Back to Home

Privacy Policy

Effective date:

Operated by PEAK AGENCY LLC, a California limited liability company.

This Privacy Policy explains what data PEAK AGENCY LLC (“Peak Agency”, “we”, “us”) collects when you use PeakBot — the web dashboard at peakbot.pro and the PeakBot Discord application (together, the “Service”) — how we use it, who processes it, how long we keep it, and the rights you have over it.

The short version: we collect what’s needed to run an AI Discord server builder — your Discord account basics, the structure of servers you manage, the messages you send our AI, billing status via Stripe, and product analytics. We do not sell your personal information, we do not use it for third-party advertising, and we do not use your Discord data to train AI models.

1. Who We Are

The data controller for the Service is PEAK AGENCY LLC, a California limited liability company. For any privacy question or request, contact us at [email protected] or via our Discord support server. PeakBot consists of two connected services: the Dashboard (web application at peakbot.pro) and the Discord Bot (added to Discord servers by their administrators). The bot operates inside Discord servers owned and administered by third parties and reads, creates, modifies, and deletes server resources on behalf of server administrators.

2. Information We Collect

2.1 Account & Dashboard Data

  • Discord account data: your Discord user ID, username, display name, avatar, email address, and the list of servers you belong to, provided through Discord OAuth2 using the identify, guilds, guilds.join, and email scopes. The guilds.join scope is used only to add you to our support server when you request it.
  • Server data: server IDs, names, icons, channel and role lists, and member counts for servers where you use PeakBot, plus a record of your permissions in those servers.
  • AI conversation data: the messages you send to the AI Server Builder, the AI’s responses, and the server plans generated during your sessions.
  • Usage and cost logs: we log AI usage for cost tracking and abuse prevention — your guild ID, user ID, the text of messages you send to the AI Builder, the model used, token counts, and processing cost.
  • Billing data: your Stripe customer ID, subscription plan, status, billing interval, renewal dates, applied discounts, and a history of subscription events (upgrades, downgrades, cancellations, payment failures). We never receive or store your full card number — Stripe processes all payment details (see Section 4).
  • Product analytics (first-party): we run our own analytics to understand how the product is used. Events (page views, clicks on key buttons, checkout steps, scroll depth, cancellation-flow steps, and A/B experiment exposures) are recorded with a per-tab session ID, the page URL, referrer, your browser’s user-agent string, your user ID if you are signed in, and a one-way hash of your IP address (we do not store raw IP addresses). We also record daily dashboard visits and, for A/B tests, which variant you saw.
  • Login security: a one-way hash of the IP address you last signed in from, used for security and abuse prevention.
  • Template interactions: your Discord user ID is recorded when you like, rate, report, publish, or use a server template.
  • Preferences & notifications: dashboard layout customizations, notification inbox items, weekly digest settings, and which in-app announcements you have seen.
  • Google Analytics: we use Google Analytics 4 to collect website usage data (pages visited, session duration, device type, browser, approximate location). See Section 9.

2.2 Discord Bot Data

When PeakBot is added to a Discord server, it collects and stores the following, depending on which features the server administrator enables:

  • Server configuration: all feature settings configured through the dashboard (welcome/goodbye messages, moderation rules, XP settings, tickets, auto-responders, notifications, reaction roles, polls, giveaways, events, verification, onboarding, inactive-kick rules, and similar), stored with the guild ID.
  • XP and leveling: member user IDs, XP, levels, message counts, voice minutes, and last-activity timestamps.
  • Moderation data: warnings (user ID, moderator ID, reason), moderation action logs (bans, kicks, mutes, warns, durations), and appeal submissions with review notes.
  • AI moderation logs: when AI Moderation is enabled, message content is scored by the OpenAI Moderation API; the returned category scores, the action taken, the user ID, channel ID, and a short snippet of the offending message may be stored for audit and review.
  • Ticket data: ticket records, form submissions, and — when a ticket is closed — a full transcript of the ticket channel (message text, authors, timestamps, attachment URLs). Tickets are the only feature where full message bodies are persistently stored.
  • Invite & source tracking: who invited whom, invite codes, join/leave dates, fake-invite flags, and manual adjustments.
  • Server backups: complete snapshots of server structure (channels, roles, permissions, feature configurations and data) that administrators create and can restore.
  • Engagement features: poll questions and per-user votes; giveaway entries and winners; event details and RSVP lists; onboarding responses; verification session records and answers.
  • Member activity & security: last-active timestamps for inactive-member management, flagged-account records, raid logs, and temporarily locked channel permissions.
  • Integrations: Roblox account links (Discord user ID, Roblox user ID and username, link timestamp — verified via a one-time code in the public Roblox profile), and Disboard bump history (timestamps and user IDs of bumps).
  • Voice, embeds & webhooks: temporary voice channel ownership records, saved custom embeds (with creator user ID), per-server bot profile customizations, and webhook credentials (webhook ID, channel ID, name, token) created through PeakBot for embed delivery.
  • Aggregates: daily message counts per server and daily mention/reaction counts per user — counts only, no message content.

2.3 Message Content

The bot uses Discord’s Message Content privileged intent. Message content is processed only for the purposes below, and — except for ticket transcripts and short AI-moderation snippets — is not persistently stored by us:

  • Auto-moderation: real-time scanning for profanity, spam, excessive caps, mass mentions, invite links, and filtered URLs; on a violation, up to 200 characters may be posted to the server’s own log channel within Discord.
  • AI moderation: message text is sent to the OpenAI Moderation API for category scoring when the server administrator enables this feature (see 2.2).
  • Spam detection: recent messages are cached in memory for up to 5 minutes to detect repeats, then cleared.
  • Auto-responder: messages are checked against server-configured triggers in real time and not retained.
  • XP awards: only the fact that a message occurred is tracked (user ID and timestamp), not its text.
  • Ticket transcripts: full message history of a ticket channel is saved when the ticket closes.
  • Message logging: when enabled by the administrator, deleted/edited messages (up to 1,024 characters) are posted to a log channel inside Discord — not stored in our database.
  • Disboard bump detection: the bot reads Disboard’s bump confirmations; only bump metadata is kept.

We never sell message content and never use it to train AI models, consistent with Discord’s Developer Policy. If we ever change how we handle message content, we will disclose it to you in advance.

3. How We Use Information (and Legal Bases)

Where GDPR or similar laws apply, we rely on the legal bases noted in brackets:

  • To authenticate you and operate your account, the dashboard, the AI Server Builder, and the bot features you or your server administrator enable [performance of a contract];
  • To process subscriptions and payments through Stripe, send billing-related notices (renewal reminders, payment-failure notices), and keep required financial records [contract; legal obligation];
  • To send you service messages via Discord DM — such as trial or renewal notices, cancellation confirmations, win-back offers after you cancel, and feature notifications you can control in your dashboard settings [contract; legitimate interests];
  • To secure the Service: rate limiting, abuse and fraud prevention, anti-raid protection, hashed-IP login checks, and admin action audit logs [legitimate interests];
  • To understand and improve the product through first-party analytics and A/B experiments, reviewed in aggregate [legitimate interests];
  • To monitor AI usage and costs and enforce fair-use limits [legitimate interests];
  • To comply with law and respond to lawful requests [legal obligation].

We do not use your personal information for third-party advertising, and we do not make decisions with legal or similarly significant effects about you by automated means. AI moderation acts only within your Discord server under rules its administrator configures, and its actions can be reviewed and reversed by the server’s moderators.

4. Third Parties & Subprocessors

We do not sell your personal information. We share data only with the service providers that make PeakBot work, listed with details on our subprocessors page:

  • Discord — authentication and all bot operations in your servers;
  • Anthropic, Google (Gemini), OpenAI, Cohere — AI processing. Your AI Builder messages and relevant server context are sent to these providers to generate responses; message content is sent to OpenAI’s Moderation API when AI Moderation is enabled. Under the API terms we use, none of these providers use your data to train their models; they may retain inputs briefly for trust-and-safety monitoring under their own policies;
  • Pinecone — stores vector embeddings for our knowledge retrieval system; these are derived from documentation and template content, not from your personal data;
  • Stripe — payment processing. Your payment details go directly to Stripe; we receive only billing metadata (customer ID, subscription status, amounts);
  • Railway — hosting for our application, databases, and Redis;
  • Google Analytics — website usage measurement (Section 9);
  • YouTube, Twitch, Roblox, Disboard — only when you use the corresponding integration, as described in Section 2;
  • Legal requirements — we may disclose data when required by law, or to protect the rights, safety, or property of Peak Agency, our users, or others.

If Peak Agency is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction; we will notify you of any change in ownership or in how your data is handled.

5. Data Storage & Security

  • PostgreSQL databases (Railway): account, billing, analytics, and AI usage data for the dashboard; a separate database holds all bot feature data (configurations, XP, moderation logs, transcripts, backups, and the rest of Section 2.2).
  • Redis (Railway): chat sessions, rate-limit counters, OAuth tokens, usage tracking, and caches.
  • Bot memory: short-lived caches (30 seconds to 10 minutes) for spam detection and settings, cleared automatically.
  • Your browser: your sign-in token, cached profile, and preferences are kept in local storage on your device (Section 9).

Databases are encrypted at rest; all data in transit uses HTTPS. Internal service-to-service calls are authenticated with signed tokens and secrets, raw IP addresses are hashed before storage, and administrative actions on our side are audit-logged. No method of transmission or storage is 100% secure and we cannot guarantee absolute security — but if a breach affects your data, we will notify you and the relevant authorities as required by law (including within 72 hours where GDPR applies), and we will notify Discord where its Developer Terms require it.

6. Discord Privileged Intents

  • Server Members intent: powers welcome/goodbye messages, invite tracking, anti-raid detection, activity tracking, and inactive-member management.
  • Message Content intent: powers auto-moderation, AI moderation, spam detection, auto-responders, XP tracking, ticket transcripts, and Disboard bump detection — handled as described in Section 2.3.

7. Data Retention

Dashboard data

  • AI chat sessions: up to 90 days in Redis, then deleted automatically.
  • AI usage/cost logs (including your AI Builder message text): retained while your account exists; deleted or anonymized on verified deletion request (Section 8).
  • Product analytics events: retained in aggregate-friendly form; hashed IPs only, never raw.
  • OAuth tokens: 7 days in Redis, then deleted automatically.
  • Billing records and subscription event history: retained for up to 7 years as required for tax, accounting, and audit purposes.
  • Google Analytics: 14 months (our GA4 retention setting).
  • Browser local storage: on your device until you log out or clear it.

Bot data

  • Server configurations, XP data, moderation and security logs, tickets and transcripts, invite/source tracking, engagement data (polls, giveaways, events, onboarding, verification), integration links, saved embeds, and webhook records: retained while the feature is in use, and deleted within a reasonable period after PeakBot is removed from the server or upon a verified deletion request — whichever comes first. Server administrators can also delete most records directly (Section 8).
  • Server backups: capped per server; oldest backups are deleted automatically when the cap is reached.
  • Warnings: subject to administrator-configured decay, and manually removable.
  • In-memory caches: cleared within minutes or on restart.

8. Data Deletion

You can request deletion of your personal data at any time by emailing [email protected] (subject: “Data Deletion Request”) with your Discord username/ID, or through our Discord support server. We will verify the request and complete deletion within 30 days, except for records we must keep by law (e.g., billing records) or for legitimate security purposes — and we will tell you if anything is retained and why.

When PeakBot is removed from a Discord server, that server’s cached data is cleared immediately and its stored data is deleted within a reasonable period, consistent with Discord’s Developer Policy. Server administrators can also delete specific data themselves at any time through the dashboard or bot:

  • reset XP/leveling for a user or the whole server;
  • delete warnings and moderation log entries;
  • delete tickets and their transcripts;
  • delete server backups, polls, giveaways, and events;
  • delete Roblox links and webhooks created through PeakBot;
  • disable any feature to stop its data collection going forward.

9. Cookies, Local Storage & Do Not Track

PeakBot sets one first-party cookie of its own:

  • peakbot_locale — remembers your language preference (1 year).

Google Analytics 4 sets cookies to distinguish users and sessions:

  • _ga and _ga_<ID> — analytics identifiers (expire after 2 years). We use GA4 for measurement only — not for advertising — with all advertising signals disabled via Google Consent Mode. Visitors in the EEA, UK, and Switzerland are asked for consent before these cookies are set and can decline; everyone can opt out with the Google Analytics Opt-out Browser Add-on or by clearing site data to be asked again.

We also use browser local/session storage (not cookies) for your sign-in token, cached profile, language, dashboard preferences, demo-mode flags, and a per-tab analytics session ID. This data stays on your device until you log out or clear your browser data.

Do Not Track: some browsers send a “Do Not Track” signal. There is no common industry standard for responding to it, and we do not respond to DNT signals at this time. Note that Google Analytics may collect information about your activity over time across our site; we do not permit third parties to collect personal information about your activity across other sites for advertising.

10. Your Rights

Regardless of where you live, we give you the right to access the personal data we hold about you, to correct it, to delete it (Section 8), to object to or ask us to restrict certain processing, and to receive a portable copy of data you provided. To exercise any of these, email [email protected]; we respond within 30 days (one month where GDPR applies).

If you are in the EEA, UK, or Switzerland, additionally:

  • our legal bases are listed in Section 3, and where we rely on legitimate interests you may object at any time;
  • where processing is based on consent, you may withdraw consent at any time without affecting prior processing;
  • you have the right to lodge a complaint with your national supervisory authority (Art. 77 GDPR) — though we’d appreciate the chance to resolve your concern first;
  • providing your Discord account data is necessary to create an account; the Service cannot be provided without it.

You can also limit collection at the source: disable individual bot features (stops that feature’s collection), leave servers that use PeakBot, or revoke PeakBot’s OAuth access in your Discord settings.

11. California Residents

We do not sell your personal information, and we do not share it with third parties for cross-context behavioral advertising. The categories of personal information we collect are described in Section 2; the categories of third parties that process it are in Section 4. You may review, correct, or request deletion of your information using the process in Sections 8 and 10 — these rights are available to all users, including California residents. Our Do Not Track disclosure is in Section 9. When we make material changes to this policy, we notify users as described in Section 14 and update the effective date at the top of this page.

Because we do not sell or share personal information for advertising, opt-out preference signals such as Global Privacy Control do not change how we process your data — there is nothing to opt out of.

12. International Data Transfers

We are a U.S. company and your data is processed in the United States, where our service providers are also located. Where data is transferred from the EEA, UK, or Switzerland, we rely on appropriate safeguards — our providers’ data processing agreements incorporating the European Commission’s Standard Contractual Clauses and, where applicable, their EU–U.S. Data Privacy Framework certifications.

13. Children

The Service is not directed to children under 13 (or the higher minimum age Discord requires in your country), and we do not knowingly collect personal information from them. If we learn we have collected personal information from a child below the applicable age, we will delete it and terminate the account. Parents or guardians can contact us at [email protected].

14. Changes to This Policy

We may update this policy as the Service evolves. If a change is material, we will notify you through the Service, our Discord server, or the contact details on your account before it takes effect, and we will update the effective date at the top of this page. Prior versions are available on request.

15. Contact

PEAK AGENCY LLC
Privacy contact: [email protected]
Discord: Discord support server

PEAK AGENCY LLC — Questions? Email [email protected] or join our Discord support server.

PeakBot is an independent product of PEAK AGENCY LLC and is not affiliated with, endorsed by, sponsored by, or created by Discord Inc. “Discord” is a trademark of Discord Inc.