Privacy Policy for AgencyMod
Last updated: 23 September 2026
This privacy policy explains how we process personal data when AgencyMod is used on a Discord server, when you use the dashboard at bot.agencyscripts.dev and when you buy AgencyMod Premium. AgencyMod is a Discord bot for moderation, tickets, logs, welcome messages, button roles, FiveM tools, monitoring, a server list and optional AI features.
1. Controller
Agency Scripts, Sole Proprietor: Leon Rudolf
Die Halde 2, 64853 Otzberg, Germany
Email: [email protected]
Legal notice: agencyg.de/impressum
2. How AgencyMod works
Server administrators add AgencyMod to their Discord server and decide in the dashboard which features are switched on. AgencyMod only processes the data that the switched-on features need. Most features work on data that Discord sends to every bot on a server. We do not sell personal data and we do not use it for advertising profiles.
3. Data we process
3.1 Discord data on servers that use AgencyMod
Server ID, name and icon; IDs and names of channels and roles; IDs, usernames, display names, avatars and roles of members; the date a member joined. Discord provides this data to the bot. We use it to run the features a server has enabled, for example welcome messages, automatic roles, moderation commands and logs.
3.2 Message content
AgencyMod reads messages in channels it can see, in order to provide the enabled features (for example spam and link filters, ping protection, the counting game, commands and AI answers when AgencyMod is mentioned). Message content is processed in memory and is not stored in our database, with these exceptions that a server can switch on:
- Logs: the content of deleted or edited messages is posted into the log channel of that server on Discord.
- Ticket transcripts: when a ticket is closed, a transcript is posted into the server's transcript channel and, if enabled, sent to the person who opened the ticket.
- Applications: the answers to an application form are stored until a decision is made and for 90 days afterwards.
- Spam protection: When auto moderation removes a message, we store a case with the user ID, channel, rule, detected keywords, the text of the message and the text that the text recognition found in attached images. The removed image itself is deleted and is neither stored nor shown again anywhere. With the case, the server's moderators can lift a punishment or report a false detection to us.
Images and text recognition: When image recognition is switched on, AgencyMod briefly loads images posted in channels into memory, creates a checksum (MD5) of each image and reads the text in the image with a text recognition program (Tesseract) that runs on our own server in Germany. The images are not passed on to anyone for this and are not stored by us. AgencyMod keeps checksums and a member's latest messages in memory for at most 10 minutes to recognise the same message or the same image in several channels.
3.3 Data stored in our database
- Server settings from the dashboard, including texts the server writes itself (welcome messages, custom commands, AI instructions and knowledge).
- Warnings: user ID, moderator ID, reason and time.
- Tickets: channel, opener, category, status and times (no message content).
- Counting game: current number, last user and record.
- Applications (see 3.2).
- Tebex: if a server connects its own Tebex store, the redeemed transaction IDs and the Discord user who redeemed them. The Tebex secret key of that server is stored encrypted at rest on our server and is never shown again in the dashboard.
- Monitors: the targets a server wants to watch (websites, ports, game servers) and their status.
- Server list: the public information a server chooses to publish (name, icon, description, tags, member count, invite link) and bump times.
- Premium: status, type, runtime and payment references (see 3.5).
- AI usage: counters per server and day (number of requests and tokens), without content.
- A change history of dashboard settings (who changed what and when), limited to the last 500 entries per server.
- Tebex purchase logs: for every purchase that Tebex reports to the bot, the transaction ID, the packages bought, the amount, the buyer's name in the store and the status (no email addresses, no IP addresses, no real names).
- Reviews: if you review a server (in the server list or in Discord), your Discord user ID, display name, profile picture, the stars, your text and the time. Name, picture, stars and text are public: on the server's page in the server list, in the server's Discord channel and in the widget the server can embed on its website. You can change or delete your review yourself at any time.
- Documentation knowledge: if a server links public documentation pages, AgencyMod fetches these pages (respecting robots.txt) and stores their visible text to answer questions about them.
- Uploaded images: images a server uploads in the dashboard (backgrounds, logo, profile picture and banner of the bot). Embedded metadata such as camera or location data is removed on upload.
- Team access: the roles and user IDs a server gives access to its dashboard, with the areas they may change.
- Spam protection: strikes per server and user ID (number, latest reason, time) and the cases described in 3.2.
- Shared scam image blocklist: when an image is recognised as a scam advertisement, we store its checksum (MD5), the detected keywords, the score, the time and the server on which it was recognised. The list applies to all servers that use AgencyMod and contains neither the image nor any user data.
- Reported false detections: when a moderator reports a false detection, we receive the case (message text, text recognised in the image, rule and punishment), the server name, the user ID of the reporting person and their note. The report appears in an internal channel of our Discord server that only our team can see, so that we can check and improve the detection.
3.4 Dashboard login
You log in with Discord (OAuth2, scopes identify, guilds and guilds.join). We receive your Discord user ID, username, avatar and the list of servers you are a member of, including your permissions there, so that we can show only servers you are allowed to manage. We do not receive your email address or password. With guilds.join, AgencyMod adds you to the Discord server of Agency Scripts right after you log in, where you get support and news, just like when you log in to our shop. Discord asks for this permission on its login screen, and you can leave that server at any time without any effect on the dashboard. Your login is kept in a signed, encrypted session cookie for up to 7 days.
3.5 Payments
Premium is paid through PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg). PayPal processes your payment data under its own privacy policy. We receive and store the order or subscription ID, the amount, the currency, the status, and the Discord user and server the purchase belongs to. We keep these records for 10 years, because German tax law requires it.
3.6 AI features (Premium)
If a server switches on AI features, the question, a limited part of the recent conversation in that channel or ticket, and the instructions and knowledge text written by the server are sent to a specialised AI provider based in the USA to generate an answer. We name the provider on request. The provider processes the data on our behalf and may keep it for up to 30 days to detect abuse; it does not use it to train its models. We do not store the content of AI requests. AI answers are marked as AI answers.
If an admin uses the setup assistant, their request, the server's settings without secrets and the names of its channels and roles are sent to the provider. If a server has linked documentation pages, matching excerpts of these pages are sent along with questions.
For the AI protection of auto moderation (Premium), the text of a message and, if present, the text recognised in attached images are sent to the provider for checking.
3.7 Website
The website bot.agencyscripts.dev is delivered through Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA), which processes your IP address to deliver the page and to protect it against attacks. Our own web server logs requests without IP addresses. We only use technically necessary cookies (login session, language).
3.8 YouTube videos
Our start page shows a video that is hosted on YouTube. It is only loaded when you click on it: before that, the page shows an image from our own server and your browser does not connect to YouTube. After your click, the video is loaded from YouTube in privacy-enhanced mode (youtube-nocookie.com), a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google then receives your IP address, the page you came from and technical data about your browser, and may also process data in the USA. The legal basis is your consent given by the click (Art. 6(1)(a) GDPR); if you do not want this, simply do not start the video. More in Google's privacy policy: policies.google.com/privacy
4. Purposes and legal bases
- Providing AgencyMod and the dashboard as requested by server administrators and users: Art. 6(1)(b) GDPR.
- Moderation, security, preventing spam and abuse on servers that use AgencyMod, and keeping the service stable: Art. 6(1)(f) GDPR. Our legitimate interest, and that of the server communities, is a safe and working service.
- Payments and tax records: Art. 6(1)(b) and (c) GDPR.
- Text recognition in images, the shared scam image blocklist and the review of reported false detections: Art. 6(1)(f) GDPR. Our legitimate interest, and that of the server communities, is to stop scams and spam quickly and across all servers and to correct false detections.
5. Recipients
Discord Inc. (the platform the bot runs on), Cloudflare (website delivery), PayPal (payments) and the AI provider (only for AI features). AgencyMod itself runs on our own server in Germany. We only pass on data where it is necessary for the purposes above or where we are legally obliged to do so.
6. Transfers to countries outside the EU
Discord, Cloudflare and the AI provider are based in the USA. Transfers take place on the basis of the EU-U.S. Data Privacy Framework where the recipient is certified, and otherwise on the basis of the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
7. Retention
- All data of a server is deleted 30 days after AgencyMod is removed from that server. Administrators can also delete it at any time in the dashboard.
- Warnings are kept until a moderator removes them, or until they expire according to the server's setting.
- Ticket data is deleted 90 days after the ticket was closed.
- Applications are deleted 90 days after the decision.
- AI usage counters are deleted after 90 days.
- Payment records are kept for 10 years (tax law).
- The login cookie expires after 7 days at the latest.
- Tebex purchases are deleted 400 days after the purchase.
- Reviews stay until you delete them or the server deletes its data; if AgencyMod is removed from the server, they are deleted after 30 days.
- Uploaded images that are no longer used are deleted after 3 days.
- Documentation texts are refreshed daily and deleted as soon as the server removes the links.
- Spam protection cases are deleted after 30 days, reported false detections after 90 days and strikes one year after the latest hit.
- Entries on the scam image blocklist remain until we remove them after a review, for example after a reported false detection.
8. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). To use these rights, write to [email protected] or open a ticket in the category AgencyMod on help.agencyg.de. Please include your Discord user ID.
You also have the right to lodge a complaint with a supervisory authority, for example: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Postfach 3163, 65021 Wiesbaden, Germany.
9. Children
AgencyMod is meant for people who meet Discord's minimum age in their country. We do not knowingly collect data from children below that age.
10. Changes
We update this policy when AgencyMod changes. The current version is always available at bot.agencyscripts.dev/privacy.