Discord Bot Privacy Policy
Effective October 6, 2026
What this covers
This covers the Discord bot component of Formation — the part that lives inside a Discord server and responds to slash commands. It’s written in plain language because the bot doesn’t collect much. Everything else about how Formation handles your information is in the main Privacy Policy, and the Discord Bot Terms set the rules for using it.
Data we collect
Only what’s needed to operate the features below:
- Your Discord user ID and username — when you run
/link. - The server (guild) ID and name — when an administrator runs
/connect. - Command inputs, such as the day and time you give
/available— each time a command is used, to act on it. - Button clicks on reminder messages (RSVP) — when you click ✅ or ❌ on a posted reminder. The reminder message is then updated to show who has responded, using members’ display names, so anyone who can see that channel can see the responses.
- Direct messages we send you — only if you’ve turned on DM reminders. The bot can’t read your DMs.
- Role changes — if an organization turns on role syncing, the bot adds or removes one designated role on your Discord account to match your Formation team roster.
Data we don’t collect
- Message content from your server’s channels. The bot requests no privileged Discord permissions and can’t read regular chat messages.
- A bulk list of your server’s members, or their presence or activity status.
- Anything from a channel or DM the bot wasn’t directly invoked in or didn’t itself post.
The bot only sees a slash command’s own inputs, a button click’s own identity, and — for role syncing — the single member it’s told to update. It has no standing visibility into your server beyond that.
How data is used
Strictly to operate Formation for the organization that connected it: attributing commands to the right person, keeping a Discord role in sync with a Formation team roster, and delivering the reminders an organization or an individual has opted into. None of it is used for advertising, profiling, or any purpose unrelated to running the connected organization.
Retention and deletion
- Account links last until you disconnect Discord from your Formation account, at which point the stored Discord ID is deleted.
- Server links last until an administrator disconnects the bot, at which point the stored server ID is deleted.
- Linking codes (the short codes
/linkand/connectgenerate) expire after 10 minutes and are deleted on use or expiry. - RSVP responses are stored as ordinary Formation attendance records, governed by that organization’s own data retention.
Sharing
Data collected by the bot is not sold, rented, or shared with third parties for their own purposes. It stays within the Formation deployment operated for the connecting organization, which is hosted in the United States with the providers listed in the main Privacy Policy. Discord, as the platform the bot runs on, handles the interaction under its own policy — see Discord’s Privacy Policy.
Age requirement
The bot is not directed at children. You must meet Discord’s minimum age to use Discord, and Formation itself requires you to be at least 13, with a parent’s or guardian’s permission if you are under 18.
Changes to this policy
We may update this Discord Bot Privacy Policy at any time. When we do, we will notify you — by email to the address on your account and/or with a notice inside Formation — and we will change the effective date at the top of this page. For material changes we aim to give at least 14 days’ notice before they take effect.
If you keep using Formation after a change takes effect, you accept the updated Discord Bot Privacy Policy. If you don’t agree with a change, stop using Formation and contact us, and we’ll delete your data. Which version of our documents you accepted, and when, is recorded with your account.
Contact
Questions or data-deletion requests: [email protected].