Privacy Policy

Effective Date: July 23, 2026

ScamSentry is a proactive Discord safety and moderation bot. In servers where administrators configure the service, ScamSentry automatically analyzes newly posted messages for phishing links, known scam phrases, suspicious images, unsafe attachments, forwarded content, and configured detection rules. This policy explains what data ScamSentry accesses, how it is used, where it may be stored, and how to request deletion.

Contact: abuse@scamsentry.app, admin@scamsentry.app

1. Scope and administrator control

Server administrators choose whether to install ScamSentry, select the server's moderation or alert channels, and configure available protection features. Individual members cannot opt out of server-wide moderation because allowing an individual opt-out would permit malicious users to bypass the server's safety rules. Server administrators may disable available features or remove ScamSentry at any time.

2. Data ScamSentry accesses

To provide proactive moderation, ScamSentry may access:

3. Why message content access is necessary

ScamSentry must evaluate eligible server messages automatically when they are posted, before a member interacts with malicious content. Slash commands and message context commands require a person to act first and therefore cannot provide equivalent proactive protection. Discord AutoMod does not provide ScamSentry's image OCR, perceptual-image-hash comparison, forwarded-content inspection, or custom attachment analysis.

ScamSentry uses message content only for safety, moderation, service security, and related support. It is not used for advertising, unrelated profiling, or training artificial-intelligence or machine-learning models.

4. Message, attachment, OCR, and image-hash processing

ScamSentry may temporarily download an image into process memory to run optical character recognition (OCR) or generate a difference hash (dHash). The default OCR implementation runs on ScamSentry's infrastructure. A privately hosted OCR container may also be used; when enabled, image bytes remain within ScamSentry's private infrastructure.

A dHash is a non-reversible visual signature used to recognize reposted or slightly modified scam images. It cannot reconstruct the source image. ScamSentry may retain a dHash and the image's aspect ratio as a safety signature.

Raw message text, OCR text, and original attachment bytes are not intentionally written to ScamSentry's off-platform database or filesystem as ordinary detection records. They are processed in memory and are not intentionally backed up. In-memory evidence may remain temporarily while a detection, report, or feedback workflow is active and is cleared when the process restarts.

5. Data stored outside Discord

ScamSentry may retain limited operational data outside Discord, including:

ScamSentry does not intentionally collect or store Discord passwords, account tokens, payment information, or private login credentials.

6. Discord-hosted moderation evidence

When a message triggers a detection, ScamSentry may delete the original message, notify the affected user, and re-upload evidence to a server-configured Discord moderation channel or to restricted Discord administrator, report, feedback, or safety-review channels operated by ScamSentry.

Depending on the event, a Discord-hosted evidence message may contain message text or a preview, the author and relevant Discord identifiers, the channel and message link, attachment details or copies of suspicious images, the detection reason, OCR results, dHashes, and the moderation outcome. These evidence messages are stored by Discord and remain subject to Discord's and the relevant channel owner's retention practices. Deleting the original message does not automatically delete a Discord-hosted evidence copy.

7. Retention

8. Safety-message resource requests

Some automated safety direct messages may contain a unique 1×1 image-resource URL used to support the account-recovery and service-security workflow. The signed URL may contain an encoded Discord user ID, username, and generation timestamp. Encoded data is not encrypted and may be readable by a person who obtains the URL.

When the resource is requested, operational records may include the resource path, the encoded or decoded identifiers and timestamp, request time, IP address, and user agent. This information is used only for the related safety workflow, debugging, service operation, security, and abuse prevention. It is not used for advertising or cross-service tracking.

9. Data sharing and service providers

Data may be disclosed only as necessary to:

ScamSentry does not sell personal data, disclose it to data brokers or advertising networks, or share message content for advertising.

10. Security

ScamSentry uses reasonable administrative and technical safeguards designed to protect Discord API data. Network communications with Discord, MongoDB Atlas, and public ScamSentry services use encrypted connections. Persistent stores containing Discord API data are required to be encrypted at rest, and access to administrative systems is restricted to authorized operators. No system can be guaranteed completely secure.

11. Deletion requests

To request deletion of applicable off-platform activity or configuration data, email abuse@scamsentry.app or admin@scamsentry.app with the subject Data Deletion Request. Include your Discord user ID and, when relevant, the server ID. ScamSentry may request reasonable verification that you control the relevant account.

Applicable off-platform data will be deleted within 30 days after verification, except when limited retention is required for security, abuse prevention, an active dispute, or legal compliance. De-identified dHashes and aggregate statistics that are no longer linked to a person are not treated as user activity records. ScamSentry may be unable to delete evidence stored in Discord channels controlled by independent server administrators; users may also need to contact those administrators.

12. Children

ScamSentry is intended for use on Discord and is not directed toward children under Discord's minimum age requirements.

13. Changes

This policy may be updated when ScamSentry's features or data practices change. The current version will remain publicly available through ScamSentry's website and application profile.