RollerBoi — Privacy Policy

Last updated: 10 August 2026

RollerBoi (“the bot”) is a Discord application and companion web dashboard built for the RollerCoin community. This policy describes exactly what data the bot handles, why, who it is shared with, how long it is kept, and how to have it deleted.

Who is responsible

RollerBoi is operated by Captain Jellybones (“we”, “us”) as an independent community project. We are the data controller for the data described below.

Independence. RollerBoi is not operated by, affiliated with, endorsed by, or sponsored by RollerCoin or its operators. The person who runs RollerBoi is a RollerCoin player and a volunteer moderator on the official RollerCoin Discord server, and acts in a personal capacity only. RollerBoi is likewise not affiliated with or endorsed by Discord Inc.

Contact us — for privacy requests, bug reports, feedback, or to report misuse of the bot — at github.com/CaptainJellybones/RollerBoi-Public.

What we collect

Discord identifiers

User IDs, server (guild) IDs, channel IDs, role IDs and message IDs. These are the handles the Discord API gives us and are needed to run every feature. We do not store usernames or avatars — where the dashboard shows them, they are fetched live from Discord at the moment of display and held only in a short-lived memory cache.

Server configuration

Which features a server has enabled, per-feature settings chosen by its administrators (channels, roles, reward layouts, scoreboard themes and similar), and which roles that server designates as moderators.

Moderation and administration log

Actions taken by server staff, in the dashboard or through staff commands: who did what, to what, and when. Stored as Discord user IDs only. Ordinary member activity — chatting, playing games, winning prizes — is not written to this log.

Competition and prize data

Content you or your moderators submit to a feature

A small amount of content is stored because the feature cannot work otherwise. We list it explicitly rather than claiming we store none:

Dashboard sign-in

If you sign in to the web dashboard, Discord’s OAuth flow gives us your user ID, username, avatar and the list of servers you can manage. This is held in a server-side session and a session cookie so you stay signed in.

What we do not collect

How we use it, and our legal basis

We use this data only to operate the bot’s features for the server that invited it. Under the GDPR our lawful bases are:

We do not sell, rent or license your data. We do not share it with data brokers, advertising networks or any other monetisation service. We do not use it to train machine-learning or AI models. We do not use it to profile you, to discriminate against you, or to make decisions about your eligibility for anything outside the bot’s own features.

Who we share it with

This is the complete list of parties that receive any data through RollerBoi.

RecipientWhat reaches themWhy
Discord Everything the bot posts, reads or acts on Discord is the platform the bot runs on. Their handling is covered by Discord’s Privacy Policy.
Google (Google Sheets, via a service account under our Google Workspace) For the Ban Roulette feature only: the Discord usernames, RollerCoin profile links and team names in the sign-up sheet a server administrator connects, plus the pass/fail result the bot writes back. Server administrators run these sign-ups on a Google Sheet; the bot reads it and writes back whether each row was applied.
OpenWeatherMap A city name and country code only — chosen from a fixed list inside the bot. Nothing identifying you is sent. To look up current weather for the /weather command.
Groq (Groq Cloud, United States) For the optional AI Chat feature only, and only for a message that addresses the bot directly — an @mention of it, or a reply to something it said: the text of that one message with all mentions replaced by placeholders, plus the bot’s own previous message. Nothing else from the channel is sent, and no Discord user IDs, usernames or avatars are sent. To write the bot’s reply. Groq state that customer inputs and outputs are not used to train or fine-tune AI models. We store none of it: the message is sent, the reply is posted, and nothing is written to our database.
RollerCoin (public website) For the optional Tournament feature only: a request to the public profile page of the RollerCoin username a player submitted, to fetch their public avatar for a player card. To draw the player’s avatar on their tournament card.

Beyond these, we share data only where we are legally required to, or where you expressly ask us to.

Where your data is held

The bot, the dashboard and their databases run on a single server hosted in Stockholm, Sweden (Oracle Cloud Infrastructure, eu-stockholm region) — inside the EU/EEA. Google Sheets data is processed under our Google Workspace agreement. If a server switches on the optional AI Chat feature, the messages that address the bot are sent to Groq in the United States to generate a reply, and are not stored there or here.

How long we keep it

DataKept for
Promo drops, claims and encrypted codes90 days after a drop finishes, then automatically purged
Everything belonging to a serverDeleted 30 days after the bot is removed from that server. Re-inviting it within 30 days cancels the deletion.
Dashboard sessions7 days, or until you sign out
Live game state (RollerCoindle events, spin state)Expires automatically — between 90 minutes and 7 days depending on the item
Server configurationUntil changed by an administrator, or the server deletion above
Moderation log, disqualifications and competition bansRetained while the bot is in the server — these are the server’s accountability and anti-abuse record

Your rights and how to delete your data

If you are in the EU/EEA or the UK you have the right to access, correct, delete, restrict or object to our processing of your data, and to receive a copy of it. You can exercise these rights wherever you are — we apply them to everyone.

Asking for deletion

You can either:

What a deletion does not remove, and why

If you are subject to an active competition ban or have a recorded disqualification, we keep that record. A ban exists precisely to stop the banned person re-entering, so deleting it would defeat the measure it records; we rely on our legitimate interest in preventing abuse of prize competitions. It holds only your Discord user ID and the reason. Entries in the moderation log that record what a moderator did are likewise retained as the server’s accountability record. If you think a ban is wrong, ask a server administrator or contact us — having it lifted is the remedy here.

Other ways to stop the bot processing your data

If you believe we have handled your data improperly, you may complain to your local data protection authority. In Sweden this is the Swedish Authority for Privacy Protection (IMY).

Security

If we become aware of unauthorised access to your data we will begin remediation immediately and notify affected users and Discord as required, and the relevant supervisory authority where the law requires it.

Children

RollerBoi is not directed to anyone under 13, or under the minimum age required in their country, consistent with Discord’s Terms of Service. We do not knowingly collect data from such users. If you believe a child’s data has reached us, contact us and we will delete it. RollerBoi contains no age-restricted (18+) material.

Changes

We may update this policy. The “last updated” date above always reflects the current version, and material changes will be announced in the servers where the bot operates.