PRIVACY POLICY
The scripturealone.net website and the custom Discord bots operated by Fully Awakened Ministries for the Scripture Alone community
Effective date: August 11, 2026
Scope — what this covers, and how to read it
This document has two parts with different legal characters:
- The Privacy Policy is a notice. It explains how Fully Awakened Ministries processes personal data and the lawful bases we rely on. It is not something you "agree" to by contract; it informs you.
- The Terms of Service are a contract governing your use of our services.
It applies to the online services Fully Awakened Ministries operates for the Scripture Alone community: our website at scripturealone.net, our custom, self-hosted Discord bots, our Discord Activity for watching lectures together, and our Scripture Alone Radio stream. Broadly, our Discord software falls into three groups: a moderation and community-features bot (referred to in this document as Catherine); a set of audio bots that stream audio into listen-only voice channels — eight staff-controlled library bots, plus one member request bot that plays what members ask for; and a lecture Activity that plays video from our own media library inside a voice channel (Section 3.11). For security reasons we do not publish a detailed inventory of our bots or the underlying software they run on.
What this does not cover. Third-party bots hosted and operated by other companies — for example Dyno, Carl-bot, ProBot, or YAGPDB — are governed by their own policies. Third-party services we link to (Discord, PayPal, Spreadshop, Google, audio sources) each have their own policies too.
Assent. These Terms govern use of the Services. For interactions that matter contractually — submitting a form, using bot features — we obtain affirmative acceptance. For ordinary browsing of the website or listening to the radio, these Terms apply as notice, to the extent they are enforceable without a separate agreement; we do not claim that merely viewing a page or hearing the stream forms a contract. The Privacy Policy applies as notice regardless, and special-category processing stands on the lawful bases in Section 4, not on passive conduct. We also provide conspicuous in-server notices for logging and automated moderation.
1. Plain-language summary
- Fully Awakened Ministries is the data controller for the personal data described here.
- Most bot data is ordinary Discord information (user IDs, usernames, server/channel/role IDs, timestamps). Catherine stores the most — moderation records, voice join/leave history, activity counts, and virtual-economy balances — in local databases and in Discord staff-log channels.
- Some features send data to outside services: automated image moderation to OpenAI; message text in auto-translation channels, and text you give the translate command, to a third-party translation service — selected automatically by the translatepy library, and which may be Google, DeepL, or another; forum search to OpenAI; website form submissions to Google Forms; donations via PayPal; merchandise via Spreadshop.
- Our website uses no analytics or ad-tracking cookies and serves its own fonts. The one exception is our Podcast page, which embeds a Spotify player that connects you to Spotify when the page loads (see Sections 3.8 and 5).
- Our forms collect sensitive information (religious beliefs, and for the mentor application, gender) — provided voluntarily to apply. Self-harm support tickets may contain mental-health information. We treat both with extra care (see Sections 3.7 and 4).
- We do not sell your data, and we do not use it for advertising.
- You have rights over your data, including access and deletion — see Section 10.
- The audio bots keep no user database and store no user identifiers at all — only their own playback state, an index of the audio library, and staff-created playlists, plus routine operational logs that do not record who issued a command. They request no privileged Discord intents and keep no member cache.
- The lecture Activity asks you to authorise it, and receives only your Discord user ID, username and avatar, and your own roles in this server — nothing about anyone else. It holds these in memory only, never on disk, and they are gone when the app restarts. Video is fetched by our server from our own media library, so that library never sees your connection.
2. Who we are (the data controller)
The website, bots, and radio are operated by Fully Awakened Ministries ("we", "us", "our"), a Texas-based religious nonprofit ministry recognized by the IRS as a 501(c)(3) church (federal EIN 46-2466880), which runs this Discord community. For any privacy question, data-rights request, or complaint, use our contact form at scripturealone.net/contact.
We are generally the controller of the data we collect to operate these services. Some providers we use are independent controllers for their own parts (notably Discord, PayPal, Spreadshop, and Google) and are responsible for their own processing under their own policies. Discord Inc. provides the underlying platform and is an independent controller for the account and message data you create on Discord; this policy covers only what our services do with data, not Discord itself.
3. What data we process
3.1 Account and technical identifiers
Standard Discord identifiers: your user ID, username and server nickname, the server (guild) ID, channel and role IDs, message IDs, and event timestamps. Discord provides these automatically when you interact with a server the bot is in. In addition, where a bot uses the Server Members Intent (see Section 3.10), it may receive and transiently cache member and role information for members of the server generally — not only those who interact with it — in order to resolve permissions and run member-dependent features. That cache is held in memory and is not written to disk.
3.2 Message content
Some Catherine features process message text:
- Word filtering. The filter and translate components scan message text against a configured word list to enforce community rules, and may delete matching messages. The check happens in the moment and does not keep a stored copy of your message — but see Section 3.6 for moderation records that can quote content.
- Translation. In channels set up for automatic translation, Catherine reads each new message and sends its text to a third-party translation service to post a translation so other members can follow along; she also translates text you give the translate command. Translation runs through the translatepy library, which routes the text to one of several public translation services (such as Google or DeepL) and by default selects one automatically (see Section 5). We do not keep a copy of the message text.
- Forum search. The forum "tag search" sends your search query text to OpenAI when a local keyword match does not resolve it.
- Activity counting. The role-stats feature counts messages and reactions and stores counts and first-activity locations (not message content). It also records join timing and changes to the belief/denomination self-identification roles you choose — see Section 3.5.
- Command input. Text you pass to a command is processed to run that command; some commands log the command and its arguments to a staff channel (see Section 3.6).
3.3 Images
Automated image moderation downloads the images you post and, where enabled, user avatar images, and sends the image data to OpenAI's moderation service to classify them, and then acts on the result (see Section 6 for what "acts on" means and how to appeal). It does not store the images; it may log the action (who, when, categories flagged) to a staff channel.
3.4 Voice-channel activity
Voice logging records when users join, leave, or switch voice channels — user ID, event type, before/after channel IDs, timestamp — in a local database, and can reconstruct historical events from a Discord log channel's message history. Used for moderation and aggregate reporting.
3.5 Moderation, engagement, and economy records
- Staff audit: moderation actions — acting moderator ID, target user ID, action, any reason text, timestamp — including actions attributed by reading server audit logs and command messages.
- Core moderation (cases, warnings, mutes, ban records): target, responsible staff, reason, timestamps. Anti-nuke monitors the rate of sensitive admin actions.
- Engagement: message/reaction counts, first-activity and per-channel activity; last-seen time; badge assignments.
- Membership analytics (role-stats): each member's join timestamp, and a history of changes to the belief/denomination self-identification roles they choose (when such a role is added or removed), used to produce aggregate membership statistics for staff. Because these roles can reveal religious belief, this is treated as special-category data — see Section 4.
- Virtual economy: in-server virtual-currency balances and transactions. This is play-money with no real-world value.
- Games: game state and scores keyed to players and server.
3.6 Records from Discord that may contain your content
Several features create records — kept in Discord staff channels — that can contain or quote content you posted on Discord. (For information you provide through our website forms rather than through Discord, see Section 3.8.)
- Ticket transcripts generated on close and posted to a staff log channel.
- Moderation reasons that may quote the message that prompted an action.
- Staff-audit entries derived from reading command messages.
- Voice history reconstructable from Discord log-channel messages.
- Server-event logs (joins/leaves, bans, role/nickname changes) forwarded to staff log channels.
These are records under our control even when hosted in Discord. Their storage and retention are covered in Sections 8 and 9.
3.7 Self-harm support and health-related data
Our restriction tools can open a private ticket channel (for example, the self-harm support workflow) visible only to the affected user and staff, and can generate a transcript posted to a staff log channel on close. Such a ticket may contain mental-health or crisis information, which we treat as sensitive.
Important: these tickets are not an emergency service and are not monitored by professionals; staff responses may be delayed. If you or someone else is in immediate danger, contact local emergency services or a crisis line (e.g. in the US, call or text 988). To protect a person from imminent harm, we may — consistent with applicable law — disclose ticket information to emergency services, a guardian, Discord, or others where we reasonably believe it is necessary to prevent serious harm. When a ticket is opened we present a clear notice and require a separate, affirmative "I explicitly consent…" control before any sensitive content is collected; we rely on that explicit consent for the mental-health information you choose to share, and on vital interests only where a person is physically or legally incapable of giving consent and is at imminent risk. Access to these tickets is limited to designated staff; see Section 4 for our lawful basis and Section 9 for retention.
3.8 The website (scripturealone.net)
The website is self-hosted. Apart from the embedded podcast player described below, it uses no analytics, no advertising trackers, and no third-party cookies on our own pages, and serves its own fonts.
Information you submit through the website is provided directly by you through our web pages, not collected from the Discord platform. Even where a form asks for your Discord tag or user ID, you are typing that in yourself; at that point our website is acting as a separate service, independent of Discord, and Discord is not involved in — or responsible for — what you submit here. This is distinct from the Discord-side records described in Section 3.6.
- Web server logs. Ordinary access logs record your IP address, browser/user-agent, pages requested, and timestamps, used to run and secure the site.
- Forms. The Apply, Ban Appeal, Mentorship, Moderation feedback, and Presenter pages carry forms that — although styled to match our site — submit to Google Forms. Submitting a form sends what you enter, together with network metadata such as your IP, to Google (see Section 5). We identify you by your Discord tag / user ID, not by email or phone. A submission can include your Discord tag and user ID, age, gender, timezone, church/denominational affiliation, answers to doctrinal questions, and free-text responses.
- Sensitive information in forms. Because these forms ask about religious beliefs, a submission necessarily includes special-category data; the mentor application also asks your gender and doctrinal views, which we treat as additional sensitive information. You provide these voluntarily to apply; see our lawful basis in Section 4. Provide only what you are comfortable sharing.
- Donations use a PayPal link; see Section 5 for the donor data we receive. We never receive your card or bank credentials.
- Merchandise is sold and fulfilled by a third-party Spreadshop store.
- Scripture Alone Radio (self-hosted) logs listener connection data such as IP address and the stream requested, to deliver audio and count listeners.
- Embedded podcast player. Our Podcast page embeds a Spotify player. When that page loads, your browser connects directly to Spotify to display it, which lets Spotify receive your IP address and device/browser information and set its own cookies in the player, under Spotify's own privacy policy (see Section 5). The Apple Podcasts, YouTube, Amazon Music, and Podchaser buttons on that page are ordinary outbound links and send nothing until you click them.
3.9 The audio (music) bots
The audio bots stream audio into listen-only voice channels. They fall into two classes, and the difference matters for your data:
- Eight library bots, controlled by staff only. They play from libraries that are ours — most from a library held on the bot host, one from our own self-hosted media library elsewhere on our network. They send nothing to any third party.
- One member request bot, which any member holding the relevant role may use. Because it plays what you ask for, the search term or link you supply is sent to an outside audio source to find it (Section 5). It is the only audio bot that contacts a third party.
Except where noted, what follows applies to both classes, and their data handling is deliberately minimal:
- No ordinary messages are read. We do not request Discord's privileged Message Content Intent, and the bots cannot read ordinary channel messages. They are driven by slash commands, which Discord delivers as a structured interaction rather than as a message. That interaction necessarily identifies who ran the command and carries their roles, which we use at that moment to check permission — and the request bot's interaction also carries the search term or link you supplied, which it uses to find what you asked for. Because there is no command message, there is nothing of that kind to retain, and none of the above is written to a user record (see the next bullet).
- Minimal persistent storage. On the bot host, each bot persists only its own playback state (which track is selected and the position within it), an index of the audio library, and staff-curated playlists consisting strictly of public-domain media or authorized, self-generated content designated solely for internal bot playback. It keeps no user database and no message archive, and stores no user identifiers — the interaction data described above is used at the moment of the command and then discarded, not saved. Operational logs record technical detail such as which bot is playing which track, and errors — never who issued a command, and never the search term — used only for debugging and kept only for the operational-log retention period (Section 9). Nothing is sent to third parties except the audio-source lookups in Section 5.
- No member cache. Permission checks read the issuing user's roles directly from the interaction Discord sends with the command. The bots therefore hold no cache of the server's members, in memory or on disk, and need no privileged intent to perform those checks (see Section 3.10).
- No audio recording. The bots play outbound audio only; they do not record or store anything spoken or played in voice channels.
- Private, not public. Each bot has Discord's "Public Bot" setting disabled and runs only in our server; it cannot be added elsewhere, and is not available for purchase or commercial use.
3.10 Discord Gateway Intents
Discord "privileged intents" control what a bot may receive. For transparency and to match the intent requests we file with Discord:
- The audio bots request no privileged intents at all. They ask Discord only for basic server information and voice-channel state — the minimum needed to join a voice channel and play audio. They request neither the Message Content Intent nor the Server Members Intent, so they cannot read ordinary message content and hold no member list. Role checks are satisfied from the interaction payload Discord sends with each command.
- Catherine requests the Message Content Intent, because moderation and word-filtering must inspect message text (Sections 3.2–3.6), and the Server Members Intent for member-dependent moderation (role automation, join/leave handling, and acting on non-invoking members).
- The lecture Activity is not a gateway client and requests no intents of any kind. It learns your roles from the permission you grant it when you open it (Section 3.11).
3.11 The lecture Activity
Alongside the audio bots we run a Discord Activity — an app that opens inside Discord's own window so members can watch lectures from our library together in a voice channel, in sync. It is separate software from the bots and establishes identity differently, because an Activity receives no bot interaction to read.
- You authorise it, and it asks for two things. When you open the Activity, Discord asks whether
you consent. It requests exactly two OAuth scopes:
identifyandguilds.members.read. UnderidentifyDiscord returns your basic profile; of that we use your user ID, username and avatar. Underguilds.members.readDiscord returns your own membership of this server, including your roles — only your membership, so it cannot be used to look up anyone else. Because you grant these rather than a bot holding them, the Activity needs no privileged intents. - Your roles can reveal religious belief. The membership Discord returns includes every role you hold here, which may include the belief or denomination roles members self-select. We use them only to decide whether you may control playback, and we disclose them to no one. Section 4 states the basis on which we process them.
- What is kept, and for how long. While your viewing session exists we hold your user ID, display name, your roles, whether those roles permit you to control playback, and an opaque session identifier. This lives in memory only and is never written to disk. It is released the moment you close the Activity and cleared about 30 seconds later — the brief delay exists so that a dropped connection can reconnect without asking you to authorise again. If a connection ends abnormally, or you authorise and never open a session, it expires after one hour of inactivity at the latest. Nothing survives a restart. The access token Discord issues is exchanged immediately for the opaque session identifier and is not stored.
- Shared playback state contains no participant identifier. What the room records is which lecture is playing, the position within it, and the time that position was measured — not who is watching, and we do not join it to any record of who was present. Operational logs written by the Activity record the room and the item, never the viewer.
- Our media library receives no connection from you. Video is fetched by our server and passed on to you, so the media library receives no connection, network address, or request from your device. The credential our server uses to read that library never reaches your browser.
- Our web server does see your connection. The Activity is served over our own web server, which keeps ordinary access logs — network address, time, and what was requested — as any website does (Sections 8 and 9). The point above concerns the media library, not our web tier.
- Discord is in the path. Discord serves the Activity through its own domain and forwards requests to us, so Discord necessarily handles this traffic under its own privacy policy (Section 5).
- Restricted to this server. The Activity resolves your membership against the single server it is configured for; it does not run elsewhere.
4. Lawful bases for processing
Where the GDPR or UK GDPR applies (for example, to users in the EEA or UK), we rely on the following Article 6 bases, and — for sensitive data — the following Article 9 conditions. US state privacy laws may treat religious beliefs and similar data as "sensitive" and require opt-in consent even where a nonprofit is otherwise exempt.
| Processing | Article 6 basis | Article 9 (special-category data) |
|---|---|---|
| Moderation, anti-abuse, and safety logging; web/radio security logs; engagement records | Legitimate interests (Art 6(1)(f) — operating a safe community), balanced against your rights | Not deliberately collected; any incidental special-category content is minimized (see the note below) |
| Running a feature you request (commands, games, translation, audio, the technical transmission of a form) | Contractual necessity (Art 6(1)(b)) — necessary to provide the feature you asked for | — |
| The lecture Activity — authenticating you, confirming you are a member of this server, and holding your session and the shared playback position | Contractual necessity (Art 6(1)(b)) where you have accepted these Terms; otherwise legitimate interests (Art 6(1)(f) — providing a members-only feature you asked for, and controlling access to it) | — |
| The lecture Activity receiving the roles you hold here — which may reveal religious or denominational belief — in order to decide whether you may control playback | Legitimate interests (Art 6(1)(f) — access control) | Art 9(2)(d) — processing by a not-for-profit body with a religious aim, in the course of its legitimate activities, with appropriate safeguards, relating solely to its members and regular contacts, and not disclosed outside the ministry without consent |
| Reviewing, evaluating, deciding, and retaining applications (Apply / Mentorship / Presenter) — ordinary fields such as Discord ID, age, timezone, and non-special-category written answers | Legitimate interests (Art 6(1)(f) — assessing and selecting volunteers/mentors) | Special-category answers are covered by the explicit-consent rows below or the incidental-data note |
| Religious-belief and doctrinal answers in the Apply / Mentorship / Presenter forms | Consent | Explicit consent (Art 9(2)(a)) |
| Role-stats logging of changes to the belief/denomination roles a member publicly self-selects in the server | Legitimate interests (Art 6(1)(f) — aggregate membership statistics) | Data manifestly made public by the data subject (Art 9(2)(e)) |
| Gender data (mentor form) | Consent | Not for gender alone. If an answer reveals another Article 9 category (e.g. sexual orientation or health), Art 9(2)(a) applies only where the separate explicit-consent control specifically covers that category; otherwise we minimize, redact, or delete it under the incidental-data note below |
| Ban-appeal and moderation-feedback form responses | Legitimate interests (handling appeals and feedback) | — |
| Self-harm / mental-health ticket content | Consent; and vital interests in an emergency | Explicit consent (Art 9(2)(a)); vital interests (Art 9(2)(c)) only where a person is incapable of giving consent and at imminent risk |
| Donation and accounting records | Legitimate interests (and legal obligation where a law that applies to us requires it) | — |
| Legal demands and legal claims | Legal obligation (Art 6(1)(c)) for a compulsory demand recognised under applicable law; legitimate interests (Art 6(1)(f)) to establish or defend legal claims | Art 9(2)(f) where sensitive data is involved in a legal claim |
Notes on the sensitive-data bases:
- Where we rely on explicit consent for sensitive data, withdrawal stops further processing (without affecting what was already done); we do not fall back to another Article 9 condition if you withdraw. You may decline to provide it, though we may then be unable to process that application.
- We rely on the religious-nonprofit condition (Art 9(2)(d)) only where its conditions are met — a qualifying nonprofit, our legitimate activities, our members or regular contacts, appropriate safeguards, and no disclosure outside the organisation without your consent — and not as an automatic substitute for consent.
- We do not use consent as the basis for unavoidable moderation, because server participation would make that consent not freely given.
- Our filtering, moderation, tickets, appeals, feedback, and application free-text responses may incidentally encounter special-category data (e.g. religious or health statements) that we did not solicit. Our default is to minimize, redact, or delete such content rather than rely on it, and we do not use it for profiling. Where a specific situation genuinely requires processing it, we identify and rely on the Article 9 condition applicable at that time (for example, your explicit consent, or Art 9(2)(f) for a genuine legal claim); we treat no single condition as a universal basis, and where none applies we remove the content.
5. Third-party recipients
Some features send data to outside parties. The table shows each recipient, its role, and what is sent; each recipient's own privacy policy (on its website) governs its own processing. "Independent controller" means that party decides its own purposes; "processor" means it processes on our behalf under our instructions and a processing agreement.
| Recipient | Role | Data sent | Purpose / notes |
|---|---|---|---|
| Discord (Discord Inc., US) | Independent controller (platform) | Bot interactions; any records we keep in Discord channels; and, for the lecture Activity, your authorisation of it, the profile and membership data Discord returns to us, and the Activity's traffic — which Discord serves from its own domain and forwards to our server | Platform operation. Only Discord-based activity transits Discord — donations, merch, and website forms do not. |
| OpenAI (US) | Processor | The image and avatar data you post, downloaded and sent for moderation; forum query text (forum search) | Content moderation; semantic search |
| Translation services via translatepy — e.g. Google (US), DeepL (EU) | Independent third-party services (public endpoints; no data-processing agreement with us) | Message text in auto-translation channels, and text you give the translate command | Automatic and on-demand translation; translatepy selects a service automatically |
| Google (Google Forms/Sheets, US) | Processor for the form content we collect under our account; independent controller for Google's own service/security processing | Form submissions (see 3.8) plus network metadata (e.g. IP) | Receiving applications, appeals, feedback |
| PayPal (US) | Independent controller | Payment data you give PayPal | Donations. PayPal typically shares donor name, email, amount, and transaction ID with us; we keep these for accounting/tax. We never receive your card/bank credentials. |
| Spreadshop / Spreadshirt (US/EU) | Independent controller | Your order, shipping, and payment details | Merch sales/fulfilment (handled by Spreadshop) |
| Giphy (US) | Independent controller | Your GIF search terms | GIF features |
| Audio sources (e.g. YouTube, SoundCloud, Bandcamp) | Independent controllers | The song or search terms you request | Audio lookup for the member request bot only. Our staff-curated audio bots play from a pre-indexed library held on our own host and send nothing to these services |
| Spotify (US/EU) | Independent controller | Your IP address and device/browser information when the Podcast page loads its embedded player, plus any cookies Spotify sets in the player | Embedded podcast player on our Podcast page; governed by Spotify's own privacy policy |
For our processors (OpenAI, and Google as to the form content it stores for us), retention and deletion follow our instructions and processing agreement, and their held data is included in our response to a valid rights request. For independent controllers, their own policies govern.
We do not sell personal data and do not "share" it for cross-context behavioral advertising (as those terms are used under US state laws). We disclose data only (a) to the recipients above to provide the feature you used; (b) to our staff, who see moderation records and logs for their roles; and (c) where required by law or to prevent serious harm (Section 3.7).
6. Automated moderation and your safeguards
Two features act automatically:
- Image moderation: flagged images/avatars may be deleted, and the action logged to staff; repeat or severe cases may lead to staff moderation. Results are reviewable by staff.
- Anti-nuke: may automatically limit administrative actions that look like an attack.
These do not make decisions producing legal or similarly significant effects without the possibility of human involvement. If you believe an automated action was wrong (a false positive), you may request human review and appeal via our contact form at scripturealone.net/contact or a #modmail ticket.
7. International data transfers
We operate in the United States, and several providers (Discord, Google, OpenAI, PayPal, Giphy, Spotify) host data in the US; DeepL processes within the EU; and text sent for translation is processed in the US or the EU depending on the service translatepy selects. If you are in the EEA or UK, your data may be transferred to the US. Where GDPR/UK GDPR applies, we rely on an appropriate safeguard for each recipient — for most US providers this is Standard Contractual Clauses (with the UK Addendum) and/or the provider's EU–US Data Privacy Framework certification. Ask us via our contact form at scripturealone.net/contact for current details.
8. Where your data is stored
- On our bot host: Catherine's local databases and configuration files, and local logs. Not copied to any cloud database we run.
- In Discord staff channels: ticket transcripts, moderation-reason records, staff-audit and server-event logs, and reconstructable voice history (Section 3.6). These live in Discord.
- In Google: website form submissions, in Google Forms / Google Sheets under our Google account.
- On the audio-bot hosts: playback state, the audio-library index, staff-created playlists, and routine operational logs (which may include a processed command but no user identifiers; no message archive).
- In memory on the Activity host: viewing-session details (your user ID, display name and roles) and the shared playback position, for the life of the running process only — never written to disk.
- On our web server: ordinary access logs for the Activity and the website (network address, time, and what was requested), plus the Activity's own operational logs recording rooms and items.
- With providers: whatever each recipient in Section 5 holds — for processors under our instructions and agreement, for independent controllers under their own policies.
- Backups: operational backups may retain copies for a limited period after deletion from the live system.
9. How long we keep data
We keep data only as long as needed for the purpose, then delete or de-identify it, according to the following schedule.
| Category | Retention |
|---|---|
| Web-server, radio, bot, and Activity operational and access logs | Up to 30–90 days |
| Activity viewing sessions and shared playback state | In memory only. Cleared about 30 seconds after you close the Activity; at most one hour of inactivity where a connection ended abnormally |
| Voice-activity and engagement history | Up to 12 months |
| Unsuccessful application / appeal responses | Decision + up to 6 months |
| Approved applications and accepted-applicant data (incl. religious, doctrinal, gender, age) | Duration of the mentor/presenter relationship + up to 12 months, then deleted or de-identified |
| Successful ban appeals | Resolution + up to 6 months |
| Moderation-feedback and other non-application form responses | Up to 12 months |
| Ticket transcripts (incl. self-harm) | A short fixed period after closure (e.g. 30–90 days), minimized |
| Ordinary moderation records | Duration of membership + up to 12 months |
| Ban-enforcement data | Minimal (user ID + reason) while the ban is in force |
| Economy, game, badge, and account state | Until you leave the server or request deletion, or the feature is reset |
| Audio-bot playback settings and playlists | Until changed or the server is removed |
| Donation / accounting records | As required by applicable tax/accounting law |
| Provider inputs/outputs (OpenAI; translation services) | OpenAI per our configured retention settings; translation services per each service's own terms |
| Backups | Rotating schedule; deleted copies expire with the backup cycle |
The safety exception is narrow: an active ban may require keeping a user ID and a minimal reason; it does not justify keeping every historical message, voice event, or ticket indefinitely.
10. Your rights
Subject to applicable law, you may request to: access your data; correct it; delete it; restrict or object to processing; obtain portability; and withdraw consent where we rely on it (without affecting prior processing). We do not discriminate against you for exercising these rights. Where the GDPR/UK GDPR applies, you may also complain to your supervisory authority (in the UK, the ICO). US state-law residents may have equivalent rights and may use an authorized agent.
How to make a request. Use our contact form at scripturealone.net/contact. Because much of the data is Discord-based, include your Discord user ID. We will verify your identity proportionately (for example, confirming control of the Discord account), respond within the timeframe applicable law requires, and tell you if an exception applies. If we deny a request, you may appeal by replying to our decision at the same contact; where a US state law grants an appeal right, we will follow its process and tell you how to escalate (for example, to a state Attorney General) if we still cannot grant it.
What deletion can and cannot reach. We can delete data in Catherine's databases, records we hold in Discord staff channels, and your Google Forms responses. For the lecture Activity, a session exists only in memory and clears itself about 30 seconds after you close it, or after an hour of inactivity at the outside; ask us and we will clear it sooner. Activity and web access logs age out on the schedule in Section 9. For our processors (OpenAI, and Google as to form content), we instruct deletion or return and include their held data in our response. Text sent to third-party translation services is handled under those services' own terms. Independent controllers (Discord, PayPal, Spreadshop, Giphy) delete under their own policies. Backups expire on their own cycle, and we may retain or de-identify minimal records where we have a legal obligation or an overriding safety reason (Section 9). We will not delete records in a way that would improperly expose or remove another person's data or staff-confidential material.
11. Children and young people
Discord requires users to be at least 13 (older in some countries). Our services are not directed to children under 13, and we do not intend to collect their data; because bots process activity in active channels, we cannot guarantee we never encounter it, and we will delete under-13 personal data we become aware of. Our forms collect age, gender, and religious beliefs and may be completed by users aged 13–17; we minimize and restrict access to such data, and — where required — will seek guardian involvement. If you believe a child's data has been submitted, contact us through our contact form at scripturealone.net/contact.
12. Security and breach handling
We store bot data on access-controlled hosting, on a volume that is encrypted at rest; administrative access uses key-based authentication, and service credentials (API keys, bot tokens) are kept in environment configuration, not in the bots' source. Access to sensitive forms and crisis transcripts is limited to designated staff. No system is perfectly secure and we cannot guarantee absolute security, but we take reasonable measures. If a personal-data breach occurs, we will investigate and notify affected users, regulators, or others where required by law.
13. Changes to this policy
We may update this policy. Changes apply prospectively after we post the updated version and effective date, and we will announce material changes in the community server. Where a change requires it, we will seek fresh consent rather than treating continued use as consent to new sensitive processing.
14. Contact and complaints
Privacy questions, data-rights requests, or complaints: use our contact form at scripturealone.net/contact. You may also contact your data-protection supervisory authority where one applies.