Selfself
Home Premium Legal
Sign in
← Legal & Policies SELF // PRIVACY

Privacy Policy

What Self processes, what it stores, what it does not store, and why the data is needed.

Effective October 5, 2026Version 1.75
ON THIS PAGE
1. Scope 2. Discord account and server information 3. OAuth tokens are not stored 4. Support, feedback, and dashboard content 5. Security and operational data 6. Self AI 7. Sessions and browser storage 8. Why Self uses information 9. When information is shared 10. Retention 11. Your choices and requests 12. Security 13. Changes and privacy questions

1. Scope

This Privacy Policy describes information processed by Self, bony.lol, the Self Discord bot, dashboard, support tools, Self AI, and related services. It explains the categories of information Self currently needs to operate these features and how that information is used.

2. Discord account and server information

When you sign in, Self requests the Discord OAuth scopes “identify” and “guilds”. Discord returns your account identity and the servers visible to your account. Self keeps only servers you can manage for dashboard use.

Self may store the following where needed to operate the dashboard and bot:

  • Discord user ID, username, display name, avatar URL, access level, and first/last-seen timestamps.
  • Discord server ID, server name, icon URL, owner ID, and the relationship between a dashboard user and servers they manage.
  • Server configuration such as enabled features, selected channel or role IDs, welcome settings, moderation/logging settings, anti-spam/link/invite settings, command overrides, and feature flags.
  • Limited bot runtime, command, and configuration state used to operate requested features, measure reliability, and verify whether authorized changes were applied.
  • Discord announcement content intentionally approved for the website’s What’s New feed. Internal source metadata may be retained where needed for synchronization, but normal dashboard users receive only the information needed to display the announcement.

3. OAuth tokens are not stored

Self exchanges the temporary Discord OAuth authorization code for an access token during sign-in, uses that token immediately to request your Discord identity and manageable guild list, and then discards it. The OAuth access token is not written to Self’s database and is not placed in your dashboard session.

Self does not request or store your Discord password. Bot credentials, OAuth client secrets, AI provider keys, and bot-control secrets are server-side configuration and are not intentionally exposed to browser JavaScript.

The dashboard stores the Discord identity and manageable-server information it needs after login—not the Discord OAuth access token itself.

4. Support, feedback, and dashboard content

Self stores information you choose to submit through the website so those features can function. This can include support-ticket subjects and messages, ticket status and assignment, suggestions and bug reports, Self AI/support-chat messages, and the server associated with a request.

Staff presence and administrative records may be processed internally so support queues, accountability, and service operations can function. Normal users receive only the limited support-availability or assignment information needed for their own experience.

5. Security and operational data

Self records limited operational information needed for reliability, abuse prevention, and troubleshooting. This includes login/activity events, application errors, administrative audit entries, rate-limit counters, release information, command metrics, and bot-control requests.

Self minimizes or transforms certain identifiers used for abuse prevention and limits operational records where practical. Hosting, network, or system logs may separately contain request metadata such as an IP address, timestamp, path, or user agent depending on infrastructure configuration.

6. Self AI

Self AI stores chat messages in Self’s database so conversations, support handoff, and staff assistance can work. If the AI provider is configured, Self sends the current message, recent conversation context, and relevant Self product knowledge to the configured provider to generate a response. Self requests provider-side response storage to be disabled where supported; the provider still processes the request under its own applicable terms and privacy practices.

If AI mode is not configured, Self can answer certain product questions using local site knowledge instead. If you request a human, authorized support staff can access the conversation to respond. Do not send passwords, authentication codes, private keys, payment credentials, or other secrets to Self AI or support chat.

7. Sessions and browser storage

Self uses protected authenticated sessions and browser cookies to keep you signed in. Sessions expire and may be invalidated when access changes or for security reasons. Browser-facing protections are used for state-changing requests.

The website may use browser storage for non-sensitive interface preferences such as the current bot-derived color theme, music/player state, or similar presentation settings.

8. Why Self uses information

  • Authenticate users and determine dashboard, support, Premium, or Developer access.
  • Verify current Discord server-management permissions before returning protected server data.
  • Save server configuration and operate bot/dashboard features requested by authorized users.
  • Provide tickets, feedback, live support, Self AI, update feeds, and staff workflows.
  • Detect abuse, enforce rate limits, investigate security issues, diagnose failures, and maintain service reliability.
  • Measure command/service health and improve Self’s usability and functionality.

9. When information is shared

Self does not sell personal information and does not use dashboard data for third-party targeted advertising.

Information is shared only as reasonably needed to operate Self—for example with Discord for bot/API actions, the configured AI provider for Self AI requests, infrastructure providers that host or deliver the service, or authorized support/developer personnel who need access to operate or secure Self. Information may also be disclosed when required by law or to protect rights, safety, users, or the service.

10. Retention

Self keeps information for as long as reasonably needed for the feature that created it, service security, support, dispute resolution, and legitimate operational needs. Operational and diagnostic records may be automatically limited or rotated so they do not grow indefinitely.

Support tickets, feedback, assistant conversations, server configuration, and registry information do not currently use one universal automatic deletion period and may remain until removed, no longer needed, or the service’s retention practices change.

11. Your choices and requests

You can sign out to end the current dashboard session and can remove Self or revoke permissions through Discord where available. Where applicable, you may request access to, correction of, or deletion of eligible information associated with your account through the dashboard Support Center. We may need to verify the Discord account involved before acting on a request.

Some records may be retained where reasonably necessary for security, fraud or abuse prevention, legal obligations, dispute resolution, or enforcement of these policies.

12. Security

Self uses layered technical and organizational safeguards intended to protect accounts, server settings, support information, and administrative systems. Access to sensitive functions is restricted and revalidated as appropriate. No internet-connected service can guarantee absolute security.

If you believe you found a vulnerability, follow the Responsible Disclosure / Security Policy rather than testing it against other users or real server data.

13. Changes and privacy questions

We may update this Privacy Policy as Self’s features or data practices change. The effective date at the top identifies the current version, and material changes may also be surfaced through the website or dashboard where reasonably appropriate. For an account-specific privacy request, use the Support Center in the dashboard. If you cannot access the dashboard, use Self’s existing community support channel. A dedicated privacy contact method may be added later.

OTHER POLICIES
Terms → Acceptable Use → Security →
Self logoSelf
Terms Privacy Acceptable Use Security Support
© 2026 Self. Self is not affiliated with Discord.