Privacy Policy
This policy explains what data we collect when you use the HolyHawse panel, why we process it and how we protect it. Because the panel manages your Discord servers and bots, some data comes directly from Discord.
1 Information we collect
To provide the service we collect:
- Account details: username, email address, name and an irreversible hash of your password (bcrypt). The password itself is never stored.
- Discord link: your Discord user id, username and avatar once you connect your account.
- Bot details: the name, prefix, settings and token of the bots you add. Tokens are stored encrypted (section 3).
- Usage records: the commands you run from the panel, the settings you change and when.
- Technical data: IP address, browser and operating system, session identifier.
- Support conversations: the tickets you open and live chat messages.
2 How we use information
We process the data only to:
- Run the panel and manage your account and bots.
- Enforce permissions: decide who may run which command.
- Security: detect unauthorised access, abuse and automated attacks.
- Answer your support requests.
- Send technical notices about the service.
- Find bugs and improve the panel.
3 Bot tokens
A bot token carries every permission your bot has on Discord; leaking it means losing the bot. Tokens are therefore never kept in plain text: they are stored encrypted with AES-256-GCM and decrypted in memory only while the bot connects to Discord.
The encryption key lives outside the database, in a server environment variable. Even if the database file alone were obtained, the tokens could not be read.
A token is never shown in full in the panel; only its last few characters appear. Key rotation is supported, and records encrypted with an older key remain readable.
4 Data received from Discord
When your bot connects to your servers it receives server, channel, role and member information from Discord. This data is used to render the panel.
Only the following is stored permanently:
- Server id and name, and whether the bot is present there.
- Protection backups: a snapshot of roles, channels and member roles (only when backups are enabled).
- Moderation records: who was acted on, when, and with which action.
5 Cookies and sessions
We use a single session cookie to keep you signed in. It is marked HttpOnly, so scripts in the browser cannot read it, and it is sent only over a secure connection when the site is served over HTTPS.
We use no third-party advertising or tracking cookies. Your language and theme preferences are stored the same way.
6 How long we keep data
We keep data only as long as needed:
- Account data: until your account is deleted.
- Command and audit records: for a limited period, for accountability and security review.
- Backups: until you delete them or newer backups supersede them.
7 Sharing
We do not sell your data. We share it with third parties only where the service requires it: Discord (necessary for the bot to work), email delivery and — if you use it — the payment provider.
Where a legal obligation arises, disclosure is limited to what is requested.
8 Security
The main measures we take:
- Passwords are hashed with bcrypt; bot tokens are encrypted with AES-256-GCM.
- Form submissions are protected with CSRF tokens.
- Two-factor authentication (TOTP) and backup codes are supported.
- Sign-in attempts are rate limited; administrative actions are written to an audit log.
9 Your rights
You have the right to access, correct, delete and export your data. When you delete your account your personal data is removed; audit records that must be retained are anonymised. Use the contact page for such requests.
10 Children’s privacy
In line with Discord’s terms, the panel is not directed at anyone under 13. If we learn that we hold data belonging to such a user, we delete it.
11 Changes
This policy may be updated from time to time. When something material changes, the date at the top of the page is updated and, where needed, a notice is shown in the panel.
12 Contact
For questions or requests about privacy, reach us through the contact page.