the service, including Discord for bot and OAuth functions, Cloudflare for secure delivery, the hosting provider for application storage and processing, and an AI provider when an AI-assisted feature is deliberately used. Information may also be disclosed where required by law or needed to protect users, the service, or its legal rights.

8. Retention

Configuration and operational records are retained while needed to provide the selected features. Active sessions are retained until logout, expiry, or invalidation. Logs, transcripts, tickets, moderation records, recovery data, and backups may be retained for different periods based on feature settings, operational needs, security, and legal obligations. Data that is no longer needed is deleted or anonymised where practical.

9. Your choices and requests

Server owners can disable features, remove stored configurations through available controls, or remove Rallybit from their server. You can log out of the dashboard and revoke Rallybit through Discord’s authorised-app settings. Requests to access, correct, or delete information associated with you or a server can be made through the official support server. Rallybit may need to verify identity and server authority before acting on a request.

10. Security

Rallybit uses reasonable technical and organisational safeguards, including protected secrets, restricted administrative controls, secure session cookies, permission checks, audit records, and encrypted HTTPS connections. No internet service can guarantee absolute security. Report suspected security issues privately through the official support route and do not publish credentials or exploit details.

11. International processing and children

Infrastructure and service providers may process information in countries other than your own, subject to their safeguards and applicable law. Rallybit is intended for people who meet Discord’s minimum age requirements and is not knowingly directed to younger children.

12. Changes and contact

This policy may be updated as Rallybit’s features or providers change. The updated date above identifies the current version. Material changes will be communicated through the website or official support community where practical. Privacy questions or data requests can be raised through the support server linked on the Rallybit website.