Privacy Policy

Effective Date and Last Updated: July 23, 2026

ScamSentry is a proactive Discord safety and moderation bot. In servers where administrators configure the service, ScamSentry automatically analyzes newly posted messages for suspicious Discord invite links, known scam phrases, suspicious images, unsafe attachments, forwarded content, and configured detection rules. This policy explains what data ScamSentry accesses, how it is used, where it may be stored, and how to request deletion.

Contact: abuse@scamsentry.app, admin@scamsentry.app

1. Scope and administrator control

Server administrators choose whether to install ScamSentry, select the server's moderation or alert channels, and configure available protection features. Individual members cannot opt out of server-wide moderation because allowing an individual opt-out would permit malicious users to bypass the server's safety rules. Server administrators may disable available features or remove ScamSentry at any time.

2. Data ScamSentry accesses

To provide proactive moderation, ScamSentry may access:

3. Why message content access is necessary

ScamSentry must evaluate eligible server messages automatically when they are posted, before a member interacts with malicious content. Slash commands and message context commands require a person to act first and therefore cannot provide equivalent proactive protection. Discord AutoMod does not provide ScamSentry's image OCR, perceptual-image-hash comparison, forwarded-content inspection, or custom attachment analysis.

ScamSentry uses message content only for safety, moderation, service security, and related support. It is not used for advertising, unrelated profiling, or training artificial-intelligence or machine-learning models.

4. Message, attachment, OCR, and image-hash processing

ScamSentry may temporarily download an image into process memory to run optical character recognition (OCR) or generate a difference hash (dHash). The default OCR implementation runs on ScamSentry's infrastructure. A privately hosted OCR container may also be used; when enabled, image bytes remain within ScamSentry's private infrastructure.

A dHash is a non-reversible visual signature used to recognize reposted or slightly modified scam images. It cannot reconstruct the source image. ScamSentry may retain a dHash and the image's aspect ratio as a safety signature. Confirmed scam-image dHashes and aspect ratios may also be published in ScamSentry's public open-source GitHub dataset so other safety applications can identify matching images. The public dataset does not include original images, message or OCR text, attachment URLs, or Discord user, channel, or server identifiers.

Raw message text, OCR text, and original attachment bytes are processed temporarily in memory and are not intentionally persisted in off-platform storage. Copies of flagged evidence may be uploaded to server-configured or restricted Discord-hosted review channels. In-memory evidence may remain temporarily while a detection, report, feedback, or safety-review workflow is active and is cleared when the process restarts.

5. Data stored outside Discord

ScamSentry uses MongoDB Atlas and limited encrypted operational storage outside Discord. Stored data may include:

ScamSentry does not intentionally collect or store Discord passwords, account tokens, payment information, or private login credentials.

6. Discord-hosted moderation evidence

When a message triggers a detection, ScamSentry may delete the original message, notify the affected user, and re-upload evidence to a server-configured Discord moderation channel or to restricted Discord administrator, report, feedback, or safety-review channels operated by ScamSentry.

Depending on the event, a Discord-hosted evidence message may contain message text or a preview, the author and relevant Discord identifiers, the channel and message link, attachment details or copies of suspicious images, the detection reason, OCR results, dHashes, and the moderation outcome. These evidence messages are stored by Discord and remain subject to Discord's and the relevant channel owner's retention practices. Deleting the original message does not automatically delete a Discord-hosted evidence copy.

7. Retention

8. Data sharing and service providers

Data may be disclosed only as necessary to:

ScamSentry does not sell personal data, disclose it to data brokers or advertising networks, or share message content for advertising.

9. Security

ScamSentry uses reasonable administrative and technical safeguards designed to protect Discord API data. Private configuration and operational data stored in MongoDB Atlas are encrypted at rest. MongoDB Atlas encrypts cluster storage and snapshot volumes using AES-256, and database connections use TLS. Other private persistent stores and backups containing Discord API data are also encrypted at rest. Access to administrative systems is restricted to authorized operators, and communications with Discord and public ScamSentry services use HTTPS. Public dHashes and aspect ratios published in the GitHub dataset are intentionally public and are not access-restricted. No system can be guaranteed completely secure.

10. Deletion requests

To request deletion of applicable off-platform activity or configuration data, email abuse@scamsentry.app or admin@scamsentry.app with the subject Data Deletion Request. Include your Discord user ID and, when relevant, the server ID. ScamSentry may request reasonable verification that you control the relevant account.

Applicable off-platform data will be deleted within 30 days after verification, except when limited retention is required for security, abuse prevention, an active dispute, or legal compliance. De-identified dHashes and aggregate statistics that are no longer linked to a person are not treated as user activity records. ScamSentry may be unable to delete evidence stored in Discord channels controlled by independent server administrators; users may also need to contact those administrators.

11. Children

ScamSentry is intended for use on Discord and is not directed toward children under Discord's minimum age requirements.

12. Changes

This policy may be updated when ScamSentry's features or data practices change. The current version will remain publicly available through ScamSentry's website and application profile.