Privacy Policy
Effective date: 24 August 2026
Last updated: 8 September 2026
Version: 1.1
This Privacy Policy explains how the independently operated Discord bot blood collects, uses, stores, shares, and deletes information. The service is operated by the blood Development Team (“blood,” “we,” “us,” or “our”). For data-protection questions or requests, use the contact methods in Section 16.
blood is a third-party Discord application. Discord separately processes information under the Discord Privacy Policy. Server owners and administrators also control how their servers, channels, permissions, logs, tickets, and moderation records are used. In many situations, a server owner or administrator independently determines why a server-level feature is enabled and who may view its output.
1. Scope
This Policy applies when you visit blood.best, interact with blood, use a blood command or component, appear in a server where an authorized administrator has enabled a blood feature, receive a functional blood direct message, or contact blood support.
Website verification
blood.best uses Cloudflare Turnstile to help prevent automated abuse. Cloudflare processes browser and network signals to perform this check under its Privacy Policy. Our server validates the verification result and sets a signed, first-party security cookie. This cookie is not used for advertising, is inaccessible to page scripts, and its proof is valid for up to eight hours. It is a session cookie, although browsers that restore sessions may preserve it. The public bot status page and this policy remain available without completing verification.
It does not govern Discord’s own processing, a server administrator’s independent use of Discord messages or exported information, or a third-party site you choose to visit.
2. Information blood may process
blood processes only the categories needed for enabled features, security, support, and reliable operation.
2.1 Discord identifiers and server metadata
- Discord user, guild, channel, category, role, message, webhook, emoji, sticker, invite, and application identifiers;
- guild names, channel names, role names, role colors, role hierarchy and permissions;
- usernames, global/display names, nicknames, avatars, banners, public badges, account creation time, server join time, and boost status;
- member roles, permission state, presence category when available, and voice-channel membership metadata;
- message timestamps, links, reactions needed by configured features, and command invocation context.
2.2 Command, message, and user-provided content
- commands, arguments, modal submissions, button/select interactions, aliases, tags, embeds, templates, autoresponders, autoreacts, filters, sticky messages, ticket content, suggestions, polls, giveaway entries, reminders, AFK reasons, notes, proofs, and configuration values;
- deleted or edited message text, author information, attachment metadata or cached attachment copies, and embedded-message JSON when snipe or server logging features apply;
- birthday month/day, timezone, weather location, linked Roblox username/ID, media URLs, music search queries, cryptocurrency transaction identifiers, and other information voluntarily supplied to a relevant command;
- support requests and the information you provide while asking for help or exercising a legal right.
Do not provide blood with passwords, Discord tokens, payment-card data, protected health information, government identifiers, or other sensitive information unless a future feature expressly and lawfully requires it.
2.3 Moderation, safety, and administration records
- warnings, bans, temporary bans, kicks, mutes, timeouts, jails, unmute/unban actions, reasons, durations, responsible moderator IDs, case history, proof URLs or attachments, moderation notes, and removal/edit audit history;
- anti-nuke, anti-raid, honeypot, command restriction, ignore, fake-permission, whitelist, blacklist, lockdown, and security-event configuration or records;
- saved role snapshots, forced nicknames, temporary roles, role restoration, ticket access, and setup state;
- message counts, voice-session timestamps, invite attribution, last-seen activity, display-name history, and other records needed for the specific information, logging, levels, or moderation feature.
2.4 Technical and operational information
- timestamps, error messages, stack traces, extension/runtime state, rate-limit events, process-reload state, database integrity results, and identifiers needed to diagnose a failure;
- local database files, configuration files, generated embed files, logs, and operator-created recovery backups;
- network request details necessarily disclosed to Discord or a third-party provider when a command requests that provider.
blood does not use cookies through the Discord bot itself. If a standalone blood website or account system is introduced later, this Policy will be updated before additional tracking or account data is used.
3. Voice and music privacy
blood’s music system is designed to connect to voice channels with self-deafening enabled and self-muting disabled, allowing blood to transmit music without listening to members.
blood does not need to receive, record, store, transcribe, or analyze member voice audio. Voice-related records are limited to metadata needed for features such as VoiceMaster and server logs-for example, user/channel IDs, join and leave times, temporary-channel ownership, access settings, and mute/deafen/connect state.
Music titles, search terms, and supplied source URLs may be sent to the relevant source or metadata provider to locate playable audio. blood does not sell or use those queries for advertising.
4. Sources of information
Information may come from:
- Discord’s API and events made available according to the bot’s approved intents and server permissions;
- you, when you use a command, component, modal, ticket, reminder, or support channel;
- server owners, administrators, and moderators who configure blood or create server records;
- public third-party services queried at your request;
- blood’s own operational events, such as a command result, moderation case, security trigger, or error log.
5. Why blood processes information
blood uses information to:
- execute commands and provide requested bot features;
- remember guild and user preferences or scheduled tasks;
- provide moderation records, role restoration, tickets, logs, security protection, and auditability;
- resolve media, music, weather, dictionary, profile, game, cryptocurrency, and other information requests;
- prevent abuse, enforce the Terms of Service, investigate security incidents, and maintain a global server blacklist;
- diagnose errors, recover from restarts, protect data integrity, and improve reliability;
- respond to support, privacy, legal, and enforcement requests;
- comply with law and Discord’s platform requirements.
blood does not use Discord message content to train artificial-intelligence or machine-learning models. blood does not profile users for employment, housing, insurance, credit, advertising, or eligibility decisions.
6. Legal bases where GDPR or similar law applies
Depending on the feature and context, processing relies on one or more of:
- performance of a service or steps requested by you, such as executing a command, reminder, music request, or ticket action;
- legitimate interests, including operating and securing blood, preventing abuse, maintaining records expected for moderation, debugging errors, and protecting users and servers, balanced against affected users’ rights;
- consent or your voluntary action, particularly for optional user-supplied preferences or a requested direct message, where consent is the appropriate basis;
- compliance with legal obligations and establishment, exercise, or defense of legal claims.
Server owners and administrators are responsible for identifying an appropriate basis for their own decision to enable server logging, moderation, tracking, or automation features. Where processing relies on consent, consent may be withdrawn without affecting earlier lawful processing.
7. Automated and administrator-configured actions
blood can automatically react to configured events-for example, anti-nuke or anti-raid thresholds, filters, autoroles, timers, reminders, mute/jail expiry, VoiceMaster cleanup, and security restrictions. These actions follow rules selected by the server’s authorized administrators or blood’s security settings.
An affected user may ask the relevant server administrators to review a server-level action. Appeals concerning a blood-wide blacklist or blood’s own enforcement may be submitted through a Support Ticket. blood does not use automated decisions for credit, employment, housing, insurance, or similarly significant off-platform eligibility decisions.
8. How information is shared
blood does not sell, rent, or trade personal data. blood does not disclose Discord API data to data brokers, advertising networks, or monetization services.
Information may be disclosed only as needed to:
- Discord, because all bot events, commands, messages, embeds, attachments, voice connections, and direct messages operate through Discord;
- server administrators and authorized channel members, when an enabled feature posts a log, ticket, moderation record, leaderboard, reminder, or other response in Discord;
- source and lookup providers, when you invoke a command that requires an external request;
- service providers or maintainers assisting with secure operation, hosting, debugging, or recovery and bound to use information only for that purpose;
- authorities or affected parties where reasonably necessary to comply with law, protect rights or safety, investigate fraud/abuse, or respond to a valid legal request;
- a successor operator, if blood is reorganized or transferred, subject to Discord’s rules, continued protection, and notice where required.
9. External services
Depending on the command, blood may send a search term, public username, public identifier, transaction hash, location query, URL, or similar requested value to an external service. Providers currently or potentially used by implemented features include:
- Discord and Discord’s CDN;
- YouTube/Google, Spotify oEmbed, yt-dlp-supported media sources, and FFmpeg processing;
- Open-Meteo weather and geocoding;
- TikTok, Roblox, GitHub, Mojang/Minecraft, Steam, Xbox, Riot/Valorant, Telegram, Cash App, Snapchat, osu!, and public profile pages where the related command is used;
- DictionaryAPI, Urban Dictionary, CoinGecko, Blockstream, Blockchair, Cloudflare’s public Ethereum endpoint, and related public information services;
- nekos.best for requested roleplay media;
- jsDelivr, GitHub raw assets, Twemoji, and Discord CDN for public image/badge/emoji assets;
- screenshot or rendering providers used by a command, where clearly relevant to that request.
Those providers receive the network information normally associated with a server request and the value necessary for the lookup. Their own privacy policies apply. blood does not send them your Discord password or bot token. Avoid using an external lookup command if you do not want its query sent to that provider.
10. Retention
Retention depends on the feature:
- Snipe records: deleted and edited message records stored for snipe features expire after approximately two hours and are checked for deletion regularly.
- Removed servers: when blood is kicked, banned, or otherwise disappears from a guild, guild-scoped database rows and that guild’s saved embed JSON are retained for 24 hours to permit accidental-removal recovery. If blood is not re-added, the retention service deletes that guild-scoped data after the period. Re-adding blood during the period cancels scheduled deletion.
- Discord log messages and attachments: copies posted into a guild’s log or ticket channels remain in Discord until deleted by someone with authority or by Discord. The guild controls access to those channels.
- Feature configuration and records: aliases, moderation history, role snapshots, tickets, levels, reminders, birthdays, timezones, templates, security settings, and similar records remain while needed for the enabled feature, until removed/reset, until their scheduled completion/expiry, or until guild deletion applies.
- Operational logs and backups: local diagnostic logs and recovery backups may remain until manually rotated or deleted. They are kept for continuity, troubleshooting, security, and recovery and are not intended for public distribution.
- Global security records: a server blacklist and evidence needed to prevent repeated abuse may be retained until reviewed, removed, no longer necessary, or legally required to be deleted. The global blacklist is intentionally not automatically erased merely because blood leaves the listed server.
- Legal and dispute records: limited information may be retained longer where necessary for fraud prevention, safety, legal compliance, or establishment, exercise, or defense of claims.
Deletion from blood does not automatically delete copies already posted in Discord, cached by Discord, exported by a server administrator, or held by an external provider.
11. Data security
blood uses access controls, Discord permission checks, restricted log channels, input validation, bounded external requests, local SQLite storage, backups, and operational safeguards intended to protect availability and data. Access to production files and backups is limited to blood’s operator/development environment.
No system is perfectly secure. Users should not place secrets or unnecessary sensitive data in blood. If we discover unauthorized access affecting Discord API data, we will investigate, mitigate it, and notify Discord, affected users, or authorities when required.
12. International processing
Discord and external providers may process information in countries other than your own. Their terms and transfer safeguards apply to their processing. blood’s operator will use required safeguards for protected international transfers where applicable and will provide further information through a privacy request when legally required.
13. Children
blood is not directed to anyone below Discord’s minimum age or a higher minimum digital-consent age required in their country. Do not use blood if you are not eligible to use Discord. If we learn that blood holds personal data collected unlawfully from an ineligible child, we will take reasonable steps to delete it.
14. Your choices and rights
You may have rights to:
- request access to and a copy of personal data about you;
- correct inaccurate or incomplete information;
- request deletion or restriction of processing;
- object to processing based on legitimate interests;
- withdraw consent where consent is the basis;
- request portability where applicable;
- complain to your local data-protection authority;
- receive information about relevant automated processing and request human review where applicable.
Some information can be managed directly with blood commands, such as clearing name history or removing optional settings. Server-level Discord messages may need to be handled by that server’s administrators.
Submit a request through a # Tickets. Include your Discord user ID, identify the server and information involved, and state the right you want to exercise. We may request reasonable proof of account or server ownership, but will never ask for your password or token.
Where GDPR applies, we will respond without undue delay and ordinarily within one month. That period may be extended where legally permitted due to complexity or request volume, with notice. A request may be limited or refused where law permits-for example, when identity cannot be verified, another person’s rights would be harmed, retention is legally required, or a request is manifestly unfounded or excessive.
15. Changes to this Policy
blood’s features and legal obligations may change, including if optional paid services, a website, new providers, or new categories of data are introduced. We may update this Policy and will change the date and version above. Material changes will be announced or otherwise made reasonably visible when practical; urgent legal, safety, security, or Discord-required changes may take effect immediately.
Continued use after an updated Policy takes effect means the updated Policy applies to later processing. Where consent is legally required for a new purpose, continued use alone will not replace the required consent.
16. Contact
The data-control contact for blood is the blood Development Team. Privacy requests, security reports, complaints, and questions may be submitted through:
- Support server: discord.gg/shard
- Support tickets: # Tickets
If you believe your rights were not respected, you may also complain to the data-protection authority responsible for your location. Do not include passwords, account tokens, payment-card information, or unnecessary sensitive information in a request.