Legal
Privacy Notice.
Effective date: 16 June 2026
This Privacy Notice explains how Sidelight processes personal data when the Sidelight Discord bot is used in a Discord server.
Sidelight is a UK-based organisation that provides custom Discord bot tools for community management, moderation, engagement features, staff workflows, and related server operations.
Sidelight is not Discord and is not operated by Discord. Use of Sidelight takes place within Discord and remains subject to Discord’s own terms, policies, privacy information and platform rules.
The official version of this Privacy Notice is published on Sidelight’s website (https://sidelight.dev/). If this notice is copied into a Discord server, document, message or third-party page, the website version should be treated as the current version.
For privacy requests, contact: privacy@sidelight.dev
1. Definitions
In this Privacy Notice:
-
“Sidelight” means the organisation operating and maintaining the Sidelight Discord bot framework.
-
“Bot” means the Sidelight Discord bot and any Sidelight bot deployment used in a Discord server.
-
“Client” means the person, organisation, community team, brand, artist team, agency, server owner or authorised representative that asks Sidelight to provide or configure the Bot for a Discord server.
-
“Server” means a Discord server in which the Bot is installed or used.
-
“Server owner” means the person or organisation responsible for the Discord server in which the Bot is used.
-
“Server staff” means moderators, administrators, managers or other authorised people with staff permissions in the relevant Discord server.
-
“User” means a Discord user who interacts with the Bot, is present in a server where the Bot is used, or is included in data processed by an enabled Bot feature.
-
“Deployment” means a configured instance or profile of the Bot used for a particular Discord server or client.
-
“Feature” means a specific Bot function, such as moderation, levelling, giveaways, scheduled messages, direct message forwarding, music games or external feed posting.
-
“Personal data” means information relating to an identified or identifiable person.
2. Scope of this notice
This notice applies to the Sidelight Discord bot and its related bot features.
This notice applies to Sidelight-operated Discord bot deployments. Individual deployments may use different Discord application IDs, names or bot profiles depending on the client and server configuration.
Sidelight deployments are configured per Discord server. Not every feature described in this notice is enabled in every server. The personal data processed depends on the features enabled by the relevant client or server owner.
This notice is Sidelight-wide. It is not a separate privacy notice for each individual Discord server.
The client or server owner decides which Sidelight features are enabled in their Discord server. Server owners and authorised administrators are responsible for telling their members which features are active in their server, including any features that involve moderation logging, direct message forwarding, giveaways, levelling, games, scheduled messages or external feed tools.
3. Sidelight, Discord and server-owner responsibilities
Sidelight is responsible for the operation, security and maintenance of the Sidelight bot framework and the Sidelight-controlled systems used to run it.
The relevant client or server owner is responsible for deciding how Sidelight is used in their server, which features are enabled, which staff roles have access to bot commands, what server rules apply, and how members are informed about the use of the Bot.
Discord is responsible for its own platform, account systems, message hosting, platform logs, user settings, account security, Discord-side retention and any other processing carried out by Discord independently of Sidelight.
Discord separately controls personal data processed through Discord’s own platform, including Discord account data, platform logs, message hosting, user settings, device information, account security and Discord-side retention. Users should review Discord’s own privacy information for details about Discord’s processing.
Depending on the deployment and feature, Sidelight may act as a service provider or processor for the client, and may also make limited operational decisions about security, maintenance, abuse prevention and technical operation.
Server staff access to Bot data depends on the server’s Discord permissions, role configuration, channel access and enabled Sidelight features.
4. How Sidelight collects data
Sidelight collects or receives personal data through Discord and through enabled Bot features.
Sidelight may collect data when a User sends a command, clicks a button, uses a menu, reacts to a message, enters a giveaway, submits a game answer, submits a track URL, sends a direct message to the Bot, is moderated by server staff, receives XP, appears in a leaderboard, or is included in an audit record.
Sidelight may also receive data from server staff when they configure features, create scheduled messages, submit moderation reasons, create embeds, set welcome wording, configure giveaways or set server-specific Bot content.
Where external feed or scraper features are enabled, Sidelight may collect public event, artist, source URL, image, post state or deduplication data from public websites or public APIs.
Where third-party integrations are enabled, Sidelight may send or receive limited data needed to provide the relevant feature, such as track-link lookup data from Songlink/Odesli or webhook delivery data for configured server features.
5. Personal data Sidelight may process
Sidelight may process the following categories of personal data, depending on the enabled features.
5.1 Discord account and identity data
Sidelight may process Discord user IDs, usernames, display names, avatar references, guild IDs, role IDs, channel IDs, thread IDs, message IDs and related Discord identifiers.
This data is used to identify users, apply permissions, record actions, run server features, prevent duplicate entries, manage role-based access and keep Bot functions working correctly.
5.2 Command and interaction data
Sidelight may process slash command inputs, button interactions, select menu interactions, reaction interactions, command timestamps, staff command usage, channel references and related metadata.
This data is used to provide Bot features, carry out requested actions, maintain audit records, troubleshoot errors and prevent abuse.
5.3 Message data
Sidelight may process message content where a feature requires it.
For levelling and XP, Sidelight does not persist raw message content. The levelling feature stores XP metadata only, including guild ID, user ID, XP, level and last message timestamp. Message content may be checked transiently at runtime to confirm that a message meets minimum length requirements before XP is awarded. The feature may also use attachment counts, mention counts and whether a message was sent in a thread.
For sticky messages, custom messages, scheduled messages, music games, giveaway messages and similar features, Sidelight may process the message content needed to create, store, send, update or manage the relevant feature.
Sidelight does not store deleted or edited message history as a general feature.
5.4 Direct messages sent to the Bot
If direct message forwarding is enabled for a server, direct messages sent to the Bot may be forwarded to authorised server staff through Discord.
A direct message sent to the Bot is not necessarily a private message to Sidelight only. Where direct message forwarding is enabled, the content may be visible to authorised server staff.
Sidelight does not store the full direct message content locally as part of that forwarding process. Direct message content is forwarded through Discord so that authorised staff can review and respond where appropriate.
Direct message attachments are not stored locally by Sidelight for the DM forwarding feature. They may be forwarded through Discord as part of the message handling flow.
Users should not send confidential, sensitive or private information to the Bot unless they are comfortable with authorised server staff reviewing it.
5.5 Moderation data
Sidelight may process moderation data where moderation features are enabled.
This may include the action type, target user ID, target username where stored by the relevant feature, moderator ID, moderator name where stored by the relevant feature, guild ID, timestamps, reason text, duration, expiry time, audit context and related moderation metadata.
Moderation actions may include timeouts, removal of timeouts, kicks, bans, permanent bans and temporary bans.
Temporary ban records may include guild ID, user ID, username, creation time, moderator ID, moderator name, scheduled unban time and reason text.
Moderation data is used for server safety, staff accountability, abuse prevention, audit records, appeal handling and enforcement of server rules.
5.6 Giveaway data
Where giveaway features are enabled, Sidelight may process giveaway entries, entrant Discord user IDs, guild IDs, giveaway IDs, entry counts, entry timestamps, winner user IDs, reroll records, host details, manager role settings, prize descriptions, message IDs, channel IDs, giveaway timing and persistent giveaway state.
Entrants are primarily stored by Discord user ID. Usernames or display names may be resolved from Discord at runtime when displaying or announcing results.
Giveaway data is used to operate giveaways, prevent duplicate entries, select winners, manage rerolls, resolve disputes and maintain the integrity of the giveaway process.
5.7 Levelling, XP and leaderboard data
Where levelling features are enabled, Sidelight may store guild ID, user ID, XP, level and last message timestamp.
Sidelight does not store raw message content for levelling.
Levelling and leaderboard data is used to operate XP systems, show rankings, calculate levels and support community engagement features.
5.8 Music game and activity data
Where music-related games or custom activity features are enabled, Sidelight may process submitted answers, selected answer indexes, correctness results, answer timestamps, dates, user IDs, usernames, track URLs, message IDs, thread IDs, round IDs, guild IDs and related game state.
For example, a lyric game may store a User’s selected answer and whether it was correct. A track submission game may store a submitted URL, user ID, message ID and submission time.
This data is used to operate the game, calculate results, prevent duplicate submissions, display outcomes and maintain leaderboards or round history where enabled.
5.9 Scheduled message data
Where scheduled message features are enabled, Sidelight may process scheduled send times, message text, embed content, attachment references, guild IDs, channel IDs, author IDs, job IDs, execution state, attempts, error records and cancellation records.
Uploaded scheduled-message attachments may be stored temporarily until the message is sent, cancelled or permanently failed. Once the scheduled job is completed, cancelled or failed, the job record and related attachment files are removed as part of the scheduler lifecycle.
5.10 External feed and scraper data
Where external feed or scraper features are enabled, Sidelight may process public event data, artist data, source URLs, deduplication records, event details, images, post state, webhook delivery state and related metadata.
Sidelight’s scraper-style features are intended to use public-facing websites or public APIs. Sidelight does not intentionally scrape private user accounts, authenticated dashboards, member-only areas or private pages.
5.11 Custom bot-profile content
Sidelight may store or process custom content provided by the client or server staff. This may include welcome wording, embed text, brand colours, status lines, channel mentions, role mentions, prompts, guidance text, server-specific labels and feature configuration.
This data is used to customise the Bot for the relevant server and provide the enabled features.
5.12 Technical, security and audit data
Sidelight may process technical and security data including uptime events, status events, runtime errors, local audit logs, command results, permission checks, role hierarchy checks, security events, configuration status and operational metadata.
This data is used to maintain the Bot, diagnose problems, protect the service, prevent misuse, confirm actions and support operational security.
5.13 Sensitive information
Sidelight does not intentionally ask Users to provide sensitive personal information through the Bot.
Users and server staff may still choose to include sensitive information in direct messages, moderation reasons, attachments, command inputs, scheduled messages, game submissions or other Discord content processed by enabled features.
Users should not send sensitive information to the Bot unless it is necessary and they understand that, depending on the enabled feature, authorised server staff may be able to review it.
Sidelight is not intended to be used for the routine collection or processing of special category data. If sensitive information is included in content processed by an enabled feature, Sidelight handles it only as part of the relevant feature, request, moderation, safety or support context.
6. Why Sidelight processes personal data
Sidelight processes personal data for the following purposes:
-
To provide enabled Discord bot features.
-
To operate moderation, safety and staff workflow tools.
-
To run giveaways, games, leaderboards, scheduled messages, sticky messages, direct message forwarding and other community features.
-
To identify users, staff, roles, channels, messages and servers accurately within Discord.
-
To apply permissions and prevent unauthorised command use.
-
To maintain audit records and accountability for staff actions.
-
To prevent abuse, spam, manipulation, unauthorised access and misuse.
-
To troubleshoot errors and keep the Bot operational.
-
To support clients and server administrators.
-
To handle privacy requests and related correspondence.
-
To comply with applicable legal, regulatory, security and platform obligations.
-
To maintain the integrity and security of Sidelight deployments.
7. Lawful basis for processing
Sidelight primarily relies on legitimate interests for processing personal data needed to operate the Bot, provide requested server features, support moderation, maintain audit records, prevent abuse, secure the service and assist server administrators.
These legitimate interests include operating community management tools, maintaining server safety, supporting staff workflows, preventing misuse, preserving giveaway and game integrity, securing the Bot and providing the service requested by clients.
Where Sidelight provides services to a client, some processing may also be necessary for contractual purposes between Sidelight and the client.
Where Sidelight is legally required to keep, disclose or process data, the lawful basis may be compliance with a legal obligation.
Sidelight does not rely on consent for core operational logging or basic Bot functionality unless a specific feature expressly states that it is consent-based.
| Purpose | Examples of data used | Lawful basis |
|---|---|---|
| Providing enabled Bot features | Discord IDs, role IDs, channel IDs, command inputs, interaction data and feature configuration | Legitimate interests. Contract may apply where the data relates to the client, server owner or authorised server staff acting under a Sidelight client relationship. |
| Moderation and audit logging | Moderator IDs, target user IDs, action type, timestamps, reason text and audit context | Legitimate interests |
| Server safety and abuse prevention | Command usage, permission checks, role hierarchy checks, audit records and security events | Legitimate interests |
| Giveaways and community activities | Entrant IDs, entry timestamps, winner records, game answers, track URLs and round state | Legitimate interests. Contract may apply where the data relates to the client, server owner or authorised server staff acting under a Sidelight client relationship. |
| Scheduled messages and staff workflows | Message payloads, attachments, execution times, job IDs and author IDs | Legitimate interests. Contract may apply where the data relates to the client, server owner or authorised server staff acting under a Sidelight client relationship. |
| Direct message forwarding | Direct messages and attachments sent to the Bot, where forwarding is enabled | Legitimate interests |
| External feed and scraper features | Public event data, source URLs, images, deduplication records and webhook state | Legitimate interests. Contract may apply where the data relates to the client, server owner or authorised server staff acting under a Sidelight client relationship. |
| Security, troubleshooting and maintenance | Runtime errors, uptime events, operational metadata, audit logs and configuration state | Legitimate interests |
| Privacy requests and support | Discord user ID, server details, request content, correspondence and verification information | Legitimate interests and legal obligation where applicable |
| Legal or regulatory compliance | Records required to respond to lawful requests, disputes or legal obligations | Legal obligation, or legitimate interests where no direct legal obligation applies |
8. Data minimisation
Sidelight aims to process only the data needed for the enabled features.
For levelling, Sidelight stores XP metadata and timestamps, not raw message content.
For giveaway entries, Sidelight primarily stores Discord user IDs and entry metadata.
For direct message forwarding, Sidelight forwards direct messages through Discord and does not locally store the full DM content or DM attachments as part of that feature.
For scheduled messages, Sidelight stores message payloads and uploaded attachments only for the scheduled job lifecycle.
For moderation, Sidelight stores the data needed for audit, safety, staff accountability and appeal handling.
Sidelight does not sell personal data and does not use Discord message content for advertising profiling.
Sidelight does not use Bot data to train AI or LLM models.
Sidelight uses Discord API data only as needed to provide the Bot’s stated and enabled functionality. Sidelight does not mine or scrape Discord services, does not use Discord API data to profile Users outside the Bot’s stated functionality, and does not disclose Discord API data to advertising networks, data brokers or advertising-related services.
9. How long data is kept
Sidelight keeps personal data only for as long as it is needed for the relevant feature, server administration, moderation, audit, security, dispute handling, legal compliance, backup recovery or operational maintenance.
Because Sidelight is used across different servers and feature configurations, retention periods may vary by feature and deployment.
| Data category | Retention approach |
|---|---|
| Levelling, XP and leaderboard data | Retained until reset by server administrators, removed by Sidelight following a valid deletion request, or no longer needed for the relevant server. |
| Giveaway data | Retained while needed to operate the giveaway, handle winner selection, support rerolls, resolve disputes and maintain giveaway integrity. |
| Moderation and audit data | Retained while needed for server safety, abuse prevention, staff accountability, appeals, dispute handling, audit records or legal reasons. |
| Scheduled message data | Retained until the scheduled item is sent, cancelled or permanently failed. |
| Scheduled-message attachments | Retained only for the scheduled job lifecycle and removed when the job is sent, cancelled or permanently failed. |
| Direct messages forwarded to staff | Not locally stored by Sidelight as part of the direct message forwarding feature. |
| External feed and scraper records | Retained while needed to avoid duplicate posting, manage feed state, troubleshoot errors and operate the relevant feature. |
| Technical and security records | Retained while needed for troubleshooting, security, abuse prevention and operational maintenance. |
| Privacy request records | Retained while needed to handle the request, verify the outcome, maintain appropriate records and comply with legal or regulatory obligations. |
| Client configuration and custom bot-profile content | Retained while the deployment remains active, or until removed during offboarding or following a valid deletion request. |
| Backups | Retained for a limited period depending on hosting and deployment configuration, then overwritten or deleted as part of the backup cycle. |
If a User leaves a Discord server, Sidelight does not automatically delete all data associated with that User. Some data may be retained so that server features continue to work if the User returns, or so that moderation, audit, giveaway or safety records remain intact.
If a client stops using Sidelight, Sidelight will handle the client’s server data as part of offboarding. Where requested, Sidelight may provide the client with relevant exportable data. The client must give written instructions for deletion or transfer. Data will then be deleted or returned according to the agreed offboarding process, subject to any legal, security, backup or dispute-related requirements.
10. Backups
Sidelight deployments may use hosting-level or operational backups.
Backups are used for recovery, continuity and protection against accidental loss or technical failure. Backup retention is limited and depends on the hosting and deployment configuration.
Where personal data is deleted from active systems, it may remain in backups for a limited period until those backups expire or are overwritten. Sidelight does not use backup copies for normal operational access unless recovery is required.
11. Security
Sidelight uses technical and organisational measures to protect personal data.
Sidelight SQLite databases are encrypted using SQLCipher for all deployments.
Secrets such as bot tokens, webhook URLs, database keys, API credentials and environment variables are treated as confidential operational secrets and are not intended to be exposed publicly.
Permanent Bot storage is held in encrypted databases. Temporary files used for scheduled message attachments may exist outside the database only for the scheduled job lifecycle and are removed when the job is sent, cancelled or permanently failed.
Sidelight uses role-based and permission-based controls around staff and moderation commands. Server owners and administrators are responsible for assigning Discord roles and permissions carefully and for ensuring that only trusted staff have access to sensitive commands.
Sidelight also uses audit logging, permission checks, role hierarchy checks and feature configuration controls to reduce misuse.
No method of transmission or storage is completely secure. Sidelight works to protect data, but cannot guarantee absolute security.
12. Hosting and international processing
Sidelight is operated from the United Kingdom.
Sidelight is intended to use UK or European hosting locations for Bot deployments where available and selected.
Some third-party services involved in providing the Bot, including Discord and external APIs, may process data outside the UK or European Economic Area.
Where Sidelight transfers personal data internationally and transfer safeguards are required, Sidelight uses appropriate safeguards, such as adequacy arrangements, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or equivalent safeguards provided by the relevant third-party service.
Sidelight may process data relating to Users located worldwide because Discord servers may include members from different countries.
This notice is written from a UK privacy-law perspective and is intended to provide practical transparency to Discord users worldwide.
Users can request more information about the safeguards used for international transfers by contacting Sidelight at:
13. Third-party services
Sidelight may use third-party services to provide Bot functionality.
These may include:
-
Discord and the Discord API.
-
Hosting providers used to run the Bot.
-
Songlink/Odesli for track and music-link lookups.
-
Webhook services used for configured server features.
-
Public websites or public APIs used by enabled scraper or feed features.
-
Backup and infrastructure services used for operational recovery.
Sidelight uses third-party service providers to host, operate, secure, back up and support the Bot. These providers may process personal data only where needed to provide their services to Sidelight or the relevant deployment.
Sidelight does not currently use third-party analytics, error tracking, crash reporting or monitoring services such as Sentry, Rollbar, Datadog, New Relic or similar external telemetry platforms.
Sidelight does not currently use AI services or large language model APIs as part of the Bot.
Sidelight does not use Bot data to train AI models.
A current list of third-party service categories can be requested by contacting Sidelight at:
Third-party services have their own terms and privacy practices. Discord Users should also review Discord’s own privacy information and platform terms.
14. Disclosure of data
Sidelight may disclose or make data available to the following categories of recipient where necessary:
-
Authorised server staff, where features such as moderation logs, direct message forwarding, giveaway management, scheduled messages or audit tools are enabled.
-
The relevant client or server owner, where data relates to their Discord server and enabled Bot features.
-
Sidelight maintainers, where needed for maintenance, support, troubleshooting, security, deletion requests or operational administration.
-
Hosting and infrastructure providers, where needed to run, store, back up or secure the Bot.
-
Discord, because the Bot operates through Discord and uses Discord’s APIs and platform.
-
External API or feed providers, where an enabled feature requires a lookup, webhook call or public data retrieval.
-
Legal, regulatory or law enforcement bodies, where Sidelight is legally required to disclose data or where disclosure is necessary to protect rights, safety or security.
Sidelight does not sell personal data.
15. Automated decision-making
Sidelight does not use personal data for automated decision-making that produces legal or similarly significant effects on Users.
Some Bot features may automatically carry out configured server actions, such as awarding XP, recording giveaway entries, selecting giveaway winners, applying scheduled actions or enforcing staff-configured moderation workflows. These features operate according to server configuration and Bot logic, not profiling for legal or similarly significant automated decisions.
16. Children and younger Users
Sidelight operates within Discord and relies on Discord’s platform rules, including Discord’s age and account requirements.
Sidelight is not directed at people under 13 or under the minimum age of digital consent in their country.
Sidelight is not designed to knowingly collect personal data from children outside the normal operation of Discord server features.
Server owners are responsible for ensuring that their server is operated appropriately for its audience and complies with Discord’s rules and applicable laws.
17. Your rights
Depending on your location and the applicable law, you may have rights in relation to your personal data. These may include the right to request access, correction, deletion, restriction, objection, portability, or information about how your data is processed.
To make a request, contact:
Where a specific feature relies on consent, Users may withdraw that consent at any time by contacting Sidelight or by following any feature-specific opt-out process made available in the relevant server.
Sidelight will normally respond to valid privacy requests within one month. This may take longer where a request is complex, where verification is required, or where the request involves information held across multiple deployments or backups.
Where a request relates to data controlled or configured by a client or server owner, Sidelight may need to consult the relevant client or server owner before completing the request.
Some data may not be deleted immediately or in full where it is still needed for moderation, safety, audit, legal compliance, dispute handling, security, backup integrity or the legitimate administration of a Discord server.
Moderation records may be retained where needed for server safety, abuse prevention, appeals, audit records or legal reasons.
Privacy requests are handled manually by the Sidelight team.
Sidelight does not normally charge a fee for privacy requests. A reasonable fee may be charged, or a request may be refused, where the law allows this, including where a request is manifestly unfounded or excessive.
18. Information needed for privacy requests
To help Sidelight identify the relevant data, privacy requests should include:
-
The Discord user ID connected to the request.
-
The Discord server/guild involved, if known.
-
The feature involved, if known.
-
The type of request being made, such as access, correction or deletion.
-
Any additional information needed to verify the request and locate the relevant records.
Sidelight may need to verify the requester’s identity or confirm their connection to the relevant Discord account before acting on a request.
19. If data is not provided
Some Sidelight features cannot work without the data needed for that feature. For example, giveaways require entrant IDs, moderation tools require target user and moderator details, levelling requires user IDs and XP metadata, and scheduled messages require the scheduled message payload. If the necessary data is not available, the relevant feature may not work correctly or may not be available.
20. Change of purpose
Sidelight will only use personal data for the purposes described in this notice, unless Sidelight reasonably considers that another purpose is compatible with the original purpose or is otherwise permitted by law. If Sidelight needs to use personal data for an unrelated new purpose, this notice will be updated or Users will be given appropriate information where required.
21. Complaints
If you are unhappy with how Sidelight handles your personal data, you can contact Sidelight at:
As Sidelight is based in the UK, you may also have the right to complain to the UK Information Commissioner’s Office.
22. Changes to this notice
Sidelight may update this Privacy Notice from time to time to reflect changes to the Bot, enabled features, legal requirements, Discord platform requirements, security practices or operational arrangements.
The updated version will be published with a new effective date.
23. Contact
For privacy questions, data access requests, deletion requests or other personal data enquiries, contact: