Legal
Privacy Policy
Last updated: June 11, 2026
1. Who we are
Seramate is the team behind Seraphita, an AI-driven World of Warcraft companion bot for Discord, and this admin panel. When this policy says "we", "us", or "our", it means the Seramate team. You can reach us at [email protected] or in our Discord support server.
2. What this policy covers
This policy applies to the Seraphita Discord bot (in servers where an administrator has installed it) and this admin panel. It does not cover Discord itself, Patreon, or other third-party platforms we integrate with — those are governed by their own privacy policies.
3. Data we collect
Account data (when you sign in)
Signing in to the admin panel uses Discord OAuth with the identify and guilds scopes. We receive and store your Discord ID, username and display name, avatar and banner, locale, two-factor authentication status, Nitro status, and the list of servers you can manage. We do not receive your email address from Discord. We also store the OAuth tokens Discord issues so the panel can work on your behalf. For security, sign-in records include the IP address and browser user-agent of the session.
Bot conversation data
When you talk to Seraphita in a server where it is installed, we receive and store the message content, your Discord ID and username, the channel and server IDs and names, any message you replied to, and any attachments (such as images), which are kept in our file storage. We also record technical metadata such as AI token usage per message.
Administrators of the server where a conversation took place can view it — including full message content and attachments — together with activity, sentiment, and relationship analytics, through the admin panel.
AI-derived data
Seraphita personalizes its behavior based on past interactions. For that we store per-conversation sentiment (positive, neutral, negative, or romantic), a per-user relationship score that decays over time, short evaluation notes explaining score changes, and memory facts the bot has learned about you from conversations. Aggregated views of this data (activity, sentiment distribution, and relationship leaderboards) are shown to server administrators on their server dashboard.
Role management data
For servers using automatic roles, we store the rules administrators create, the role assignments the bot makes, and audit logs of every sync (who triggered it, which roles were granted or revoked, and why). If you link your Seramate account to your Discord account, we associate the two and evaluate your game data (PvP titles, arena ratings, achievements, class, region, streamer status) against the server's rules. To apply roles, the bot reads server member lists and manages roles using the permissions granted at installation.
Billing data
We track your credit balance and membership tier. If you link a Patreon account, we receive your Patreon user ID, email, membership tier, and pledge details from Patreon. We never receive or store payment card or bank details — all payments are handled by Patreon.
4. How we use your data
- To run the bot: answer messages, keep conversational context, and personalize responses using memory and relationship data.
- To assign and remove Discord roles according to rules configured by server administrators.
- To provide server administrators with dashboards about bot activity in their server.
- To track credit usage and apply membership tiers.
- To keep the service secure: authentication, abuse prevention, and rate limiting.
- To answer support requests.
We do not sell personal data and we do not use it for advertising.
5. AI processing
To generate responses, conversation content — messages, usernames, relevant memory and relationship context, and image attachments — is sent to large language model providers via OpenRouter, which routes requests to models from Anthropic, OpenAI, and Google. Their handling of this data is governed by their own terms. We do not use your conversations to train models of our own.
Please avoid sharing sensitive personal information (such as health, financial, or identity details) in conversations with the bot.
7. Third-party services
We rely on a small set of service providers to operate Seraphita:
- Discord — the platform the bot runs on; we exchange data with Discord's API to read and send messages and manage roles.
- OpenRouter (routing to Anthropic, OpenAI, and Google models) — receives conversation content to generate AI responses.
- Cloudflare — network proxying and file storage for attachments.
- Patreon — payments and memberships; we receive membership details only if you link your Patreon account.
These providers may operate servers in countries other than yours. We share only what is needed for them to perform their function.
8. Data retention
- Conversations leave the bot's active context after about 24 hours of inactivity. Stored conversation history (including attachments) is kept for at most 30 days, or until deletion is requested — whichever comes first.
- Relationship scores decay over time when you don't interact with the bot; memory data is kept while your account or server remains active.
- Audit and security logs are kept for up to 365 days; most (role syncs, AI activity, sign-in records) are deleted within a week.
- Account data is kept while you use the service. You can delete your account yourself at any time, or request deletion by contacting us (see below).
9. Security
Data is encrypted at rest and in transit (TLS). Cookies are restricted to first-party use and marked Secure (the server-side session cookie is additionally HTTP-only), and access to production data is restricted to the operating team. No method of storage or transmission is 100% secure, but we work to protect your data using current good practices. If a data breach affects your personal data, we will notify affected users and, where required, regulators without undue delay. If you believe you've found a security issue, please contact us.
10. Your rights and choices
You can always:
- Delete your account yourself from your profile page . This permanently deletes your conversations and attachments, AI memory and relationship data, account links, and roles the bot manages for you. Audit logs are kept for their normal retention period, and minimal credit-usage records are kept so deleting an account cannot be used to reset credit limits.
- Request a copy, correction, or deletion of your data by contacting us — this applies to everyone, including server members who have only chatted with the bot and never used this panel.
- Revoke the panel's access to your Discord account in Discord's settings (Authorized Apps).
- Unlink your Patreon or Seramate account.
- If you are a server administrator, remove the bot from your server, which stops all collection there.
Depending on where you live, laws such as the GDPR or CCPA may give you additional rights — including access, portability, correction, deletion, and objection. We honor reasonable requests regardless of where you are located. Send requests to [email protected] — we aim to respond within 30 days, and in any case within the timeframe required by applicable law.
11. Children
The service operates on Discord, which requires users to be at least 13 years old (older in some countries). Seraphita is not directed at children, and we do not knowingly collect data from anyone below Discord's minimum age. If you believe a child's data has been collected, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the service evolves. Updates are posted on this page with a new "Last updated" date, and material changes are announced in our Discord server.
13. Contact us
For privacy requests or questions, email [email protected] or ask in our Discord support server.