RollerBoi — Privacy Policy
RollerBoi (“the bot”) is a Discord application and companion web dashboard built for the RollerCoin community. This policy describes exactly what data the bot handles, why, who it is shared with, how long it is kept, and how to have it deleted.
Who is responsible
RollerBoi is operated by Captain Jellybones (“we”, “us”) as an independent community project. We are the data controller for the data described below.
Independence. RollerBoi is not operated by, affiliated with, endorsed by, or sponsored by RollerCoin or its operators. The person who runs RollerBoi is a RollerCoin player and a volunteer moderator on the official RollerCoin Discord server, and acts in a personal capacity only. RollerBoi is likewise not affiliated with or endorsed by Discord Inc.
Contact us — for privacy requests, bug reports, feedback, or to report misuse of the bot — at github.com/CaptainJellybones/RollerBoi-Public.
What we collect
Discord identifiers
User IDs, server (guild) IDs, channel IDs, role IDs and message IDs. These are the handles the Discord API gives us and are needed to run every feature. We do not store usernames or avatars — where the dashboard shows them, they are fetched live from Discord at the moment of display and held only in a short-lived memory cache.
Server configuration
Which features a server has enabled, per-feature settings chosen by its administrators (channels, roles, reward layouts, scoreboard themes and similar), and which roles that server designates as moderators.
Moderation and administration log
Actions taken by server staff, in the dashboard or through staff commands: who did what, to what, and when. Stored as Discord user IDs only. Ordinary member activity — chatting, playing games, winning prizes — is not written to this log.
Competition and prize data
- Sign-ups. When you enter a competition you submit your public RollerCoin profile link. We store it alongside your Discord user ID so prizes can be paid out to the right account.
- Duplicate checks. We compare submitted profile links within a competition to detect one person entering through several Discord accounts. Where a match is found we record the profile ID and the Discord accounts involved, for a moderator to review.
- Disqualifications and competition bans. If a moderator disqualifies an entry, we record that decision, who made it, and the accounts affected.
- Promo-code claims. When you win a code we record that you won a specific code (by internal code ID), and when. We never log or display the code value itself in readable form.
Content you or your moderators submit to a feature
A small amount of content is stored because the feature cannot work otherwise. We list it explicitly rather than claiming we store none:
- Scheduled announcements — the message text a moderator writes with
/schedule messageis stored until the message has been posted, so it survives a restart. - Game guesses — the words you submit while playing RollerCoindle are stored for the duration of that event so your board and score can be shown.
- Promo-drop challenges — the prompt and accepted answers an administrator sets up for a drop.
- Tournament entries — the RollerCoin username and character build a player submits when joining a tournament.
Dashboard sign-in
If you sign in to the web dashboard, Discord’s OAuth flow gives us your user ID, username, avatar and the list of servers you can manage. This is held in a server-side session and a session cookie so you stay signed in.
What we do not collect
- General message content. Some features read messages as they arrive so they can react — auto-replies, the community-vote feature, chat drops, and secret-word drops. Those messages are processed in memory and discarded. Nothing is written down beyond the specific items listed above.
- Behavioural profiles. We do not track when you are online, build activity patterns, infer your location, or profile your relationships with other users. An earlier version of the weather feature recorded activity hours to guess a timezone; that was removed and the stored data deleted.
- Passwords, tokens or credentials of any kind. We will never ask you for them.
- Payment or financial information.
- Special-category data (health, biometrics, beliefs, and similar).
- Readable promo-code values. Codes are encrypted at rest with AES-256-GCM and decrypted only in memory, at the moment one is delivered to its winner.
How we use it, and our legal basis
We use this data only to operate the bot’s features for the server that invited it. Under the GDPR our lawful bases are:
- Legitimate interests — running the bot, delivering prizes, keeping a moderation record, and preventing abuse of prize competitions (such as one person entering through multiple accounts).
- Consent — where you voluntarily submit something to take part, for example entering a competition with your profile link or joining a tournament.
We do not sell, rent or license your data. We do not share it with data brokers, advertising networks or any other monetisation service. We do not use it to train machine-learning or AI models. We do not use it to profile you, to discriminate against you, or to make decisions about your eligibility for anything outside the bot’s own features.
Who we share it with
This is the complete list of parties that receive any data through RollerBoi.
| Recipient | What reaches them | Why |
|---|---|---|
| Discord | Everything the bot posts, reads or acts on | Discord is the platform the bot runs on. Their handling is covered by Discord’s Privacy Policy. |
| Google (Google Sheets, via a service account under our Google Workspace) | For the Ban Roulette feature only: the Discord usernames, RollerCoin profile links and team names in the sign-up sheet a server administrator connects, plus the pass/fail result the bot writes back. | Server administrators run these sign-ups on a Google Sheet; the bot reads it and writes back whether each row was applied. |
| OpenWeatherMap | A city name and country code only — chosen from a fixed list inside the bot. Nothing identifying you is sent. | To look up current weather for the /weather command. |
| Groq (Groq Cloud, United States) | For the optional AI Chat feature only, and only for a message that addresses the bot
directly — an @mention of it, or a reply to something it said: the text of
that one message with all mentions replaced by placeholders, plus the bot’s own previous
message. Nothing else from the channel is sent, and no Discord user IDs, usernames or
avatars are sent. |
To write the bot’s reply. Groq state that customer inputs and outputs are not used to train or fine-tune AI models. We store none of it: the message is sent, the reply is posted, and nothing is written to our database. |
| RollerCoin (public website) | For the optional Tournament feature only: a request to the public profile page of the RollerCoin username a player submitted, to fetch their public avatar for a player card. | To draw the player’s avatar on their tournament card. |
Beyond these, we share data only where we are legally required to, or where you expressly ask us to.
Where your data is held
The bot, the dashboard and their databases run on a single server hosted in Stockholm, Sweden (Oracle Cloud Infrastructure, eu-stockholm region) — inside the EU/EEA. Google Sheets data is processed under our Google Workspace agreement. If a server switches on the optional AI Chat feature, the messages that address the bot are sent to Groq in the United States to generate a reply, and are not stored there or here.
How long we keep it
| Data | Kept for |
|---|---|
| Promo drops, claims and encrypted codes | 90 days after a drop finishes, then automatically purged |
| Everything belonging to a server | Deleted 30 days after the bot is removed from that server. Re-inviting it within 30 days cancels the deletion. |
| Dashboard sessions | 7 days, or until you sign out |
| Live game state (RollerCoindle events, spin state) | Expires automatically — between 90 minutes and 7 days depending on the item |
| Server configuration | Until changed by an administrator, or the server deletion above |
| Moderation log, disqualifications and competition bans | Retained while the bot is in the server — these are the server’s accountability and anti-abuse record |
Your rights and how to delete your data
If you are in the EU/EEA or the UK you have the right to access, correct, delete, restrict or object to our processing of your data, and to receive a copy of it. You can exercise these rights wherever you are — we apply them to everyone.
Asking for deletion
You can either:
- Ask an administrator of the server in question. They can erase your data for that server from the dashboard, which deletes your promo-claim records and your competition sign-ups (including the profile link you submitted) and removes you from any duplicate-check records.
- Or contact us directly at github.com/CaptainJellybones/RollerBoi-Public. Tell us your Discord user ID and which server, and we will action verified requests promptly.
What a deletion does not remove, and why
If you are subject to an active competition ban or have a recorded disqualification, we keep that record. A ban exists precisely to stop the banned person re-entering, so deleting it would defeat the measure it records; we rely on our legitimate interest in preventing abuse of prize competitions. It holds only your Discord user ID and the reason. Entries in the moderation log that record what a moderator did are likewise retained as the server’s accountability record. If you think a ban is wrong, ask a server administrator or contact us — having it lifted is the remedy here.
Other ways to stop the bot processing your data
- Don’t enter competitions — sign-up data is only created when you submit it.
- Sign out of the dashboard to clear your session.
- Server administrators can disable any feature, or remove the bot entirely.
- For the AI Chat feature: don’t
@mentionthe bot, or ask a server moderator to add you to that feature’s opt-out list — listed members’ messages are never sent to the AI provider, even if they mention the bot.
If you believe we have handled your data improperly, you may complain to your local data protection authority. In Sweden this is the Swedish Authority for Privacy Protection (IMY).
Security
- Promo codes are encrypted with AES-256-GCM before being written to the database; the bot refuses to start without a valid encryption key.
- The server’s storage volumes are encrypted at rest by the hosting provider.
- The database is not publicly reachable and is access-controlled.
- The dashboard is served over HTTPS with hardened session cookies and standard security headers.
- Secrets are held in the server environment, never in the codebase.
If we become aware of unauthorised access to your data we will begin remediation immediately and notify affected users and Discord as required, and the relevant supervisory authority where the law requires it.
Children
RollerBoi is not directed to anyone under 13, or under the minimum age required in their country, consistent with Discord’s Terms of Service. We do not knowingly collect data from such users. If you believe a child’s data has reached us, contact us and we will delete it. RollerBoi contains no age-restricted (18+) material.
Changes
We may update this policy. The “last updated” date above always reflects the current version, and material changes will be announced in the servers where the bot operates.