Does your Discord bot need a privacy policy?
If your bot stores or processes any information about users or servers, and nearly every useful bot does, you should publish one. Discord's Developer Terms and Developer Policy expect you to be transparent about the data you collect and to protect it, and you'll typically be asked for a privacy policy link when you verify a growing bot or list it in the App Directory. Server owners also look for one before they add a bot.
Where to add the privacy policy link
In the Discord Developer Portal, open your application and go to General Information. There are fields for a Terms of Service URL and a Privacy Policy URL. It's also good practice to link the policy from your bot's website, its top.gg or directory listing, and a /privacy command.
What bots typically collect
- Discord IDs: user, server (guild), channel and message IDs
- Profile data: usernames, display names and avatars
- Server configuration: prefixes, roles, welcome messages and other settings
- Feature data: levels, economy balances, reminders, tickets and warnings
- Logs: command usage, moderation actions and error logs
- Linked accounts: data from other services if users connect them, for example through OAuth2
Message content
Reading the content of messages requires the privileged Message Content intent, and Discord reviews its use for verified bots. If your bot reads or stores message content, for moderation, logging or commands, say exactly what it reads, whether it stores anything, and for how long. If it only responds to slash commands, say that it doesn't read other messages.
Retention and deletion
Explain how long you keep each kind of data and what happens when your bot is removed from a server. Give users and server owners a clear way to request deletion, such as a command, a support server or an email address. Discord's developer rules expect you to honor deletion requests and not keep data longer than you need it.
Checklist for your bot
- The policy lists IDs, profile data, settings and logs the bot stores.
- Message content access is explained, or you state that the bot doesn't use it.
- Third-party services, such as your host, database and error tracking, are mentioned.
- Retention periods and deletion requests are covered.
- The data is not sold, as Discord's rules require.
- The URL is in the Developer Portal and on your listings.
Frequently asked questions
Does a small bot in a few servers need a privacy policy?
It's strongly recommended, and you'll need one if the bot grows and you verify it. A short policy is easy to write early and saves trouble later.
Do I also need terms of service for my bot?
The Developer Portal has a field for them, and they help you set rules for acceptable use and limit your liability. The terms and conditions template is a good starting point.
Where can I host my bot's privacy policy?
Any public web page works. Legiflare hosts it on a permanent link for free, so you don't need a separate website for your bot.