This policy explains how Shufen Bot ("we") processes personal data as data controller under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"). It covers our Discord bot, our web dashboard (shufenbot.com) and our payment flows.
In short: we process messages only for moderation, for the bot to reply to you, and for features a server turns on. We do not profile anyone, we do not sell data and we do not send mass DMs. We look at your game/online status only in the moment, for the Team Finder and online counter, and we do not store it.
1. Data Controller
| Controller | Shufen Bot |
|---|---|
| Website | shufenbot.com |
| [email protected] | |
| Contact channel | Discord support server |
2. Data We Process
2.1 Payments (subscriptions and Diamond packs)
| Category | Data | Source |
|---|---|---|
| Identity | First and last name | You / payment provider |
| Contact | Email address, phone number | You / payment provider |
| Address | Billing address | You |
| Transaction security | IP address, browser information, timestamp | Automatic |
| Transaction | Amount, status, order number, payment type | PayTR / Shopier / Polar |
| Digital identity | Discord user ID, username | Discord OAuth2 |
2.2 Using the bot
| Category | Data | Source |
|---|---|---|
| Digital identity | Discord user ID, server ID, channel and role IDs | Discord API |
| Server membership | Join/leave time, roles, nickname | Discord API (Server Members intent) |
| Usage statistics | Command usage, message count, voice time, hourly activity counters | Bot activity |
| Economy | Gold/Diamond balance, inventory, transaction history | Bot |
| Preferences | Liked songs, playlists, birthday, privacy choices | You |
| Message content | Text of messages sent in server channels (for the purposes in Section 3; mostly processed in real time without being stored) | Discord API (Message Content intent) |
| Moderation records | Automod decisions, warn/mute/ban records, violation counts and a short message excerpt | Bot |
2.3 Discord privileged intents we use
- Message Content: automod (profanity, spam, links, scams, threats), AI replies when you mention or reply to the bot, prefix commands, keyword auto-responses, verification and application flows, and the optional server-wide sentiment summary a server admin can turn on.
- Server Members: welcome/goodbye messages, verification and auto-roles, anti-raid and anti-nuke protection, invite tracking, timed roles and staff activity statistics.
- Presence: only for Team Finder & Online Counter (see Section 3.5). Your game and online status is read at that moment and not stored; we keep no online time, play history or music data. Older game/music statistics were removed and deleted on 7 October 2026.
Note: We never collect, process, store or see card numbers, CVV codes or expiry dates. These are handled only by the payment institutions.
3. How We Use Message Content and AI
3.1 Automatic moderation (automod)
In servers where automod is enabled, message text is first checked by rules inside the bot and, when needed, by an AI moderation service (Groq or OpenAI). Only the message text is sent; your Discord username and ID are not. The action configured by the server admin (delete, warn, timeout, etc.) is then applied. When a rule is broken, a short excerpt is kept for moderators to review (see Section 7).
3.2 AI chat
Your message is sent to the AI provider only when you mention the bot or reply to one of its messages. The conversation context (at most the last 8 exchanges) is kept in memory only, is never written to the database, and is discarded after 30 minutes of inactivity.
3.3 Server-wide sentiment (optional)
Off by default. If a server admin turns it on in the dashboard, the overall tone of messages in that server is measured with AI. No identity is sent to the service and the result is stored only as a daily server-wide total; no per-person sentiment score is kept.
3.4 Critical safety alerts
When a serious risk such as self-harm, grooming, scams, doxxing or threats is detected, the message is double-checked with AI to reduce false alarms and the server's moderators are notified. These records are deleted after 90 days.
3.5 Team Finder & Online Counter
The /playing command shows which games are being played in the server right now and who is playing a game; the Looking for a team button posts a message that pings at most 10 of those players. A server may also show the online member count (an anonymous total only) in a channel name. For this, your game and online status is read only at that moment; who plays what, for how long or when someone is online is never stored, and no statistics or profiles are built. You can opt out for all servers in /privacy → Team finder; you are then not listed or pinged anywhere.
3.6 What we do not do
- No profiling: personality/behaviour types, social scores, "ban risk" or "churn risk" predictions, writing-style fingerprinting for alt-account detection, friendship/relationship graphs and clustering people into groups were removed on 7 October 2026, and all data they produced was deleted.
- We do not sell data obtained from Discord or share it for advertising or marketing.
- We do not use your messages to train AI models.
- We do not send mass or unsolicited DMs. Announcements go to server channels only; DMs are used only for things you started (reminders, purchase notices, setup reminders).
- AI output alone never bans a member; the server admin always decides which actions automod may take.
4. Purposes
- Processing payments for subscriptions and Diamond packs and delivering digital products
- Invoicing, accounting and tax obligations
- Account management and sign-in with Discord
- Providing bot features (moderation, music, economy, levels, verification, welcome, statistics, etc.)
- Keeping servers safe (automod, anti-raid, anti-nuke)
- Handling support requests
- Preventing fraud and unauthorised access
- Meeting legal obligations (tax, consumer law, etc.)
- Improving the service (aggregated, anonymous statistics)
5. Legal Bases
- Performance of a contract (KVKK 5/2-c): selling subscriptions/Diamonds and providing the bot features you use
- Legal obligation (KVKK 5/2-ç): tax law, Laws No. 6563 and 5651
- Legitimate interest (KVKK 5/2-f): server safety and moderation, fraud prevention, service security
- Explicit consent (KVKK 5/1): marketing communication (if given)
6. Recipients
| Recipient | Data | Purpose |
|---|---|---|
| Discord Inc. (USA) | Data processed through the Discord API | Running the bot |
| Groq, Inc. (USA), OpenAI (USA) | Message text only (no username or ID) | Automod, AI chat, optional sentiment |
| PayTR Ödeme Hizmetleri A.Ş., Shopier (Türkiye), Polar | Name, email, IP, amount, order details | Processing payments |
| Google LLC (USA) - AdSense | Cookie identifiers, IP address, browser information | Showing and measuring ads on the website |
| Authorities (on request) | Relevant personal data | Legal obligations |
International transfers are made in line with Article 9 of KVKK.
7. Retention
| Data | Retention |
|---|---|
| Raw message text (automod / AI input) | Not stored; discarded after processing |
| AI chat context | In memory only, up to 30 minutes |
| Game / online status (Team Finder, counter) | Not stored; read only at that moment |
| Message excerpt in moderation records | 30 days (then the text is removed, only the count remains) |
| Critical safety records | 90 days |
| Activity, voice, music listening and interaction counters | 395 days |
| Daily server-wide sentiment totals | 395 days |
| Unfinished setup drafts | 30 days |
| Economy, inventory, playlists, preferences | Until you delete them |
| Support conversations | 3 years |
| IP address and transaction logs | 2 years |
| Identity and contact details (payments) | Membership + 3 years |
| Payment and invoice records | 10 years |
Expired data is deleted or anonymised by automatic cleanup jobs.
8. Security
- TLS encryption in transit
- Database access control and role-based permissions
- No passwords or card data in logs
- No identity sent to AI services
- Firewall, regular security patches and dependency updates
- Access limited to authorised people; breach notification to the Board and affected people
9. Cookies
- Session cookies: required for sign-in and session management.
- Preference cookies: remember your theme and language.
- Advertising cookies: some pages show Google AdSense (Google LLC, USA) ads; Google may use third-party cookies to serve and measure ads. You can turn off personalised ads in Google Ad Settings.
- No other third-party tracking or analytics cookies are used.
10. Your Rights and Controls
10.1 In the bot
- /mydata (/verilerim) shows you, privately, a summary of what is stored about you in a server.
- /privacy (/gizlilik) lets you opt out of features (including Team Finder) and delete your data. It also works in DMs.
- Server admins can turn off automod, sentiment and other features in the dashboard at any time.
10.2 Under KVKK Article 11
- Learn whether your data is processed and request information about it
- Learn the purpose of processing and whether data is used accordingly
- Know the third parties your data is transferred to
- Request correction, or deletion under KVKK Article 7, and notification of this to recipients
- Object to a result against you that arises solely from automated analysis
- Claim compensation for damage caused by unlawful processing
11. How to Contact Us
- Write to [email protected]. You can also reach us on our Discord support server.
- Include details that verify your identity (your Discord username and ID).
- Requests are answered free of charge within 30 days at the latest.
12. Changes
We may update this policy when laws or our service change. The current version is always available at shufenbot.com. Important changes are announced via [email protected].