J.A.D.E. System — Legal Document

Privacy Policy

Last revised: June 2025  ·  Controller: J.A.D.E. Development Team
00 Summary 01 Who We Are 02 Data Collected 03 TikTok Data 04 Legal Basis 05 How We Use Data 06 Sharing 07 Retention 08 Security 09 Your Rights 10 Children 11 International 12 Updates 13 Contact
§ 00 Plain Language Summary
Key Points

We collect the minimum data needed to run J.A.D.E. — Discord server IDs, channel/role IDs, session tokens, and configuration you set. We do not sell your data. We do not store Discord message history. We do not store TikTok account credentials or private user data. You can request deletion of your data at any time.

The full policy below explains this in legal detail as required by applicable data protection law, including the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and the California Consumer Privacy Act (CCPA/CPRA) where applicable.


§ 01 Who We Are & Data Controller

J.A.D.E. (Just Another Digital Entity) is a Discord bot platform and companion web portal. The data controller for personal data processed through the Services is the J.A.D.E. development team.

For the purpose of UK GDPR and EU GDPR, J.A.D.E. is the data controller in respect of personal data processed when you use the Services. Where J.A.D.E. processes personal data on behalf of Discord or TikTok's platforms, it does so as a data processor subject to those platforms' respective privacy frameworks.

Contact details for privacy queries are set out in Section 13.


§ 02 Personal Data We Collect

We collect data in two categories: data you provide directly (through Discord OAuth or Portal configuration), and data collected automatically when you use the Services.

Data Type What It Is Why Collected
Discord User ID Your unique Discord account identifier, obtained via OAuth2 login to the Portal. Authenticate your Portal session and verify administrative permissions.
Discord Username & Avatar Your Discord display name and profile picture, obtained from the Discord API at login. Display your identity within the Portal UI.
Discord Guild (Server) IDs The IDs of Discord servers you share with J.A.D.E., obtained from the Discord API (guilds scope). Determine which servers you administer so you can manage Bot settings for those servers.
Discord OAuth2 Access Token A temporary bearer token issued by Discord authorising J.A.D.E. to retrieve your profile and guild list on your behalf. Make authenticated requests to the Discord API during your Portal session. Not persisted to disk beyond the session lifetime.
Server Configuration Data Channel IDs, role IDs, XP settings, economy settings, welcome message text, moderation log channels, and other bot configuration options you set via the Portal or Bot commands. Store your Bot configuration so the Bot can operate correctly in your server.
Economy & XP Records Virtual currency balances and XP/level data associated with Discord User IDs within a specific server. Operate the economy and leveling modules. Data is server-scoped and not cross-server.
Message Count Data Aggregate message counts per Discord User ID per server, used for leaderboards. Power the message activity leaderboard. Individual message content is never stored.
Invite Usage Records Which Discord invite codes were used for joins, attributed to the inviting user's Discord ID. Operate the invite tracking module and leaderboard.
Moderation Records Warning logs and moderation actions including the Discord User ID of the subject and the moderator, with reason and timestamp. Enable moderation module functionality and administrator review.
Session Data A server-side session token stored in a browser cookie identifying your active Portal login. Maintain your authenticated session across Portal page loads. Sessions expire on logout or after a period of inactivity.
What We Do Not Collect

J.A.D.E. does not collect or store: the content of Discord messages (beyond aggregate message counts), private Discord direct messages, passwords, payment card data, or any sensitive personal data categories as defined under GDPR Article 9.


§ 03 TikTok Integration — Data Handling

When you enable TikTok monitoring features, J.A.D.E. accesses data from the TikTok for Developers API as follows:

Data Element Source How Used Stored?
Target TikTok Username Entered by server administrator in the Portal. Identifies which public TikTok account to monitor for new uploads. Yes — stored as part of server configuration.
Video Metadata TikTok public API response (video ID, title, thumbnail URL, video URL, publish timestamp). Used to construct a Discord embed notification for new video uploads. Notification state only — the last-seen video ID per monitored account is stored to prevent duplicate notifications. Raw metadata is not retained.
TikTok Account Credentials Not collected. J.A.D.E. does not request TikTok Login Kit authorization from monitored accounts. Monitoring is performed using TikTok's public content APIs only. Not stored — not collected.
TikTok User Private Data Not collected. J.A.D.E. does not request or access private account data, follower lists, DMs, analytics, or any non-public TikTok data. Not stored — not collected.

All TikTok data accessed by J.A.D.E. is publicly available content that TikTok makes available through its developer platform. J.A.D.E. does not scrape, crawl, or harvest TikTok content outside of the official API. J.A.D.E.'s use of TikTok API data complies with TikTok's API Terms of Service.

If TikTok modifies its API policies or revokes J.A.D.E.'s API access, TikTok monitoring features may be suspended or terminated. In such a case, any stored TikTok-related configuration (username, notification channel ID) will be retained only for the purpose of re-enabling the feature if access is restored, and may be deleted by the server administrator at any time.


§ 04 Legal Basis for Processing (UK/EU GDPR)

Where UK GDPR or EU GDPR applies, J.A.D.E. processes personal data on the following legal bases:

Processing Activity Legal Basis (GDPR Art. 6)
Discord OAuth2 login and session management Article 6(1)(b) — Processing necessary to perform the service you have requested (authentication).
Storing server configuration and bot settings Article 6(1)(b) — Necessary to provide the Bot's core functionality you have configured.
Economy, XP, message count, and leaderboard data Article 6(1)(b) — Necessary to provide the Bot features you and your server community have opted to use.
Moderation logs Article 6(1)(f) — Legitimate interest of server administrators in maintaining community safety and accountability.
TikTok notification state (last-seen video ID) Article 6(1)(b) — Necessary to fulfil the notification service you have configured.
Session cookies Article 6(1)(b) — Strictly necessary to operate the authenticated Portal session.

§ 05 How We Use Personal Data

J.A.D.E. uses collected data exclusively for the following purposes:

  • Authenticating and maintaining your Portal login session via Discord OAuth2.
  • Verifying your administrative permissions in Discord servers where the Bot is installed.
  • Storing and applying Bot configuration settings you define through the Portal or Bot commands.
  • Operating economy, XP, leveling, invite tracking, Hall of Fame, and moderation modules within the scope of each individual server.
  • Monitoring configured TikTok accounts for new video uploads and delivering embed notifications to your designated Discord channel.
  • Generating and displaying server-scoped leaderboards within the Portal.
  • Diagnosing technical issues and maintaining service integrity.

We do not use personal data for: advertising, profiling, sale to third parties, cross-server tracking of users, or any purpose not listed above.


§ 06 Data Sharing & Third Parties

J.A.D.E. does not sell, rent, or trade personal data to any third party.

Data is shared with or accessed by third parties only in the following limited circumstances:

  • Discord Inc.: J.A.D.E. communicates with Discord's API to authenticate users and operate Bot functions. Discord's own Privacy Policy governs Discord's processing of your data. J.A.D.E. passes only the minimum necessary data back to Discord (e.g. sending messages or embeds to channels you have configured).
  • TikTok (ByteDance): J.A.D.E. makes outbound API requests to TikTok's public developer APIs to retrieve publicly available video metadata. J.A.D.E. does not transmit any of your personal data to TikTok. TikTok's own Privacy Policy governs TikTok's processing of API request data.
  • RSS and Public Feed Providers: When configured, J.A.D.E. makes outbound HTTP requests to public RSS feed URLs. These requests do not contain personal data beyond a standard HTTP User-Agent header.
  • Legal Compliance: We may disclose data if required by applicable law, court order, or regulatory authority, or if necessary to protect the rights, safety, or property of J.A.D.E. or others.
  • Infrastructure Providers: The J.A.D.E. software is self-hosted. If the hosting environment involves third-party server infrastructure (e.g. a cloud or VPS provider), that provider may have incidental access to stored data as part of operating the underlying compute environment. Such providers are contractually prohibited from accessing or using your data for any other purpose.

§ 07 Data Retention

We retain personal data only for as long as necessary to provide the Services or as required by law.

Data TypeRetention Period
Portal Session Data (cookies)Deleted on logout or after session inactivity timeout.
Discord OAuth2 Access TokenHeld in memory for the duration of the session only. Not persisted to disk.
Server ConfigurationRetained indefinitely while the Bot is installed in your server. Deleted upon Bot removal (see deletion rights below).
Economy, XP, Leaderboard DataRetained while the Bot is installed. Can be reset by administrators using Bot commands. Deleted upon Bot removal on request.
Moderation LogsRetained while the Bot is installed, at the discretion of the server administrator. Can be cleared by administrators.
TikTok Last-Seen Video IDRetained while the TikTok monitor is active for a given server. Deleted when the feature is disabled or the Bot is removed.

We do not retain personal data after the purpose for which it was collected has been fulfilled, unless retention is required by law.


§ 08 Data Security

J.A.D.E. implements appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or disclosure. These measures include:

  • Authentication of all Portal access via Discord OAuth2, with session tokens validated server-side on each request.
  • Strict permission checks verifying that Portal users hold Administrator-level permissions in any server they attempt to manage.
  • Storage of configuration data in a local SQLite database with file-system-level access controls.
  • No transmission of personal data to external parties beyond what is strictly necessary for the Services to function.

No system can guarantee absolute security. In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify affected parties in accordance with our obligations under applicable data protection law.


§ 09 Your Rights

Depending on your location, you may have the following rights in relation to your personal data:

Right of Access
You may request a copy of the personal data J.A.D.E. holds about you.
Right to Rectification
You may request correction of inaccurate personal data held about you.
Right to Erasure
You may request deletion of personal data held about you, subject to legitimate retention requirements.
Right to Restriction
You may request restriction of processing in certain circumstances (e.g. while accuracy is contested).
Right to Object
You may object to processing based on legitimate interests where your interests override ours.
Right to Portability
Where processing is based on consent or contract, you may receive your data in a portable format.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw it at any time without affecting prior processing.
CCPA / CPRA Rights
California residents have the right to know, delete, and opt out of sale of personal information. J.A.D.E. does not sell personal information. You may submit requests as described below.
How to Exercise Your Rights

To exercise any of the above rights, contact J.A.D.E. via the designated support channel. For deletion requests, the most immediate method is to remove the Bot from your server and contact us to confirm full data purge. We will respond to all verified requests within 30 days.

If you believe J.A.D.E. has not handled your personal data in compliance with applicable law, you have the right to lodge a complaint with your local data protection supervisory authority. For UK residents, this is the Information Commissioner's Office (ICO) at ico.org.uk. For EU residents, this is the supervisory authority in your EU member state.


§ 10 Children's Privacy

The Services are not directed at children under the age of 13 (or the applicable minimum digital age in the user's jurisdiction). J.A.D.E. does not knowingly collect personal data from children under 13. If we become aware that we have inadvertently collected personal data from a child under 13, we will take steps to delete that information as promptly as practicable.

If you are a parent or guardian and believe your child has provided personal data to J.A.D.E., please contact us using the details in Section 13.


§ 11 International Data Transfers

J.A.D.E. is developed and primarily operated from the United Kingdom. By using the Services, you acknowledge that your data may be processed in the United Kingdom or in the country where the hosting infrastructure is located.

Where J.A.D.E. transfers personal data outside the UK or EEA — for example, when making API requests to Discord's servers (US-based) or TikTok's servers — such transfers are made on the basis of recognised transfer mechanisms, including adequacy decisions and standard contractual clauses, to the extent applicable. For API interactions with third parties, those transfers are governed by the respective third party's own privacy frameworks.


§ 12 Changes to This Policy

We may update this Privacy Policy periodically to reflect changes to the Services, legal requirements, or our data practices. Where changes are material, we will provide reasonable notice via the Portal or the J.A.D.E. support channel prior to the changes taking effect.

The "Last revised" date at the top of this document indicates when this Policy was most recently updated. We encourage you to review this Policy periodically. Continued use of the Services after the effective date of any update constitutes acceptance of the revised Policy.


§ 13 Contact & Data Requests

For all privacy-related queries, data subject rights requests, deletion requests, or concerns regarding J.A.D.E.'s data handling practices, please contact the J.A.D.E. development team through the designated support channel on the J.A.D.E. Discord support server.

Please include the following information in your request to enable us to verify your identity and respond efficiently:

  • Your Discord User ID or username.
  • The Discord server ID(s) relevant to your request, if applicable.
  • A clear description of the data or right you are exercising.

We aim to respond to all privacy requests within 30 calendar days. For complex requests, we may notify you that an extension of up to a further 60 days is required, in accordance with applicable data protection law.

Your privacy matters to us. J.A.D.E. collects only what is necessary to run the service — nothing more.

This policy is provided for informational purposes and does not constitute legal advice. If you have legal concerns, please consult a qualified legal professional.