Introduction
Vetox ("we," "us," or "our"), operating from the Kingdom of Bahrain, provides a Discord bot service and associated web dashboard (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By using the Service, you consent to the data practices described in this policy.
Information We Collect
We collect information in several categories:
Discord Data
When you add Vetox to your Discord server or interact with the bot, we collect:
- Discord user ID, username, and avatar
- Server (guild) ID, name, and member count
- Server configuration settings and preferences you set through the dashboard or bot commands
- Message content is received by the bot to power moderation features (auto-moderation, spam detection) and logging when enabled by server administrators. Message content is processed in real-time and is not permanently stored in our databases
- Voice channel activity data (join/leave timestamps) for XP and statistics features when enabled
- A list of Discord servers you are a member of (server ID, name, and icon) when you log in to the dashboard, used to display and manage servers where you have permissions
- Encrypted authentication tokens from Discord to maintain your dashboard session and access your server list. These tokens are stored using encryption and are never shared with third parties
Usage Data
We automatically collect certain information when you use the Service:
- Bot command usage and interaction data
- Dashboard page views, feature usage, and session duration
- Browser type, operating system, and device information when accessing the dashboard
- IP addresses for security, rate limiting, and fraud prevention
- Login session records including IP address, approximate location (city, country), browser, operating system, and device type for account security and session management
Payment Data
When you purchase premium services, all payment processing is handled entirely by Paddle (our payment processor). We do not store any payment data, including credit card numbers, bank account details, or billing addresses. Paddle processes and secures all payment information directly. We only receive subscription status confirmations (active, cancelled, expired) to manage your premium access.
Cookies & Similar Technologies
We use the following types of cookies:
Essential Cookies
Session cookies to maintain your authentication state on the dashboard. These are required for the Service to function and cannot be disabled.
Analytics Cookies
We use analytics cookies to understand how visitors interact with our website, helping us improve performance and user experience.
How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service including bot features, dashboard functionality, and premium services
- Process premium subscriptions and manage billing through Paddle
- Analyze usage patterns to improve our services, fix bugs, and develop new features
- Provide customer support and respond to inquiries via our Discord support server
- Detect, prevent, and address fraud, abuse, and security issues
- Ensure compliance with Discord's Terms of Service and applicable laws
- Send service-related notifications such as subscription updates and important changes
Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA) and United Kingdom, we process personal data under the following legal bases as defined in Article 6 of the GDPR:
- Consent — Where you have given clear consent for us to process your personal data for a specific purpose, such as enabling optional features like message logging
- Contract — Processing necessary for the performance of our Service agreement with you, including providing bot functionality and premium features
- Legitimate Interests — Processing necessary for our legitimate interests, such as improving the Service, ensuring security, and preventing fraud, where these interests are not overridden by your rights
- Legal Obligation — Processing necessary to comply with a legal obligation, such as responding to valid legal requests or maintaining required records
Information Sharing & Third Parties
We do not sell, trade, or rent your personal information. We may share information only in the following circumstances:
- Paddle — Our payment processor handles all payment transactions. Their processing of your data is governed by Paddle's Privacy Policy
- Subscription & Usage Analytics — We use privacy-focused analytics services to measure aggregate website usage and subscription metrics so we can improve the Service. These providers process only limited technical and subscription-related data on our behalf and never receive your message content or Discord data
- Hosting Providers — Our infrastructure providers host the servers that run the Service. They process data on our behalf under strict data processing agreements
- Cloudflare — We use Cloudflare for DNS, content delivery (CDN), and network security to keep the Service fast and protected. As traffic passes through Cloudflare's network it processes connection data such as IP addresses and provides privacy-first, cookieless performance analytics. Your use of these services is governed by Cloudflare's Privacy Policy
- Content Protection — We use a third-party content-protection and DMCA verification service to detect and deter unauthorized copying of our website content. It loads a verification script that may receive your IP address and browser information; it does not track you across other websites and never receives your Discord data
- Discord API — We interact with Discord's API to provide bot functionality. Your use of Discord is governed by Discord's Privacy Policy
- AI Processing — When a server administrator enables our optional AI-powered features (such as AI auto-moderation or the AI assistant), the relevant message content and images are processed by a third-party AI provider solely to deliver that feature. This data is processed in real-time and is NOT used to train any AI models, is NOT retained or stored by the provider after processing, and is never sold or used for any other purpose. These features are off by default and are controlled by the server's administrators
- Legal Requirements — We may disclose information if required by law, court order, or governmental regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others
- With Your Consent — We may share information with third parties when you explicitly authorize us to do so
International Data Transfers
Vetox operates from the Kingdom of Bahrain, and our infrastructure may be located in various countries. Where personal data of users in the European Economic Area (EEA) or the United Kingdom is transferred to a country that has not received an adequacy decision, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses (or the UK International Data Transfer Addendum) — or another lawful transfer mechanism provided by our processors. By using the Service, you acknowledge that your information may be processed outside your country of residence.
Data Retention
We retain your data based on the type of information and its purpose:
- Server configuration data — Retained while Vetox remains active in your server and deleted upon bot removal
- XP and leveling data — Retained while the server uses the leveling feature, with inactive data expiring based on configured retention periods
- Moderation records — Retained according to the duration set by server administrators and applicable legal requirements
- Usage statistics — Retained for up to 92 days for analytics purposes
- Payment records — Retained as required by tax and financial regulations
- Account data — Retained while you maintain an active account. You may request deletion at any time
Server Backup
Server Backup is an optional feature that lets a server's administrators save a copy of their Discord server and restore it later, including into another server they manage. This section explains what a backup contains, how it is stored, who can access it, and how long it is kept.
What a backup contains
A backup captures the server as it is at that moment. Depending on the options the administrator selects and the server's plan, it can include:
- Server settings (name, description, icon and banner images, verification, notification and similar options), roles with their permissions, and channels with their permission overwrites, public threads and forum posts. Private threads are never included
- Custom emojis and stickers
- The server's ban list (banned user IDs and ban reasons)
- Members' nicknames and role assignments, limited to members who have a nickname or at least one role and to the member limit of the server's plan
- The most recent messages in each channel, up to the number per channel the administrator selects: the author's user ID, username and avatar, the message text, embeds, links to attachments, pins and timestamps. Messages are captured only when the administrator chooses to include them
- The files attached to those messages, when the administrator chooses to store attachments. They are downloaded from Discord's content delivery network at backup time and kept with the backup
- When change tracking is turned on, a log of structural changes to the server (channels, roles, emojis, stickers and settings) together with the Discord user ID and username of the person who made each change, taken from the server's audit log. Change records never contain message content
Encryption and storage
Backups and stored attachment files are encrypted at rest (AES-256-GCM). Each backup has its own encryption key, which is itself protected by master keys held by Vetox. Backups are stored on the infrastructure we operate for the Service and are never uploaded to a third-party storage or backup service. A backup is sealed when it is created and is never edited afterwards.
Who can access backups
Backups belong to the server they were taken from and are managed by that server's administrators:
- Viewing, creating, restoring and deleting backups is available only to the server owner and to members with the Administrator permission, in the dashboard and in the bot's commands alike. Within that group, the server's backup permission settings decide who may create backups and who may restore or delete them
- Restoring a backup replaces the server's channels and roles, so by default only the server owner can do it; the owner can extend this to administrators in the server's backup settings. We take a safety copy of the server's structure before every restore
- A backup is tied to the person who created it. Only that person can restore it into another server they manage, and they can see their own backups from their dashboard; deleting one follows the backup permission settings of the server it was taken from
Retention and deletion
Backups are the server's data. They are kept until they are deleted under one of the following rules:
- Backups created by an administrator do not expire on their own. They are kept until they are deleted, one at a time or all at once, which by default only the server owner can do; the owner can extend this to administrators in the server's backup settings
- Automatic backups are rotated: when a new one is created, the oldest backups beyond the number the server's plan keeps are deleted
- Safety copies taken before a restore are deleted automatically after 7 days
- Tracked change records are deleted automatically after the retention period included in the server's plan
- Changing or cancelling a premium plan never deletes backups. Backups above the new plan's limit remain visible but cannot be restored while the limit is exceeded
- When Vetox has been removed from a server for 30 days, all of that server's backups, stored files and change records are deleted
- When we delete a server's Vetox data at its owner's request, its backups, stored files, change records and backup settings are deleted with it
- Deleting a backup removes its snapshot and its stored attachment files immediately
Your data inside other servers' backups
If you ask us to delete your personal data, we remove you as the creator of any backups and as the recorded actor of any tracked changes, so they are no longer linked to your account. Backups are never edited after they are created, so messages you wrote that a server administrator captured in that server's backup remain inside it, in the same way they would remain in a copy of the server's data held by its owner, until that backup is deleted under the rules above. If you want a specific backup removed, contact that server's administrators.
Staff access
Vetox staff do not open the contents of backups. The only exception is a support request from the server owner: with the owner's consent, staff may open that server's backup through the same dashboard views the owner uses, solely to handle that request, and every such access is recorded in our audit log.
Data Security
We implement industry-standard security measures to protect your information, including encrypted connections (HTTPS/TLS), access controls, secure authentication, and regular security reviews. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security. We encourage you to keep your Discord account credentials secure and report any suspected security issues immediately.
Children's Privacy
Our Service is not directed to children under the minimum age required by Discord's Terms of Service. We do not knowingly collect personal information from children below this age. If we discover that we have collected data from a child under the applicable minimum age, we will delete it promptly. If you believe a child has provided us with personal information, please contact us through our Discord support server.
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right of Access — Request a copy of the personal data we hold about you
- Right to Rectification — Request correction of inaccurate or incomplete personal data
- Right to Erasure — Request deletion of your personal data, subject to legal retention requirements
- Right to Restriction — Request that we restrict processing of your personal data in certain circumstances
- Right to Data Portability — Request your personal data in a structured, commonly used, machine-readable format
- Right to Object — Object to processing of your personal data based on legitimate interests
- Right to Withdraw Consent — Withdraw consent at any time where processing is based on consent
- Right to Lodge a Complaint — File a complaint with your local data protection authority if you believe your rights have been violated
To exercise any of these rights, please contact us through our Discord support server at https://discord.gg/vetox. We will respond to your request within 30 days. Upon a verified deletion request, we will remove your personal data from our databases, including your profile, server configurations you own, and login history. Some data may be retained where required by law or for fraud prevention.
Changes & Contact
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated policy on our website and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us through our Discord support server at https://discord.gg/vetox.
The founders/owners of the project are
Yousef Emad Abdel Wahab (Ryo.)
Ali Hasan Mohamed (Ali M.)