✨ The short version
We need your Discord account to log you in — ID, name, avatar, and email only.
Builder profiles are public by default. You can hide your profile, achievements, or individual published bots at any time.
We store your Bot Kits and your encrypted Discord bot token to run your bot.
We don't store message content for ads or analytics, and we never sell your data.
Delete your account and your data is gone within 30 days.
But please do read the details below.
Where your data lives
Your Discord account
User ID, display name, avatar URL, email — sign-in only
Your bot logic
Bot Kit JSON — versioned, owned by you, exportable
Your Discord bot token
AES-256-GCM at rest — never in Kit JSON, exports, or logs
Bot runtime data
Leaderboards, counters, stored values — per-bot, isolated
Deploy signals
Pub/sub + cached Kit JSON — deploy signals only, not your bot token
What we collect
💡 Only what we need to give you an account and run your bots.
Account information
When you sign in with Discord, we receive your Discord user ID, display name, avatar URL, and email address. We use this to create and identify your Kitcord account and to contact you about important service changes.
Your builder profile is public by default and may show your display name, avatar, account age, unlocked achievements, and summary cards for published bots. Draft bot content, email addresses, Discord application IDs, and bot secrets are never shown. Profile, achievement, and individual bot visibility can be changed from your profile settings.
Bot configuration
We store your Bot Kit definitions(the JSON files describing your bot's flows and logic), your bot's Discord application ID, your encrypted Discord bot token (from the Developer Portal — not your login), and optionally an interactions public key for interaction-only bots. The bot token is encrypted with AES-256-GCM before being written to our database and is never returned to any client interface.
Bot runtime data
Each bot has an isolated SQLite database file on our servers for runtime state — things like leaderboard scores, counters, activity logs, or key-value data your bot stores. This data belongs to your bot. You can download Bot Kit JSON today; a full export ZIP with your SQLite snapshot and Mini Engine is available from bot Settings.
Usage / energy data
We track per-bot ⚡ energy consumption (flow runs, piece types, hourly buckets, and gateway upkeep for full-gateway bots) to power your usage dashboard and enforce your energy balance. We do not record the content of messages your bot sends or receives for analytics.
What we never collect
Discord message content stored for marketing or analytics
Personal data about your Discord server members (unless your bot stores it in its own Vault)
Browsing behaviour outside of Kitcord
Any data that could be used for advertising targeting
Anything beyond what's needed to run the Service
Your bot may process messages in memory when your flows need them to respond — that's your bot working, not us snooping. We don't sell your data. Optional ⚡ top-ups (when available) are the only paid hosting piece.
How we use your data
💡 To run your account, host your bots, and fix things when they break.
We use your data exclusively to:
Authenticate your account via Discord OAuth
Run your bots on Discord on your behalf
Meter energy usage and enforce your energy balance
Send you essential service notifications (never marketing without consent)
Debug issues and investigate potential abuse — only when needed
How we protect your data
💡 Encryption in transit and at rest. Each bot's data is isolated from every other bot.
Encrypted at rest with AES-256-GCM before being written to our database. Never included in Kit JSON, exports, or any API response.
User accounts, bot metadata, and kit versions stored in MongoDB Atlas. At-rest encryption enabled at the cluster level.
Each bot's runtime database is a separate file on our servers, inaccessible to other bots or users.
Pub/sub bridge between app and engine. Deploy signals and hot-cached Kit JSON pass through — not your bot token.
All connections between your browser, our app, and our services use TLS encryption.
Who we share your data with
💡 Only the services we need to run Kitcord. We don't sell it. Ever.
Discord
Required to operateTo connect your bot to Discord's gateway and handle interactions. Without this, your bot doesn't work.
MongoDB Atlas
Required to operateOur database provider, where user accounts, Bot Kits, and encrypted credentials are stored.
Our hosting infrastructure
Required to operateThe servers that run kitcord-engine (our bot runtime) and store SQLite files. Self-operated.
Law enforcement
Only when we receive a valid legal request and are required by law to comply.
Export & data portability
Today you can download your Bot Kit JSON anytime, for free — no secrets inside. A full self-host ZIP (Kit + SQLite snapshot + Mini Engine) is available from Settings; export stays free. Mini Engine use is subject to LICENSE.md in the bundle.
This is a core commitment, not a premium feature. We believe you should always be able to leave with what you built, whether you've never topped up ⚡ or not.
Data retention and deletion
💡 Active account = data kept. Deleted account = data gone within 30 days.
We keep your data for as long as your account is active. If you delete your account, we will delete your user record, all associated Bot Kits, and all runtime SQLite files within 30 days.
We may retain aggregated, non-identifying usage statistics for internal analytics for up to 12 months.
To request deletion of your account and data, email privacy@kitcord.com.
Children
💡 Kitcord is not for users under 13.
Kitcord is not directed at children under 13 years of age (or the minimum digital consent age in your jurisdiction, if higher). We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us at privacy@kitcord.com and we will delete it promptly.
Changes to this policy
💡 We'll give you 7 days notice before any material change takes effect.
If we make material changes to this policy — changes that affect what we collect, how we use it, or who we share it with — we will notify you via email and/or an in-app banner at least 7 days before they take effect.
Minor clarifications (fixing typos, improving plain-English explanations without changing the underlying commitments) may be made without notice.
Privacy questions?
Data requests, deletion, questions about what we store — we're a real team and we'll respond.