Effective date: August 1, 2026
Last updated: August 26, 2026
This Privacy Policy explains how CoUnity, LLC ("CoUnity", "we", "us") collects, uses, shares, retains and protects information when you interact with our Discord applications and related services (the "Services").
We operate several Discord bots and supporting web services. This policy applies to all of them. Not every feature described here runs in every Discord server — what is actually collected about you depends on which features the administrators of your server have enabled, and on what you choose to submit.
Controller and contact
CoUnity, LLC
226 Southbrook Dr
Byhalia, MS 38611-7431
United States
For any privacy request, including opting out or deleting your data: privacy@counity.xyz
1. A note on how Discord bots work
When you use a Discord server, Discord Inc. is the platform operator and processes your data under its own Privacy Policy. We receive a limited subset of that data through Discord's API, and only for the servers our bots have been added to.
Two consequences worth understanding up front:
We cannot delete data that lives in Discord itself. Your account, your profile, and the messages you have posted in a server belong to Discord and to that server's history. If you want a message removed from a channel, that is a request for Discord or the server's moderators, not for us. We can only delete the records we hold.
The administrators of your server decide which features are active. They choose whether wallet linking, content tracking, message bridging or an AI assistant runs in their server. Where a server administrator configures our Services to collect information, they act as a controller of that information alongside us, and they have their own obligation to tell their members what they have enabled.
2. Information we collect
2.1 Discord account and server identifiers
Received automatically from Discord's API when you interact with a feature:
Your Discord user ID (a numeric identifier)
Your username, display name or server nickname, and avatar URL, where a feature needs to show or label you
Server (guild), channel, role, thread and message identifiers
Your roles in a server, where a feature depends on them
We treat your numeric Discord user ID as the primary way to identify your records, because it is a pseudonymous identifier rather than your name.
2.2 Message content
Some features necessarily read what you write. Where enabled by a server's administrators, this may include:
Moderation: message content is evaluated against that server's rules. Messages that do not violate a rule are not retained; where a message is actioned, we may retain a record of the action and a copy or excerpt of the content.
Designated content channels: where a server runs a channel for sharing links or submissions, we store a record of your post, including the link and engagement counts.
Bridged channels: where a server mirrors a channel to or from another platform, message content, author name and attachments are transmitted to that platform in order to display them there.
AI assistant features: where a server runs a conversational assistant, your message and the assistant's reply are processed and may be logged so the feature can maintain context and so administrators can review quality and safety.
If you do not want a feature to process what you write, do not use the channels where that feature is active. Server administrators can tell you which channels those are.
2.3 Information you choose to give us
Collected only when you submit it yourself, typically through a command or a form:
Blockchain wallet addresses, where you choose to link a wallet
Email address, where you apply to a program that asks for one
Third-party profile links or handles, such as a code-hosting or social profile, where you submit them as part of an application
Free-text submissions, such as questions, nominations, applications or feedback
2.4 Activity and participation records
Generated as you use the Services:
Votes, nominations, submissions, questions and similar participation records
Attendance and session participation
Points, scores, tiers, ranks and eligibility status derived from your activity or from public blockchain data
Codes issued or claimed by you, and their status
2.5 Moderation and administrative records
Records of moderation actions and the reason recorded for them
Escalation records, including notes written by a moderator
Audit records of administrative actions, identifying which administrator acted, on what, and when
2.6 Technical and operational data
Application logs recording that an operation happened, when, and whether it failed. We deliberately exclude usernames and other directly identifying text from these logs and keep only numeric identifiers.
For our web endpoints: IP address, used for rate limiting and abuse prevention, and request metadata such as path, timestamp and response status.
2.7 What we do not collect
We do not ask for, want, or knowingly store:
Private keys, seed phrases, recovery phrases or wallet passwords. No CoUnity service will ever ask you for these. Anyone who does is attempting to defraud you.
Payment card numbers or bank account details
Government identification documents
Precise geolocation
Special-category data such as health, biometric, religious or political information
Your presence or activity status. None of our applications requests Discord's
Presence intent, so we do not receive or store whether you are online, idle or
offline, what game or application you are running, or your custom status.
3. How we use information
To operate the features a server has enabled, and to respond to your commands
To verify eligibility and assign or remove roles
To enforce a server's rules and to keep communities safe
To prevent fraud, abuse, spam and circumvention of moderation
To produce aggregate statistics and reporting for server administrators and, where applicable, program partners
To diagnose faults and maintain reliability
To comply with law and to enforce our Terms of Service
We do not use your information for advertising, and we do not sell it.
We do not train AI models on your data
Where a server runs a conversational assistant, your message is sent to an AI
provider so that a reply can be generated for you, and relevant text may be stored
so the assistant can retrieve context for future questions. That is the whole of
it. Specifically:
We do not train, fine-tune or otherwise adjust any machine-learning model
using your messages or your personal information.
Retrieval is not training. Where your text is converted into a numerical
representation to find related material, that representation is used only to
look things up; no model learns from it and no model weights change.
Where a moderator approves an answer so the assistant can reuse it, what is
stored is the text of that answer, as reference material. It does not alter a
model.
AI providers process your message in order to return a reply, and nothing more.
Every request we send carries an explicit instruction that the provider must not
retain the request or use it to train its own models, and our provider account is
configured to route only to providers that honour this. So the restriction applies
to each individual request, not merely to a setting that could later be changed.
Legal bases (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies, we rely on:
Purpose
Legal basis
Operating features you actively invoke
Performance of a contract, or your consent
Wallet address, email, profile handles you submit
Your consent (Art. 6(1)(a))
Moderation, safety, anti-abuse, audit records
Legitimate interests (Art. 6(1)(f))
Aggregate reporting to administrators
Legitimate interests (Art. 6(1)(f))
Retaining records to meet a legal obligation
Legal obligation (Art. 6(1)(c))
Where we rely on consent, you may withdraw it at any time — see Section 7. Withdrawing consent does not affect processing that already took place, and may mean a feature can no longer work for you.
4. When we share information
We do not sell personal information and we do not share it for cross-context behavioural advertising. We share it in four situations.
4.1 With the server you are in
Features are visible inside the server by design. Leaderboards, participation counts, submission lists and role assignments are visible to other members, and administrators can see and export the records for their own server.
4.2 With service providers acting on our behalf
We use third parties to run the Services. They may process your information only for us, on our instructions, and not for their own purposes. By category:
Category
What they receive
Cloud hosting and databases
All stored records, and application logs
Workflow and record-keeping platforms
Application and program data, which may include your Discord username, email address, wallet address and submitted profile links
Team communication tools
Escalation records, including message excerpts and moderator notes
Messaging platform bridges
Message content, author name and attachments from bridged channels
Blockchain data providers
Wallet addresses, in order to read public on-chain data during verification and eligibility checks
AI and language model providers
Message content and context, for conversational assistant features
Some of these providers are located in the United States and elsewhere.
4.3 With program partners
Where you apply to a program, ambassador scheme or similar initiative, the information you submit in that application — which may include your Discord username, email address, wallet address and profile links — is shared with the partner or client operating that program so they can review your application. We will make clear at the point of application when this applies.
4.4 For legal reasons
Where required by law, legal process or a lawful government request; to establish, exercise or defend legal claims; or to protect the rights, safety and property of CoUnity, our users or the public.
5. International transfers
We are based in the United States and our service providers may process information in the United States and other countries. If you are in the European Economic Area, the United Kingdom or Switzerland, this means your information may be transferred outside your country to a jurisdiction that may not provide the same level of data protection.
Where we make such transfers we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses or another lawful transfer mechanism, together with the security measures in Section 6. You may request further information about these safeguards at privacy@counity.xyz.
6. Security
We take commercially reasonable technical and organisational measures to protect information, including:
Encryption in transit (TLS) for all connections to our services and providers
Encryption at rest for our databases and stored data
Access controls limiting who can reach production systems and data
Deliberate minimisation of personal data in operational logs, keeping numeric identifiers rather than usernames
Restricting exports of personal data to server administrators and moderators
No system is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any relevant authority to the extent required by applicable law.
7. Your choices: opting out and deleting your data
7.1 The simple options
Leave the server, which stops future collection by our Services in that server, though it does not by itself delete records already held.
Do not use a feature. Most collection happens only when you invoke a command or post in a channel where a feature is active.
Unlink your wallet. Where a wallet-linking feature is available, you can unlink it using the relevant command, or ask us to do it.
7.2 Opting out, and requesting deletion, by email
To opt out of data collection, or to request deletion of the data we hold about you, email us at:
privacy@counity.xyz
Please include:
The subject line "Data Deletion Request" or "Opt-Out Request"
Your Discord user ID (the numeric ID — in Discord, enable Developer Mode under Settings → Advanced, then right-click your name and choose "Copy User ID")
The Discord server(s) you used our Services in, if you know them
Whether you want all your data deleted, or only specific data such as a linked wallet or an email address
Verification. So that we do not act on a request from someone impersonating you, we will confirm that the request genuinely comes from the holder of that Discord account — usually by asking you to confirm from the Discord account itself. We cannot action a request we are unable to verify.
Timing. We will acknowledge your request promptly and complete it within 30 days. If a request is complex and we need longer, we will tell you why and keep you informed, in line with applicable law.
What we will do. We will delete or irreversibly anonymise the records we hold about you across our systems, including records held by our service providers on our behalf.
What we cannot do, and will tell you honestly:
We cannot delete your Discord account, profile or message history — that is Discord's, and yours to manage with them.
We cannot retract information already shared with a program partner under Section 4.3; we will tell you who received it so you can contact them, and we will pass your request on.
We may retain the minimum necessary to comply with a legal obligation, to resolve a dispute, or to enforce a moderation decision — for example, retaining a numeric identifier so that a ban is not trivially evaded. Where we do this we will tell you what was kept and why.
Aggregate or anonymised statistics that can no longer be linked to you may be retained.
Effect of opting out. Opting out means features that depend on your data cannot work for you: you may lose roles, eligibility, points, standing in a program, or the ability to use certain commands. This is a consequence of the request, not a penalty, and we will tell you what you are giving up before we proceed if it is significant.
7.3 Your rights under the GDPR / UK GDPR
If you are in the EEA, the UK or Switzerland, you have the right to:
Access the personal data we hold about you, and receive a copy
Rectify inaccurate or incomplete data
Erase your data ("right to be forgotten")
Restrict processing in certain circumstances
Object to processing based on our legitimate interests
Data portability — receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible
Withdraw consent at any time, where we rely on consent
Not be subject to a decision based solely on automated processing that has legal or similarly significant effects. Our automated role assignments are based on objective criteria and can be reviewed by a human on request.
Lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.
7.4 Your rights under the CCPA / CPRA
If you are a California resident, you have the right to:
Know what personal information we collect, use, disclose and share, and the categories of sources and recipients
Delete personal information we hold about you
Correct inaccurate personal information
Opt out of the sale or sharing of personal information. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of — but you may still ask us to confirm this.
Limit use of sensitive personal information. We do not use sensitive personal information for purposes beyond providing the Services.
Non-discrimination. We will not deny you service, charge you differently or give you a lesser experience for exercising these rights. Note that if you ask us to delete data a feature depends on, that feature will stop working — that is a technical consequence, not discrimination.
Use an authorised agent to make a request on your behalf, with proof of authorisation.
To exercise any of these rights, use the email process in Section 7.2.
8. Retention
We keep personal information only as long as necessary for the purposes described in this policy, and specifically:
Active feature data — while our Services remain in your server and the relevant feature is enabled
Pending verification challenges — short-lived; they expire and are removed
Bridged message records — retained only briefly, as needed to keep a mirrored conversation coherent
Moderation and audit records — retained while needed for safety and accountability
Operational logs — retained on a rolling short-term basis by our hosting provider
Aggregate statistics — may be retained indefinitely once they can no longer be linked to you
When our Services are removed from a server, or when you make a verified deletion request, we delete or anonymise the associated records as described in Section 7.2.
9. Children
Our Services are not directed to children. You must be at least 13 years old, or the minimum age required in your country to use Discord, whichever is higher, as required by Discord's Terms of Service. We do not knowingly collect information from anyone below that age. If you believe a child has provided us information, contact privacy@counity.xyz and we will delete it.
10. Changes to this policy
We may update this policy as our Services change or as the law requires. We will update the "Last updated" date above, and for material changes we will provide notice through the servers where our Services operate, or by another reasonable means. Continued use after a change means you accept the updated policy.
11. Contact
Questions, requests or complaints:
privacy@counity.xyz
CoUnity, LLC
226 Southbrook Dr
Byhalia, MS 38611-7431
United States