Privacy updatePublished 2 October 2026

Stoatmod / Privacy update

What we changed.
Why it should apply to everyone.

After a privacy review by Stoat, we rebuilt a lot of how Stoatmod handles your data. This page explains what we changed and what we keep now. It also explains why we think Stoat should hold every bot to the same rules.

Read the privacy policy

Less data, kept for less time.

We've stopped using outside AI, IP checks, cross-server sharing and per-user stats. What's left is kept only as long as moderation, consent and appeals need it.

  • AI runs on our own hardware
  • Clear deletion deadlines
  • Anonymous server totals only

01 / What we changed

We switched things off, deleted old data and collect less.

All of this is already done. None of it is a promise about the future.

01

We stopped sending messages to OpenAI

Moderation now runs on our own model, on hardware we control. Your messages no longer go to an outside AI company, and we haven't used anyone's messages to train or fine-tune the model.

02

We removed the developer webhook

We deleted the developer audit webhook and its channel, along with anything it had queued up or kept.

03

We deleted old data

Old message content, member information and hashed IP identifiers covered by the review are gone, including from the backups we manage.

04

We dropped IP and alt-account checks

We no longer store IP addresses or IP fingerprints, and we've stopped checking for alt accounts, VPNs, proxies, Tor or IP reputation.

05

We stopped sharing between servers

Join histories and cross-server alerts are gone, and so is the data behind them. Global bans and warnings stay, because we still need them to deal with abuse directly.

06

We removed personal stats

No more popular-word lists, per-user activity counts or leaderboards. The dashboard only shows anonymous totals for each server now.

02 / What we keep, and for how long

Everything we keep has a deadline.

We keep only what each feature needs to work, and time-limited content is deleted automatically. The privacy policy has the full details, including exactly what each form collects.

FeatureHow it worksWhen it's deleted
Join CAPTCHA

Off unless a server turns it on. You have to agree to a short privacy notice before you can submit it.

We delete verification records within 30 days.

Member applications

You see the privacy notice before any questions. Only moderators of the server you're applying to can read your answers.

Deleted 14 days after you apply, whatever the outcome. If nobody has decided by then, the application is denied automatically.

AI moderation

We only keep a message if the AI actually took action on it. Ordinary messages, deleted messages and harmless edits aren't saved.

If you don't appeal, the message is deleted 30 days after the decision.

Appeals

Appealing has its own privacy notice. If you appeal in time, we keep the message until a moderator decides, but never for more than 10 days after you appeal.

So an appeal on day 29 could keep the message until day 39 at the latest. It's deleted once the appeal is decided, or when it's automatically rejected at 10 days.

Helping improve the AI (optional)

When you appeal, you can tick a box to let us use your own moderated message to help fix mistakes the AI makes. It's unticked by default.

If you opt in, we can keep that one message for up to 90 days after the appeal is decided. We haven't trained on anyone's messages so far.

Your server's own mod log

If a server has a mod-log channel set up, we post each automatic decision there. Those messages belong to that server, not to us. They live on Stoat, outside our database and files.

03 / What's still there

Moderators can still see what happened without us keeping your message forever.

After a message is deleted, a server's moderators can still see the outcome, why the AI acted and the scores it gave. They can see what Stoatmod did, but the dashboard doesn't become a permanent archive of people's messages.

  • Global bans and warnings stay. Only authorised Stoatmod admins can see them, and only to deal with abuse directly.
  • Each server's moderators can see only their own server's members and history. We've asked Stoat to confirm this Members tab can stay as it is, and we're waiting for a reply.
  • Server stats are anonymous totals only. No popular words, no per-person counts and no rankings.
  • Moderators can choose to get a private ping when someone appeals in their server. The ping doesn't include the message or the appeal itself.

04 / Why we're raising this

Whether a bot has to follow the privacy rules shouldn't depend on who runs it.

On 5 September, Stoat Trust & Safety gave us 30 days to remove or redesign the parts of Stoatmod that collected or kept data without consent, and we did. The notice quoted Stoat's published Community Guidelines:

“We do not permit the gathering of any personally identifiable information (PII) without end-user consent. This includes, but is not limited to, the automated scraping of messages, member lists, and user profiles without explicit permission from the users whose data is being collected.”

Stoat Community Guidelines, quoted in Stoat's notice · 5 September 2026

In our reply the same day, we asked whether the same requirements apply to log_it and other logging bots. Stoat's answer on 10 September didn't address that question. We asked again that day and named AutoMod as well. On 13 September, Stoat Trust & Safety replied:

“I will not disclose or discuss any details of enforcement actions or compliance issues involving outside bot operators with an outside party. Each bot service on the platform must comply with our policies independently, and any other potential infringement by another operator does not change the requirements enforced for Stoatmod.”

Mana, Lead, Trust & Safety, Stoat · 13 September 2026

We agree that every bot should comply independently, and we understand why individual cases are kept private. The general rule is published, but the detail we were held to isn't. That detail covers what counts as consent, how long data can be kept, what statistics are allowed and when a self-hosted model can run without opt-in. We only learned it through private emails, which say, for example:

“Aggregate statistic collection would need to be genuinely anonymous and cannot reasonably be used/collected to identify individual users. The statistics also cannot contain message content or user-level records.”

“These identifiers should never be retained indefinitely for the reason(s) that they may potentially be useful in the future.”

Mana, Lead, Trust & Safety, Stoat · 10 September 2026

“The content outlined may be processed without individual user opt-in as long as the content is destroyed after the initial assessment has finished, and it cannot be retained to create an archive.”

“Processing should continue to remain limited to what is necessary and should not be used to create records or profiles about individual users.”

Mana, Lead, Trust & Safety, Stoat · 13 September 2026

If every bot must meet these requirements independently, every bot developer needs to be able to read them. Right now, other developers can't know them, and users can't check whether the bots in their servers follow them. The examples below show why that matters. bronx, for instance, keeps per-person message counts with no expiry and ranks people on leaderboards any member can see, which is the kind of “user-level records” Stoat told us aren't allowed.

Read the full email chain with Stoat Trust & SafetyPDF · 7 messages, 5 Sep to 2 Oct · opens in a new tab ↗
Why this matters more

AutoMod has a direct link to Stoat.

AutoMod's own website says its developer has been on the Stoat team since 2023, and its support server has Stoat's verified badge. Its docs advertise automatic message filtering and logging of edited and deleted messages. Yet its website has no privacy policy, no terms and no privacy notice telling users what it collects, how long it keeps it, or how to say no or ask for deletion.

A staff link and a verified badge don't mean Stoat runs AutoMod. They do tell users it can be trusted. If we have to provide detailed notices, consent and deletion controls while a bot run by a Stoat staff member, carrying that badge, publishes none of the basics, that looks like unequal treatment. Stoat should either explain what makes the cases different or apply the same minimum rules to both.

We didn't ask about anyone else's case. We asked for the rules everyone is held to.

Keeping cases confidential doesn't stop Stoat from publishing the requirements it already enforces. Without them, users can't fairly compare bots, and developers can't tell whether similar features are judged the same way.

05 / Examples

Why we asked.

We raised log_it and AutoMod with Stoat because of what their public docs seemed to describe when we looked. We looked at bronx later. AutoMod and bronx are open source, so we also read their code to check what they actually do. log_it's code isn't public. These examples are here to show why a platform-wide answer is needed, not to accuse anyone.

Bot example · open source

AutoMod

01FHGJ3NPP7XANQQH8C2BE44ZY

AutoMod's developer is on the Stoat team, and its support server is verified by Stoat. Its website and docs have no privacy policy, terms or privacy notice, and neither does its source repository. Here's what the code we read on 2 October 2026 shows.

  • The text of every message goes into its logs

    Every message AutoMod sees, in every server, is printed with its full text to the bot's process log. Node.js prints these lines by default, and we found nothing in the code that turns them off. Nothing says where those logs go or how long they're kept.

    packages/bot/src/bot/modules/command_handler.ts#L40
  • Every command logged with who ran it

    Each command is also logged with the person's username and user ID, the server's name and the full text of the command.

    packages/bot/src/bot/modules/command_handler.ts#L126
  • Edited and deleted messages are copied

    When a server turns on logging, the old and new text of edited messages and the text and attachment links of deleted ones are posted to its log channel. Text-file copies are uploaded to Stoat's file server too. This stays inside Stoat, but members aren't told it happens.

    packages/bot/src/bot/modules/mod_logs.ts#L42
  • Warnings kept with no expiry

    Every warning is stored against the person's user ID and server, including automatic ones from the word filter and spam rules. Nothing deletes them unless a moderator does it by hand.

    packages/bot/src/bot/modules/antispam.ts#L149
  • Votekick votes stored

    Votekicks save who voted against whom, in which server and when. We found nothing that deletes these records.

    packages/bot/src/bot/modules/votekick.ts#L97

To be fair to AutoMod, we found no per-person activity stats, no sharing between servers and no messages sent to an outside AI service. Its issue is that it keeps message text and records about people without telling them, and without saying for how long.

Bot example · code not public

log_it

01J4Q9DS6CV4DNCW6AZRMV349A

Its public pages seemed to describe collecting server and channel IDs, event activity, and edited and deleted messages, which are kept in a local log.txt file. The deletion wording didn't seem to cover what stays in that file. Its developers publish the website's code but not the bot's, so we can't check what it actually does.

Bot example · open source

bronx

01FZB4GBHDVYY6KT8JH4RBX4KR

bronx is open source, so we read its code as well as its website. The website and docs have no privacy policy or terms, and neither does the source repository. Here's what the code we read on 2 October 2026 shows.

No consent

Nobody opts in to being tracked or ranked, and nobody can opt out.

  • Everyone is tracked automatically

    Every message from every person in every server bronx is in is counted against their user ID. Before recording, the code doesn't check any server setting or personal preference.

    main.cpp#L1010-L1021
  • There's no opt-in, opt-out or notice

    We found no consent prompt, no privacy notice and no command that lets someone stop being tracked or ranked. The only way to exclude someone is a global ignore that only the bot's owner can use.

    cogs/owner.h#L709-L714
  • Anyone can see the rankings

    The stats commands are open to every member. They show who sends the most messages in a server, and across all servers with the global option. People are listed whether or not they've ever used bronx.

    cogs/stats.h#L161-L187
  • Even server admins aren't asked

    XP levels stay off until an admin turns them on. Activity tracking and the leaderboards don't: they start as soon as bronx joins a server.

    main.cpp#L1023-L1025

Other personal data it handles:

  • Deleted messages shown to any member

    Up to 10,000 recent messages are held in memory. When one is deleted, its author, content and attachment count move to a list of the last 25 deleted messages in that channel. The .snipe command reposts them, and nothing in its code limits it to moderators. A server can restrict it, but only if it chooses to.

    cogs/snipe.h
  • Per-person activity history, with no expiry

    Each person's daily message, edit, delete and command counts are stored for every server and every channel. We found no time limit. These records are only removed when the bot leaves the server.

    database/tables.cpp
  • A leaderboard across servers

    Anyone can run .stats top g to rank the most active people across every server bronx is in, even outside a server. People are ranked whether or not they've ever used bronx.

    cogs/stats.h#L161-L187
  • Every command logged with a timestamp

    Each command a person runs is saved with their user ID, the channel and the time, with no expiry.

    database/tables.cpp
  • Server details sent to a developer channel

    When bronx joins or leaves a server, it posts the server's name, ID, owner and member counts to a fixed Stoat channel. A developer webhook like this is something Stoatmod was told to remove.

    main.cpp
  • Applications kept indefinitely

    Application answers are stored with the applicant's user ID and no deletion deadline. Stoatmod has to delete them after 14 days.

    database/tables.cpp
  • Ban sharing and message relays between servers

    Servers can link their bans to each other, and bridged channels relay members' messages, names and avatars to other platforms. Both are set up by admins, but members get no privacy notice about either.

    cogs/bridge.h
What these examples don't prove

Public docs don't tell us how either bot actually works today, what it really keeps, what consent it gets or whether it's been looked at by Stoat. Similar features don't mean identical processing either. What the examples do show is why everyone needs a clear rule that applies to similar behaviour.

06 / What we're asking Stoat for

Public rules, not details of anyone's case.

Stoat can keep enforcement private and still give everyone the same rules. We're asking it to publish:

  1. 01

    One clear consent standard for every bot, including what counts as actually saying yes.

  2. 02

    Clear rules on moderation, logging, message context and automatic filtering within a server.

  3. 03

    Maximum retention times and deletion rules for live data, files, logs and backups.

  4. 04

    A clear line between sending data to an outside company and running a model yourself.

  5. 05

    One platform-wide rule for records, alerts, bans and warnings that cross servers.

  6. 06

    A minimum privacy notice for any bot that reads messages or handles member data.

  7. 07

    A way for users and bot developers to get an answer on policy without anyone's private case being exposed.

07 / What happens next

We'll keep telling you what we change.

We'll keep documenting what we do with data, fix things when the evidence says we should, stick to our deletion deadlines and give you a real choice wherever consent is needed. We're also happy for every other bot on Stoat to get the same scrutiny we did.

We're not asking for special treatment. We're asking for one set of rules that everyone follows.