Last updated: October 3, 2026
This policy explains what SparkY ("we", "the Bot") collects, why, and how long it is kept. Using the dashboard or the Bot means you accept this policy.
Dashboard accounts: your Discord user ID, username, and OAuth access/refresh tokens (used only to list servers where you have Manage Server permission).
Sessions: a signed session cookie (no third-party tracking cookies).
Ticket content: messages in support channels the Bot operates in, kept temporarily in memory to provide conversation context to the AI model.
Server configuration: settings, documentation files, staff roles, channel IDs, and encrypted API keys uploaded by server administrators.
Operational logs: basic technical logs (errors, tool calls) stored on the host server.
We do not sell data, we do not run advertising or analytics trackers, and we do not collect data from servers where the Bot is not installed.
Message context from support tickets is sent to the AI provider configured for that server (such as Google Gemini via OpenRouter) to generate replies, and is subject to that provider's privacy policy. Discord receives data as part of normal bot operation, under Discord's privacy policy. Giveaway verification uses Discord OAuth solely to check membership and join dates in a specific server.
API keys are encrypted at rest. Dashboard sessions are signed and HTTP-only. The dashboard runs on a private server with firewall protection.
Ticket conversation context is kept only while a ticket is active and is discarded afterwards. Dashboard session tokens expire after 7 days. Server configuration persists until the server owner changes it or asks for deletion. Operational server logs (errors, tool calls) are stored for a maximum of 3 days and are automatically deleted after that - they exist only to debug problems and are never used to build user profiles. This deletion is automatic; individual log entries cannot be recovered once expired.
You can request removal of your data by asking a server administrator to delete the relevant ticket, or by removing the Bot from your server (which stops all new data collection). Server owners can request full deletion of their server's configuration and docs at any time.
The Service is not directed at children under 13 (or the minimum age in your country). We do not knowingly collect data from children.
This policy may be updated occasionally. Material changes will be reflected on this page with an updated date.