Privacy Policy
Diskey does not create user accounts, does not store passwords, and does not maintain a database for user tokens or server rosters. Bot tokens are processed in-memory and stored solely in AES-256-GCM encrypted httpOnly session cookies that expire automatically or on disconnect.
1. Scope & Who We Are
This Privacy Policy describes how Diskey ("we", "us", or "our") handles data when you visit our website and use our Discord Bot control dashboard. Diskey is an independent management interface that interacts directly with the Discord REST API v10.
Diskey operates on a zero-database architecture designed for maximum credential safety and transparency.
2. Information We Process
We only process technical data strictly necessary to execute your Discord Bot management commands:
- Discord Bot Token: Provided by you to authenticate requests directly to the Discord REST API.
- Discord Guild & Member Data: Retrieved on-demand from Discord API (server names, channel lists, role definitions, member rosters) and rendered directly in your browser without database persistence.
- Technical Request Headers: Standard HTTP headers (e.g. IP address, User-Agent, Accept-Language) processed ephemerally by our hosting infrastructure (Vercel) to deliver web pages.
- Client Preferences: Stored locally in your browser (theme mode and language preference).
3. How We Use Information
Your bot token is used exclusively to sign authenticated HTTP requests to official Discord endpoints (https://discord.com/api/v10) on your behalf.
We do not train machine learning models on your data, do not build user behavioral profiles, and do not track your browsing history across the web.
4. What We Do Not Do
- We do NOT sell, rent, or monetize your personal information or bot credentials.
- We do NOT use third-party analytics trackers, advertising pixels, or cross-site tracking cookies.
- We do NOT maintain a persistent database of bot tokens, Discord messages, or server members.
- We do NOT retain your token after you click Disconnect or after your session expires.
6. Third-Party Services
Our service interacts with the following third parties:
• Discord Inc. (API & CDN): Discord REST API processes your bot commands, and Discord CDN serves user avatars and guild icons. Your use of Discord is subject to the Discord Privacy Policy.
• Hosting Infrastructure (Vercel / Cloud Edge): Serves application static files and Edge runtime routing. Standard access logs may record IP addresses for DDoS protection.
7. Data Retention & Deletion
Session data expires automatically after 8 hours of inactivity. When you click "Disconnect", the session cookie is permanently erased from your browser and discarded from memory.
To revoke bot access immediately on the Discord side, you can reset your bot token at any time in the Discord Developer Portal.
8. Security Measures
We implement rigorous defense-in-depth security standards:
- Encrypted Sessions: Authenticated payload is sealed with authenticated AES-256-GCM encryption.
- Strict CSP: Content Security Policy headers prevent cross-site scripting (XSS) and restrict script execution.
- Ephemeral Tokens: Raw bot tokens are never logged, never exposed to client-side JavaScript, and never written to database tables.
- Rate-Limit Throttling: Built-in safeguards prevent request flooding and respect Discord REST API rate limits.
9. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please reach out via our official channels at ikhlasdigitalhub@gmail.com.