Privacy Policy
GuildPilot Privacy Policy
Effective date: 18 July 2026
Last updated: 10 August 2026
1. About this Privacy Policy
This Privacy Policy explains how GuildPilot collects, uses, processes, stores and deletes information when you use:
- The GuildPilot Discord bot;
- The GuildPilot website and dashboard;
- GuildPilot payments pages;
- GuildPilot moderation, warning, AutoMod and logging tools;
- Ticket systems, ticket transcripts and web ticket archives;
- Welcome messages and welcome cards;
- Member activity, statistics, member-review and leveling features;
- Embeds, Smart Panels, Components V2 panels and role interactions;
- Counting, server counters and channel-control features;
- Automatic voice channels and LFG/LFP features;
- Pilot Premium;
- Pilot custom Discord bots;
- Pilot Markets;
- Pilot Coin, the Kiosk and virtual exchange features;
- Pilot Packs, virtual items, item marketplace and Pilot profiles; and
- Other related GuildPilot services.
GuildPilot is:
Email: support@guildpilot.co.uk
Website: guildpilot.co.uk
The GuildPilot operator is responsible for personal information processed for account authentication, service administration, security, support, payments, subscriptions, entitlements and GuildPilot's infrastructure.
Discord server owners and authorised administrators decide which GuildPilot features are enabled in their servers. They may also have their own responsibilities for explaining to server members how personal information is processed through the tools they configure.
This Privacy Policy does not replace any privacy information that a Discord server owner may be required to provide to their own members.
2. Information GuildPilot Collects
The information GuildPilot processes depends on the features enabled by a Discord server owner or authorised administrator.
GuildPilot does not collect every category described below from every server or every Discord member.
2.1 Discord login and dashboard information
When you sign in to the GuildPilot dashboard, GuildPilot uses Discord OAuth to authenticate you and determine which Discord servers you are authorised to manage.
GuildPilot may receive:
- Your Discord user ID;
- Your Discord username and display name;
- Your Discord avatar and profile information;
- A list of Discord servers connected to your account;
- Information about which servers you own or are authorised to manage; and
- Relevant Discord permission information.
Your Discord OAuth access token is used during the authentication process. GuildPilot does not retain the OAuth access token after the GuildPilot dashboard session has been created.
GuildPilot may use strictly necessary session information to keep you signed in, protect your dashboard session and prevent unauthorised access.
2.2 Discord server information
When GuildPilot is installed in a Discord server, GuildPilot may process and store:
- Discord server ID;
- Server name;
- Server icon reference;
- Server owner ID;
- Approximate server member count;
- Bot installation and update timestamps;
- Selected dashboard or bot language;
- Configured command channels;
- Blocked or allowed command-channel IDs;
- Dashboard administrator role IDs;
- Channel IDs and channel metadata;
- Role IDs and role metadata;
- GuildPilot bot role IDs;
- Custom bot role IDs;
- Configured logging, ticket, welcome, market and feature channel IDs;
- Cached channel and role information;
- Feature status and configuration information;
- Diagnostic results; and
- Information required to determine whether GuildPilot has the necessary permissions to operate.
Cached channel and role information may be refreshed when server settings change or when an administrator uses the dashboard.
2.3 Server configuration data
GuildPilot stores settings created by server owners and authorised administrators.
These settings may include configurations for:
- Welcome messages;
- Welcome cards;
- Uploaded welcome images;
- Moderation commands;
- Warning systems and warning thresholds;
- Punishment escalation rules;
- AutoMod rules, blocked terms, blocked domains, spam rules and exclusions;
- Channel-control rules, including media-only, command-only, suggestions, reviews and LFG/LFP channels;
- Join and leave logs;
- Message edit and deletion logs;
- Voice-channel logs;
- Ticket panels;
- Ticket questions;
- Ticket categories;
- Ticket permissions;
- Ticket inactivity settings;
- Ticket archive channels;
- Web ticket archive settings;
- Embeds;
- Capsules;
- Smart Panels;
- Components V2 panels;
- Self-role actions;
- Ticket actions;
- Button and menu interactions;
- Counting channels;
- Member and server counters;
- Automatic voice channels;
- LFG/LFP launchers and selected criteria;
- Leveling;
- Level rewards;
- Leveling card and ranking card settings;
- Member activity and statistics settings;
- Pilot Markets settings;
- Pilot Markets economy, competition, tax, announcement and achievement settings;
- Pilot Coin, Kiosk and exchange settings;
- Pilot Packs settings;
- Item marketplace settings;
- Pilot profile settings;
- Pilot Premium entitlements;
- Pilot custom bots; and
- Other server-specific GuildPilot features.
2.4 Member activity, statistics and member-review information
When member activity tracking, statistics or member-review features are enabled, GuildPilot may store or process:
- Discord user ID;
- Discord server ID;
- Activity date;
- Number of messages sent during that date;
- Total time spent in voice channels during that date;
- Join, leave or membership signals;
- Member display name, username and avatar where needed for display;
- Member role or permission context where needed for dashboard review;
- Moderation, ticket, warning or leveling summaries shown to authorised administrators; and
- Aggregated server statistics.
GuildPilot does not store the contents of messages for the member activity feature.
The activity system counts messages but does not use the message text to calculate activity.
Member activity records older than 90 days are deleted automatically.
2.5 Active voice-session information
While a member is connected to a voice channel, GuildPilot may temporarily store:
- Discord user ID;
- Discord server ID;
- Discord voice-channel ID; and
- Voice-session start time.
This information is used to calculate voice activity accurately.
The temporary session record is removed or completed after the member leaves the voice channel, the session is otherwise ended, or an automated recovery process resolves an interrupted session.
2.6 Leveling information
When leveling is enabled, GuildPilot may store:
- Discord user ID;
- Discord server ID;
- Display name;
- Avatar URL;
- Total experience points;
- Current level;
- Active or inactive status;
- The time a level was reached;
- Daily activity XP history;
- Command or bonus XP records;
- Level reward records; and
- The time the leveling record was last updated.
GuildPilot does not need to store ordinary message content to award experience points.
Leveling records are not currently deleted automatically based solely on their age.
When a member leaves a server, their leveling record will normally be marked as inactive. Where the server administrator has enabled the reset-on-leave option, the member's leveling record will instead be deleted when they leave.
Server administrators may also reset leveling data through supported GuildPilot controls.
2.7 Moderation, warning, AutoMod and channel-control information
When moderation, warning, AutoMod or channel-control tools are used, GuildPilot may process and store information such as:
- The Discord user ID of the affected member;
- The Discord user ID of the moderator or administrator;
- Discord server ID;
- Moderation action type;
- Warning points;
- Warning status;
- Moderation or warning reason;
- Relevant timestamps;
- Punishment duration;
- Punishment expiry time;
- Whether a punishment is active, expired or removed;
- AutoMod rule configuration;
- Blocked terms, blocked domains, spam limits and exception lists;
- Channel-control configuration;
- Suggested post, review post, media-only or command-only validation information;
- LFG/LFP post, criteria and expiry information; and
- Related configuration or audit information.
This information allows GuildPilot to carry out moderation commands, maintain warning totals, apply configured thresholds, expire temporary punishments, enforce configured AutoMod or channel rules and provide records to authorised server administrators.
Moderation reasons, imported moderation records, AutoMod rule text and ticket questions are entered by the server's administrators or moderators. Server administrators should avoid entering unnecessary sensitive personal information.
Where message-content checks are enabled, GuildPilot may process message content as needed to enforce configured rules. GuildPilot does not use ordinary message content for unrelated profiling.
2.8 Ticket information
When the GuildPilot ticket system is enabled, GuildPilot may process and store:
- Ticket creator Discord user ID;
- Discord server ID;
- Ticket channel ID;
- Ticket panel or category ID;
- Selected ticket type;
- Answers submitted through ticket forms;
- Ticket status;
- Assigned or claiming staff member ID;
- Ticket creation and update timestamps;
- Awaiting-user status;
- Ticket inactivity information;
- Ticket closure information;
- Ticket archive configuration;
- Ticket transcript delivery information;
- Web ticket archive status;
- Ticket archive message text where web archiving is enabled;
- Ticket attachment metadata where web archiving is enabled; and
- Transcript delivery or archive-reference information.
Ticket form answers and messages may contain information entered voluntarily by Discord members. Server owners are responsible for configuring appropriate ticket questions and ensuring that members are not asked to provide unnecessary sensitive information.
2.9 Ticket transcripts and web ticket archives
When ticket transcript archiving is enabled, GuildPilot processes the messages and relevant ticket information required to generate a transcript.
The completed transcript may be sent to the Discord archive channel selected by the server administrator.
For traditional Discord-delivered transcripts, the contents of the completed ticket transcript are not retained in the GuildPilot database after the transcript has been generated and sent to the configured Discord channel. GuildPilot may retain limited ticket metadata or a reference showing that the transcript was generated or delivered.
Where threaded web ticket archiving is enabled, GuildPilot may store searchable ticket message text and attachment metadata for the configured web archive. Ticket media remains hosted by Discord and is loaded from the private Discord archive when an authorised dashboard manager opens the transcript.
Copies posted to Discord are stored by Discord and the relevant server. Those copies are subject to:
- Discord's own privacy and retention practices;
- The server's channel permissions;
- Actions taken by the server owner or moderators; and
- Any server-specific retention policy.
Deleting information from GuildPilot does not automatically delete a transcript or message that has already been posted to Discord.
2.10 Logging information
When logging features are enabled, GuildPilot may process information required to create logs for:
- Members joining or leaving a server;
- Newly created Discord accounts joining a server;
- Edited messages;
- Deleted messages;
- Voice-channel joins, leaves and movements;
- Moderation actions;
- Ticket actions;
- Auto Voice actions;
- Leveling actions;
- Pilot Markets actions;
- Pilot Packs or marketplace actions; and
- Other configured server events.
Where message edit or deletion logging is enabled, GuildPilot may temporarily process the relevant message content so that the configured log can be sent to the server's Discord logging channel.
GuildPilot does not ordinarily retain message edit or deletion log content in its database after the log has been sent to Discord, unless a specific feature such as web ticket archiving separately stores ticket archive content.
Logs posted to a Discord channel are retained by Discord and the relevant server until they are deleted through Discord.
Server owners are responsible for selecting appropriate logging channels, restricting access to those channels and informing their members where required.
2.11 Embeds, Smart Panels, Components V2 and interactions
When an administrator creates an embed, capsule, Smart Panel or Components V2 panel, GuildPilot may store:
- Embed titles and descriptions;
- Panel content;
- Images, icons and URLs supplied by the administrator;
- Button and menu labels;
- Target Discord channel IDs;
- Associated role IDs;
- Associated ticket configurations;
- Action types;
- Message IDs;
- Creator or administrator IDs;
- Creation and update timestamps;
- Draft or saved configuration state;
- Interaction configuration; and
- Delivery or edit status.
When a member interacts with a panel, GuildPilot may process their Discord user ID and the selected action so that it can add, remove or toggle a role, open a ticket, process a form, route an action or perform another configured action.
2.12 Counting and server counter information
When counting or counter features are enabled, GuildPilot may store or process:
- Discord server ID;
- Configured channel ID;
- Current count or counter state;
- The Discord user ID of the last participating member;
- Member, bot, online, role or server statistics used by a configured counter; and
- Relevant update timestamps.
2.13 Automatic voice-channel and LFG/LFP information
When Automatic Voice is enabled, GuildPilot may process and store:
- Discord server ID;
- Discord user ID;
- Lobby channel ID;
- Temporary voice-channel ID;
- Temporary channel owner ID;
- Whitelist or ban settings;
- Configured permissions;
- Channel name and user limit;
- Creation and update timestamps; and
- Information required to manage or delete the temporary channel.
Temporary voice channels and related operational records may be removed when the channel becomes empty or when an authorised user deletes the channel.
When LFG/LFP features are enabled, GuildPilot may process and store:
- LFG/LFP channel ID;
- Original poster Discord user ID;
- Selected game or activity criteria;
- Selected Auto Voice target configuration;
- Message and component IDs;
- Expiry information; and
- Deletion or moderation state.
2.14 Pilot Markets, Pilot Coin, Kiosk, Packs, marketplace and profiles
When Pilot Markets, Pilot Coin, the Kiosk, Pilot Packs, the item marketplace or Pilot profiles are enabled, GuildPilot may process and store:
- Discord server ID;
- Discord user ID;
- Market configuration;
- Local virtual currency name, symbol and settings;
- Virtual balances and bank balances;
- Virtual currency issuance records;
- Pilot Coin wallet balances;
- Pilot Coin ledger entries;
- Pilot Coin reserve, treasury, insurance, exchange and reconciliation records;
- Kiosk or exchange quotes, confirmations, rates, fees and execution status;
- Market asset settings;
- Virtual asset holdings;
- Pending, confirmed, filled, cancelled or rejected virtual orders;
- Virtual transaction history;
- Cost basis, realised and unrealised profit/loss, portfolio snapshots and net worth;
- Daily trading statistics and cooldown information;
- Achievement progress and unlocks;
- Competition entries, isolated competition balances, competition holdings, rankings and prize deliveries;
- Monthly portfolio-tax records where enabled;
- Public portfolio and leaderboard eligibility settings;
- Public leaderboard display rows where enabled;
- Pack configuration, availability and purchase limits;
- Pack purchases, pack instances and pack openings;
- Pack item lots, quantities, rarity, value and ownership state;
- Marketplace listings, fills, taxes, reservations, expiries and settlement records;
- Pilot profile visibility, profile handle, equipped items, titles, frames and showcase choices;
- Announcement outbox and delivery records; and
- Administrative audit records.
These records are used to operate the virtual entertainment features, keep each server economy isolated, prevent duplicate rewards or trades, settle virtual purchases and marketplace fills, calculate leaderboards, protect against abuse and maintain an audit trail.
Pilot Markets, Pilot Coin, server currencies, Packs, pack items, badges, achievements and profiles are virtual. They have no cash value and cannot be bought with real money or withdrawn for money or goods.
2.15 Pilot Premium and payment information
Where Pilot Premium is purchased, subscribed to, redeemed or activated, GuildPilot may store information required to manage the purchase, subscription or entitlement, including:
- Premium status;
- Selected product or package;
- Product code;
- Entitlement source;
- Subscription or entitlement start and expiry dates;
- Activation information;
- Discord user ID associated with the entitlement;
- Discord server IDs using the entitlement;
- The number of authorised servers or assigned guild slots where applicable;
- Stripe order ID;
- Stripe checkout session ID;
- Stripe payment intent ID;
- Stripe charge ID;
- Currency;
- Expected amount;
- Paid amount;
- Payment, refund, dispute, chargeback, failure or expiry status;
- Provider event IDs and event payloads required for secure fulfilment;
- Discord Premium entitlement ID and SKU information where applicable; and
- Administrative records required to provide support.
GuildPilot may use Stripe for website payments and Discord for Discord Premium guild subscription entitlements. Stripe and Discord process payment information under their own privacy policies and terms.
Unless expressly stated during payment, GuildPilot does not require full payment-card details to be stored in the GuildPilot database. Full card details are normally handled by the payment provider rather than GuildPilot.
2.16 Pilot custom bots
When a server uses a Pilot custom bot, GuildPilot may store:
- The custom bot's Discord application ID;
- Bot user ID;
- Bot name;
- Bot avatar;
- Bot display settings;
- Presence or status configuration;
- Linked Discord server ID;
- Custom bot configuration;
- Relevant channel and role IDs;
- Operational status;
- Installation and update timestamps; and
- An encrypted Discord bot token.
The encrypted token is used only to connect and operate the authorised custom Discord bot.
Access to custom-bot tokens and management tools is restricted to authorised GuildPilot administrators and systems that require access to operate the service.
A custom bot token should be removed when the custom bot is permanently disconnected, deleted or no longer authorised, subject to reasonable security, recovery and backup processes.
2.17 Uploaded images and files
GuildPilot may store images or files uploaded through the dashboard for features such as:
- Welcome cards;
- Welcome backgrounds;
- Leveling cards;
- Ranking cards;
- Embeds;
- Smart Panels;
- Custom bot avatars;
- Pilot Packs catalogue assets;
- Pilot profile or collectible visuals; and
- Other supported visual configurations.
Uploaded content remains stored until it is replaced, deleted through supported dashboard controls, removed as part of a feature deletion, archived as part of an audit record where necessary, or removed following a valid deletion request.
Administrators must only upload content they are authorised to use.
2.18 Dashboard audits, diagnostics and service records
GuildPilot may store limited operational information required to administer and secure the service, including:
- Dashboard actions;
- Administrator Discord user IDs;
- Discord server IDs;
- Action types;
- Configuration changes;
- Timestamps;
- Bot permission checks;
- Diagnostic results;
- Error information;
- Command or interaction metadata;
- Service-health information;
- Worker and scheduled-task results;
- Payment-provider event processing results;
- Pilot Coin reconciliation and safety alerts;
- Marketplace or virtual-economy integrity checks; and
- Custom bot operational information.
These records are used to investigate faults, protect GuildPilot, respond to support requests, prevent abuse and maintain service stability.
Diagnostic and error records may include relevant Discord IDs where necessary to identify the affected server, feature or interaction.
2.19 Support communications
When you contact GuildPilot, GuildPilot may receive:
- Your name or Discord username;
- Your email address;
- Your Discord user ID;
- Your Discord server ID;
- The contents of your support request;
- Screenshots or files you provide;
- Purchase, subscription or transaction references where relevant; and
- Correspondence relating to the request.
Support information is used to respond to your enquiry, investigate technical problems, verify authority and maintain an appropriate support record.
3. Where Information Comes From
GuildPilot may receive information:
- Directly from you;
- From Discord through its API, gateway, OAuth services and entitlement systems;
- From Stripe through checkout, payment, refund, dispute and webhook events;
- From Discord server owners and authorised administrators;
- From moderators using GuildPilot commands;
- From members interacting with GuildPilot features;
- From GuildPilot's bot processes, workers, dashboard, payment systems and custom bot systems; and
- From service diagnostics and security monitoring.
GuildPilot only accesses Discord information that Discord makes available to the bot or dashboard and that is permitted by the bot's permissions and the server's configuration.
4. How GuildPilot Uses Information
GuildPilot may use information to:
- Authenticate dashboard users;
- Verify server ownership and management permissions;
- Operate the GuildPilot bot and dashboard;
- Provide features configured by server administrators;
- Calculate member message and voice activity;
- Operate statistics, member-review and change-history features;
- Operate leveling and level rewards;
- Carry out moderation actions;
- Record warnings and apply configured warning thresholds;
- Operate AutoMod and channel-control rules;
- Create and manage tickets;
- Generate ticket transcripts and web ticket archives;
- Send configured server logs;
- Create and manage temporary voice channels;
- Manage LFG/LFP posts and launchers;
- Manage embeds, Smart Panels, counters and role interactions;
- Operate Pilot Markets, Pilot Coin, Kiosk, Packs, marketplace and profile features;
- Operate Pilot custom bots;
- Manage Pilot Premium access;
- Process Stripe website payments;
- Process Discord Premium entitlements;
- Prevent duplicate payments or duplicate fulfilment;
- Maintain accurate configuration, entitlement, payment and transaction records;
- Diagnose technical problems;
- Monitor service health and performance;
- Prevent misuse, abuse, fraud and unauthorised access;
- Protect GuildPilot, Discord servers and users;
- Respond to support requests;
- Process data access or deletion requests;
- Enforce GuildPilot's Terms of Service; and
- Comply with legal obligations.
GuildPilot does not sell personal information.
GuildPilot does not use ordinary member activity data to read or analyse the contents of members' conversations.
5. Lawful Bases for Processing
Where UK data-protection law applies, GuildPilot relies on one or more lawful bases depending on the purpose of the processing.
5.1 Performance of a contract
GuildPilot may process information where it is necessary to:
- Provide the bot, dashboard, Pilot Premium or paid service requested by a user;
- Process a purchase, subscription, entitlement, refund or support request;
- Operate Pilot Markets, Pilot Coin, Packs, marketplace and profile features selected by a server;
- Operate a Pilot custom bot;
- Maintain an account, entitlement or subscription;
- Provide support; or
- Fulfil GuildPilot's obligations under its Terms of Service.
5.2 Legitimate interests
GuildPilot may process information where necessary for legitimate interests, including:
- Operating configured Discord features;
- Maintaining service stability;
- Preventing abuse and unauthorised access;
- Preventing payment fraud, duplicate fulfilment, marketplace abuse and virtual-economy manipulation;
- Investigating errors;
- Securing GuildPilot infrastructure;
- Maintaining administrative, moderation, payment and virtual-economy records;
- Supporting Discord server owners;
- Improving reliability; and
- Protecting GuildPilot's legal rights.
Where GuildPilot relies on legitimate interests, it considers whether those interests are outweighed by the rights and freedoms of affected individuals.
5.3 Legal obligations
GuildPilot may process or retain information where required to comply with applicable law, respond to lawful requests, maintain tax or accounting records, or meet regulatory obligations.
5.4 Consent
Where GuildPilot specifically asks for consent, the information will be processed for the purpose explained when consent is requested.
Consent may be withdrawn at any time. Withdrawing consent does not affect processing that occurred lawfully before it was withdrawn.
6. Information Sharing
GuildPilot does not sell or rent personal information.
Information may be shared in the following circumstances.
6.1 Discord
GuildPilot sends information to Discord when carrying out configured actions, including:
- Sending bot responses;
- Publishing welcome messages;
- Posting server logs;
- Creating ticket channels;
- Posting ticket transcripts;
- Managing roles;
- Creating or deleting voice channels;
- Applying moderation actions;
- Posting Pilot Markets, Packs, marketplace or competition announcements; and
- Operating custom bots.
Information sent to Discord is also processed under Discord's own privacy practices.
6.2 Server owners and administrators
Information may be made available to server owners, moderators or authorised administrators through:
- GuildPilot dashboard pages;
- Discord commands;
- Moderation records;
- AutoMod and channel-control records;
- Activity, statistics or leveling displays;
- Member-review pages;
- Ticket channels;
- Web ticket archives;
- Transcript archive channels;
- Logging channels;
- Pilot Markets, Kiosk, Packs, marketplace and profile pages; and
- Other configured features.
Access depends on the permissions configured by the relevant Discord server.
6.3 Payment and entitlement providers
GuildPilot may use Stripe to process website payments and Discord to process Discord Premium guild subscription entitlements.
Stripe may process payment details, billing details, fraud-prevention information, checkout-session information, payment status, refund status and dispute information under Stripe's own privacy policy and terms.
Discord may process subscription, entitlement and server information under Discord's own privacy policy and terms.
GuildPilot receives only the information reasonably needed to confirm payment or entitlement status, activate access, prevent duplicate payment, provide support, handle refunds or disputes and keep required records.
6.4 Hosting and infrastructure providers
GuildPilot uses OVHcloud to host its services and infrastructure.
OVHcloud may process or store information on GuildPilot's behalf where required to operate:
- The GuildPilot website;
- The dashboard;
- The Discord bot;
- Databases;
- Background workers;
- Pilot custom bots;
- Uploaded files; and
- Related infrastructure.
GuildPilot may use additional technical providers where reasonably necessary to provide, protect or maintain the service. Such providers are only given access to information required for their services.
6.5 Legal and safety disclosures
GuildPilot may disclose information where reasonably necessary to:
- Comply with a legal obligation;
- Respond to a valid court order or lawful authority request;
- Investigate suspected fraud, abuse, manipulation or security incidents;
- Enforce GuildPilot's Terms of Service;
- Establish, exercise or defend legal claims; or
- Protect the rights, safety and security of GuildPilot, its users or others.
6.6 Business changes
If responsibility for GuildPilot is transferred, reorganised or acquired, relevant information may be transferred as part of that change, subject to applicable data-protection requirements.
7. International Processing
GuildPilot is operated from the United Kingdom.
Some service providers, including Discord, Stripe and hosting or infrastructure providers, may process information in countries outside the United Kingdom.
Where GuildPilot is responsible for an international transfer of personal information, GuildPilot will take reasonable steps to ensure that an appropriate transfer mechanism or safeguard is used where required by applicable law.
Information sent directly to or stored by Discord or Stripe is also subject to those providers' own international data-transfer arrangements.
8. Data Retention
GuildPilot retains information only for as long as it is reasonably required for the purposes described in this Privacy Policy.
Different categories of information have different retention arrangements.
8.1 Discord OAuth tokens
Discord OAuth access tokens used for dashboard authentication are not retained after the GuildPilot dashboard session has been created.
8.2 Member activity records
Daily message and voice activity records older than 90 days are deleted automatically.
8.3 Active voice sessions
Temporary active voice-session information is retained until the voice session ends or an interrupted session is resolved.
8.4 Leveling records
Leveling information does not currently have an automatic age-based deletion period.
When a member leaves a server:
- Their record is normally marked inactive; or
- Their record is deleted where reset-on-leave is enabled.
Leveling information may also be removed through a server reset, supported administrator control or valid deletion request.
8.5 Server settings and configuration
Server settings and configuration information are generally retained while GuildPilot or an associated Pilot custom bot is connected to the relevant Discord server.
Removing the bot stops most further collection from that server but does not necessarily cause all existing information to be deleted immediately.
Existing information may remain until:
- It is deleted through the dashboard;
- The relevant configuration is removed;
- The server owner submits a valid deletion request;
- GuildPilot applies an applicable cleanup process; or
- It is no longer reasonably required.
8.6 Moderation, warning, AutoMod and channel-control records
Moderation, warning, AutoMod and channel-control records may be retained while required to operate the server's configured systems, maintain warning totals, manage punishment expiry, audit automated actions and provide records to authorised administrators.
Temporary punishments may be marked expired or inactive when they end. Expiry does not necessarily delete the underlying moderation record.
Records may be removed through supported administrator controls or a valid deletion request, subject to legal, security and dispute-resolution requirements.
8.7 Ticket information and web archives
Active ticket information is retained while required to operate and manage the ticket.
Ticket metadata may remain after closure until it is deleted through available controls, an applicable cleanup process or a valid deletion request.
Traditional ticket transcript content is not retained in the GuildPilot database after the completed transcript has been sent to the configured Discord archive channel.
Where threaded web ticket archiving is enabled, GuildPilot stores searchable ticket message text and attachment metadata for 90 days after the ticket closes. Ticket media remains hosted by Discord and is loaded from the private Discord archive for authorised dashboard managers.
8.8 Discord logging content
Message or event information processed to create a configured Discord log is not ordinarily retained in the GuildPilot database after the log has been delivered.
Copies posted in Discord remain there until removed through Discord by someone with the necessary server permissions.
8.9 Pilot Markets, Pilot Coin, Packs, marketplace and profile records
Virtual economy records may be retained for as long as reasonably necessary to operate the feature, preserve server economy integrity, prevent duplicate transactions, investigate abuse, resolve disputes, correct technical errors and maintain an audit trail.
Some records, including transaction ledgers, Pilot Coin ledger entries, exchange quotes, marketplace fills, pack openings, purchase records, competition settlements, tax records, achievement unlocks, reconciliation records and related audit records, may be retained long-term because they are needed to keep the virtual economy consistent and explain past changes.
Deleting a server configuration or disabling a feature may stop future use but does not necessarily delete historical transaction or audit records immediately.
8.10 Payment, subscription and entitlement records
Payment, refund, dispute, checkout, subscription and entitlement records may be retained for as long as reasonably necessary to:
- Activate paid access;
- Prevent duplicate payment or duplicate fulfilment;
- Provide support;
- Process refunds or disputes;
- Detect fraud or abuse;
- Maintain accounting and tax records;
- Reconcile Stripe and Discord provider events; and
- Establish, exercise or defend legal claims.
Full card details are normally retained by the payment provider rather than GuildPilot.
8.11 Uploaded images
Uploaded images are generally retained until they are replaced, deleted through the dashboard, removed with the related configuration, archived where reasonably needed for security or audit purposes, or deleted following a valid request.
8.12 Custom bot information
Custom bot configuration and encrypted tokens are retained while required to operate the authorised custom bot.
They may be deleted when the custom bot is permanently removed, the entitlement ends or an authorised administrator requests deletion, subject to security and backup processes.
8.13 Support, security and diagnostic information
Support correspondence, dashboard audit information, diagnostics and security records may be retained for as long as reasonably necessary to:
- Resolve the request or technical issue;
- Maintain service security;
- Investigate abuse;
- Resolve disputes;
- Enforce agreements; or
- Meet legal obligations.
8.14 Backups
Deleted information may remain temporarily in restricted backups until those backups are overwritten or expire through GuildPilot's normal backup cycle.
Backup copies are not intended to be used for ordinary service operations after the live information has been deleted.
9. Removing GuildPilot and Deleting Server Data
A server owner or authorised administrator may:
- Remove GuildPilot from the Discord server;
- Remove an associated Pilot custom bot;
- Disable individual features;
- Delete supported configurations through the dashboard;
- Reset supported member records;
- Delete uploaded images;
- Remove saved panels, embeds and settings;
- Disable Pilot Markets, Packs, Kiosk or profile features where supported; or
- Submit a server data-deletion request.
Removing GuildPilot from a server may stop further collection but does not guarantee immediate deletion of all previously stored information.
To request deletion of stored server data, contact:
support@guildpilot.co.uk
The request should include:
- The relevant Discord server ID;
- The requester's Discord user ID;
- A description of the information or server concerned; and
- Sufficient information to confirm that the requester is the server owner or an authorised administrator.
GuildPilot may need to verify the requester's authority before deleting server-wide information.
Some limited information may be retained where reasonably necessary for:
- Legal compliance;
- Security;
- Fraud and abuse prevention;
- Payment, accounting and tax records;
- Virtual economy integrity;
- Dispute resolution;
- Establishing or defending legal claims;
- Enforcing GuildPilot's Terms of Service; or
- Backup recovery.
Deleting GuildPilot data does not automatically delete messages, logs, ticket transcripts, marketplace messages, Pilot Markets announcements or other information that has already been sent to Discord.
10. Individual Data Rights
Depending on the circumstances and applicable law, individuals may have the right to:
- Be informed about how their personal information is used;
- Request access to their personal information;
- Request correction of inaccurate information;
- Request deletion of their information;
- Request restriction of processing;
- Object to processing based on legitimate interests;
- Request transfer of information in certain circumstances;
- Withdraw consent where processing is based on consent; and
- Complain to a data-protection supervisory authority.
These rights are not absolute and may not apply in every situation.
For example, GuildPilot may need to retain certain information where it is required for security, legal compliance, payment records, virtual economy integrity or the establishment, exercise or defence of legal claims.
To make a data-protection request, contact:
support@guildpilot.co.uk
Please include enough information to:
- Identify the relevant Discord account or server;
- Explain the request; and
- Verify that the information relates to you or that you have authority to act for the relevant server.
GuildPilot will respond within the time limits required by applicable law.
11. Complaints
Questions or concerns about GuildPilot's use of personal information should first be sent to:
support@guildpilot.co.uk
12. Security
GuildPilot uses reasonable technical and organisational measures designed to protect information from:
- Unauthorised access;
- Accidental loss;
- Unlawful disclosure;
- Misuse;
- Alteration; and
- Destruction.
These measures may include:
- Restricted administrative access;
- Permission controls;
- Authentication requirements;
- Encryption of Pilot custom bot tokens;
- Payment webhook signature verification;
- Server and database access controls;
- Logging and diagnostic monitoring;
- Software updates;
- Transaction and reconciliation checks for virtual economy features; and
- Backup and recovery processes.
No internet-based service can guarantee absolute security.
Server owners are also responsible for:
- Protecting their Discord accounts;
- Restricting dashboard administrator roles;
- Configuring appropriate Discord permissions;
- Restricting access to moderation, ticket and logging channels;
- Protecting custom bot tokens;
- Reviewing payment, Premium and administrator access; and
- Removing access when an administrator no longer requires it.
13. Data Breaches
Where GuildPilot becomes aware of a personal-data breach, GuildPilot will investigate the incident and take reasonable steps to contain and address it.
GuildPilot will notify affected individuals or the relevant supervisory authority where notification is required by applicable law.
14. Third-Party Services
GuildPilot operates through and alongside Discord.
GuildPilot is not responsible for Discord's independent collection, storage or use of information.
When information is posted to Discord, including:
- Bot messages;
- Moderation logs;
- Welcome messages;
- Ticket channels;
- Ticket transcripts;
- Activity leaderboards;
- Leveling information;
- Pilot Markets announcements;
- Packs or marketplace notices; and
- Virtual economy leaderboards,
that information becomes subject to Discord's systems, permissions and privacy practices.
GuildPilot may also use Stripe for website payments. Stripe's own privacy policy applies to information Stripe processes as a payment provider.
Links or integrations with other third-party services may also be governed by the privacy policies of those services.
15. Administrator Responsibilities
Discord server owners and authorised administrators should:
- Enable only the GuildPilot features reasonably required by their server;
- Provide appropriate privacy information to their members;
- Avoid entering unnecessary sensitive information into moderation reasons, AutoMod rules, ticket questions or market announcements;
- Restrict access to logs, tickets, transcripts and web ticket archives;
- Review dashboard administrator roles regularly;
- Review Premium, custom bot and payment authority carefully;
- Configure Pilot Markets, Packs, Kiosk and marketplace features only where they are appropriate for their community;
- Delete information that is no longer required; and
- Respond appropriately to requests from their members.
GuildPilot is not responsible for the independent actions of a server owner or administrator who exports, copies, reposts or otherwise uses information obtained through GuildPilot.
16. Changes to This Privacy Policy
GuildPilot may update this Privacy Policy to reflect changes to:
- GuildPilot features;
- Pilot Premium and payment arrangements;
- Data-handling practices;
- Legal requirements;
- Hosting arrangements;
- Security processes; or
- Third-party services.
The latest version will be published through the GuildPilot website.
Where a change materially affects how personal information is processed, GuildPilot may provide additional notice through the website, dashboard, Discord support server or another appropriate method.
17. Contact
For privacy questions, data requests or server data-deletion requests, contact:
GuildPilot
Email: support@guildpilot.co.uk
Website: guildpilot.co.uk
GuildPilot Games Privacy Section
Account and progression data
When you use GuildPilot Games, we process the Discord user ID, username and avatar supplied by Discord, together with your generated call sign, leaderboard privacy setting, Games level, lifetime XP, achievements, cosmetics, upgrades, daily streak, Core Pass progress and mission history. This links progress to the same account across the website and Activity.
Activity and gameplay data
While you play, we process Activity instance, guild and channel identifiers, room identifiers, lobby membership, gameplay intentions, results, content versions, wave snapshots, the accepted-action journal, connection status and technical timing needed for synchronization, recovery and abuse prevention. We do not provide custom text chat, record or process Discord voice, or collect a date of birth or identity document.
Games currencies and payments
XP, Core Shard, Pilot Token, reward, purchase, adjustment, reversal, promotion and reconciliation events are linked to your user ID and idempotency keys. When website Pilot Token sales are enabled, Stripe processes the payment and supplies order, payment and event identifiers; GuildPilot does not store full card details. Some financial, ledger and audit records are deliberately immutable to prevent duplicate grants, handle disputes and preserve economy integrity.
Player safety
Blocks, avoids, reports, removal votes, AFK state and abandonment history may be processed for matchmaking, moderation and community safety. A report may include the selected category, description and match context supplied by the reporting user.
Visibility, deletion and retention
Public leaderboards show a generated call sign unless you allow your Discord display name in Games profile settings. Data is retained while needed to operate the feature, protect the service, audit rewards and meet legal obligations. Account deletion forfeits Games progress, Core Shards, Pilot Tokens and bound items; some immutable financial, accounting, dispute and fraud-prevention evidence may be retained where legally required or stripped of direct identity.
Discord and controls
Activity authentication uses the Discord Embedded App SDK and a server-side OAuth exchange with the minimal identify scope. You can change leaderboard visibility from the Games profile page and use GuildPilot's public support channel for data or safety requests.