Skip to content

Privacy Policy

Last updated: 28/09/2026

This policy explains what the Miwi Discord bot, its dashboard and website ("Miwi", "we") process, why, and what you can do about it. Miwi is operated by Hasibur Rahman, Dubai, United Arab Emirates.

Discord permissions and privileged intents

Miwi uses three privileged gateway intents that Discord requires bots to justify. Here is exactly what each one is used for:

  • Server Members — to know when members join, leave or change (roles, nicknames, timeouts). Used for antinuke, raid protection, welcome messages, autoroles, sticky roles, member logs and moderation. Miwi stores member IDs only where a feature needs them (for example a moderation case or a sticky role).
  • Message Content — to read messages for prefix commands (like m!help), AutoMod filters, autoresponders, AFK replies and message edit/delete logs. Messages are processed in real time and are not stored, except when a server enables a feature that keeps them (edited and deleted messages sent to that server's own log channel, ticket transcripts, or the last deleted message for /snipe, kept briefly in memory).
  • Presence — to give roles based on a member's status or activity ("presence roles") when a server turns that feature on, and to name join-to-create voice channels after the game being played. Presence data is not stored.

Data we process

  • Discord identity: user IDs, usernames and avatars; server IDs, names, icons, owners and member counts.
  • Server configuration: the settings admins choose (channels, roles, module options, whitelist, dashboard access list) and a log of configuration changes.
  • Moderation and security records: moderation cases, warnings, antinuke, raid and AutoMod events, including the IDs of the people involved and reasons given.
  • Tickets: ticket metadata and, when a server enables transcripts, the ticket's messages. Server admins set transcript retention.
  • Join-to-create voice channels: which temporary channel belongs to whom, and who its owner trusted or blocked, while it exists.
  • Votes, Voter Cash and Premium: Top.gg vote events, your Voter Cash balance and ledger, premium redemptions and entitlements.
  • Dashboard sessions: a session cookie and your Discord OAuth tokens, stored encrypted and used only to list the servers you can manage.
  • Public server directory: servers with 500 or more members appear with their name, icon, member count and an optional admin-written description. Admins can hide their server any time under Dashboard → General.
  • Game statistics: games played, wins and best scores.
  • Operational logs: to run Miwi, fix bugs, provide support and prevent abuse we keep service logs. These can include which commands were used, by which user and in which server, messages people send to Miwi in direct messages, server join/leave events, and technical error reports. Credentials and tokens are always removed from logs.

Third-party services

Some features send the minimum data needed to an outside service:

  • Discord — the platform Miwi runs on.
  • AI (/ai) — your question is sent to Groq to generate the answer. Don't include personal information in questions.
  • Translation — text you translate is sent to Google Translate.
  • Crypto lookups — coin names, addresses or transaction IDs you look up are sent to CoinGecko, BlockCypher and alternative.me. Miwi never holds or moves funds.
  • Top.gg — sends us vote notifications.
  • Hosting — GalaxyGate; the website is hosted on Vercel.

Cookies

The dashboard uses strictly necessary cookies only: a session cookie and a short-lived sign-in cookie. There are no advertising or third-party tracking cookies.

Why we process it

To provide the features you or your server admins enable, keep servers secure, prevent abuse, support users and operate the service reliably.

Retention

  • Ticket transcripts: the retention each server sets.
  • Dashboard sessions: deleted within a day of signing out or expiring.
  • Operational logs and error reports: kept only as long as needed to run and fix Miwi.
  • Server settings and records: kept while Miwi is in the server, and afterwards so everything is still there if Miwi is re-added; deleted on request.

Your rights and deletion

You can ask for a copy of your data, or for it to be deleted, by contacting us. Server admins can request deletion of their server's data. Some records (for example moderation cases a server keeps) may be retained where needed for safety or legal reasons.

Security

Data is stored in access-controlled databases; OAuth tokens are encrypted; the owner panel requires two-factor authentication; staff access is audited.

Children

Miwi is for people old enough to use Discord under Discord's own terms.

Changes

We'll update this page and its date when this policy changes.

Contact

hasib@kortzlab.pro or our support server.

Privacy Policy · Miwi