Lumabot

Privacy Policy

Last updated September 19, 2026

This policy explains what personal data Lumabot collects and stores, why, who can see it and what your rights are. It covers the Discord bot, the website at lumabot.eu, the Lumabot API at api.lumabot.eu and the Custom bots we host.

We only store what a feature needs to work. We do not sell your data and we do not show advertising.

1.Who is responsible

Lumabot is run by the Lumabot team ("we"). You can reach us through the support server: https://discord.lumabot.eu

Discord processes your data on its own behalf under its own policies. This policy only covers what Lumabot adds on top of that.

2.Data we receive and store

Depending on which features are used on a server, Lumabot stores the following.

  • Identifiers from Discord: the IDs of servers, users, channels, roles and messages, and sometimes names, nicknames and avatars, so that features can work and be shown.
  • Server settings: everything an administrator configures with commands and panels, including texts such as welcome messages, embeds, tags and ticket messages.
  • Statistics and XP: for each member, per day and per channel, the number of messages sent (not their content), voice time, muted time and deafened time, plus XP and levels for text and voice.
  • Casino: chip balance, daily reward streaks, boosts, statistics such as total wagered and won, achievements, and team membership.
  • Moderation: warnings and other sanctions (reason, moderator, date), temporary bans and their end date, blacklists, forbidden roles, and the actions detected by anti-raid rules.
  • Invites: which invite a member used, who invited whom, join and leave dates, invite counts and bonus invites.
  • Roles: sticky roles and temporary roles (with their expiry date) attached to a member.
  • Tickets: who opened, claimed, closed or reopened a ticket, and when. If a server enables transcripts, the ticket conversation is exported to a file.
  • Other features: giveaway participants and winners, suggestions and votes, the author of a tag, the owner of a temporary voice channel, family relationships (partner, children), music playlists (name, tracks, share code).
  • AFK status (time and reason) and previous usernames, which are kept by the Lumabot API so they work across servers.
  • Backups: see the dedicated section below.
  • Premium and payments: your Discord ID, email address and Stripe customer ID, and your purchases and the server each Premium plan is assigned to. For a Custom bot we also store its bot token and the credentials of its dedicated database, so we can run it.
  • Technical data: error reports (command name, error and the IDs of the server, channel and user involved) and the standard access logs of the website's web server, which include your IP address.

3.Messages

Some features read message text in real time to work, for example the link filter, bad-word filter, anti-spam, tags and anti-raid. Except for the cases below, we do not store the content of your messages in our databases.

  • Backups: when a server creates a backup that includes messages, it saves the text, author ID, display name, avatar, embeds and attachment details of the latest messages of each channel, up to the limit of the server's plan.
  • Ticket transcripts: only when a server turns them on, the conversation of a ticket is exported to an HTML file that is sent to the server's log channel and/or to the person who opened the ticket. A copy of that file may stay on our server.
  • Deleted messages: the /channel snipe command keeps recently deleted messages in the bot's memory so moderators can see them. They are not written to a database and disappear when the bot restarts.
  • Logs: if a server enables message logs, deleted and edited messages are posted by the bot in that server's own log channel on Discord.

4.The website

This website does not use cookies, advertising or analytics tools. Its fonts are served from the site itself. The stats page loads public numbers from api.lumabot.eu, and like any web server ours records standard access logs (such as your IP address and the page requested) for security and troubleshooting. The public statistics contain no personal data: they are totals for servers, members, shards and commands.

5.Why we use your data

  • To provide the features that servers and members choose to use.
  • To keep the Service secure, prevent abuse and fix bugs.
  • To process payments and give you access to Premium and Custom plans.
  • To answer your requests and comply with the law.

6.Who can see it and who we share it with

We do not sell personal data.

  • Other people on Discord: features are visible by design. Activity cards and leaderboards show members' statistics to the server, the worldwide casino leaderboard shows rankings across servers, and the /member prevname command lets anyone look up the previous usernames Lumabot has recorded for a user.
  • Server administrators and staff see the settings, logs, sanctions, tickets and statistics of their own server.
  • Discord, which delivers the messages and commands the bot handles.
  • Stripe, which processes payments and receives the information needed for a purchase.
  • Music providers (Deezer, Apple Music, SoundCloud) receive the search or link you play with the music feature.
  • Our hosting provider, which runs the servers where the data is stored, and our own error-tracking tool.
  • Authorities, when the law requires it.

7.How long we keep it

  • Server and member data is kept while the bot and its features are in use. Removing Lumabot from a server does not delete the data automatically, so that settings are back if you re-add it. You can ask us to delete it at any time.
  • A backup and its files are deleted when the backup is deleted.
  • AFK status is removed when it is cleared, and previous usernames and other records are kept until deleted.
  • Deleted messages kept for /channel snipe stay in memory only.
  • Payment records may be kept as long as the law requires.
  • Server logs are rotated automatically and kept for a limited time.

8.Your choices

You can stop the collection of your data and ask for it to be deleted, whenever you want.

  • Stop the collection: members can switch off the recording of their statistics and XP for their account with /member privacy, and server administrators can do the same for their whole server with /guild privacy. While it is switched off, Lumabot no longer records that activity, and the messages of accounts that switched it off are left out of backups.
  • Ask for deletion: switching the collection off does not delete what was already collected. To have your data deleted, ask us at any time through the support server: https://discord.lumabot.eu. Server administrators can ask for the deletion of their server's data in the same way.

9.Your rights

Depending on where you live, for example in the European Union, you also have the right to access your data, correct it, restrict or object to its use, and receive a copy of it. To use any of these rights, contact us through the support server: https://discord.lumabot.eu. We may need to check that you own the Discord account, and we aim to answer within one month.

If you think your rights are not respected, you can complain to your data protection authority.

10.Children

Lumabot follows Discord's minimum age and is not meant for children below it. If you believe a child's data has been collected, contact us and we will delete it.

11.Security and transfers

We take reasonable measures to protect data: limited access to our servers and databases, encrypted connections to the API and payments handled by Stripe. No system is perfectly secure. Discord, Stripe and other providers may process data outside your country under their own safeguards.

12.Changes to this policy

We may update this policy when features or the law change. The date at the top shows the latest version, and important changes will be announced in the support server.

13.Contact

For any question about your data, join the support server: https://discord.lumabot.eu