Privacy Policy
ScamSentry is a proactive Discord safety and moderation bot. In servers where administrators configure the service, ScamSentry automatically analyzes newly posted messages for suspicious Discord invite links, known scam phrases, suspicious images, unsafe attachments, forwarded content, and configured detection rules. This policy explains what data ScamSentry accesses, how it is used, where it may be stored, and how to request deletion.
Contact: abuse@scamsentry.app, admin@scamsentry.app
1. Scope and administrator control
Server administrators choose whether to install ScamSentry, select the server's moderation or alert channels, and configure available protection features. Individual members cannot opt out of server-wide moderation because allowing an individual opt-out would permit malicious users to bypass the server's safety rules. Server administrators may disable available features or remove ScamSentry at any time.
2. Data ScamSentry accesses
To provide proactive moderation, ScamSentry may access:
- Discord user IDs, usernames, server IDs, channel IDs, message IDs, and message links.
- Message text, links, embeds, components, forwarded-message snapshots, attachment metadata, attachment URLs, and images.
- Server configuration, including selected alert channels, enabled protection features, and moderation settings.
- Detection results, including matched phrases, invite details, OCR results, perceptual image hashes, and moderation outcomes.
- Operational statistics, such as protected-server counts, processed-message counts, deleted scam-message counts, and alerted-user counts.
3. Why message content access is necessary
ScamSentry must evaluate eligible server messages automatically when they are posted, before a member interacts with malicious content. Slash commands and message context commands require a person to act first and therefore cannot provide equivalent proactive protection. Discord AutoMod does not provide ScamSentry's image OCR, perceptual-image-hash comparison, forwarded-content inspection, or custom attachment analysis.
ScamSentry uses message content only for safety, moderation, service security, and related support. It is not used for advertising, unrelated profiling, or training artificial-intelligence or machine-learning models.
4. Message, attachment, OCR, and image-hash processing
ScamSentry may temporarily download an image into process memory to run optical character recognition (OCR) or generate a difference hash (dHash). The default OCR implementation runs on ScamSentry's infrastructure. A privately hosted OCR container may also be used; when enabled, image bytes remain within ScamSentry's private infrastructure.
A dHash is a non-reversible visual signature used to recognize reposted or slightly modified scam images. It cannot reconstruct the source image. ScamSentry may retain a dHash and the image's aspect ratio as a safety signature. Confirmed scam-image dHashes and aspect ratios may also be published in ScamSentry's public open-source GitHub dataset so other safety applications can identify matching images. The public dataset does not include original images, message or OCR text, attachment URLs, or Discord user, channel, or server identifiers.
Raw message text, OCR text, and original attachment bytes are processed temporarily in memory and are not intentionally persisted in off-platform storage. Copies of flagged evidence may be uploaded to server-configured or restricted Discord-hosted review channels. In-memory evidence may remain temporarily while a detection, report, feedback, or safety-review workflow is active and is cleared when the process restarts.
5. Data stored outside Discord
ScamSentry uses MongoDB Atlas and limited encrypted operational storage outside Discord. Stored data may include:
- Server and channel identifiers needed for server settings, alert destinations, feature toggles, and moderation configuration.
- Configured detection phrases, banned-image dHashes, aspect ratios, and related hash-match information.
- Aggregate operational statistics.
- Temporary moderation, hash-review, hot-list, whitelist, report, feedback, and administrator-review identifiers needed to operate the associated workflow. These records may include Discord user, server, channel, or message identifiers and message links, but do not intentionally include raw message text, OCR text, or original attachment bytes.
ScamSentry does not intentionally collect or store Discord passwords, account tokens, payment information, or private login credentials.
6. Discord-hosted moderation evidence
When a message triggers a detection, ScamSentry may delete the original message, notify the affected user, and re-upload evidence to a server-configured Discord moderation channel or to restricted Discord administrator, report, feedback, or safety-review channels operated by ScamSentry.
Depending on the event, a Discord-hosted evidence message may contain message text or a preview, the author and relevant Discord identifiers, the channel and message link, attachment details or copies of suspicious images, the detection reason, OCR results, dHashes, and the moderation outcome. These evidence messages are stored by Discord and remain subject to Discord's and the relevant channel owner's retention practices. Deleting the original message does not automatically delete a Discord-hosted evidence copy.
7. Retention
- Raw message and attachment data: message text, OCR text, and original attachment bytes are processed in memory and are not intentionally persisted in off-platform storage. Discord-hosted evidence copies are governed separately as described below.
- In-memory evidence: retained only while needed for an active moderation, report, feedback, or safety-review workflow and cleared when the process restarts.
- Temporary moderation and safety identifiers: retained only while reasonably needed for the associated operational or review workflow. Short-lived hot-list entries normally expire after approximately two minutes.
- Server configuration: retained while needed to operate ScamSentry for the server and removed when no longer necessary or following a valid deletion request.
- Aggregate statistics and configured phrases: may be retained while needed to operate and measure the service.
- De-identified dHashes: may remain until manually removed because they are needed to recognize repeated scam images and cannot reconstruct the source image. Confirmed scam-image dHashes and aspect ratios may also remain in the public GitHub dataset and its version history.
- Discord-hosted evidence: remains until deleted by the relevant server staff, channel owner, or ScamSentry administrator.
- Backups: retained data in encrypted backups is removed through normal backup rotation. Data deleted after a valid request is not restored for ordinary operational use.
8. Data sharing and service providers
Data may be disclosed only as necessary to:
- Discord, as part of normal bot/API operation.
- Server moderators or administrators through their configured Discord channels.
- ScamSentry's authorized administration and moderation team through restricted Discord review channels.
- Hosting, database, content-delivery, or infrastructure service providers acting on ScamSentry's behalf.
- Users of ScamSentry's public GitHub hash dataset, which contains confirmed scam-image dHashes and aspect ratios but not original images, message or OCR text, attachment URLs, or Discord user, channel, or server identifiers.
- Authorities when disclosure is required by applicable law.
ScamSentry does not sell personal data, disclose it to data brokers or advertising networks, or share message content for advertising.
9. Security
ScamSentry uses reasonable administrative and technical safeguards designed to protect Discord API data. Private configuration and operational data stored in MongoDB Atlas are encrypted at rest. MongoDB Atlas encrypts cluster storage and snapshot volumes using AES-256, and database connections use TLS. Other private persistent stores and backups containing Discord API data are also encrypted at rest. Access to administrative systems is restricted to authorized operators, and communications with Discord and public ScamSentry services use HTTPS. Public dHashes and aspect ratios published in the GitHub dataset are intentionally public and are not access-restricted. No system can be guaranteed completely secure.
10. Deletion requests
To request deletion of applicable off-platform activity or configuration data, email abuse@scamsentry.app or admin@scamsentry.app with the subject Data Deletion Request. Include your Discord user ID and, when relevant, the server ID. ScamSentry may request reasonable verification that you control the relevant account.
Applicable off-platform data will be deleted within 30 days after verification, except when limited retention is required for security, abuse prevention, an active dispute, or legal compliance. De-identified dHashes and aggregate statistics that are no longer linked to a person are not treated as user activity records. ScamSentry may be unable to delete evidence stored in Discord channels controlled by independent server administrators; users may also need to contact those administrators.
11. Children
ScamSentry is intended for use on Discord and is not directed toward children under Discord's minimum age requirements.
12. Changes
This policy may be updated when ScamSentry's features or data practices change. The current version will remain publicly available through ScamSentry's website and application profile.