Privacy
What is stored
Karen stores Discord IDs — users, servers, roles, channels — along with the configuration you set and a record of the moderation actions it takes. IDs are what Discord uses to identify things, so a moderation bot cannot function without them.
Message content is not collected as a matter of course. Individual features do read the message they are invoked on, and a few store what they must to work at all: the image block list stores perceptual hashes of blocked images, and ticket transcripts store the messages sent inside a ticket channel.
Signing in
Signing in with Discord stores an OAuth access and refresh token, encrypted at rest with AES-256-GCM. It is used for one thing: reading which servers you belong to and administer, so the dashboard can show you those and refuse the rest. It does not grant access to your direct messages.
Your dashboard session is a cookie set by this site, readable only by the server. Logging out clears it.
What is not done with it
Nothing is sold, rented, or shared with advertisers or analytics providers. Data is not used to build profiles of individuals beyond what the moderation features you enabled require.
Removal
Removing the bot from a server stops all collection for that server. To have stored data for a server or an account deleted, ask through the support server; the request is handled manually, as there is no self-service deletion in the dashboard today.
Third parties
Karen talks to Discord's API, which is subject to Discord's own privacy policy. Nothing you send the bot is passed to a language model or any other text-processing service: the AI features this policy previously described have been removed.
Changes
This page is edited when the practices it describes change. The date above reflects the last edit.