ChichBot — Privacy Policy
For ChichBot, ChichControl, ChichFarm and optional ChickFarm integrations
Effective date: 10.10.2026
Data controller/operator: DHeaven
Privacy contact: svetoslavevgenev123@gmail.com
Postal/business contact, if required: [ADDRESS]
1. Our approach to privacy
ChichBot is designed to provide Discord community features while limiting the information it needs. This Privacy Policy explains how the operator handles personal data when you interact with ChichBot, sign in to ChichControl, or enable an optional connection with the ChickFarm Minecraft server. It also explains the choices and rights available to you.
ChichBot is a third-party Discord application, not a Discord-owned service. Discord and Minecraft-related services separately process information under their own terms and privacy policies. Server owners and administrators determine some server-specific settings and may independently be responsible for how they use exported or accessible moderation and community records.
2. Information we may process
We process only the data needed for enabled features and authorized operations:
| Category | Examples | Why it may be needed |
|---|---|---|
| Discord account and server data | User ID, display name, avatar, guild ID, roles, channel IDs, permissions, locale | Commands, permissions, onboarding, roles, and server configuration |
| Community activity | Eligible message or voice activity metadata, XP, levels, achievements, game outcomes, FarmCoin balances and transaction records | Enabled leveling, games, rewards, anti-abuse controls, and virtual economy |
| Moderation and support | Reported message excerpts or relevant content when authorized, case IDs, reasons, warnings, ticket messages, transcripts, application answers, evidence references, staff action history | Moderation, tickets, appeals, applications, and security |
| Dashboard and authentication | Discord OAuth identity and permitted server list, server-side authorization/session records, preference settings, permitted actions, audit trails | ChichControl sign-in, access control, and accountability |
| Minecraft integration (optional) | Minecraft username and UUID, verified Discord-to-Minecraft link, approved join/leave or achievement events, server status metadata | Verified linking and enabled ChickFarm features |
| Technical and security information | IP address or approximate network metadata in necessary web/server logs, browser type, request times, error and rate-limit events | Service reliability, attack prevention, diagnosis, and abuse response |
| Information you choose to submit | Poll votes, suggestions, event RSVPs, reminder details, optional birthday information, and support requests | Delivering the corresponding feature |
We do not ask for your Discord password, Discord user token, or Minecraft password. We do not archive every Discord message by default. Some content-based moderation requires access to message content and may operate only when the relevant Discord permissions and features are enabled.
3. Sources of information
Information may come directly from your interactions, Discord's approved APIs and events, server administrators' configured modules, or an authenticated ChickFarm companion integration when enabled. Dashboard authentication uses Discord OAuth2 with the minimum permissions needed for the feature (such as identity and, where necessary, guild selection). We do not use unauthorized scraping or self-bots.
4. Purposes and lawful bases (where GDPR applies)
We process personal data only when there is an applicable lawful basis. Depending on the feature and circumstances, these may include:
Providing requested functionality (contract or steps requested by you): responding to commands, maintaining requested tickets, authenticating dashboard users, keeping virtual balances, and delivering enabled services where this basis is appropriate.
Legitimate interests, subject to a balancing assessment: protecting accounts and servers, preventing abuse and fraud, applying proportionate moderation and audit controls, troubleshooting failures, and maintaining service security.
Consent: optional features requiring affirmative choice, such as Minecraft account linking, optional birthday announcements, optional AI requests, or nonessential tracking technologies where legally required. You may withdraw consent through available settings or by contacting us, without affecting prior lawful processing.
Legal obligations: processing or retaining specific records when necessary to comply with a valid legal requirement.
A server administrator enabling a module is not, by itself, a substitute for any consent legally required from an individual member. The precise lawful basis for each deployed processing activity must match its actual operation.
5. How features affect visibility
Levels, leaderboards, and FarmCoins: If a server enables these modules, eligible activity may generate stored scores and virtual transactions. Profiles, leaderboards, rewards, or roles may be visible to other server members depending on the feature. Where implemented, you can opt out of optional rankings or request deletion subject to limited security and legal exceptions.
Tickets, applications, and moderation: Messages, attachments, evidence, transcripts, and staff notes may be accessible to authorized staff assigned to the relevant workflow. Ticket transcripts are not made public by default. Moderation filters may automatically flag or restrict activity; you can seek human review through available server appeal channels. We do not use automated decisions intended to determine legal rights or similarly significant outcomes without applicable safeguards.
ChichControl: Authorized staff may view guild-scoped operational records necessary for their role. Actions involving settings, moderation, or balances may produce audit records. Administrators cannot obtain access to other guilds merely by changing a URL.
Minecraft bridge: Verified linking can associate your Discord ID with a Minecraft UUID and selected events. Linking is optional. Public Minecraft server-status checks alone do not establish your identity or authorize collection of a player roster.
AI integration: AI assistance is disabled unless separately enabled. Before a request is sent to an external AI provider, users must receive a clear disclosure of what content would be sent, which provider is involved, and any provider retention arrangements. We do not use Discord message content for AI model training unless Discord expressly permits it and all other legal requirements are met.
6. Sharing and service providers
Personal data may be accessed by authorized staff for a legitimate service purpose, or handled by contracted infrastructure providers supporting hosting, database storage, security, and diagnostics. If an optional integration is enabled, the minimum necessary data may be exchanged with its disclosed provider. We may disclose information when legally required or needed to protect users and service security, subject to applicable law.
We do not sell Discord API data, provide it to data brokers or advertising networks, or use it for targeted advertising. We do not share Discord API data with unrelated third parties except as Discord's developer rules allow.
Actual processors/services before publication: [LIST HOST, DATABASE, ERROR MONITORING, AI PROVIDER IF ENABLED, AND ANY OTHER RELEVANT RECIPIENTS OR LINK TO CURRENT PROCESSOR LIST].
7. Retention and deletion
We retain identifiable information only for as long as it is needed for the enabled purpose, consistent with Discord's requirements and applicable law. The following are proposed default retention settings and must be checked against the actual deployed configuration before this policy is published:
| Information | Proposed default |
|---|---|
| Single-use Minecraft linking codes | Expire within 15 minutes, then delete or invalidate |
| Dashboard sessions | Until logout/revocation or a maximum of 30 days |
| Routine security and error logs | 30 days |
| Closed ticket content and transcripts | 90 days after closure |
| Staff applications | 90 days after final decision |
| Resolved moderation cases and access-controlled audit records | 180 days after resolution/action, unless a justified longer period applies |
| XP, virtual balances, inventories, verified links, and other active-member feature data | While needed for the enabled feature; review/delete within 30 days after the account is unlinked, the member leaves, or the relevant feature/server is removed, unless another valid reason applies |
| Completed individual game sessions | 30 days; non-identifying aggregates may be kept longer |
| Old backups containing deleted records | Rotated out within 30 days under the backup schedule |
We may retain narrowly scoped information longer where required for an unresolved security incident, valid appeal, legal obligation, or legal claim, provided retention is justified and access is restricted. User requests or Discord instructions requiring earlier deletion take precedence where applicable; a default retention period is not a reason to postpone a valid deletion request. Removing the bot stops new collection from that server but does not by itself remove messages or copies held independently by Discord or server members.
8. Your choices and rights
You can use available commands/settings to adjust optional features, unlink a Minecraft account, or request a copy or deletion of data associated with your Discord account. To exercise a privacy right, contact svetoslavevgenev123@gmail.com and include your Discord user ID and the nature of the request. Do not send passwords or authentication tokens. We may request proportionate identity verification before disclosing or changing records.
Depending on applicable law, including the GDPR, you may have rights to access, rectification, erasure, restriction, data portability, object to certain processing, and withdraw consent. Requests will be handled within applicable legal deadlines; exceptions will be explained when legally permitted. You may complain to your local data protection authority. In Bulgaria, this is the Commission for Personal Data Protection (cpdp.bg); EEA residents may contact their competent supervisory authority.
Deleting ChichBot data is separate from deleting data stored by Discord, Minecraft services, or other independent server operators.
9. Website cookies and local preferences
ChichControl may use strictly necessary cookies or equivalent session mechanisms for Discord sign-in, session security, CSRF protection, and secure navigation. These are used to deliver services you explicitly request. Dashboard theme, language, motion, and sound preferences may be saved locally or associated with your profile.
Optional analytics or nonessential tracking technologies, if introduced, will be explained and will require any consent mandated by local law before activation. Users will be able to withdraw that consent. FarmSound is off by default and plays only after you actively enable it; enabling sounds does not grant microphone access.
10. Security
We apply risk-appropriate measures such as access controls, guild-specific authorization, secured connections, protected server-side tokens, input validation, rate limiting, audit trails, secret handling, and retention limits. OAuth tokens and bot credentials should never be exposed in the browser or public logs. No system is completely risk-free. If a reportable data breach occurs, we will notify affected people and authorities as required by law and notify Discord where its developer rules require it.
11. International data transfers
Some service providers or integrations may process data outside your country or the European Economic Area. Where required, we will use lawful transfer mechanisms and applicable protections. Hosting location and relevant transfers before publication: [COUNTRY/REGION AND TRANSFER MECHANISM, IF APPLICABLE].
12. Children and age requirements
The Services are not intended for users below Discord's minimum permitted age or a higher local minimum. We do not knowingly seek personal information from children who are not eligible to use Discord. If we discover ineligible processing, we will take appropriate steps to remove the data.
13. Changes to this policy
We may update this policy to reflect feature, legal, provider, or operational changes. We will revise the effective date and give appropriate notice of significant changes. Where new processing requires consent, it will not start until valid consent has been obtained.
14. Contact
Operator / data controller: DHeaven
Privacy requests: svetoslavevgenev123@gmail.com
Website: https://chickbot.pages.dev
ChichBot • Made by DHeaven • More Than a Bot. A Part of ChichFarm.