This document sets out exactly what data the Kirby Discord bot keeps, why, for how long, and how to have it deleted. It describes how the service actually works, not a generic template.
1. What the bot does
Kirby offers 97 commands across nine areas. Each keeps different data, listed in the next section:
- Music — voice channel playback, queue, playlists, favourites, lyrics, audio filters, 24/7 mode, and an Activity playable inside Discord.
- Moderation — ban, kick, timeout, warnings, message purge, channel lock, slowmode, role and nickname management.
- Anti-raid — eight automatic protections: join flood, anti-nuke, join gate, captcha, anti-spam, webhook monitoring, mass-DM detection, username filter.
- Crypto (read-only) — live prices, conversion, balance of a public address, transaction details, price alerts, address watching.
- Wallet — a custodial wallet for Litecoin, Ethereum, Solana and USDT (Polygon and BNB Chain). See section 3, devoted entirely to it.
- Giveaways — draws, entries, winners.
- Invite tracking — which invite link brought each member in, inviter leaderboard, staff adjustments.
- Utilities — server, member and role cards, polls, reminders, tags, translation, QR codes, calculator, AFK, avatars and banners, support tickets.
- Settings — language, colour, emojis, autorole, welcome and leave messages.
- Fun — dice, coin flip, jokes, would-you-rather, image captions.
Two ways to install the bot
The application installs on a server — where it is granted permissions and its commands are visible to every member — or on your account. In that second case about thirty commands (crypto, wallet, utilities, fun) follow you everywhere: into your direct messages, and even into servers where the bot is not present. Replies there are visible only to you, and the host server receives nothing. An account installation grants no moderation permission whatsoever.
Either installation can be removed at any time from Discord: Settings → Authorized Apps for an account, or by removing the bot from the server.
2. What we keep
| Data | Why | Retention |
|---|---|---|
| Discord IDs (user, server, channel, role) | Tie settings, wallet and history to the right account | As long as the service is used |
| Server settings: language, colour, emojis, log channels, autoroles, welcome messages, anti-raid configuration | Run the bot as configured | Until the bot is removed from the server |
| Music: tracks played, favourites, playlists, player settings | Queue, resume after restart, server statistics | Periodic automatic purge |
| Moderation: warnings, tickets, anti-raid logs | Tools requested by server administrators | Until deleted by an administrator |
| Giveaways: entries and winners | Running the draw and verifying it | Until the giveaway is deleted |
| Invites: who invited whom, the code used, join and leave dates, staff-granted bonuses | Inviter leaderboard, requested by administrators | Until /invites clear or the bot is removed |
| Reminders, tags, polls, AFK status | Give back what you saved | Until due or deleted by you |
| Crypto: price alerts, watched addresses | Notifying you; these addresses are public on the blockchain | Until you remove them |
| Wallet: encrypted recovery phrase, hashed PIN, addresses, movement history | Running the custodial wallet | Until /wallet delete |
| Encrypted Discord access tokens (Music Activity and dashboard) | Authenticating you in the Activity opened from Discord, and on the website dashboard | Deleted after 60 days of inactivity |
| Kirby Premium: your settings (colour, badge, banner, AFK GIF, theme, visibility), the history of your latest calculations and conversions (50 at most), your favourites, your monthly counters | Providing the subscription perks and the “Your month on Kirby” card | Until Erase my settings; counters erased after 13 months |
| Kirby Premium subscription: the item purchased, its scope (account or server), the start and end dates, and any refund | Knowing who is entitled to the perks, and until when. Discord passes these entitlements to us; we never see your payment method | Kept, including after a refund or Erase my settings: it is the accounting record of the purchase. No setting and no history is attached to it |
| Images you upload: banner, AFK GIF, tag or poll image | Showing them where you placed them. A copy is kept because Discord links expire after 24 hours | Until replaced, removed, or the tag is deleted |
| Kirby Premium linked role: encrypted Discord access tokens | Updating your linked role when your subscription changes | Until Erase my settings, or until you remove the app in Discord |
The website dashboard
If you sign in at dash.kirby-tickets.com, Discord gives us your
id, name, avatar and the list of your servers — only to show you
the ones you can configure. That list is not stored: it is requested from Discord
on each visit and kept in memory for one minute, long enough to draw the page.
Your browser receives a cookie (kdash) holding
nothing but a session number: it keeps you signed in from one visit to the next,
and does nothing else. No analytics, no advertising tracker, no third-party
service. Signing out destroys the session server-side — deleting the
cookie alone would not. You can also revoke access at any time from
Discord → Settings → Authorized apps.
Kirby Premium: what becomes public, and only if you ask
Three switches in the My perks panel, all off by default, make
information visible beyond your servers. The supporters wall
(dash.kirby-tickets.com/supporters) shows your name, avatar, badge
and seniority. Your public page shows the same, plus the tags
you mark public and your highest-valued Mudae characters, without server
names. The bot's status can thank you by name, in every server
it is in. Turning the switch off, or the end of the subscription, removes them
at once.
What we do not keep
- The content of your messages. The bot reads commands addressed to it and, for anti-spam, counts messages without archiving them. Your conversations are not stored. One exception: when a message mentions a Kirby Premium subscriber who is away (AFK), its first 200 characters, its author and its link are kept for them, and erased when they come back.
- Your IP addresses, beyond the web server's technical logs, kept briefly for security and diagnostics.
- Your email, phone number or payment details: the bot never asks for them.
3. The wallet: what you need to know
The wallet is custodial
Your private keys are generated and held on our server, tied to your Discord ID. They are encrypted (AES-256-GCM) and your PIN is never stored in clear text: it is hashed with a salt unique to your account.
In plain terms: the service operator has technical access to your funds. Only use this wallet if you accept that dependency, and do not leave amounts on it that you could not afford to lose.
You can retrieve your private keys and recovery phrase at any time with
/wallet export_keys: they are sent to you by direct message and
remain usable in any external wallet. The bot does not erase them on its side —
for that, use /wallet delete.
4. Who can see what
- Server administrators see the configuration and moderation data of their server. They have no access to your wallet or your keys, and cannot withdraw funds on your behalf.
- Replies to sensitive commands (PIN, private keys, backup code) are sent by direct or ephemeral message, never in a channel.
- Some commands are public by nature: wallet balance, deposit address, history, withdrawal, address balance, transaction, and server, member and bot cards. Do not run them in a channel if you would rather that information were not visible there.
5. Third-party services
To work, the bot queries outside services. It sends them the bare minimum — never your Discord identity:
- Discord — the platform itself (Discord's policy).
- Blockchain explorers and nodes — receive an address or a transaction ID to look up. A blockchain address is public by nature.
- Price providers (CoinGecko, Coinbase, Kraken, Binance) — receive a coin name, no personal data.
- Audio and lyrics sources — receive a search term or a link.
- Translation service — receives the text you explicitly ask to translate.
- Top.gg — receives the bot's server count, aggregated.
6. Seeing and deleting your data
Seeing it, and taking a copy
Sign in to the dashboard: the bottom of the page lists what the bot keeps about you, section by section, with the number of entries. One button downloads a full copy as JSON — tags, reminders, alerts, giveaway entries, invites, liked tracks, tickets, Kirby Premium settings and history, and the non-sensitive parts of your wallet.
What this export does not contain: your private keys and
recovery phrase. Those come out only through /wallet export_keys,
by direct message, after entering your PIN. A web download must not become a
shortcut to the funds of someone who left a session open.
Deleting it
- Your wallet:
/wallet delete(PIN + typed confirmation). Permanently erases the recovery phrase, the PIN and the addresses. Use/wallet export_keysfirst if funds remain on your addresses: after deletion, the bot can no longer return them to you. - Your other personal data: reminders, tags, alerts and
watched addresses can be removed from their own commands. An administrator
can erase your invite entries with
/invites clear— in both directions: your own join and the ones you brought in. - Your Kirby Premium settings: the Erase my
settings button in the My perks panel (opened from
/help), including after your subscription ends. It erases the settings and their images, the history, favourites, monthly counters and the linked-role connection. - A server's data: remove the bot from the server.
- Any other request: contact us (section 9). We reply within a reasonable time.
7. Security
- Recovery phrases encrypted with AES-256-GCM; the encryption key is not stored in the database.
- PINs hashed (scrypt, unique salt per account), compared in constant time, and temporarily locked after repeated failures.
- Site served over HTTPS with strict security headers.
No system is flawless. We cannot guarantee absolute security, and we would rather say so than imply otherwise.
8. Minors
The service follows Discord's terms: it is not intended for people below the minimum age Discord requires in their country.
9. Contact
For any question or deletion request, write to us on the Discord support server. It is the fastest route, and the only one we monitor consistently.
10. Changes
This policy may change along with the service. The date at the top shows the latest revision; significant changes will be announced on the support server.