Meet Custodian
Custodian avatar

Custodian / Your side of the agreement

Privacy Policy

What arrives, what stays, and what you can change.

Effective 15 September 2026Application 1546698960662438009
01 / Your choiceOptional means adjustable.Change your settings
02 / Your recordsAsk. Correct. Remove.Make a data request
03 / Your voiceSomething feel off?Report it privately

Who this policy covers

This is the privacy policy for Custodian, Discord application 1546698960662438009, and its connected Big If True website controls. Big If True is operated by HiLleywyn. Contact the operator through the private request center; choose Policy question for privacy or identity-verification problems. You can submit a general question without signing in.

Effective 15 September 2026. Server owners decide where a bot is installed and which features are enabled. They may keep separate moderation records. Discord and linked third-party services operate under their own policies. This page describes our processing; it does not grant access to a channel or change Discord’s terms.

What comes in, and why

User, server, channel, role and message IDs; usernames, nicknames and membership changes; moderation actions, reasons and evidence; invite attribution; verification and containment state; scam or rule-match evidence; message and reaction activity used for optional levels and statistics; puzzle attempts, answers, hints, polls, predictions, giveaway entries, vote confirmations, rewards and role selections. Voice-state events describe joining/leaving a channel; the bot does not record voice audio.

SourcePurposeWho can see the result
A command, mention, button or form you useProvide the feature you requested; validate eligibility and prevent duplicate actionsA channel answer is visible to people who can view that channel. A private/ephemeral interface has a narrower audience.
Permitted server events and historySupport enabled features and relevant context; apply optional privacy preferencesAuthorized bot infrastructure and the feature’s intended audience. Private channel access is checked.
Website Discord sign-inAssociate preferences and requests with the right Discord account; check membership in the configured Big If True server to hide its Join buttonsYou and authorized operators; public comments/reactions show your chosen Discord identity.
Operational recordsProtect the service, enforce usage limits, reconcile actions and investigate failuresAuthorized operators and necessary infrastructure providers.
A report or feedback submissionReview the issue, communicate an outcome and prevent abuse of the reporting systemThe requester and authorized reviewers. We do not publish a report or automatically send it to its subject.

Do not submit passwords, access tokens, payment-card details, identity documents or other unnecessary sensitive information. If sensitive content appears in a relevant message, report or attachment, it may be processed as part of that feature; avoid including it and request removal if needed. We do not sell personal data, create advertising audiences from Discord conversations, or use Discord message content to train our own models.

Why we process personal data

Where a legal basis is required, processing a requested command, storing an item you choose to save and maintaining your account support the service agreement. Necessary security, moderation, reliability and abuse-prevention processing support legitimate interests, subject to the rights and reasonable expectations of affected people. Legal obligations can require limited records or disclosures. Optional processing must use consent where applicable law requires it; a default setting does not replace a legally required consent. You can withdraw an optional choice without changing the lawfulness of earlier processing. Contact the operator to object, request restrictions or ask which basis applies to a particular record.

Your choices, with the tradeoffs

Use your privacy controls after Discord sign-in. Settings apply to the signed-in Discord ID across supported deployments, rather than to everyone in a server. Optional processing defaults to enabled unless you or an existing server-scoped setting has disabled it.

  • AI memory and ambient context: for Big, Disco and Ticker, turning this off prevents supported personal-memory reads/writes and excludes your authored messages from new ambient channel-context retrieval. Explicit requests you send still need to be processed. A reply may be less personalized, and the bot may need you to repeat context.
  • Custodian activity statistics: turning this off stops new optional message/reaction activity earning and associated level/streak statistics. You will stop earning through those paths. Existing scores and earned roles are not automatically removed.
  • Ticker optional analytics: turning this off stops new optional command telemetry from being retained. Quotes, charts and alerts still work; essential accounting and failure/security processing continue.
  • Existing material: a setting is not a retroactive erasure. Old saved replies, shared summaries, public posts, quotes supplied by other people and provider records may still contain earlier material. Request deletion for a review of those copies.
  • Notifications and stored features: use Account settings for Big topic notifications and the bot’s own remove/unsave/alert controls for user-created items. Removing a bot stops future event access; it does not itself erase stored data.

Disco’s ,disco optout is an additional server-scoped control. A global website opt-in does not override an existing server opt-out. Safety enforcement, permission checks, requested transactions, request receipts and usage limits are essential to providing the service and cannot be disabled with optional switches. A change cannot recall a request already sent to a provider or a message already posted.

AI, tools and service providers

This bot’s primary member features are moderation and community tools.

Big, Disco and Ticker share AI infrastructure, memory services and a usage ledger, with bot identities and access checks preserved. A staff-started cross-bot exchange supplies all three participants with its topic, relevant channel material and the complete current exchange; the completed exchange can be recalled in a relevant later discussion. It does not authorize unrelated private-channel access.

Provider / recipientInformation involvedReason
DiscordBot events, commands, messages, application identity and permissionsRun the Discord application and deliver interactions.
OpenRouter and the selected AI model providerContent and context needed for an AI request, tool results and request metadata; only when an AI feature is invokedGenerate an answer or supported content. Provider routing and retention depend on the selected model and account configuration.
News/search sources and retrieval providersSearch terms, article URLs and necessary request metadataRetrieve sources for research or news. Do not include unnecessary personal details in searches.
CoinGecko, Finnhub, Alternative.me and TradingViewRequested symbols, chart options and network request metadata when using market toolsProvide Ticker’s market data, sentiment and chart rendering.
GIPHY / configured GIF providerA GIF search term and network metadata when that feature is usedReturn requested GIFs.
Cloudflare and hosting infrastructureWebsite request IP/network metadata, requested paths and traffic processed through the serviceDeliver and protect the website and API.
Authorized operators and server moderatorsOnly records relevant to operations or the server’s configured moderation featuresProvide support, safety review, access decisions and incident response.

We do not promise that every provider offers zero retention or that every selected model uses identical data practices. Provider-side retention, subprocessors and international processing follow their applicable agreements and settings. We do not give providers a general right to train on Discord content through this policy. Data can be processed outside your country. Where law requires a transfer safeguard or other protection, the operator must apply it before that processing.

Provider references: Discord privacy · OpenRouter privacy · Cloudflare privacy. These links leave Big If True.

Storage, retention and security

The default raw chat-statistics ledger retains up to 90 days. Aggregated levels, streaks and reward records can last longer. Moderation-log retention defaults to no automatic expiry; server configuration can set a shorter period. Verification, activity entries, vote evidence, configuration, backups and restore journals have no single automatic expiry. Relevant records are reviewed for removal or restricted retention when you make a request.

Bot records use PostgreSQL; recent AI state uses Redis. Big’s website and story/community records use SQLite and local service storage. Files and generated artifacts may also use service-managed disk storage. Access is restricted to the bot services and authorized operators; browser connections use HTTPS. Private request text and reviewer notes are encrypted before storage, with the key kept separately from the request database.

We do not claim that every legacy database, log or backup has application-level encryption. Encryption and retention also depend on the host and backup configuration. A published policy alone is not proof of an independently audited security certification.

Website recordRetention / behavior
Discord OAuth authorization stateExpires after 10 minutes. Used to bind the login to the browser.
Website sessionExpires after 7 days; the server stores a token hash. Sign-out revokes that session.
Discord OAuth access tokenUsed to fetch your identify profile, then revoked; not retained in your browser or the account database.
Privacy preference and policy acknowledgmentKept to apply your choice and record the policy version you marked as read. Ask to remove it; removing an opt-out record can restore a default, so the operator may retain a minimal suppression record at your request.
Private requests and review notesRetained while handling the request and any necessary follow-up or abuse/legal dispute. No fixed automatic expiry is currently configured; request removal or a retention explanation.
Security and infrastructure logs / backupsRetention is configuration-dependent. A deletion review must identify applicable copies and any restricted legal/security hold; no unsupported fixed backup-erasure deadline is promised.

We retain information only for a service purpose, a necessary security or dispute purpose, or a legal obligation. Records without an automatic expiry still require operator review and deletion when no longer needed. If a security incident affects your data, we will investigate, take protective action and notify affected people and Discord where required.

Access, correction and deletion

Request deletion Ask for your data

  • Sign in with the Discord account concerned. Choose this bot or all four, specify what you want removed or exported, and include relevant server/message IDs if useful. We do not ask for a password or government ID in this form.
  • You receive a private request ID and can follow its status, add information or withdraw the request. “Received” means saved for review; it does not mean data has already been deleted.
  • A reviewer verifies scope and checks the bot databases, saved material, derived context, relevant files and backups. They can ask for more information without exposing another person’s records.
  • We act without undue delay, subject to applicable legal time limits. The response records what was removed, corrected or supplied, what remains, why it remains, and any further steps or retention period. There is no automatic promise of instant deletion.
  • Deletion can remove memories, saved items, scores or feature state and cannot reliably be undone. It may stop associated alerts or personalized behavior. Public messages already delivered to Discord and copies made by others are separate; the reviewer will explain which bot-controlled copies can be removed.
  • Essential suppression, security, moderation evidence or legal records may need restricted retention. We will explain a refusal or partial outcome rather than silently treating it as complete. You may appeal through the same request.

Depending on your location, you may also have rights to object, restrict processing, withdraw consent, receive portable data or complain to a data-protection authority. We honor applicable rights without charging for an ordinary request or retaliating for using them. If you cannot sign in, submit a Policy question explaining the access problem so the operator can arrange proportionate verification.

Gateway intents: which events arrive

An intent controls which Discord events an application receives. It is separate from a permission to act in a channel. Message Content and Server Members are privileged intents and can require Discord approval. Receiving an event does not mean every field is permanently stored.

IntentStatusSpecific purpose or limitation
GuildsEnabledTrack server, channel, role and permission structure for configured tools.
Server MembersPrivileged · enabledHandle joins/leaves, verification, role rewards, nickname changes and moderation membership checks. Without it, automated welcome, member monitoring and role synchronization can be incomplete.
Message ContentPrivileged · enabledRead prefix commands, puzzle answers, moderation evidence and rule/scam matches. Without it, ordinary-message moderation and text commands are limited; supported interaction buttons remain usable.
Guild MessagesEnabledReact to message creation, edits and deletions for moderation and optional statistics.
Guild / Direct ReactionsEnabledProcess configured reaction interactions, rewards and optional reaction statistics.
Guild ModerationEnabledRecord ban events and moderation/audit activity.
Guild Voice StatesEnabledRecord relevant voice-channel state changes in configured event logs. No audio recording.
Guild InvitesEnabledMaintain invite attribution for member joins and audit records.
Auto Moderation Configuration / ExecutionEnabledRecord rule changes and enforcement events for safety review.
Guild Webhooks / IntegrationsEnabledObserve configuration changes and support security auditing.
Guild ExpressionsEnabledObserve emoji/sticker changes for audit and configured expression tools.
Guild Scheduled EventsEnabledTrack event lifecycle and participation changes for configured server logs.
Direct Messages / Direct TypingNot requestedCustodian can send an allowed DM without subscribing to incoming DM message events.
Presence / Guild Typing / Message Poll intentsNot requestedNo online-status monitoring or typing analytics. Custom poll buttons use interactions instead.

No bot requests the privileged Presence intent. Discord’s gateway documentation defines the event families and approval rules.

Every permission, explained

This inventory separates a feature’s purpose from the effective grant observed in the Big If True server on 15 September 2026. Other servers can grant a different set, and channel overwrites can narrow access. A permission does not automatically authorize every member to invoke a staff action. Server owners can inspect the bot role and channel permissions in Discord.

Custodian currently has Administrator in the audited server. It makes all permissions available and bypasses channel restrictions. The feature registry does not require Administrator; this is a broader deployment grant, not a claim that every permission is necessary.

The application install scopes are bot and, where application commands are offered, applications.commands. Website sign-in requests only identify; it does not request email, connections, access to your DMs or permission to join servers for you. The Use Application Commands permission is a member permission and is distinct from the installation scope.

PermissionFeature statusWhy it is there / why it is unnecessaryAudited grant
Create Instant InviteNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Kick MembersFeature useCarry out authorized staff kicks.Available through Administrator
Ban MembersFeature useCarry out authorized bans and configured containment enforcement.Available through Administrator
AdministratorNot neededNot required by the feature permission registry. It grants all permissions and bypasses channel restrictions; it is broader than the features need.Available through Administrator
Manage ChannelsFeature useCreate setup/log channels, apply moderation locks and restore authorized server structure.Available through Administrator
Manage ServerFeature useResolve invite attribution and inspect server or AutoMod configuration during auditing.Available through Administrator
Add ReactionsFeature useUse configured confirmations, choices and activity interactions.Available through Administrator
View Audit LogFeature useAttribute a moderation or configuration event to its actor.Available through Administrator
Priority SpeakerNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
VideoNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
View ChannelFeature useSee only channels available to the bot.Available through Administrator
Send MessagesFeature usePost requested answers and configured feature messages.Available through Administrator
Send TTS MessagesNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Manage MessagesFeature useRemove violating messages, purge on staff request and maintain activity posts.Available through Administrator
Embed LinksFeature useShow rich source links and panels.Available through Administrator
Attach FilesFeature useDeliver generated images, charts or requested exports.Available through Administrator
Read Message HistoryFeature useRetrieve a permitted reply target or relevant earlier messages.Available through Administrator
Mention EveryoneFeature useConditional: mention the configured puzzle notification role if it is not mentionable. This broad grant is unnecessary when that role is already mentionable.Available through Administrator
Use External EmojisNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
View Server InsightsNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
ConnectNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
SpeakNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Mute MembersNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Deafen MembersNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Move MembersNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Use Voice ActivityNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Change NicknameNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Manage NicknamesFeature useApply configured dehoisting and impersonation corrections.Available through Administrator
Manage RolesFeature useApply verification, containment, self-selected, leveling and vote reward roles; restore authorized roles below the bot.Available through Administrator
Manage WebhooksFeature useInspect webhooks during security auditing. This grant allows more than the inspection feature uses.Available through Administrator
Manage Guild ExpressionsNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Use Application CommandsNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Request to SpeakNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Manage EventsNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Manage ThreadsFeature useMaintain puzzle/review threads, including access for an eligible private review participant.Available through Administrator
Create Public ThreadsFeature useCreate configured puzzle, activity or setup threads.Available through Administrator
Create Private ThreadsFeature useOpen private containment/review discussions.Available through Administrator
Use External StickersNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Send Messages in ThreadsFeature useAnswer and update feature posts inside accessible threads.Available through Administrator
Use ActivitiesNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Timeout MembersFeature useApply configured or staff-authorized timeouts.Available through Administrator
View Creator Monetization AnalyticsNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Use SoundboardNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Create Guild ExpressionsFeature useConditional: create a requested emoji or sticker through the configured expression tools.Available through Administrator
Create EventsNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Use External SoundsNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Send Voice MessagesNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Set Voice Channel StatusNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Send PollsNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Use External AppsNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator
Pin MessagesFeature useConditional: pin configured activity or control posts.Available through Administrator
Bypass SlowmodeNot neededNo current advertised feature requires this permission. An inherited or manual grant does not establish a feature need.Available through Administrator

Private-thread access and role hierarchy still need explicit checks in features that read or act for a member. A moderator capability is not a member command. Discord’s permission reference explains the platform-level effects, aliases and hierarchy. This inventory includes all currently documented permission flags; newly added Discord flags require a fresh review.

Cookies and local preferences

The website checks only the signed-in account’s membership in the configured Big If True server using the bot’s existing access. It does not request your server list through OAuth. The result is cached in server memory for up to 60 seconds, or 10 seconds after a failed check, and is not added to your stored profile. The website uses a secure, HttpOnly session cookie and a short-lived OAuth state cookie for sign-in. CSRF checks protect account writes. A local browser preference remembers your light/dark theme. Draft action state may be kept in session storage to resume a requested action after login. The bot hub does not add advertising cookies or third-party analytics scripts. Cloudflare and linked services may process their own technical records under their policies. Signing out does not erase account data; clearing browser storage does not delete bot records.

Questions, complaints and changes

Use the request center for a privacy question, correction, complaint or appeal. Use Abuse report for harmful use by a user, server or application. Reports are reviewed privately; relevant allegations or evidence may be shared in a limited way when needed to investigate, enforce rules or comply with law. We do not promise absolute anonymity where identification is necessary or legally required.

Material changes will update the effective date and a plain-language change note on this page. We will provide additional notice where required before materially different processing. A privacy setting does not become consent to unrelated processing. Children below Discord’s minimum age for their country must not use the apps; if we learn that an ineligible child’s data was collected, we will review and remove it as required.

Version note, 15 September 2026: first unified bot policy hub, per-bot optional processing controls and private request tracking.

Try a real-life example

“Wait, what happens if…?”

I turn memory off, then ask a question.

The bot processes your new request and the context you explicitly supply. It stops supported optional personal-memory use. It still accounts for usage and may post the answer where you asked. Old posts and summaries need a separate deletion review.

I disagree with a bot or a moderation result.

Challenge the answer, inspect its sources, or request a human review. Disagreement is allowed. Threats, harassment and attempts to access someone else’s private records are not.

I submit an abuse report without signing in.

You receive a secret receipt. Keep it: it opens the private report and follow-up thread. Losing it can mean losing access. Reports are reviewed, not automatically published or sent to the subject.

I want all four bots to forget me.

Choose “All four bots” and “Delete my data” in the request center. Verify your Discord identity, specify the scope and follow the review. The final note should explain any retained essential records and external copies.

Your copy, your pace.

Keep this page, ask about a clause, or optionally record that you have read this version. Marking it as read does not change your privacy settings or waive any rights.