Privacy Policy
DRAFT — requires review by a lawyer before Chojio accepts payment. Chojio stores form responses and ticket transcripts, which can contain whatever a member typed. That is the highest-risk data in the product and this page has to be accurate about it before launch.
What is collected
Server data: server ID, name, owner ID, locale, channel and role IDs, and the configuration you create — panels, forms, ticket categories, reaction role groups.
Form responses: the answers members submit, with the submitting user ID and a timestamp. These may contain personal information, depending on the questions an administrator chose to ask.
Ticket transcripts: messages in a ticket channel, retained so staff can review a closed ticket. Premium servers can export them.
Account data: if you sign in to the dashboard, your Discord user ID and the list of servers where you have Manage Server. Payment details are handled by Stripe and never reach Chojio’s servers.
What is not collected
Chojio does not request the Message Content intent. It cannot read ordinary channel messages, and does not.
Retention
Configuration is kept while the bot is in the server. If it is removed, data is retained for 30 days so a re-install restores the setup, then deleted. Form response and transcript retention is set per plan; exact windows to be confirmed before launch.
Subprocessors
Discord (platform), Stripe (payments), and the hosting and database providers. A current list must be published here before launch.
Your rights
You can request a copy of your data or its deletion. A server owner can request deletion of everything tied to their server. Requests made through the dashboard or the support address are actioned within 30 days.
Contact
TODO: data protection contact before launch.