Privacy Policy
Last updated 4 September 2026
This policy explains what personal data Bastion processes, why, and what rights you have. It applies to the website, the dashboard and the Discord bot.
1. Data we process when you sign in
When you sign in with Discord we receive and store:
- your Discord user ID, username, display name and avatar;
- the list of servers you are in, together with your permissions there, so we can show you which servers you can manage (cached for a few minutes, then refreshed);
- an OAuth access token, used only to read the data above on your behalf;
- your chosen language.
2. Data we process for servers
When the bot is added to a server we store the server ID, name, icon, owner ID and member count, and the configuration chosen by its administrators. For every action the bot takes we store a log entry with the affected user ID, username and avatar, the action, the outcome, the module that triggered it and, for the honeypot, the content of the message that triggered it.
3. The blacklist
The blacklist contains Discord user IDs and usernames, a category, a severity, a reason and evidence such as text, links and screenshots. This data is processed on the basis of the legitimate interest of game communities in protecting themselves against leaking, cheating and fraud. Listed persons can see their entry and the visible evidence after signing in, and can file an appeal.
4. Purposes
We use the data to operate the service: authenticate you, show you the right dashboard, enforce the configuration of each server, keep an audit trail for server administrators, and handle appeals. We do not sell data and we do not use it for advertising.
5. Sharing
Server administrators see the log entries and flagged accounts of their own server, including the public reason of an entry. They never see internal notes or hidden evidence. Data is stored with our hosting and database providers, who process it on our behalf. We disclose data to authorities only when legally required.
6. Retention
Sessions expire after 30 days. Server configuration and logs are kept while the bot is in the server and deleted on request after it is removed. Blacklist entries are kept while they are active; removed entries are kept for the purpose of handling appeals and preventing re-listing errors, and deleted on request where no legitimate interest remains.
7. Your rights
You can ask us for access to, correction or deletion of your personal data, or object to its processing. Sign in to see your own entry and evidence. For other requests, contact us through the Bastion Discord server or the address below. If you are in the EU you also have the right to lodge a complaint with your data protection authority.
8. Cookies
We use two cookies: a session cookie to keep you signed in, and a language cookie. Neither is used for tracking.
9. Changes
We may update this policy. The date at the top shows the latest version.
Questions about these terms or your data? Contact us at info@bastionsecurity.app