Privacy Policy
Last updated 1 September 2026
1. Who we are
Mini Koi is an independent Discord bot and control panel operated by jacob_koi. This policy explains what we store when you add the bot to a server or sign in to the control panel. Using Mini Koi also means Discord's own Privacy Policy applies to your Discord account.
2. What we collect
We keep the smallest amount of data needed to run the features you enable:
- Discord IDs — user, server, channel and role IDs. These are numeric identifiers, not message content.
- Server configuration — the settings you save in the control panel (feature switches, channel and role choices, templates, reaction roles, sticky messages, custom commands).
- Account basics from Discord OAuth — your user ID, username, avatar URL and the list of servers where you have Administrator permission. The `identify` and `guilds` scopes are the only scopes requested.
- Operational records — moderation actions performed through the bot (case type, moderator ID, target ID, reason, timestamp), job queue entries and panel audit logs.
- Basic technical logs — timestamps and error information used to keep the service running and to detect abuse.
3. What we do not collect
We do not read, store or sell your message history, DMs, voice audio, email address, payment details or IP-based location. We do not build advertising profiles, and we never sell or rent data to anyone.
Message content is only retained when you explicitly save it — for example a sticky message, a welcome embed or a custom command response you created yourself.
4. Why we store it
Configuration is stored so the bot behaves the way you set it up. Discord IDs let the bot address the right server, channel, role or member. Audit and moderation records exist so server staff can review what happened and so we can investigate abuse of the service.
5. Access and security
Control-panel data is protected by row-level security: you can only read or change settings for servers where Discord reports you as the owner or as holding the Administrator permission, re-checked on every sign-in. Browser clients have no direct write access to bot tables — every change goes through server-side checks.
Traffic is served over HTTPS, sign-in uses the OAuth 2.0 authorization-code flow with PKCE and single-use state, and the bot API is authenticated with a secret token. No system is perfectly secure, but we aim for least-privilege access everywhere.
6. Third parties
Discord (the platform itself), our hosting and database provider, and the GIF/sticker provider used by the media library in the embed builder. Searches you type into the GIF picker are sent to that provider to return results. We do not share your data with anyone else.
7. Retention
Settings are kept while the bot is in your server. If Mini Koi is removed, the server's configuration becomes inactive and is deleted within 30 days. Panel sign-in records and cached server lists are refreshed at each login and removed when you request account deletion. Job queue entries are pruned after they complete.
8. Your choices
You can ask for a copy of the data tied to your Discord ID, or ask for it to be deleted, by contacting us in the support server. Removing the bot from a server stops all further collection for that server. Deleting your control-panel access is immediate on request.
9. Children
Mini Koi is not for anyone under 13, or under the minimum age required by Discord in your country. If we learn that data belongs to someone below that age, it is deleted.
10. Changes and contact
If this policy changes materially, the update will be announced in the support server. For any privacy question or data request, join discord.com/invite/minikoi.
Mini Koi is an independent project. It is not affiliated with, endorsed or sponsored by Discord Inc. “Discord” is a trademark of Discord Inc.