SUMMARY
The short version
Stoatmod processes Stoat account, server, message, attachment and moderation information to provide automated moderation, security checks, statistics and a moderator dashboard.
- Message text and images may be sent to Stoatmod's self-hosted moderation model for safety classification.
- Original content from an AI moderation decision is deleted from Stoatmod's database and managed files 30 days after that decision unless an appeal is submitted.
- An appeal requires a separate privacy agreement. Its content is deleted when decided, or when automatically rejected 10 days after submission if no decision was made.
- You can separately choose to contribute your own original moderated text for AI improvement. Contributions are kept for up to 90 days after a moderator's decision and can be withdrawn. An appeal that reaches the 10-day deadline without a decision has all its content deleted, even with this option selected.
- Optional join verification and report submission use Cloudflare Turnstile for a browser CAPTCHA. Stoatmod does not scan IP addresses or match alternate accounts by IP address. Cloudflare processes network and browser information to operate its CAPTCHA.
- Member applications require a separate privacy agreement before any questions. Application records are deleted 14 days after submission, including accepted applications. Undecided applications are automatically denied at that deadline. Application answers are not sent to the AI moderation API.
- Stoatmod does not sell personal information or use it for advertising.
- Automated decisions can be challenged and submitted for human review.
01 / CONTROLLER
Who we are
Stoatmod is a moderation bot and web dashboard for communities hosted on Stoat. It provides automated moderation, server statistics, security checks, moderation records, logging and configuration tools.
Stoatmod Limitedadmin@modstoat.siteStoatmod Limited is the data controller for personal information processed to operate Stoatmod and this website, unless stated otherwise. Server owners and moderators also decide how Stoatmod is configured and used in their communities and may be separate controllers for their own moderation activities. You should also read the privacy information and rules supplied by the server you use.
Stoatmod is an independent service and is not operated by or affiliated with the Stoat platform.
02 / INFORMATION
Information we process
Stoat accounts and servers
We may process Stoat user IDs, usernames, display names, tags, nicknames, profile information available through Stoat, server IDs and names, channel/category/role IDs and names, membership events, permissions, moderator IDs and server configuration.
Messages and attachments
When message moderation is enabled, Stoatmod reads message text, links, website domains and account mentions. It uses message and channel IDs and timestamps to identify the content and carry out an action. Enabled image checks may also process image URLs and attachments. AI checks produce safety categories and model scores.
Stoatmod stores message content only when it is the subject of a moderation action. Deleting a message does not cause its content to be saved. Edited messages are reassessed, but their content is saved only if the edited message violates policy and is moderated. We do not keep routine message archives or before-and-after edit logs.
AI-moderated message content follows the 30-day limit and appeal rules below. Information you intentionally submit through an application, report, appeal or support request is handled for that separate purpose. Messages already posted in a server's Stoat moderation-log channel are held separately from Stoatmod's database.
Moderation and safety records
Records may include warnings, case IDs, kicks, bans, mutes, timeouts, reasons, model scores, moderator attribution where available, case status, verification results, dashboard changes, moderator logins, joins, leaves, deletions and edits. When Stoat does not provide an actor for an external action, Stoatmod records the actor as unavailable rather than guessing.
Global bans and warnings
Stoatmod maintains service-wide bans and warnings for enforcement by authorised administrators. It does not share a server's moderation history with other servers when someone joins or send other servers alerts about a local ban.
Dashboard authentication
We process moderator and server IDs, cryptographic hashes of one-time codes and session tokens, creation/expiry/use times, dashboard login events and dashboard changes. Codes are normally valid for ten minutes and usable once. Dashboard sessions normally last twelve hours.
The dashboard uses the strictly necessary stoat_dashboard_session and stoat_dashboard_csrf cookies for authentication and request security. They are not advertising or behavioural-tracking cookies.
Join verification
Join CAPTCHA is off by default. When a server enables it, the member must tick a separate agreement to this policy and the verification notice before the CAPTCHA loads and before submitting the form. Stoatmod processes the Stoat user and server IDs, one-time verification token, CAPTCHA result and attempts, and the agreement time and policy version solely to complete and troubleshoot that join verification. The application does not collect browser language or timezone for this purpose.
Stoatmod does not scan visitor IP addresses, store raw IP addresses in verification or report records, create IP fingerprints or link accounts by IP address. Cloudflare receives browser and network information, including an IP address, when its widget connects. Some website endpoints briefly use IP addresses in memory to limit repeated requests; hosting providers also handle network connections to deliver the service.
You can decline by leaving the form, or untick the box before submitting. Contact your server moderators for help if you cannot complete verification. To withdraw agreement or request deletion of verification records, contact admin@modstoat.site with your Stoat user and server IDs. Verification agreement does not authorise unrelated message collection, AI training or cross-server profiling.
Statistics and technical data
Statistics use daily community totals for non-bot messages, joins and leaves, plus total memberships, servers and cases. Statistics do not retain user IDs, per-user counts, individual rankings, channel activity breakdowns or words extracted from messages. We do not calculate unique active-user counts. Website infrastructure may also process IP address, request time, endpoint, browser/device details, errors and security events.
Information you provide
If you contact us, appeal a decision or make a privacy request, we may process your contact details, Stoat user ID, relevant server, request content, supporting evidence and correspondence. Appeal privacy agreement and optional AI-improvement permission are recorded separately with the notice version and time. We do not record an IP address as proof of either choice.
Sources
Information comes from Stoat and its bot API, Stoat users, server owners and moderators, your browser, Cloudflare Turnstile, Stoatmod's self-hosted moderation model and Stoatmod's automated rules.
Member applications
When a server requires an application, Stoatmod sends a separate privacy notice in a direct message before asking any questions. Read the linked policy and reply “I agree” to agree to the stated application processing. You can decline by not continuing. Server questions and rules agreements do not replace this privacy step.
We store your answers, Stoat user and server identifiers, application and verification status, agreement time and notice version, submission date, and review details. Authorised moderators of the originating server can access the application during its retention period. Application answers are not used for AI classification or model training.
- Before submission: you have seven days to finish. An unfinished application and its stored answers are deleted when that window ends.
- After submission: the application and its associated records are retained for 14 days from submission. Moderators may accept or deny it during that time.
- At the 14-day deadline: all stored application records are deleted. If no decision was made, the application is automatically denied. Accepted and manually denied applications are also deleted at the same deadline; a review does not restart the clock.
Deletion includes answers, agreement records, reviewer details, delivery state and linked application records in Stoatmod's database. It does not reverse access already granted to an accepted member. Direct messages and notices already sent on Stoat remain subject to Stoat's controls. To withdraw agreement or request earlier deletion, contact admin@modstoat.site with your user and server IDs; deleting an application may prevent its review.
03 / PURPOSE AND BASIS
Why we use information
We use information to provide moderation and server-management features; identify unsafe text, images, links, spam, mass mentions and risky names; operate join verification; create cases and audit logs; authenticate moderators; assign configured roles; provide statistics; investigate errors, abuse and security incidents; answer support and privacy requests; protect users and communities; and comply with applicable law.
Lawful bases
Under the Isle of Man Data Protection Act 2018 and the Data Protection (Application of GDPR) Order 2018, we generally rely on:
- Legitimate interests: operating a safe, secure and effective moderation service, protecting servers and users, maintaining proportionate audit records and improving reliability.
- Contract: where processing is necessary to provide Stoatmod to a server owner or administrator who requested the service.
- Legal obligation: where processing or retention is required by applicable law, a court order or a valid request from a competent authority.
- Consent: for the processing explained in the separate verification, application and appeal steps, and separately for any optional AI-improvement contribution. Optional permission is never inferred from bot installation, server membership, silence or a moderator's decision.
The optional join CAPTCHA requires a separate affirmative agreement to its stated data processing. This agreement covers verification only. An application agreement covers admission processing only. An appeal agreement covers that review only; optional AI-improvement permission is a separate choice. Messages may incidentally contain sensitive information. Stoatmod does not intentionally use content to determine a person's health, religion, political opinions, sexuality, ethnicity or other protected characteristics.
We do not sell personal information or use it for targeted advertising.
04 / AUTOMATION
Automated moderation and decisions
Stoatmod uses automated rules and self-hosted model classifications. Depending on server settings, processing may delete a message, create a warning, send a safety message, apply a timeout, restore a protected nickname, require or reject join verification, kick a user after three failed checks, or escalate repeated warnings to a timeout, kick or ban.
AI moderation evaluates content against safety categories and returns scores. Server moderators select a threshold, and configured actions may occur when a score exceeds it. Other protections consider links, message speed/repetition, mention counts, account age and CAPTCHA completion.
05 / APPEALS
Appeals, evidence and privacy agreement
Use the private appeal code from your moderation message and your Stoat user ID to access your case. Before submitting an appeal or follow-up, you must tick the unchecked box agreeing to this policy and the stated processing of your appeal. We record the case, user and server identifiers, the notice version and your agreement time.
We use your statement, relevant original moderated message, follow-ups and evidence images to investigate the decision. Only authorised reviewers and operators who need access may handle these records. Submit information relevant to your own case and avoid unnecessary information about other people.
- No appeal: original AI-moderated message content expires 30 days after the automated decision. Opening the appeal page does not extend this period.
- Submitted appeal: available message content and the submitted appeal content remain available while the appeal is open, for no more than 10 days from submission. Follow-ups and requests for more information do not restart the clock.
- Accepted or rejected by a moderator: the original message, statement, follow-ups and evidence attachments are removed from ordinary case storage when the decision is recorded. Only a separately opted-in original message may move to the restricted contribution store described below.
- No decision within 10 days: the appeal is automatically rejected and all associated user content is deleted, including any AI-improvement contribution, regardless of the optional checkbox.
Deletion covers Stoatmod's database records and managed file copies, including linked evidence and duplicate copies in stored action payloads. It does not remove moderation-log messages already posted within the originating Stoat server. Those are subject to Stoat's and the server's controls. We may retain the case identifier, decision, dates, consent record, category scores and necessary action identifiers without the deleted message or appeal content.
You can decline by leaving the form without submitting. To withdraw agreement to appeal processing or request earlier deletion, contact admin@modstoat.site with your user ID and case reference. Removing the material needed for a review may prevent us from continuing that review. Declining or withdrawing the optional AI permission does not prevent an appeal.
06 / OPTIONAL AI IMPROVEMENT
Your own moderated message and model improvement
The appeal form offers a separate, unchecked option: “Use my own moderated message to improve our AI.” Selecting it is voluntary and has no effect on whether your appeal is accepted, rejected or prioritised. Only the original message authored by the appealing account and already associated with an automated moderation decision is eligible.
The purpose is to review classification mistakes and prepare corrections for training Stoatmod's own moderation model. This includes false positives, where content was incorrectly flagged, and false negatives, where a relevant safety category was missed. An appeal decision alone does not establish that a training example is correct.
Your permission covers only your own original moderated text. It excludes messages written by somebody else, appeal statements, follow-ups, screenshots and other evidence attachments. We do not currently train models using appeal contributions. Contributions are held separately for review. We will explain any material change to this use and obtain fresh permission where the purpose, information used or recipients change.
Following a moderator's decision, an opted-in original message may be kept in a restricted holding store with the user, server, message and appeal identifiers, outcome, consent version and expiry date. It is deleted 90 days after that decision, or sooner if permission is withdrawn. Approval, rejection, later review or backup restoration must not restart the 90-day period. An automatic rejection after 10 days has no contribution exception.
To withdraw immediately, return to the appeal page with your code and user ID and select “Withdraw AI-improvement permission.” This deletes any saved contribution and stops future use. You can also contact admin@modstoat.site. Withdrawing this permission does not affect your appeal or your access to the review process.
08 / RETENTION
How long we keep information
We retain information only while reasonably needed for the purposes in this policy, security, disputes or legal compliance. Current practices include:
- submitted applications and all associated application records: 14 days after submission, whether accepted, denied or awaiting review; incomplete applications: seven days from creation;
- original AI-moderated message content: 30 days from the automated decision unless an appeal is submitted;
- content linked to a submitted appeal: until the decision, with automatic rejection and content deletion if no decision is made within 10 days of submission;
- separately opted-in original messages: up to 90 days after a moderator's decision, or until permission is withdrawn; this extension does not apply after an appeal times out;
- dashboard codes are usable for about ten minutes and only once;
- dashboard sessions are usable for about twelve hours;
- active join-verification challenges normally expire after about thirty minutes or are removed following success, moderator bypass or three failures;
- temporary login and verification rate-limit data stays in memory for about five to ten minutes;
- server snapshots are refreshed as updated server information is received;
- remaining case metadata, warnings, general event logs, configuration history and statistics are retained while operationally necessary; these records currently have no single automatic deletion period, and server administrators cannot choose a separate history-retention period;
- removed cases may remain as audit records marked as removed;
- verification agreement records, bot-side verification event records and completed verification action records expire after 30 days; this does not remove log messages already posted on Stoat and application verification flags are deleted with the application; and
- system and VPS logs follow operational logging and backup settings.
Expired content is removed automatically. Following downtime, overdue content is removed when the service resumes. The application, AI-content, appeal and optional AI-improvement deadlines are fixed and cannot be extended through server settings. Necessary case outcomes may remain without the deleted source content.
The deletion periods also apply to managed file copies and backups under our control. A backup that cannot be cleared selectively must be deleted in full. Restoring a backup does not restart a retention period. Messages already posted in the originating server's Stoat log channel are outside this deletion process; contact that server's moderators about those messages.
09 / SECURITY
How we protect information
Measures include HTTPS, hashed login codes and session tokens, expiring one-time access, server-scoped dashboard sessions, CSRF protection, secure/SameSite cookie controls, rate limiting, restricted log channels, VPS/database access controls, security headers, backups and operational monitoring.
No internet service can guarantee absolute security. Report suspected vulnerabilities or breaches to admin@modstoat.site. Never send passwords, bot tokens, API keys or dashboard codes in a support message.
10 / YOUR RIGHTS
Your information rights
Depending on your location and circumstances, you may have rights to be informed, access information, correct it, request deletion or restriction, object to legitimate-interests processing, request portability, challenge certain automated decisions, obtain human intervention, withdraw consent where applicable, and complain to a regulator.
These rights are not absolute. We may retain limited information to protect others, preserve a necessary audit record, comply with law or handle legal claims.
Right to object
You have the right to object to processing based on our legitimate interests. Tell us which processing concerns you and why. We will stop unless compelling legitimate grounds require it to continue or it is needed for legal claims.
Making a request
Email admin@modstoat.site with your Stoat user ID, relevant server, the right you want to exercise and enough information to locate the records. We may reasonably verify your identity. We normally respond within one month; legally permitted extensions may apply to complex requests.
Complaints
Please contact us first so we can investigate. You may also complain to:
Isle of Man Information CommissionerP.O. Box 69, Douglas, Isle of Man, IM99 1EQask@inforights.iminforights.im+44 1624 693260If UK data-protection law applies to your processing, you may also contact the UK Information Commissioner's Office. You may have the right to complain to another authority where you live or work.
11 / CHILDREN
Children's privacy
Stoatmod may operate in communities containing younger users. It does not intentionally collect dates of birth or identity documents. Users must meet Stoat's minimum-age requirements, their server's rules and applicable law.
We aim to collect only information necessary for moderation/security, avoid advertising and behavioural tracking, use privacy-protective defaults, restrict moderation-record access, explain automated actions and provide human review. A parent or guardian may contact us about a child's information; we may need to verify their authority.
12 / UPDATES
Changes to this policy
We may update this policy when features, providers, hosting, retention practices or legal requirements change. The revised policy will appear at https://modstoat.site/privacy with a new date. We will take reasonable steps to notify participating servers or users where a change materially affects the use of personal information.
13 / CONTACT