Privacy Policy
ScamSentry is a proactive Discord safety and moderation bot. In servers where administrators configure the service, ScamSentry automatically analyzes newly posted messages for phishing links, known scam phrases, suspicious images, unsafe attachments, forwarded content, and configured detection rules. This policy explains what data ScamSentry accesses, how it is used, where it may be stored, and how to request deletion.
Contact: abuse@scamsentry.app, admin@scamsentry.app
1. Scope and administrator control
Server administrators choose whether to install ScamSentry, select the server's moderation or alert channels, and configure available protection features. Individual members cannot opt out of server-wide moderation because allowing an individual opt-out would permit malicious users to bypass the server's safety rules. Server administrators may disable available features or remove ScamSentry at any time.
2. Data ScamSentry accesses
To provide proactive moderation, ScamSentry may access:
- Discord user IDs, usernames, server IDs, channel IDs, message IDs, and message links.
- Message text, links, embeds, components, forwarded-message snapshots, attachment metadata, attachment URLs, and images.
- Server configuration, including selected alert channels, enabled protection features, and moderation settings.
- Detection results, including matched phrases, invite details, OCR results, perceptual image hashes, and moderation outcomes.
- Operational statistics, such as protected-server counts, processed-message counts, deleted scam-message counts, and alerted-user counts.
3. Why message content access is necessary
ScamSentry must evaluate eligible server messages automatically when they are posted, before a member interacts with malicious content. Slash commands and message context commands require a person to act first and therefore cannot provide equivalent proactive protection. Discord AutoMod does not provide ScamSentry's image OCR, perceptual-image-hash comparison, forwarded-content inspection, or custom attachment analysis.
ScamSentry uses message content only for safety, moderation, service security, and related support. It is not used for advertising, unrelated profiling, or training artificial-intelligence or machine-learning models.
4. Message, attachment, OCR, and image-hash processing
ScamSentry may temporarily download an image into process memory to run optical character recognition (OCR) or generate a difference hash (dHash). The default OCR implementation runs on ScamSentry's infrastructure. A privately hosted OCR container may also be used; when enabled, image bytes remain within ScamSentry's private infrastructure.
A dHash is a non-reversible visual signature used to recognize reposted or slightly modified scam images. It cannot reconstruct the source image. ScamSentry may retain a dHash and the image's aspect ratio as a safety signature.
Raw message text, OCR text, and original attachment bytes are not intentionally written to ScamSentry's off-platform database or filesystem as ordinary detection records. They are processed in memory and are not intentionally backed up. In-memory evidence may remain temporarily while a detection, report, or feedback workflow is active and is cleared when the process restarts.
5. Data stored outside Discord
ScamSentry may retain limited operational data outside Discord, including:
- Server and channel identifiers needed for server settings, alert destinations, feature toggles, and moderation configuration.
- Configured detection phrases and de-identified banned-image dHashes.
- Aggregate operational statistics.
- Temporary user, server, message, and moderation identifiers needed for short-lived safety, report, feedback, hot-list, whitelist, and administrator-review workflows.
ScamSentry does not intentionally collect or store Discord passwords, account tokens, payment information, or private login credentials.
6. Discord-hosted moderation evidence
When a message triggers a detection, ScamSentry may delete the original message, notify the affected user, and re-upload evidence to a server-configured Discord moderation channel or to restricted Discord administrator, report, feedback, or safety-review channels operated by ScamSentry.
Depending on the event, a Discord-hosted evidence message may contain message text or a preview, the author and relevant Discord identifiers, the channel and message link, attachment details or copies of suspicious images, the detection reason, OCR results, dHashes, and the moderation outcome. These evidence messages are stored by Discord and remain subject to Discord's and the relevant channel owner's retention practices. Deleting the original message does not automatically delete a Discord-hosted evidence copy.
7. Retention
- Raw message content and attachments: not intentionally retained in off-platform persistent storage as ordinary detection records.
- In-memory evidence: retained only while needed for an active moderation, report, feedback, or safety-review workflow and cleared when the process restarts.
- Temporary safety identifiers: retained only as needed for the associated operational workflow. Short-lived hot-list entries normally expire after approximately two minutes.
- Server configuration: retained while needed to operate ScamSentry for the server and removed when no longer necessary or following a valid deletion request.
- Aggregate statistics and configured phrases: may be retained while needed to operate and measure the service.
- De-identified dHashes: may remain until manually removed because they are needed to recognize repeated scam images and cannot reconstruct the source image.
- Discord-hosted evidence: remains until deleted by the relevant server staff, channel owner, or ScamSentry administrator.
8. Safety-message resource requests
Some automated safety direct messages may contain a unique 1×1 image-resource URL used to support the account-recovery and service-security workflow. The signed URL may contain an encoded Discord user ID, username, and generation timestamp. Encoded data is not encrypted and may be readable by a person who obtains the URL.
When the resource is requested, operational records may include the resource path, the encoded or decoded identifiers and timestamp, request time, IP address, and user agent. This information is used only for the related safety workflow, debugging, service operation, security, and abuse prevention. It is not used for advertising or cross-service tracking.
9. Data sharing and service providers
Data may be disclosed only as necessary to:
- Discord, as part of normal bot/API operation.
- Server moderators or administrators through their configured Discord channels.
- ScamSentry's authorized administration and moderation team through restricted Discord review channels.
- Hosting, database, content-delivery, or infrastructure service providers acting on ScamSentry's behalf.
- Authorities or other parties when reasonably necessary to comply with law, protect users, investigate abuse, or defend the service.
ScamSentry does not sell personal data, disclose it to data brokers or advertising networks, or share message content for advertising.
10. Security
ScamSentry uses reasonable administrative and technical safeguards designed to protect Discord API data. Network communications with Discord, MongoDB Atlas, and public ScamSentry services use encrypted connections. Persistent stores containing Discord API data are required to be encrypted at rest, and access to administrative systems is restricted to authorized operators. No system can be guaranteed completely secure.
11. Deletion requests
To request deletion of applicable off-platform activity or configuration data, email abuse@scamsentry.app or admin@scamsentry.app with the subject Data Deletion Request. Include your Discord user ID and, when relevant, the server ID. ScamSentry may request reasonable verification that you control the relevant account.
Applicable off-platform data will be deleted within 30 days after verification, except when limited retention is required for security, abuse prevention, an active dispute, or legal compliance. De-identified dHashes and aggregate statistics that are no longer linked to a person are not treated as user activity records. ScamSentry may be unable to delete evidence stored in Discord channels controlled by independent server administrators; users may also need to contact those administrators.
12. Children
ScamSentry is intended for use on Discord and is not directed toward children under Discord's minimum age requirements.
13. Changes
This policy may be updated when ScamSentry's features or data practices change. The current version will remain publicly available through ScamSentry's website and application profile.