Skip to content
falls.
Terms of Service Privacy Policy Workspace

Privacy Policy

What Falls processes, why it is needed, and how to exercise control over your information.

Effective and last updated October 7, 2026

On this page

  1. Who is responsible
  2. Information we handle
  3. How we use information
  4. Who can access information
  5. Cookies and browser storage
  6. Storage and retention
  7. Your choices and privacy requests
  8. Security
  9. Age requirements
  10. Changes and contact
Contact Falls

Moderation needs context. This policy explains what information Falls handles and how to contact us about it.

01Who is responsible

This Privacy Policy covers the Falls Discord bot, its website, and its administration dashboard. It applies to people who use the Service and to server members whose information is processed by its moderation features. The Falls operator is responsible for the processing described here and can be reached at contactme@fallsbot.tech.

Discord and individual server administrators also process information under their own terms and practices. This policy describes Falls; it does not replace Discord’s Privacy Policy or the rules of a server you join.

02Information we handle

The information available to Falls depends on its Discord permissions, enabled features, and actions taken by administrators.

Account and server information

Discord user IDs, usernames, display names, avatar URLs, server IDs and names, channel and role IDs, roles and permissions, account creation dates, and server join dates. These identify the server and people involved in a command, support member management, and allow configured account-age checks.

Moderation records

Case numbers, the affected member and moderator identifiers, usernames and avatar URLs, action types, reasons, timestamps, durations, warning progress, and scheduled follow-up actions. Falls also stores server settings, configured staff roles, panel message references, and information used to calculate moderator statistics and leaderboards.

Messages, reactions, and evidence

Falls processes messages it can access to apply enabled text filters and receive moderator-submitted evidence. Authorized dashboard operators can request recent messages and attachment information from channels available to the bot when reviewing a member’s activity.

Enabled text and spam filters run locally inside the bot. Message content and attachments are not sent to any external moderation, review, or AI service.

When a message triggers a filter or a reaction is logged, message excerpts, relevant user and message identifiers, channel references, reaction details, and timestamps may be included in configured Discord log channels. Moderation cases can retain violation reasons and evidence references.

Evidence may include text, links, images, video, audio, and documents submitted by moderators. Falls may download evidence to its hosting storage, retain file metadata and links, and upload copies to a server’s configured moderation log channel. Ordinary messages are not continuously archived into a separate message-history database; selected evidence and logs can still persist as described above.

Applications and interviews

When you start an application, Falls stores the form questions, your Discord identity, draft progress, answers, attachment references, and timestamps. Submitted applications also retain the review decision, reviewer identity, reason, configured role actions, and delivery status. These records support server applications and surveys. Unrelated private messages are not stored by this feature.

Attachments are copied to bot-owned Discord messages and, after submission, to the configured private review channel. Authorized dashboard administrators can download them. Server administrators and configured reviewers can read application messages and review them in Discord. Staff may open a private interview channel with you; closing it removes your channel access while retaining the conversation for staff.

Girls verification

When an authorized verifier accepts a girls-verification session, Falls stores the member’s stated name, age, how she learned about the server, Discord identity, responsible verifier, voice-channel reference, and timestamp. The answers and applied role outcome appear in the configured verification log and staff verification archive.

Website and security information

Website requests expose technical information such as IP addresses, request paths, timestamps, and browser or network headers to the web service and its hosting provider. Falls uses IP addresses to limit failed sign-in attempts and enforce its website firewall. Firewall records may also include operator-entered IP addresses, reasons, expiry dates, and the operator’s username.

For dashboard accounts, we store the administrator’s username, a salted password hash, sign-in timestamps, and hashed session identifiers with expiry times. Operational diagnostics may contain error information and identifiers needed to investigate failures.

Support correspondence

If you email us, we receive your email address, the information you provide, and our correspondence. Please send only what is needed to answer your question or locate the relevant data.

03How we use information

Falls security checks process account creation times, join times, server and member identifiers, relevant Discord audit actions, role permissions, and channel access rules. Pending account reviews and staff suspensions store previous roles and permission overrides so an authorized owner can review and safely recover access. These checks indicate risk; they do not establish that accounts belong to the same person. Discord does not provide members’ IP addresses to Falls.

We use information to run requested moderation and administration features, maintain case records and evidence, apply configured server rules, schedule actions, display statistics, protect access, troubleshoot problems, answer support requests, and fulfill privacy or legal obligations.

We do not sell personal information, use Discord data for advertising or data brokerage, or use message content to train AI or machine learning models.

Where a legal basis is required, processing is based on providing a requested service, legitimate interests in secure and proportionate server administration, compliance with legal obligations, or consent where required. Those interests must be balanced against the rights of the people affected.

04Who can access information

  • Authorized operators and server staff. Dashboard operators can access records for the servers managed by the bot. Discord command access follows the bot’s access rules. Server members may see logs, evidence, or leaderboards if they can access the channels where administrators choose to post them.
  • Service providers. Discord processes bot interactions, messages, and uploaded media. Heroku provides application hosting and database infrastructure. Google’s Gmail service handles messages sent to our support address. These providers process the information needed to deliver their respective services.
  • Requested sharing and legal requirements. We may share information when the affected user expressly directs it, or when required by applicable law. We may provide information required by Discord under its developer terms.

Authorized administrators can export moderation records. Copies downloaded by server staff or posted in Discord channels are subject to those recipients’ access controls and retention practices. Links to externally hosted evidence may cause your browser to contact the relevant host when you open them.

Hosting, Discord, and email services may process information in countries other than your own. Applicable legal requirements and safeguards for international transfers continue to apply.

05Cookies and browser storage

The dashboard uses an essential session_token cookie to keep administrators signed in. It expires after seven days and is cleared on sign-out. Browser local storage remembers language and display-density preferences until you change them or clear your browser storage.

The public Terms and Privacy pages do not require sign-in or set a session cookie. The website does not use advertising or third-party analytics cookies, and its fonts are hosted with the website.

06Storage and retention

Moderation records, evidence references, and server configuration are stored in the application database. Ticket transcripts store message text, participants, embed details, and media links in the database for the private website preview; a text copy is posted to the configured Discord log channel. Evidence files may also be held in hosting storage and in Discord log messages. Database recovery copies support service continuity.

Application forms, drafts, submissions, decisions, and audit events are stored in the database and its recovery copies. Completing, cancelling, or reaching a draft deadline ends the questionnaire but does not automatically delete its saved data. Archiving a form preserves submitted records. Application attachments and interview conversations remain in Discord until removed there; database records have no automatic retention deadline. You can request access or deletion through the contact details below.

There is currently no fixed automatic expiry for moderation records or server settings. These remain until an authorized administrator or the operator removes them. We will delete personal data when it is no longer needed for the Service, when the affected user or Discord requests deletion, when we stop operating the Service, or when required by law. We retain an exception only where applicable law requires it.

Security incidents and completed review or recovery records expire automatically after 30 days. Short-lived join, action-attribution, and duplicate-event records expire after two days. Unresolved quarantines and staff suspensions, including their recovery information, remain until owner review or an applicable deletion request. Ordinary moderation-case deletion does not erase these separate security records.

Removing Falls from a server stops new collection from that server but does not itself erase previously stored data. Server administrators should review retained records and contact us when information is no longer needed. Individual members can request deletion of their own data directly.

Dashboard sessions expire after seven days; expired session records are cleaned up when a new session is created. Failed sign-in counters use a 15-minute window. Firewall entries remain until their configured expiry or removal. Unreferenced temporary uploads are eligible for maintenance cleanup after 24 hours, but this is not a guaranteed automatic deletion deadline.

Recent database recovery copies rotate as new snapshots are saved. A deletion request also requires review of retained evidence and recovery copies under our control. Older copies must be removed or allowed to rotate out, and a recovery must not reintroduce data that was required to be deleted. Provider logs and copies held independently by Discord or server administrators may follow separate retention rules.

07Your choices and privacy requests

To request access, correction, or deletion, email contactme@fallsbot.tech. Use the subject “Falls Privacy Request” and include your Discord user ID, the server ID if known, and what you want us to do.

You do not need a dashboard account or a server administrator’s permission to contact us about your own information. We may ask for reasonable proof that you control the relevant account or server before disclosing or changing data. Do not send passwords, access tokens, or identity documents in your initial request.

We will handle verified requests promptly and within applicable legal deadlines. If the law requires us to retain specific information, we will explain the reason and limit retention to what is required. Where another party controls a copy, we will explain which part we can address and how to contact that party.

Depending on the law that applies to you, you may also have rights to object to or restrict processing, receive a portable copy, withdraw consent where processing relies on it, or complain to a data protection authority. Contact us to exercise these rights.

Server administrators can disable optional features, restrict the bot’s permissions, or remove it. For an appeal of a server moderation decision, contact the server’s moderators. A moderation appeal and a privacy request are separate matters.

08Security

We use HTTPS for the deployed website, password hashing, expiring administrator sessions, access checks, and restricted evidence endpoints to protect information. Access should be limited to people who need it to operate the Service.

No service can guarantee absolute security. Report a suspected vulnerability or unauthorized disclosure to contactme@fallsbot.tech. If a data incident occurs, we will investigate, take appropriate action, and notify affected users and Discord as required by applicable law and Discord’s developer terms.

09Age requirements

Falls is not intended for children under 13 or anyone below the higher minimum age required to use Discord in their country. If you believe Falls has processed information about someone below the applicable minimum age, contact us so we can investigate and delete that information as appropriate.

10Changes and contact

We will update this policy when our data practices change. The effective and last-updated date is shown at the top of the page. Material changes will receive appropriate notice, and we will seek consent where required by law.

For privacy questions, deletion requests, or other concerns, contact the Falls operator at contactme@fallsbot.tech.

Also from FallsTerms of Service →
© 2026 Falls Questions? contactme@fallsbot.tech Back to top ↑