// Legal
Privacy Policy
Last updated: July 14, 2026
This policy explains, in plain language, exactly what Vela collects, why, who else ever sees it, and how to get it deleted. Where a section matters more than the rest, it says so up front instead of burying it in legalese.
1. Who this policy covers
This Privacy Policy applies to Vela — the Discord bot and the web dashboard at velabot.xyz — operated by an individual (see Terms of Service for who "we"/"us" means). It applies to anyone who is a member of a Discord server that has added Vela, and to anyone who logs into the dashboard.
Discord itself is a separate company with its own privacy policy. This page only covers what Vela — not Discord — does with data.
Discord itself is a separate company with its own privacy policy. This page only covers what Vela — not Discord — does with data.
2. Information we collect
Account & identity data. When you log into the dashboard, Discord's OAuth login gives us your Discord user ID, username, avatar, and the list of servers you're an administrator of. We request only the
Server & command data. XP/level, moderation case history, invite counts, giveaway entries, ticket records, custom tags, role/channel configuration, and similar server-management data, all tied to your Discord user ID and/or the server's ID.
Message content — three specific cases, and only these:
Content you customize. Rank-card colors and background images, welcome messages, custom tags, and embed templates that you or your server's staff configure. Custom background images are stored as image data in our database, capped in size, and are never shared outside of rendering your own card.
Reports, bans, and appeals. If someone reports a custom rank card, or a card customization is banned/appealed, we store the reporter's ID, the target's ID, and the written reason — visible to Vela's moderation staff so it can be reviewed fairly. See Section 4 for who "staff" means.
Cookies. A session cookie (so the dashboard remembers you're logged in) and a CSRF-protection cookie (a security measure, not tracking). Both are
identify and guilds OAuth scopes — we never request your email address, and Discord does not give it to us. We do not store your Discord access or refresh token; they're used once during login to fetch your profile and then discarded.Server & command data. XP/level, moderation case history, invite counts, giveaway entries, ticket records, custom tags, role/channel configuration, and similar server-management data, all tied to your Discord user ID and/or the server's ID.
Message content — three specific cases, and only these:
- Automated moderation ("heat system"). When a message triggers spam/toxicity detection in a server that has it enabled, the message is evaluated and the result is logged for a moderator audit trail.
- Support tickets. If a server uses Vela's ticket system, the full conversation in a ticket channel is saved as a transcript when the ticket closes, so staff can review it later. This is stored indefinitely unless deletion is requested — see Section 6.
- Weekly highlights ("newspaper" feature), if a server enables it. Messages that receive a lot of reactions may have up to 500 characters of their content saved, along with the author's user ID, so the server can see its "top message of the week."
Content you customize. Rank-card colors and background images, welcome messages, custom tags, and embed templates that you or your server's staff configure. Custom background images are stored as image data in our database, capped in size, and are never shared outside of rendering your own card.
Reports, bans, and appeals. If someone reports a custom rank card, or a card customization is banned/appealed, we store the reporter's ID, the target's ID, and the written reason — visible to Vela's moderation staff so it can be reviewed fairly. See Section 4 for who "staff" means.
Cookies. A session cookie (so the dashboard remembers you're logged in) and a CSRF-protection cookie (a security measure, not tracking). Both are
httpOnly and cleared when your browser session ends. We do not use analytics, advertising, or tracking cookies of any kind.3. What we do NOT collect
- Your email address, real name, or physical address
- Passwords or payment/financial information of any kind
- Your Discord access or refresh tokens (used once at login, never stored)
- Direct messages (DMs) — Vela cannot see these and never attempts to
- Messages in channels or servers Vela hasn't been added to, or where its relevant feature is switched off
- Your IP address — our rate-limiting uses IPs only transiently, in server memory, to prevent abuse; nothing is written to a database or log file
- Birthdate or age — the only "age" concept Vela uses is how old a Discord account is, from Discord's own public account-creation timestamp, for anti-raid protection. We never ask you your age.
- Browsing history, device fingerprints, or cross-site tracking data
4. Who can see your data
Inside a server, the moderation staff and administrators that server's owner has appointed can see the data relevant to running that server — case history, ticket transcripts, card reports, and similar. That's a function of the roles they hold on Discord, the same as if they were reading it directly in the channel.
Vela's own operator (the developer) has access to the full database in order to run, debug, and support the service, and reviews cross-server card reports/appeals/bans as part of moderating that specific feature. Nobody else — no other server's staff, no other user — can see your data outside the server(s) you're actually in.
We do not sell your data, and we do not share it with advertisers or data brokers. The only outside company that ever receives any of your data is described in Section 5.
Vela's own operator (the developer) has access to the full database in order to run, debug, and support the service, and reviews cross-server card reports/appeals/bans as part of moderating that specific feature. Nobody else — no other server's staff, no other user — can see your data outside the server(s) you're actually in.
We do not sell your data, and we do not share it with advertisers or data brokers. The only outside company that ever receives any of your data is described in Section 5.
5. Third-party services
Discord. Vela is built entirely on the Discord API and cannot function without it. Everything Vela does happens through Discord's platform, and your relationship with Discord itself is governed by Discord's Privacy Policy.
Groq (AI processing). Vela uses Groq, a third-party AI provider, in two specific, narrow cases:
Groq (AI processing). Vela uses Groq, a third-party AI provider, in two specific, narrow cases:
- If a server owner turns on the optional "AI Behavioral Analysis" moderation setting (it is off by default), the text of a message that trips the heat system may be sent to Groq for a toxicity/severity classification. No username or other identifying metadata is sent — just the message text itself.
- The
/roastcommand sends the target user's public Discord profile information (username, roles, join date, activity status, and similar server-visible details — not private data, and not message content) to Groq to generate a joke. Only the person running the command actively consents by choosing to run it — the target does not individually opt in. By adding Vela to a server, the server owner is representing that they have the authority to allow this bot feature to operate on their members' server-visible profile data, the same as any other moderation or utility bot feature. If you'd rather this not run on your server, ask an admin to disable or restrict the command.
6. Data retention
Data tied to a server is retained for as long as Vela remains in that server. If Vela is removed, that server's data is kept — inactive, not actively processed — so that the server can pick up where it left off if Vela is re-added later, and is not sold or repurposed while inactive.
Ticket transcripts are retained indefinitely by default, since they're a support record staff may need to reference later, unless the server or an affected user requests deletion (Section 7).
You can request full deletion of your data, or your server's data, at any time — see Section 7.
Ticket transcripts are retained indefinitely by default, since they're a support record staff may need to reference later, unless the server or an affected user requests deletion (Section 7).
You can request full deletion of your data, or your server's data, at any time — see Section 7.
7. Your rights & how to exercise them
Regardless of where you live, you can ask us to:
California residents: under the CCPA/CPRA, you have the rights above plus the right to know the categories of data collected and the right to non-discrimination for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of on that front.
EEA/UK residents: we aim to honor the same rights in spirit (access, erasure, rectification, and portability) even though Vela is a small, individually-operated service rather than a large data controller with a formal compliance program. Contact us and we'll do our best to help.
- See what we have — a summary of the data tied to your Discord user ID.
- Delete it — your XP/leveling history, card settings and images, ticket transcripts you're part of, and moderation records tied to you, subject to a server's legitimate need to retain moderation history for safety purposes (e.g., an active ban record isn't erased just because the banned user asks — but you can appeal it through the normal appeal process).
- Correct it — if something we hold about you is factually wrong.
California residents: under the CCPA/CPRA, you have the rights above plus the right to know the categories of data collected and the right to non-discrimination for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of on that front.
EEA/UK residents: we aim to honor the same rights in spirit (access, erasure, rectification, and portability) even though Vela is a small, individually-operated service rather than a large data controller with a formal compliance program. Contact us and we'll do our best to help.
8. Children's privacy
Vela is not directed at children. In line with Discord's own Terms of Service, you must be at least 13 years old (or the minimum age required in your country) to use Discord, and therefore to use Vela. We do not knowingly collect data from anyone below that age. If you believe a child has provided us data in violation of this policy, contact us and we will remove it.
9. Security
We use industry-standard practices to protect your data — encrypted connections (HTTPS) for the dashboard, hashed/secure session handling, and CSRF protection on every state-changing request. No system is perfectly secure, and we can't guarantee absolute security, but we take reasonable, ongoing steps to protect what we hold and to limit what we collect in the first place.
10. Changes to this policy
If this policy changes in a way that materially affects your rights, we'll update the "Last updated" date above and post a notice in the Vela support server. Continued use of Vela after a change takes effect means you accept the revised policy.
11. Contact
Questions, data requests, or concerns? Reach us in the Vela support server on Discord, or by email at benroram@gmail.com. Please include your Discord user ID (and server ID, if the request is server-wide) so we can locate the right data.
You can also read our Terms of Service.
You can also read our Terms of Service.