This Privacy Policy explains what data the PikaBot Discord bot, the website at pikabot.win, the licensing system, and the management dashboard (collectively, the "Service") collect, why we collect it, how long we keep it, and how you can have it removed. It supplements our Terms of Service.
PikaBot is an independently operated Discord bot and licensing service. For the purposes of data-protection law, the operator of PikaBot is the data controller. Contact: support@pikabot.win.
When you use a bot command, log into the dashboard, or are issued a license, we store your
Discord user ID (the numeric snowflake). We use it as the primary key for every record described
below. When you log into the dashboard we request only the identify OAuth2 scope; we do not request
access to your email, your servers, or your connections.
Access to licenses is gated on Discord roles. To enforce that gate, the bot reads your membership and role list in the servers it is installed in, using the Server Members intent. We evaluate your roles at the moment of a check and store only the resulting entitlement tier (for example, whether you currently qualify) — we do not persist your username, avatar, nickname, or the raw list of roles you hold. Membership data held in memory for performance is discarded when the bot restarts.
Server administrators may use an admin-only command that lists members whose Discord accounts were created within a recent window, in order to detect alt accounts used to evade bans or claim duplicate trials. This reads the publicly visible account-creation date from Discord and writes nothing to storage.
The bot uses the Message Content intent to operate its . prefix commands (for example
.license and .manage). It inspects a message only to determine whether it begins with
that prefix and, if so, to parse the command name and its arguments. Messages that do not begin with the prefix
are discarded immediately without further inspection.
Message content is never written to a database, log file, or third-party service. Only the resulting action is recorded — for example, "a license was issued to user 123456" — not the text you typed. You can decline this processing entirely by not sending prefix commands and using slash commands or the dashboard instead.
The Service does not collect, process, or store Discord presence data — your online status, custom status, or the games and applications you are playing.
| Data | Why we hold it |
|---|---|
| License records | The account identifiers (such as a game account ID) you bind, their expiry timestamps, an optional label you choose, and which Discord ID owns and last redeemed them. This is what the license check validates against. |
| Hardware bindings | A hashed machine identifier (HWID) per authorized device, to enforce the per-user device limit and to detect license sharing. |
| Wallet and ledger | Your credit balance and an immutable record of every credit and debit, including purchases and code redemptions. Required for accounting and to defend payment disputes. |
| License codes | Generated codes, who bought them, and who redeemed them, so a code cannot be redeemed twice and purchases can be attributed. |
| Trial and claim history | Records of free trials and role-based claims, to enforce one-time and cooldown limits. |
| Allowlist and bans | Discord IDs permitted to access the dashboard, and Discord IDs banned from the Service with the reason and timestamp. |
| Audit log | Administrative and account actions (issue, transfer, expire, ban) with the acting Discord ID and a timestamp, for accountability and dispute resolution. |
| Terms acceptance | The version of the Terms you accepted, the timestamp, and the IP address you accepted from. Payment processors require this as dispute evidence. |
| Client telemetry | Periodic diagnostic reports from the client software: module name, operating system, version, a hashed machine identifier, and a count of configured accounts. Used to operate, debug, and improve the Service. Account names sent by older client versions are reduced to a count on receipt and are not stored. |
| Instance links | For users who enable remote control: a hashed machine identifier, the tunnel address, and a last-seen timestamp, so the dashboard can reach your instance. |
| Server logs | IP addresses and a coarse geographic location derived from them appear in operational logs and in staff alerts about unregistered or suspicious license attempts, for security, abuse prevention, and rate limiting. |
Wallet top-ups are processed by Stripe. Card numbers and payment credentials are handled entirely by Stripe and never reach our servers or our database. We receive and store a transaction reference, the amount, the status, and the email address you supplied at checkout, if any. Stripe's own handling of your data is governed by the Stripe Privacy Policy.
Where the GDPR or a comparable law applies to you, we rely on:
We do not sell your personal data, rent it, or share it for advertising. We disclose data only to:
Some administrative events (a license issued, an allowlist change, a ban) are posted to a private staff-only channel in our Discord server, visible to our staff.
We do not use any data collected through the Service — including message content — to train, fine-tune, or evaluate machine-learning or AI models, and we do not provide it to any third party for that purpose. Automated rules do gate access (for example, an expired license or a missing role automatically fails validation), but you can always reach a human at support@pikabot.win to have a decision reviewed.
Depending on where you live, you may have the right to:
To exercise any of these, email support@pikabot.win from an address we can tie to your account, or open a ticket from the Discord account in question. We will respond within 30 days. We may ask you to confirm control of the Discord account before acting, to prevent someone else from extracting or deleting your data.
You can request deletion of your records at any time. On request we will delete your license records, hardware bindings, telemetry, instance links, and allowlist entry.
Two categories survive a deletion request, and we will tell you when this applies:
Deleting your data ends your access to any active license; we do not refund the remaining time (see Section 5 of the Terms). Removing the bot from your server, or leaving the server, does not by itself delete records already stored — send a deletion request.
Data is stored in an access-controlled database, transmitted over TLS, and reachable only by the operator and a small number of trusted staff. Hardware and machine identifiers are stored as hashes. Dashboard access requires Discord OAuth2 and issues short-lived session tokens. No system is perfectly secure; if a breach affects your personal data we will notify affected users and any regulator we are required to notify, without undue delay.
The Service is not directed at children. You must be at least 18 years old, or the age of legal majority in your jurisdiction, to use it. We do not knowingly collect data from children. If you believe a minor has provided us with data, email support@pikabot.win and we will delete it.
Our hosting, database, and payment providers may process data in countries other than yours, including the United States. Where required, we rely on the safeguards those providers offer, such as standard contractual clauses.
We may update this Policy from time to time. Material changes will be posted on this page with a revised "Last updated" date. Continued use of the Service after a change constitutes acceptance of the updated Policy.
Questions, access requests, and deletion requests: support@pikabot.win. General help is also available on our Discord server.