GHUBKIT does not sell personal data or use it for advertising.
Optional Premium subscriptions are processed through MAIB. GHUBKIT processes the billing email and limited transaction records needed to manage the subscription, but does not receive or store your full card number, card expiration date, or CVV.
Scope and who we are
This Privacy Policy applies to the GHUBKIT Discord application, the website at ghubkit.com, and the GHUBKIT web control panel. The service is operated by Assiduous Solutions S.R.L. (Moldova company IDNO 1024600049921). In this policy, “GHUBKIT,” “we,” “us,” and “our” refer to that operator.
Discord is a separate service with its own privacy practices. Server owners and administrators also decide which GHUBKIT features to enable, which channels and roles to configure, and who may view information posted by the bot inside their server.
Information we process
Discord account and control-panel data
When you sign in with Discord, GHUBKIT requests the identify and guilds
OAuth scopes. We process your Discord user ID, username, global display name, avatar, the servers
returned by Discord, and server ownership or permission information needed to determine which
control panels you may access. We do not request your Discord email address.
The web control panel uses essential HTTP-only cookies. The OAuth state cookie lasts up to 10 minutes. The signed admin-session cookie may contain your Discord profile identifiers and Discord OAuth access and refresh tokens and lasts for up to 7 days, unless you log out earlier. A selected-server preference cookie may remain for up to 180 days. Theme and interface preferences may be stored locally in your browser.
Billing and subscription data
If you start a Premium subscription, you provide a billing email separately from Discord sign-in. GHUBKIT processes that email together with the selected offer, price, currency, recurring interval, subscription status and dates, payment status, internal order identifiers, and the MAIB payment and recurring-payment identifiers needed for purchase, renewal, cancellation, and refund handling. GHUBKIT may also process the requesting IP address and limited technical details required to secure and complete the payment flow.
Card details are entered on MAIB's payment page. GHUBKIT does not receive or store the full card number, card expiration date, or CVV. The billing email is associated with your subscription, sent to MAIB as part of payment processing, and may be used for payment confirmations and payment support. GHUBKIT also shows subscription and Premium status inside the signed-in product.
Server and configuration data
We process Discord server IDs and, where available, server names and icons; channel, message, role, and category IDs; installation and last-seen timestamps; permission-related information; and the settings selected by server administrators. This data allows GHUBKIT to publish and update the correct Discord resources without repeatedly creating duplicates.
Feature and member data
Depending on the features enabled by a server, GHUBKIT may process:
- Gaming sessions: session details, scheduled times, participant Discord IDs, display names, avatar URLs, selected positions, Going/Maybe/waitlist status, and action timestamps.
- Applications: application questions and answers, applicant identity and avatar information, reviewer identity, review decisions, reasons, and configured role or channel IDs.
- Feedback: feedback text, sender and recipient Discord IDs and display names, review status, and reviewer identity. “Anonymous” feedback is hidden from the recipient and normal server members, but GHUBKIT retains the sender identity temporarily for abuse prevention, limits, and authorized moderation review.
- Tickets: ticket owner ID, channel ID, status, and timestamps. When a ticket is closed, GHUBKIT may read the latest 100 messages in the ticket channel to create a text transcript in the server’s configured Discord log channel. Attachment files are not copied into the transcript, although their filenames may be listed.
- Leaderboards: player IDs and display names, star totals, voter and recipient IDs, week identifiers, timestamps, and an optional vote comment.
- Team Spaces: team names, owner and manager identities, local access or block rules, Discord channel IDs, and activity timestamps used for configured inactivity cleanup.
- Temporary voice rooms: room owner and participant IDs, trusted, invited, blocked, pending, or split-team member IDs and display names, room settings, and voice/channel lifecycle data. GHUBKIT does not record voice audio or video.
- Anti-spam moderation: when explicitly enabled by a server and technically available, GHUBKIT processes message IDs, author IDs, message text, mention targets, attachment counts, and timing patterns in memory to detect bursts. It may delete messages, apply a Discord timeout, and post a short review copy to the server’s configured private review channel. GHUBKIT does not use message content for advertising or train artificial-intelligence models on it.
- Member warnings: when enabled by a server, GHUBKIT stores the server, member, and moderator Discord IDs, the moderator-provided reason, and creation and expiry times. Warning storage does not copy surrounding Discord messages, channel snapshots, usernames, or display names.
- Moderation safety limits: when configured by a server, GHUBKIT stores the selected moderator or role Discord IDs and their configured allowances. When a covered moderator uses a restricted action, GHUBKIT stores the server and moderator Discord IDs, the action category, its active daily, weekly, or monthly UTC reset window, a separate running total, and its expiry time. Each counter is a minimal aggregate; it does not store the affected member, reason, command content, or action history.
- Join and leave notifications: when enabled by a server, GHUBKIT processes the event type and time, Discord user ID, display name, username, avatar URL, and configured destination in a bounded in-memory gateway queue. New events are delivered on a best-effort basis and do not create a per-member Firestore delivery record. Delivery is not started for events that are already five minutes old, although a Discord request started earlier may finish later. Events may also be dropped during restarts, Discord outages, or traffic bursts. Operational outbox records created by older GHUBKIT versions are removed during the best-effort cutover or under their existing retention and cleanup rules.
- Deletion requests: the authenticated requester’s Discord user ID, current display name and username, the optional request message, submission time, review status, review time, and reviewing administrator ID. Only authorized GHUBKIT platform administrators can access this inbox.
Technical and operational data
Our hosting environment may generate security and diagnostic logs containing request timestamps, IP addresses, user-agent information, endpoint paths, error details, and operational identifiers. We use these records to operate, secure, troubleshoot, and protect the service. GHUBKIT does not currently use a third-party advertising or behavioral analytics SDK.
How we use information
We process information to:
- authenticate users and enforce server, role, ownership, and administrator permissions;
- provide the feature requested through a command, component, dashboard action, or server configuration;
- create, update, reuse, archive, or delete Discord channels, messages, roles, and other managed resources;
- prevent spam, fraud, abuse, duplicate actions, unauthorized access, and capacity-limit bypasses;
- create and renew subscriptions, verify payments, stop renewals, handle refunds, and grant or remove Premium access;
- maintain service reliability, investigate failures, measure aggregate usage, and control infrastructure cost;
- send operational notifications and respond to support, privacy, or legal requests; and
- comply with applicable law, Discord’s developer requirements, and valid legal process.
Where data-protection law requires a legal basis, processing may rely on performance of the service, legitimate interests in operating and securing GHUBKIT, the instructions or choices of server administrators, consent where applicable, and compliance with legal obligations.
How long we keep information
We keep data only for the feature lifecycle, security needs, legal obligations, or the periods below. Cleanup may take additional time where retries, backups, provider systems, or legal preservation are involved.
Pending applications remain available until they are reviewed, deleted, or the related server data is cleaned up. Ticket database records are deleted when a ticket closes. A generated transcript is uploaded directly to the server’s configured Discord log channel and may remain there until a server administrator deletes it under that server’s own retention practices.
Historical vote and weekly-usage records are pruned as new weeks are processed, while current leaderboard totals may remain until a server administrator resets or deletes them. Temporary voice-room state is kept for the active room lifecycle. Team Space and configuration data remains until deleted, automatically cleaned under configured inactivity rules, or removed with the server’s GHUBKIT data.
When GHUBKIT is removed from a Discord server, guild-scoped feature data becomes eligible for automated cleanup after a 7-day grace period. Limited installation, purge, security, or capacity records may be kept longer when necessary to preserve system integrity and document that cleanup occurred.
Your choices, access, and deletion
You may:
- log out of the web control panel to remove the GHUBKIT session cookie;
- revoke GHUBKIT’s OAuth authorization from your Discord account settings;
- use available leave, archive, delete, reset, or cleanup controls inside Discord or the control panel;
- stop future Premium renewals from the signed-in billing interface;
- ask a server owner or administrator to remove server-controlled records or Discord messages; and
- request access to or deletion of personal data controlled by GHUBKIT.
Use the authenticated deletion-request form below to contact the GHUBKIT administrator team. The request is connected to the Discord account used to sign in, so you do not need to type or expose your user ID. You may add relevant server IDs in the optional note. During the open beta, requests are reviewed and handled manually. New join/leave delivery events are not stored as per-member Firestore records. Legacy join/leave outbox records are included when a relevant guild or user-scoped deletion is processed, unless a record has already been removed by automated TTL or legacy cleanup. Automated account-wide deletion is still in development and is not performed by this form. We may need to verify scope or administrator authority before acting, and we may retain limited information when required by law, security, dispute resolution, or to prevent abuse.
Data already posted into Discord—including review logs, audit messages, application messages, or ticket transcripts—is also controlled through the relevant Discord server and Discord’s platform. A server administrator may need to delete those Discord messages separately.
Security
GHUBKIT uses access controls, permission checks, HTTP-only cookies, signed session data, secure transport, bounded background processing, and restricted administrator surfaces to reduce unauthorized access or misuse. No system is completely secure, and we cannot guarantee absolute security. If a suspected issue affects your personal data, use the authenticated request process below. Never include bot tokens, passwords, or other secrets in the optional request message.
International processing
Discord and Google Cloud operate globally, and MAIB processes information needed for payments. Information may therefore be processed in countries other than your own. Where applicable, we rely on the safeguards and transfer mechanisms provided by our service providers and applicable law.
Children
GHUBKIT is intended for people who are old enough to use Discord under Discord’s Terms of Service and local law. We do not knowingly operate GHUBKIT for children below the minimum permitted age. The authenticated request process below may be used to request deletion of data associated with the signed-in Discord account.
Changes to this policy
We may update this policy as GHUBKIT develops, including when new integrations, or materially different data practices are introduced. The “Last updated” date will change when revisions are published. Material changes may also be announced through the website or the Discord application profile.
Submit a deletion request
Only the Discord account owner can submit a request through this form. GHUBKIT uses the signed-in Discord identity as the authoritative requester and permits one active request per account.
During the open beta, this form creates a private request for manual review by the GHUBKIT team. It does not automatically scan or delete every record associated with the account.