PACKET
Sign in

Privacy Policy

Last updated: 2026-09-07 · Packet is in active alpha.

Packet helps you manage a Discord server's structure — roles, channels, categories, permissions, and related settings — as an editable, version-controlled document. This policy explains what we collect, why, who we share it with, how long we keep it, and how to get a copy of your data or delete it.

We do not sell your data, use it for advertising, or build marketing profiles.

Information you provide by signing in

When you sign in with Discord, we request only the identify and guilds permissions — your basic Discord identity and the list of servers you're in. We do not request your email address.

  • Your Discord user ID is stored so we can associate your blueprints, settings, and actions with you.
  • Your Discord access token is kept only in an encrypted, browser-only session cookie (it expires after 7 days) — it is never written to our database. We use it to ask Discord, in real time, which servers you can manage. Your server list is not stored in our database.
  • Discord is both our sign-in provider and a data recipient: when you open your server picker, we send your token to Discord's API to fetch your manageable servers.

Information about the servers you manage

  • Blueprints — the server structure you author (roles, channels, categories, permission settings, onboarding, automod rules, channel topics and pinned-post text, community settings, and references to icon/banner/emoji images by URL), plus Packet feature settings such as the role picker.
  • Snapshots and apply history — automatic backups of your structure and a record of each apply (what changed, when, the mode, and the Discord ID of who triggered it).
  • Activity log — a record of structure-changing actions (e.g. "applied," "created snapshot") with the Discord ID of who performed each.
  • Advanced direct-call log — if you use the advanced "raw" Discord-API passthrough feature, we store the full request and response of those calls. Because these can contain arbitrary Discord data, we treat them as sensitive and keep them only briefly (see Retention).
  • Feedback — if you submit feedback, we store your message, your Discord username and avatar at the time, the page you were on, and your browser/screen details, plus any replies — from our team, and any you send back, including a reply you send to our feedback message in a Discord DM.
  • Preferences — your per-account settings (theme, default options).

Message content: When Packet manages a channel, it briefly reads recent and pinned messages only to recognize messages it previously posted itself (so it doesn't duplicate them). This is processed in memory and is not stored.

Members of servers you manage

To assign roles automatically when someone joins (the Role Caller's auto-role feature), Packet uses Discord's Server Members access and is notified when a member joins a server Packet is in. It acts on that event in memory to grant the roles you configured — it does not store a member list or roster. Packet's role picker also lets members click to add or remove their own roles; those actions change roles on Discord and aren't kept as personal records.

Sticky roles (the optional "restore roles on rejoin" feature). Where a server enables sticky roles, Packet records which roles a member held when they leave, so it can put them back if the member rejoins. This is the one Role Caller feature that stores member-specific data, and only this: a member's user ID and the role IDs they had. It is deleted as soon as the member rejoins (their roles restored) and, if they never return, is pruned automatically after about 90 days. The feature is off by default.

Temporary roles (the optional /temprole feature). Where a server enables temporary roles, a moderator can grant a role that auto-expires. Packet stores the grant — the member's user ID, the role, who granted it, and when it expires — until the role is removed, then deletes the record. The feature is off by default.

Moderation cases (the optional Magistrate feature). Where a server enables moderation, a moderator can warn, mute, kick, or ban a member with the /mod commands. Packet stores a case record — the member's user ID, the moderator's ID, the action taken, the reason the moderator typed, and when — so moderators have history and the automatic escalation ladder works. When the server turns on the option to also track Discord's own moderation actions, Packet records the same kind of case for a ban / kick / timeout done through Discord's own menu, or a timeout applied by Discord's AutoMod, reading only the action, the target, and the reason from Discord's audit log. It also counts how often a member's messages trip AutoMod, and records a case only if that happens repeatedly in a short window — a count, never the messages themselves. It does not store any message content. The feature is off by default.

Activity status (the Activity roles feature). Where a server enables Packet's optional Activity roles feature, Packet uses Discord's Presence access. Through it, Discord shares a member's current activity — for example a game they're playing, or another app or service (such as music) shown in their Discord status. Packet compares that activity to the rules the server configured and adds or removes a role to match, in memory as the activity changes. It does not store any member's activity or status — the assigned Discord role is the only record. The feature is off by default and runs only where a server's admins enable it.

Server logging (the optional Logging feature). Where a server enables logging, Packet mirrors its server's activity into a channel the server's admins choose in Discord, and into a shorter-lived activity feed on the server's Status page in the dashboard. Admins choose what's included, and everything below is on by default: members joining and leaving; nickname changes; a member's roles being added or removed; bans, unbans, kicks, and timeouts (including ones AutoMod hands out on its own); channel changes; other server changes (roles, emoji, invites, threads, and similar settings); a member using one of Packet's own features, like the role picker or a custom color; and Packet's own dashboard actions, such as applying a blueprint, attributed to whoever ran them. Each entry names who did it, when there's a "who" to name, and what happened; an edit — a channel or role update, say — also lists what changed. Admins can exempt specific channels or roles from being logged at all, and choose whether each entry posts under the name of the person who did it, under "Packet Logs," or under a custom name they set.

What we keep, and for how long, depends on where it lands. The copy Packet keeps in the dashboard's activity feed is deleted automatically after the server's chosen retention period (1–365 days, 30 by default). The copy posted to your server's Discord channel is different: it's a message in your server like any other, we don't keep a separate copy of it, and we have no way to edit or retract it once it's sent — only your server's own admins can remove it there. The same is true of the ticket-opening staff summary below, when a server routes ticket activity to a log channel. The feature is off by default.

Support tickets (the optional Concierge feature). Where a server enables tickets, a member can open a private support channel from a panel. Packet stores ticket metadata — who opened it, the staff member who claimed or closed it, its status and timing, the close reason, and (if the panel asks for one) the short subject line the member types when opening. If a desk asks for feedback when a ticket closes, Packet stores the 1–5 star rating and the optional comment the member chooses to leave. To power support signals like "awaiting a reply" and first-response time, Packet sees that a message was sent in a ticket — who sent it and when — but not its text.

A staff summary when a ticket opens. Where a server also routes ticket activity to a log channel, opening a ticket posts a short staff-only summary there too — how long the member has been in the server, how old their Discord account is, how many roles they hold, their prior ticket history, and, if Moderation is on, a short summary of their case history. It's a snapshot from the moment the ticket opened, not a live view; a moderator can always pull a fresh one from the ticket itself. This only ever goes to the channel your admins chose for it, never to the ticket the member can see, and — like anything else Packet posts to a server's own channels — we can't take it back once it's there.

Separately, a server's admins can turn on an optional conversation view so support staff can read and reply to a ticket's thread from the dashboard — kept scoped to ticket channels only, for easy management of your support and your own record-keeping of those conversations. When a staff member opens a ticket, Packet reads that ticket channel's recent messages — including their text — live, on demand, only to display them, and stores none of it: an edit or deletion on Discord is reflected the next time the thread is loaded, and any attachments are shown as links only (Packet never downloads them). This uses Discord's "Message Content" permission, applies only to ticket channels, and is off unless a server's admins turn it on for their server. The tickets feature as a whole is off by default and runs only where a server's admins enable it.

Leveling, games, and coins (the optional Engagement feature). Where a server enables leveling, Packet stores activity counts — how many messages you've sent and minutes you've spent in voice there — never the content of anything you say. Those counts power your level, rank, and the server's leaderboards. Your global rank aggregates your counts across the leveling-enabled servers you're in; on global and server-group leaderboards you appear as "Anonymous" unless you opt in to being named. Where a server also turns on coins and games, Packet additionally stores your coin balance, your record of bets and payouts, your daily and streak progress, and your tournament scores and lottery tickets. Run /level privacy in any server to see exactly what's stored, control your visibility, or delete all of it — your coins included — permanently and irreversibly. The feature is off by default and counts activity only in servers whose admins enable it.

Service usage

We keep basic operational records to run and monitor the service: which servers Packet is in and when it was added or removed, and aggregate counts (number of servers, total members, work-queue depth). These describe service operation, not individual people.

Information we collect to keep the service secure

To detect and prevent abuse, we record, per request: your IP address and approximate country (from our edge provider), your browser user-agent, the page or route requested, the response status, and timing.

How we store your IP address: as-is, in plain form, for security and abuse-prevention purposes — for example, to recognize and block abusive sources. It is not anonymized or hashed in our records, and it may also appear in our operational logs. (Internally we sign a short-lived token that includes your IP to prevent tampering in transit; that is a transit-only protection and does not change how the IP is stored.)

If an address or a Discord account is blocked for abuse, we keep the blocked value (IP, range, or Discord user ID), the reason, and timing indefinitely as a security record, even after a block is lifted.

Who we share data with

We share data with the infrastructure providers needed to run Packet, and with bot-listing sites only when you ask us to:

  • Discord — your sign-in provider; we call Discord's API with your token to provide the service, and we write the structure you approve back to your server.

  • Cloudflare — our security and edge provider. To enforce blocks at the network edge, we send blocked IP addresses/ranges to Cloudflare, and we read back records of requests its protections acted on (which include client IP addresses).

  • Our hosting provider — runs the servers and databases.

  • Bot-listing sites — top.gg and discordbotlist.com. These are the only ones you trigger yourself.

    What we send. When you run /vote, we send your Discord user ID to the site you are claiming on, to ask whether you have voted for Packet there, so we can pay the reward. We send nothing else, we send it only when you run that command, and we never send it for anyone who does not. If you never run /vote, nothing about you ever reaches either site.

    What we receive. Once an hour we ask each site for its own list of recent voters, so a vote pays even if you never run the command. That request names nobody. The answer contains the Discord IDs of people who voted, and we keep a record that a vote was paid so the same vote cannot pay twice.

    Separately, we tell these sites how many servers Packet is in, so our listing shows an accurate count. That is a single number about Packet itself. It contains nothing about you, your server, or anyone in it.

No Packet feature sends your data to an AI or large-language-model provider. The "AI Blueprint" feature only gives you a prompt to copy into an AI chat of your own choosing — Packet itself transmits nothing, and what you paste there is between you and whichever service you picked.

Fixing problems

When something breaks we may look at logs and configuration to fix it. Those can contain Discord IDs and the shape of your server. We look at what the problem needs and nothing else, and we sometimes use developer tools — including AI assistants — while diagnosing it.

This is separate from the AI note above, which is about what Packet's own features do: no feature sends your data anywhere for AI processing. This paragraph is about us fixing a fault, by hand, when one happens.

How long we keep your data

DataRetention
Security request events (IP, country, user-agent, route)90 days, then deleted automatically
Cloudflare edge-security events30 days, then deleted automatically
Advanced direct-call log30 days, then deleted automatically
Activity log30 days, then deleted automatically
Session cookie / Discord access token7 days (cookie expiry); never stored on our servers
Blueprints, snapshots, templates, preferencesUntil you delete them, or the server is removed
Moderation cases (Magistrate)Kept as the server’s moderation record. A pardon marks a case inactive; it is not removed. Deleted with the server’s data
Server logging — dashboard activity feed (Logging)Per-server setting, 1–365 days (30 by default), then deleted automatically
Server logging, and the ticket-opening staff summary — posted to your server's Discord channelNot stored by us at all; it's a message in your server like any other, and only your server can remove it
Support tickets (Concierge)Until deleted, or the server is removed
Sticky roles (Role Caller)Kept as the server’s record of the roles you held when you left, so they can be put back. Deleted as soon as you rejoin; if you never do, pruned automatically after about 90 days. Off by default
Temporary roles (/temprole)Kept as the server’s record of a timed role a moderator gave you, until the role expires and is removed. Off by default
Leveling counts, coin balances, game history, and vote-reward records (Engagement)Until you erase them via /level privacy (a server Packet leaves prunes after 90 quiet days)
Apply history, feedbackUntil you delete them (or request deletion)
Install / usage records (servers joined/removed, aggregate counts)Kept for the life of the service
Blocklist recordsIndefinitely, as a security record

Your choices and your data

  • Sign out at any time to end your session.
  • Download your data — in Settings → Privacy & data, export a copy of the personal data we hold about you.
  • Delete your data — in Settings → Privacy & data, permanently delete your personal data: your security/request logs, activity, advanced-call records, feedback, preferences, and your server-role grants.

A few things are handled separately, and we'll tell you plainly:

  • Server structure is the server's data, not personal data. Deleting your personal data does not delete a server's blueprints, snapshots, or apply history — other admins of that server may rely on them. Delete those as server data, or they are removed when Packet is removed from the server.
  • Abuse records are retained. If your account or IP was blocked for abuse, that record is kept as a security record (so a blocked source can't simply reset it), even after a personal-data deletion.

You can also email us (below) to request a copy or deletion of your data, and we will honor it.

Changes

Packet is in active alpha, so this policy may change as the service evolves. We'll update the date at the top when it does.

Contact

Questions, or a privacy / data-deletion request? Email [email protected], or use the in-app Feedback page.