Legal
Privacy policy
Last updated
How SeshBot and SeshTunes handle information, in the order you're most likely to need it.
1. Introduction
This Privacy Policy describes how SeshBot and SeshTunes collect, use and protect information — both inside Discord servers and on our websites, seshbots.com and seshtunes.com. It applies to anyone who uses the bots, signs in to a dashboard, or simply visits the sites.
2. What we collect
We store what a feature needs to work, and nothing we have no use for. In practice that falls into five groups.
- Accounts and servers: your Discord user ID, the servers a bot is in, and each server's configuration — DJ roles, enabled music sources, 24/7 mode and similar settings.
- Music activity (SeshTunes): when a track is played we record its title, artist, link, source, artwork and length, the time it played, and the Discord ID and display name of whoever requested it. This powers listening history, the replay button and server stats.
- Things you save: favourite tracks, saved playlists, bookmarks marking a position in a track, saved radio stations, tracks you suggest to a server's queue, and any response you give to an in-app feedback survey — each stored against your Discord user ID.
- Moderation and community activity (SeshBot): warnings and punishments including the reason a moderator wrote, support ticket records and — where a server turns transcripts on — the messages in a closed ticket, conversations with the AI assistant, message and voice activity counts used for XP and levels, the roles you held if you leave a server so they can be restored, and a safety score calculated when you join. Where a server owner creates a backup, that backup includes which roles each member had.
- Website and security logs: when you visit our sites we log the IP address, browser user-agent, requested path and a fingerprint derived from your browser headers. This is used to block automated scanners and abuse, and for nothing else. Signing in to a dashboard also stores a Discord access token so the dashboard can act on your behalf.
3. APIs and external services
- SeshTunes: streams audio and fetches metadata and cover art. Searching reaches YouTube, YouTube Music, Spotify, SoundCloud and Deezer. Playing a link you paste also reaches whichever service that link points to — Bandcamp, Twitch, Vimeo and others — because fetching the track is the only way to play it.
- SeshBot: checks links in messages against Google Safe Browsing. Its AI assistant sends your question to Google Gemini by default — a server may instead choose OpenAI, Groq or Mistral, or supply its own key. Image scanning runs on our own servers; pictures are never sent anywhere else.
- Both: Discord for authentication, MongoDB Atlas for storage, and Cloudflare in front of our websites.
- Payments: Stripe, and only if you choose to support us. Nothing about using either bot involves it. Section 6 sets out exactly what Stripe handles and what reaches us.
4. Data sharing
We do not sell your data, and we do not share it for advertising or analytics. It is passed to the services in section 3 only to the extent a feature requires it — a search term goes to a music source in order to find the track you asked for. We may disclose data if we are legally required to.
5. How long we keep it
- Listening history: deleted automatically 30 days after a track is played.
- Queue suggestions: deleted automatically 7 days after they are made, whether or not a DJ acted on them.
- Support ticket transcripts: deleted automatically 18 days after the ticket closes, and only kept at all if the server enabled them.
- AI conversations: only the few most recent exchanges are kept as context. A server manager can clear them at any time.
- Moderation records: kept while the bot is in the server, since they are that server's own moderation history.
- VPN and proxy block logs: deleted automatically after 30 days. Other security logs are kept until we no longer need them for abuse prevention.
- Favourites, playlists and feedback: kept until you delete them, or until you delete your data using section 7.
- Server settings: kept while the bot is in the server, so your configuration survives a restart or a brief removal.
- Support link clicks: when someone opens our support link we record a random reference, the server it came from, the time, and whether the device was mobile or desktop — no IP address and no browser identifier. Kept while we still need it to see whether asking for support is worth doing.
- Payment records: kept as long as tax and accounting rules require, which is longer than the rest of this list and outside our control.
- Voice session state: temporary, and cleared when the bot leaves the voice channel.
6. If you support us
Supporting SeshTunes is optional and everything works without it — see section 7 of our Terms. If you do, a payment involves personal data, so here is exactly what happens to it.
- We never see your card. Payment is handled entirely by Stripe. Card numbers do not pass through our servers and we could not store them if we wanted to.
- What we receive from Stripe: the amount, the date, the country, and the email address you gave them. If you started from a link inside Discord we also receive the reference that ties the payment to the server you clicked from.
- What we do with it: keep an accounting record, and recognise supporters where they have asked to be recognised. We do not sell it, and we do not use it to advertise to you.
Your Discord account is not automatically linked to a payment. If you never tell us who you are, the payment stays anonymous to us.
Deleting your data under section 7 removes the link between a payment and your Discord account. It cannot remove the payment record itself — we are required to keep those, and Stripe keeps its own copy under its own policy.
7. Your rights and data deletion
You can see and delete your own data at any time, without asking us first. Sign in to the SeshTunes dashboard and open Your Data — it acts on your own account immediately. You can also ask us through our Discord support server if you would rather we handled it.
- Access: download everything we hold about you, including retention periods.
- Erasure: permanently delete your favourites, listening history, feedback and personal playlists. This cannot be undone.
- Correction and objection: contact us and we will put it right.
Playlists saved to a server rather than to your account are treated as that server's content, since other members use them, so deleting your data does not remove them. We will tell you how many were kept, and a server manager can delete them from the server's playlist settings.
The self-serve controls above cover SeshTunes. For SeshBot there is no self-serve page yet — ask us in our Discord support server or email [email protected] and we will action it by hand. There is a plain-English summary of all of this on Your data.
8. Legal basis and where you live
We process your data on the basis of legitimate interest — running the features you chose to use, and keeping our services secure. Data is stored in MongoDB Atlas and may be processed outside your country.
SeshBot makes some automated assessments about people: it scores accounts when they join a server to catch raids and throwaway accounts, and keeps a reputation score based on past moderation actions. These inform moderators and can trigger a temporary restriction; you can object to them using the contacts in section 7.
If you are in the EU or UK, the GDPR gives you the rights described in section 7, and a right to complain to your local data protection authority. If you are in California, the CCPA gives you rights of access and deletion, also in section 7 — and we confirm again that we do not sell personal information.
9. Cookies
Our websites set a small number of cookies, all of them either necessary for the site to work or optional and off by default. The cookie policy lists every one, what it does and how long it lasts, and you can change your choices at any time from the footer of any page.
10. Children
Discord requires users to be at least 13, or older where local law says so. Our services are not directed at children under that age and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will remove it.
11. Changes to this policy
We may update this Privacy Policy to reflect changes in our features or legal requirements. The date at the top shows when it last changed. Continued use of our bots and websites implies acceptance of the current policy.