LEGAL

Privacy Policy

Effective date: May 5, 2026  ·  Applies to HoneyBot and eas.lol/honeybot

This Privacy Policy describes how HoneyBot (“we”, “our”, “the bot”) collects, uses, and stores information when you add HoneyBot to your Discord server. By adding or using HoneyBot, you agree to the practices described in this policy.

1. Information We Collect

HoneyBot collects the minimum data necessary to provide its security services. We do not collect personally identifiable information such as real names, email addresses, or payment information.

Server data:

  • Discord Server (Guild) ID — to associate your configuration with your server
  • Channel IDs — to know which channels to monitor or designate as the honeypot
  • Role IDs — to optionally bypass detection for trusted roles

User and message data:

  • User IDs — to log moderation actions and prevent duplicate actions
  • Usernames — included in action logs for audit purposes
  • Message content — scanned in real time for threat detection; raw content is not stored by default (see Section 3 for edge cases)

Additional detection data:

  • Image attachments — may be processed for scam and phishing detection
  • OCR text — text may be extracted from images to detect text-based scams embedded in images
  • Image fingerprints (perceptual hashes) — stored to detect known scam images and prevent repeat abuse
  • Detection signals and scores — generated during content analysis and stored as part of action records
  • AI classification results — where AI-assisted detection is enabled, classification metadata may be stored

Configuration data:

  • Your server's HoneyBot settings (enabled features, action type, detection thresholds) stored to persist across bot restarts

2. How We Use Your Information

All collected data is used exclusively for the operation and improvement of HoneyBot:

  • To provide automated spam and scam detection in your server
  • To execute configured moderation actions (ban, kick, timeout) on detected threats
  • To maintain action logs for server owner review
  • To persist your configuration settings across sessions
  • To store and match image fingerprints against known scam content
  • To improve detection accuracy based on aggregate, anonymized patterns

Data is processed under our legitimate interest in maintaining the security and integrity of Discord communities that use HoneyBot. We do not use your data for advertising, marketing, or any commercial purpose unrelated to HoneyBot’s security functionality.

3. Data Retention

Message content is processed in real time and is not stored by default. In cases where content is flagged, limited excerpts — such as detection snippets or OCR-extracted text — may be stored temporarily for review and system improvement, and are deleted within 30 days.

Action logs (which user was actioned, when, and why) are retained for up to 90 days to allow server owners to review actions, then automatically deleted.

Detection cache — scam image fingerprints (perceptual hashes) and campaign identifiers — may be retained long-term to improve detection accuracy and prevent repeated abuse across servers.

Server configuration is retained for as long as HoneyBot remains in your server. When HoneyBot is removed, all associated configuration data is deleted within 30 days.

4. Data Sharing and Disclosure

We do not sell, trade, rent, or otherwise transfer your data to third parties.

HoneyBot may optionally use third-party AI services (such as Google Gemini) to assist in content classification for uncertain or edge-case detections. Only the minimum necessary data is transmitted, and this feature is disabled unless explicitly configured. We do not use third-party advertising networks or analytics platforms.

Data may be disclosed only in the following circumstances:

  • To comply with a legal obligation or valid legal process
  • To protect the rights, property, or safety of our users or the public
  • With your explicit consent

5. Your Rights and Data Deletion

You have the right to request deletion of all data HoneyBot holds related to your server. To request deletion:

  • Remove HoneyBot from your server — all configuration data will be automatically deleted within 30 days
  • Contact us at [email protected] with your server ID to request immediate deletion

Individual users may also request deletion of their user ID from action logs by contacting us with their Discord User ID.

7. Automated Processing and Server Administrator Responsibility

HoneyBot operates using automated detection systems and may occasionally produce false positives (legitimate users actioned) or missed detections (threats not caught). Server administrators are responsible for monitoring HoneyBot’s actions and reversing any incorrect moderation within their server.

Server administrators are also responsible for how HoneyBot is configured and used within their server, including ensuring that its use complies with Discord’s Terms of Service and applicable law.

8. Security

We implement reasonable technical and organizational measures to protect stored data against unauthorized access, alteration, or destruction. However, no method of internet transmission or electronic storage is 100% secure. HoneyBot is currently in beta and security practices are continuously being improved.

9. Children’s Privacy

HoneyBot is not directed at children under the age of 13. We do not knowingly collect information from children. Discord's own Terms of Service require users to be at least 13 years of age.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected by the “Effective date” at the top of this page. Continued use of HoneyBot after changes constitutes acceptance of the updated policy.

11. Contact

If you have any questions about this Privacy Policy or wish to request data deletion, please contact us at [email protected].