Last updated: September 14, 2026
This Privacy Policy explains what data Tournament Bot ("the bot", "we", "us") collects when you use the Discord bot or its web control panel, and how that data is used, stored, and protected.
This policy applies to anyone who interacts with the bot in a Discord server it's added to (registering for a tournament, clicking Join/Leave, receiving a reminder DM) or who logs into the web control panel with their Discord account to organize tournaments.
We collect only what's needed to run tournaments and the panel:
identify
and guilds OAuth scopes only — we never see or store your email address or your Discord
password. Access/refresh tokens are encrypted at rest (AES-256-GCM) and are only ever used server-side to
read your guild list and permissions on your behalf.httpOnly
cookie in your browser. It can't be read by page scripts and is useless outside our server.We do not collect payment information, and we do not knowingly collect any data beyond what's listed above.
Tournament and registration data is kept for as long as the tournament exists in the database, so organizers can review past participant lists. An organizer can delete a tournament (and its registrations) at any time from the dashboard. Your web panel login session is deleted when you log out or expires automatically. To request deletion of your data, contact us at kaktysgames228@gmail.com.
OAuth2 tokens are encrypted at rest. Session cookies are httpOnly and, in production, sent
only over HTTPS. Every privileged action (creating, editing, or closing a tournament) is re-checked
server-side against your actual Discord permissions — never assumed from the UI alone.
This service is not directed at children under 13 (or the minimum Discord account age in your region), consistent with Discord's own Terms of Service.
If this policy changes, the "Last updated" date at the top will change accordingly. Material changes will be noted here.
Questions about this policy or your data? Contact kaktysgames228@gmail.com.