Privacy Policy
Last updated: 12 July 2026
A moderation bot has to read messages to moderate them. This policy says plainly what ModShield looks at, what it keeps, what it does not keep, and the one case where a message leaves our systems. Operated by Deloxity, LLC.
1. Who decides what
For your dashboard account, we are the data controller. For the moderation of a server or group, the administrator who enables the bot decides which filters run and what they do β we process messages on their instructions, as their processor. If you are a member of a moderated community, your first point of contact is that community's administrators.
2. What we process
Messages (read, not archived)
To run a filter, the bot must look at the message: its text, its links, its attachments' metadata, the author and the channel. This happens in memory, as the message arrives. We do not build an archive of your community's conversations, and we do not store message content as such. Short-lived counters (for example, a sliding window used to detect a flood burst) are held in memory and lost on restart.
Moderation records (stored)
When the bot acts, it records what it did, so that you can audit and reverse it:
- Strikes β the platform user id, the server, a count, a short reason (for example βadvertisingβ), and timestamps.
- Cases β a numbered mod-log entry: the user, the moderator, the action, a short reason, the time, and any duration.
- Quarantine records β the roles a member had before being jailed, so they can be given back on release.
- Server settings β your filter configuration, allowlists and exemptions.
These records contain identifiers and short reasons β not transcripts of conversations.
Dashboard accounts
- Your email address (if you register with one) and a password hash β we never store the password itself.
- Linked platform identities you choose to connect: the provider (Discord, Telegram, Google, GitHub), your user id there, and your username.
- The servers and groups you administer, so the dashboard can show them to you.
- Teams you create or join, and your role in them.
- A login session, held in memory and expiring automatically.
3. AI moderation β the one case where a message leaves us
If a server administrator switches AI moderation on, the text of a message that passes the pre-filters is sent to a third-party AI provider so it can be classified. That provider processes it under its own terms. This is the only feature that sends message content outside our systems.
- It is off by default and must be enabled per server by an administrator.
- Short and trivial messages are filtered out before any call is made, and a hard daily cap limits how many messages can ever be sent.
- Only the message text is sent β not your server's history, not your member list.
- The classification result (flagged or not, a category, a confidence) is used to decide the action; we do not retain the message content.
If you do not want message content leaving our systems, leave AI moderation off. Every other filter runs entirely on our servers.
4. Why we process it
- To provide the moderation you configured (contract performance, GDPR Art. 6(1)(b)).
- To authenticate you and keep accounts secure.
- To keep the Service stable and prevent abuse of it (legitimate interests, Art. 6(1)(f)).
- To comply with legal obligations.
We do not sell your data. We do not use it for advertising. We do not profile your members.
5. Where it is stored, and for how long
Data is stored on servers located in Germany (European Union), encrypted in transit, with access restricted to the operators of the Service.
- Moderation records stay until you remove them β clearing a member's strikes or releasing them from quarantine deletes the corresponding record β or until the server stops using the Service.
- Strikes decay on the schedule you configure, so a past offence does not follow a member indefinitely.
- Sessions expire automatically and are never written to disk.
- Account data is kept while the account exists.
6. Third parties
- Discord and Telegram β the platforms the bot operates on. Their handling of your data is governed by their own policies.
- The AI provider β only where AI moderation is enabled (see section 3).
- Cloudflare β serves this website and the dashboard, and processes connection metadata (such as IP addresses) for security and delivery.
- A payment provider β only if and when paid plans are introduced. Card details would be handled by that provider and never stored by us.
This marketing website sets no cookies, runs no analytics and carries no advertising.The dashboard uses a single necessary cookie: your login session.
7. Your rights
Depending on where you live, you may have the right to:
- access a copy of your personal data (GDPR Art. 15; CCPA Β§1798.100);
- have it corrected (Art. 16);
- have it erased (Art. 17; CCPA Β§1798.105);
- restrict or object to processing (Arts. 18β21);
- receive it in a portable form (Art. 20);
- withdraw consent, without affecting processing done before you withdrew it (Art. 7(3)).
To exercise a right, write to [email protected]. We respond within the timelines the law in your jurisdiction requires. If you are a member of a moderated community and your request concerns that community's moderation records, we may need to refer you to its administrators, who decide what is processed there.
8. International transfers
Deloxity, LLC is established in the United States while the Service's data is stored in Germany (European Union). Where personal data is transferred outside the EEA β to us, or to a processor such as an AI provider β the transfer relies on an adequacy decision where one applies, or otherwise on Standard Contractual Clauses. A copy is available on request at [email protected].
9. Children
The Service is not directed at children under 16 and we do not knowingly collect their personal data. If you believe a child has provided us data, contact [email protected] and we will delete it without undue delay.
10. Complaints
EU/EEA residents may lodge a complaint with a supervisory authority (GDPR Art. 77), in the member state of their residence, place of work, or where the alleged infringement took place.
11. Changes
We may update this policy to reflect changes in the Service, the law, or our practices. Material changes will be communicated as required by applicable law.
12. Contact
Deloxity, LLC1111B S Governors Ave STE 48433
Dover, DE 19904
United States
Privacy: [email protected]
Support: [email protected]