Skip to main content
Back to home

Privacy Policy

Last updated: July 14, 2026

This Privacy Policy explains what information Catty ("Catty", "we", "us", or "our") collects, why we collect it, how we use and share it, and the choices you have. It applies to the Catty Discord bot and the Catty web dashboard, which share the same underlying database.

Overview

Catty is a Discord bot with a companion web dashboard for music, moderation, economy, games, server statistics, and configuration. We aim to collect only the data needed to run these features.

Catty is a free, community-operated project. We do not sell your data and we do not process payment or billing information. By adding Catty to a server or signing in to the dashboard, you agree to the practices described here.

Who Is Responsible

Catty is operated by the Catty project maintainers (the "operator"). For data tied to a specific Discord server, the server's owner and administrators act as controllers of how the bot is configured and used on that server, while we act as a processor providing the underlying functionality.

You can reach the operator through the Discord support server linked in the site footer.

Account & Profile Data

When you sign in to the dashboard, we authenticate you through Discord OAuth using the "identify", "guilds", and "email" scopes. We store:

  • Your Discord user ID (a numeric identifier used to link your data across the bot and dashboard)
  • Your Discord username, display name, and avatar image
  • Your Discord email address (used for data exports, deletion confirmations, and login alerts)
  • Discord OAuth access and refresh tokens, used to read your servers and verify your permissions. When a music connection is established, a short-lived AES-256-GCM-encrypted copy is stored in Redis for up to five minutes; OAuth tokens are never sent over the music WebSocket
  • Your dashboard preferences: theme, interface language, font size, and reduced-motion setting

Activity & Usage Data

When you interact with the bot in a Discord server, we record activity data to power statistics, leaderboards, and bot features. We do not store the text of your messages for analytics. This includes:

  • Message counts per server (how many messages you sent, not their content)
  • Command usage counts (which commands were used and how often)
  • Voice activity: IDs of voice channels you joined, session start and end times, total session duration, and time spent active, muted, and streaming
  • Music listening history: track title, author, link, thumbnail, track duration, source, playback date and time, listening duration, and who requested the track (automatically deleted after 90 days)
  • Economy and game data stored per server: balances, selected job and experience, gambling outcomes, and command cooldowns
  • Saved playlists associated with your Discord user ID

Moderation Data

If a server uses Catty's moderation tools, we store warning records that include the warned user's ID, the moderator's ID, a timestamp, and the reason text entered by the moderator. These records are tied to the server and are managed by that server's moderators.

Where a server enables verification features, the status of your verification is stored, but your submitted answers are posted to a moderator channel within that Discord server rather than retained in our database.

Technical & Session Data

To keep your dashboard account secure, we record technical information about your login sessions:

  • IP address — stored with your session and included in new-login email alerts; it is masked when shown in the session list and excluded from data exports
  • Browser, operating system, device type, and related user-agent details reported by your browser
  • Session tokens and authentication cookies that keep you signed in, plus login and last-active timestamps
  • CSRF protection tokens to prevent unauthorized actions on your account
  • We do not perform IP geolocation — we do not look up or store your city or country

Server Logging & Message Content

Catty does not store the content of your Discord messages in our database. However, if a server administrator enables logging features, events such as deleted or edited messages, joins, leaves, bans, and kicks (which may include message content, usernames, and avatars) are sent to a Discord webhook chosen by that server's administrators.

That data lives in the destination Discord channel and is controlled by the server administrators, not by Catty. Bug reports submitted through the bot send your username, user ID, server name, and the description you provide to the operator.

How We Use Your Data

We use the data described above to:

  • Authenticate you, maintain secure sessions, and verify your permissions on Discord servers
  • Operate bot features such as music playback, moderation, economy, games, and statistics
  • Display your settings, activity, statistics, and server management tools in the dashboard
  • Send transactional emails: data exports, account-deletion confirmations, and new-login security alerts
  • Protect the service: rate limiting, abuse prevention, and security monitoring
  • Diagnose errors and improve reliability and performance

Legal Bases (EEA/UK)

If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR:

  • Performance of a contract — to provide the bot and dashboard features you request
  • Legitimate interests — to secure the service, prevent abuse, and keep it running reliably
  • Consent — where you choose to enable optional features or sign in; you may withdraw consent at any time
  • Legal obligations — where we must retain or disclose data by law

How We Share Data

We do not sell your personal data. We share limited data with the service providers (subprocessors) and platforms needed to run Catty:

  • Discord — for authentication, bot functionality, and any logging webhooks your server configures (subject to Discord's privacy policy)
  • Resend — to deliver transactional emails (exports, deletion confirmations, login alerts)
  • Our hosting, database (MongoDB), and cache (Redis) providers that store and serve the data
  • Music sources — YouTube, YouTube Music, and SoundCloud for search and playback; Spotify metadata may be used to find a playable source
  • Content delivery networks — when the dashboard proxies album art and thumbnails from the platforms above

Data Retention

We keep data only as long as needed to provide the service. Key retention periods are:

  • Music listening history — automatically deleted 90 days after playback
  • Login sessions — expire after 30 days of inactivity, or sooner if you sign out or revoke them
  • Statistics and voice sessions — retained until you delete your data or the bot is removed from the server
  • Server data — purged roughly 14 days after Catty is removed from a server, including economy, warnings, and statistics for that server
  • Backups — encrypted database backups are rotated on hourly, daily, and weekly cycles, so deleted data may persist in backups until those backups age out
  • Short-lived tokens (WebSocket, deletion links, export cooldowns) expire automatically, typically within minutes to hours

Security

We use measures to protect your data, including encrypted connections, hashed and signed tokens, CSRF protection, AES-256-GCM encryption for short-lived OAuth token copies used while establishing music connections, rate limiting, and restricted administrative access.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your data, we will take appropriate steps and provide any notifications required by law.

Your Rights

Depending on your location, you may have the right to:

  • Access and receive a copy of your data (use the export feature in Settings → Data & Privacy)
  • Request correction of inaccurate information
  • Request deletion of your data (use the delete feature in dashboard settings)
  • Restrict or object to certain processing
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with your local data protection authority

Exporting & Deleting Your Data

From Settings → Data & Privacy you can export a copy of your data (sent to your Discord email as a ZIP containing your settings, sessions, statistics, music history, voice sessions, playlists, economy data, and moderation warnings) and request account deletion (confirmed by a one-time email link that requires an explicit confirmation click).

Deletion removes your dashboard account and Discord OAuth link, login sessions, dashboard preferences, statistics, voice sessions, music history, saved playlists, economy balances, and moderation warnings stored by Catty. Cached bot and dashboard data tied to your user ID is also cleared. Data may remain in rotating encrypted backups until they age out, and content sent to Discord logging webhooks configured by server administrators is not under Catty's control. To remove server-specific logging data, contact the relevant server administrators or the operator.

Cookies & Local Storage

The dashboard uses a small number of cookies and browser-storage entries. Authentication and security cookies are strictly necessary. We do not use advertising or cross-site tracking cookies.

  • Session cookies — to keep you securely signed in
  • OAuth state and CSRF cookies — to protect the login flow and your account from forged requests
  • A language cookie — to remember your interface language
  • Browser local storage — to remember your language, theme, font size, and motion preferences (cleared on sign-out)

Children's Privacy

Catty is not directed at children. You must meet Discord's minimum age requirement for your country (at least 13) to use Catty. We do not knowingly collect personal information from anyone below that age. If you believe a child has provided us data, contact us and we will take steps to remove it.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page. Continued use of Catty after changes take effect constitutes acceptance of the updated policy.

Contact

For privacy-related questions or to exercise your rights, reach out through our Discord support server (linked in the site footer) or contact the Catty operator directly.

© 2026 Catty. All rights reserved.

Checking status…
·DashboardPrivacy PolicyTerms of ServiceAdd Bot(opens in new tab)Discord Server(opens in new tab)·