Privacy Policy
Last updated: 2026-09-25
MohiBot is a Discord bot and dashboard run by one person, not a company. This page is written from the code: every item below is a real table or field in the bot's database, and nothing here is boilerplate hiding something.
Where the data lives
Everything is stored in a single SQLite database file on the service's private server. Nothing is sold, rented, or shared with advertisers, and the dashboard carries no analytics or tracking product of any kind.
What the bot stores
These are all of the tables that hold anything about a person or a server, exactly as they exist in the code:
- Servers: the server id and name, when the bot joined or left, and every setting you configure in the dashboard (channel and role ids, welcome and rules text, shortcut commands, stream-alert subscriptions, ticket and protection settings, your Star Citizen org id, music preferences).
- Logs: the event type, the id and tag of who did it and who it happened to, the channel, a summary, and an extra data blob. For a deleted or edited message that data includes part of the message text (up to 300 characters for a deletion, 200 before and after for an edit).
- Warnings: the member's id and tag, the moderator's id and tag, the reason, and the time.
- Leveling: a member's id, tag, and XP counter, per server.
- Tickets: who opened and who claimed it, the subject, status and timestamps, and the full conversation transcript when transcripts are switched on.
- Giveaways: the prize and timing, and the ids and tags of everyone who entered and who won.
- Star Citizen verification (premium): your Discord id and tag, your RSI citizen handle, whether you are in the org, who linked you, timestamps — and your PREVIOUS server nickname, because verifying renames you to your handle and unlinking has to be able to put the old name back.
- Dashboard seats: the id and tag of everyone granted access, their role, and who added them.
- Structure snapshots: automatic and manual copies of your roles, channels and permission overwrites, used to restore a server after a nuke.
- Backups (premium): on top of the structure, these copy message text, attachment URLs, author display names and avatar URLs from the channels you pick. The last ten backups per server are kept and older ones are deleted automatically.
- Premium: the server id, the expiry date, how it was granted, the PayPal subscription or order id, the Discord id of whoever paid, and which reminder was last sent to them.
- Payment orders: the PayPal order id, the server, the buyer's Discord id, the plan, the amount, and the state of the transaction.
- Two-factor authentication: your Discord id and the TOTP shared secret for your authenticator app, if you choose to enable it.
- Alert state and music cards: the last stream or video seen for each channel you follow, and the message ids of now-playing cards, which expire and are deleted on their own.
- Reviews: if you own a server and choose to write one, we store your server's name and icon, your Discord display name, the star rating and your text — and publish them on the site's front page. This is entirely optional, it only happens because you asked for it, and you can delete it from the same page at any time.
- A log of REFUSED requests — the only place an IP address is kept. When the API turns a request away (a failed login, a wrong 2FA code, an attempt to reach a server you do not have access to, or someone scanning for endpoints) one row is written with the kind of refusal, the IP, the path, the time and a repeat count. Successful requests are never logged, only the most recent 3,000 rows are kept, and older ones are deleted automatically. It exists to reveal break-in attempts, not to follow you around.
Message content, plainly
The bot stores message text in exactly three situations: part of a message when it is deleted or edited (in the log), the full ticket conversation when a ticket is closed with transcripts on, and whatever a server owner deliberately copies into a backup. There is no general archive of your chat.
AI moderation does read messages as they arrive, but it runs against a self-hosted model on the service's own infrastructure — no message content is ever sent to a third-party AI provider, and nothing from that check is stored unless it flags something, which lands in the log like any other moderation event.
Payments
Payment happens entirely at PayPal. The bot never sees or stores your card details, your name, or your PayPal email — all it receives is the transaction id, the amount and its status, which it ties to the Discord id of whoever clicked buy and the server they bought for.
The dashboard in your browser
You sign in with Discord. Your session token and language choice are kept in your browser's local storage (mohibot_token and mohibot_lang), and an order id is held in session storage while a checkout is in flight. There are no advertising cookies and no tracking.
The dashboard loads the Cairo webfont from Google Fonts, which means Google sees your IP address when the page opens. The site itself is hosted on Cloudflare Pages, which likewise sees incoming requests.
Who can see it
A server's data is visible to anyone with manage rights in that server or a seat on its dashboard: the log, warnings, tickets, Star Citizen links and backups. Ordinary members do not see those pages.
The operator can technically reach all of it. That access is used only to run, maintain and debug the service.
Third parties
- Discord — the platform itself; everything passes through it.
- PayPal — payment processing.
- Twitch, YouTube and Kick — their public APIs are polled for the channels you follow; nothing about your members is sent to them.
- Roberts Space Industries — a public profile page is read to verify a handle.
- Cloudflare Pages and Google Fonts — hosting for the dashboard and its font.
Retention and deletion
Some data is cleaned up on its own: the last ten backups and a limited number of structure snapshots are kept per server, and music cards expire by themselves. Logs, warnings, levels and tickets are kept until something deletes them.
Honestly: removing the bot from a server today records the departure date but does not automatically erase that server's rows. If you want a server's data or your own data deleted, open a support ticket from the dashboard and it will be deleted by hand.
Age
The service follows Discord's own rules, which require users to be at least 13 (older in some countries). The bot is not aimed at children and does not knowingly collect data about them.
Changes and contact
Any change to what is stored is written here and the date at the top is updated with it. For questions or deletion requests, open a support ticket from the dashboard.