← Back to Dashboard
Privacy Policy
Last updated: June 14, 2026
1. Data Controller
Cassie ("the Bot") is operated by an individual developer. For privacy-related inquiries, contact the operator through the support server or via Discord direct message. Responses will be provided within 30 days.
2. Lawful Basis for Processing
We process your personal data under the following lawful bases as defined in Article 6 of the GDPR:
- Legitimate Interest (Article 6(1)(f)) — for core Bot functionality: storing guild settings, tags, reminders, todo lists, AFK status, command overrides, and command usage statistics. This processing is necessary to provide the service you intentionally use, and it does not override your fundamental rights and freedoms.
- Consent (Article 6(1)(a)) — for AI chat history and message content used by AI features. You provide consent by actively using these features. You may withdraw consent at any time by ceasing to use AI features or requesting deletion of your data.
- Legal Obligation (Article 6(1)(c)) — where we are required to retain or disclose data by applicable law (e.g., reporting illegal content to authorities).
3. Data We Collect
Cassie collects and stores the following data when you use its features:
- Discord User ID — used to identify you for custom prefixes, reminders, AFK status, todo lists, command usage statistics, chat history, and per-user command overrides.
- Discord Guild (Server) ID — used to store server-specific settings such as custom prefix, disabled commands, tags, and allow/deny overrides.
- Discord Channel ID — used for channel-specific command overrides and settings.
- Discord Role ID — used for role-based command overrides.
- Command Usage Data — we record which command was used, in which server, by whom, and when. This is used for statistics and diagnostics.
- Message Content — when you use AI/chat features, the messages you send are stored to provide conversational context. Retained until you request deletion.
- User-Created Content — tags, reminders, and todo list items you create are stored so they can be retrieved later.
- AFK Status — your AFK message is stored to notify others when you are away.
- Announcement Preferences — which servers have subscribed or opted out of announcement broadcasts, and when they were last notified.
4. Web Dashboard Data
When you log in to the web dashboard via Discord OAuth, we collect:
- Your Discord User ID, username, and avatar URL
- Your Discord access token (used only during your session to fetch your guild list)
This data is stored in an encrypted session cookie and is deleted when you log out or after 7 days of inactivity. We do not use tracking cookies, analytics cookies, or any third-party cookies on the dashboard.
5. How We Use Your Data
Your data is used exclusively to provide the Bot's functionality:
- Processing commands and applying your settings
- Remembering your custom prefix, reminders, tags, and todo lists
- Enforcing command restrictions (disable/enable per server, channel, role, or user)
- Displaying statistics on the web dashboard
- Improving the Bot based on usage patterns (aggregated, not individual)
6. Data Storage & Retention
All data is stored in a PostgreSQL database on the same machine running the Bot. We retain data for as long as it is needed to provide the Bot's functionality:
- Guild settings, tags, reminders, todo lists, time capsules, AFK status, command overrides, command usage statistics, announcement preferences — retained indefinitely until you request deletion or remove the Bot from your server.
- Web dashboard session cookies — retained for up to 7 days of inactivity, or deleted on logout.
You may request deletion of your data at any time (see Section 11). Data needed for ongoing investigations (e.g., reported illegal content) may be retained longer until the matter is resolved.
7. Data Sharing
We do not sell, trade, or share your personal data with third parties. Data is only accessible to the Bot operator for support, maintenance, and legal compliance purposes. We do not use third-party analytics, advertising, or tracking services.
8. International Data Transfers
The Bot and its database are hosted on servers located in the United States. If you access the Bot from the European Economic Area (EEA), the United Kingdom, or other regions, your personal data will be transferred to and processed in the United States. Such transfers are protected by appropriate safeguards, including the EU-US Data Privacy Framework and Standard Contractual Clauses where applicable.
9. Data Security
We take reasonable measures to protect your data, including encrypted database connections, secure session handling, and restricted access to the server. However, no method of electronic storage or transmission is 100% secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, inform affected users.
10. Your Rights Under GDPR
As a data subject in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation:
- Right of Access (Article 15) — request a copy of the personal data we hold about you.
- Right to Rectification (Article 16) — request correction of inaccurate or incomplete data.
- Right to Erasure (Article 17) — request deletion of your data, also known as the "right to be forgotten."
- Right to Restriction of Processing (Article 18) — request that we stop processing your data while maintaining it in storage.
- Right to Data Portability (Article 20) — request your data in a machine-readable format (JSON) to transfer to another service.
- Right to Object (Article 21) — object to processing based on legitimate interest, including processing for analytics or service improvement.
- Right to Withdraw Consent (Article 7) — where processing is based on consent, you may withdraw at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us through the support server or via Discord DM. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection supervisory authority if you believe your rights have been violated.
11. How to Request Deletion
To request full deletion of your data:
- Option 1: Send a direct message to the Bot operator on Discord detailing your request.
- Option 2: Join the support server and open a ticket.
Please include your Discord User ID (right-click your profile → Copy ID) to help us locate your data. We will confirm receipt within 72 hours and complete the deletion within 30 days. Note that some data may be retained if required by law (e.g., records of illegal content reports).
12. Children's Data
Cassie is not intended for children under 13, in line with Discord's Terms of Service. However, the age of digital consent under GDPR varies between 13 and 16 depending on the EU member state. If you are below the age of digital consent in your country, you must have parental permission to use the Bot. We do not knowingly collect data from children below the applicable age. If we become aware that a child's data has been collected without appropriate consent, we will delete it promptly.
13. Contact
For privacy-related inquiries, deletion requests, or any questions about this policy:
- Support server: Join the server
- Discord DM: Message the Bot operator directly
14. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted here and the "Last updated" date will be revised. If significant changes are made, we will notify users via the support server. Continued use of the Bot after changes constitutes acceptance of the updated policy.