Last updated: 25.08.2026
riftQ.com ("we", "us", or "our") operates Lulu-Bot, (the "Bot"). This Privacy Policy explains which personal data the Bot processes when it is used in a Discord server, why that data is processed, who may receive it, and what choices are available to you.
Processing And Collection Of Data
Discord account and server data
The Bot processes Discord account and server data, including user, server, channel, message, role, and interaction IDs; usernames, display names, avatars, account and server join dates; roles and permissions; and server and feature configuration. Depending on the enabled feature, it may also process presence and voice state, invites, reactions, audit log information, message attachments, and information submitted through commands, interactions, tickets, polls, quizzes, or games.
Messages, commands and attachments
The Bot stores the content and metadata of non-bot messages sent in servers in which it is installed. It also processes message content for prefix and custom commands, automatic moderation, XP and item-drop features, ticket handling, channel rules and synchronization, event logging, and moderation evidence. Selected attachments may be downloaded temporarily when a feature, such as image recoloring or message-sequence import, requires it.
Feature-specific records
Other records include warnings, notes, mutes, kicks, bans, appeals and moderator details; ticket issue text and transcripts; CAPTCHA and new-account verification status; XP, levels and rewards; inventory, item-drop and trade data; previous nicknames; and game account, rank, challenge, match, score, or disqualification data.
Purposes Of Processing
We process this data to provide commands and administrator-selected server features; authenticate permissions; moderate communities and prevent abuse; attribute invites and welcome or verify members; manage tickets, roles, channels and server logs; provide XP, inventory, trading, game verification, challenges and tournament features; deliver configured posts and public social-media content; and maintain, secure and troubleshoot the Bot.
Automated rules may delete messages, issue warnings or infractions, change roles, reject content, or require a CAPTCHA and temporarily remove a very new account. Temporary mutes and bans may also expire automatically. Server moderators configure these features and can review or reverse actions where Discord and the Bot allow them to do so.
We do not use Bot data for advertising or AI model training, and we do not sell personal data. Aggregated feature statistics may be displayed, but the underlying operational records can remain linked to Discord identifiers.
Access To And Disclosure Of Data
Server administrators, moderators and members
Server administrators and moderators may receive information through Bot commands, moderation tools, ticket transcripts, and configured Discord log channels. Depending on server permissions and enabled features, other members may see public Bot replies, leaderboards, ranks, public inventories, trades, welcome messages, item drops, and synchronized messages. Moderation actions may be shared across servers that an administrator has configured as a moderation cluster.
Service providers
The Bot relies on service providers to operate. These can include Discord, our application and MySQL database hosts, RiftQ services, Riot or related game services, Twitter/X, QuickChart, and the Discord content-delivery network. They receive only the data involved in the applicable feature, such as Discord IDs and Bot output, stored operational records, verification and rank data, public social-media data, ticket-chart labels and statistics, or attachment requests. These providers process data under their own terms and privacy notices and may process it outside your country.
We may also disclose data where required by law or where reasonably necessary to protect users, the Bot, or others from fraud, abuse, or security threats:
- Comply with applicable law or legal obligation
- Protect the personal safety of users
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect and defend our rights
- Protect against legal liability
Data Retention And Deletion
Messages and temporary records
Stored guild-messages are automatically deleted after seven days. Moderation tools may use messages from the most recent 24 hours as evidence. Temporary mute and ban scheduling records are removed when the sanction expires, although the related moderation history may remain.
Other Bot records
Other information, including moderation, ticket, verification, XP, inventory, trade, nickname, challenge, match, configuration, and operational log records, has no uniform automatic expiry. It is retained while needed for the relevant feature, community safety, dispute resolution, security, or legal obligations, and is otherwise removed upon a valid deletion request where applicable. Discord log messages and ticket transcripts, provider records, and backups must be handled separately and may remain until deleted or expired in those systems.
Security
We use reasonable technical and organizational measures intended to protect personal data. Nevertheless, no Internet transmission or electronic storage system can be guaranteed to be completely secure.
Your Data Protection Rights
You may stop interacting with the Bot. Server administrators can restrict its permissions, disable features, or remove it from their server. Depending on applicable law, your rights may include:
- access to your personal data and information about how it is processed;
- correction of inaccurate or incomplete personal data;
- deletion of your personal data where the applicable requirements are met;
- restriction of, or objection to, processing;
- receipt of eligible data in a portable format; and
- a complaint to the competent data protection authority.
How to exercise your rights
To make a privacy request or report a privacy or security concern, contact a staff member on our Discord server or email [email protected]. Include your Discord user ID and any relevant server ID so we can locate the records. We may ask you to verify control of the relevant Discord account, but we will never ask for your Discord password or user token. Some data may be retained where continued retention is required or permitted by law; if so, we will explain this in our response.
Children's Privacy
The Bot is not directed specifically at children. You must meet Discord's minimum age and any higher minimum age required in your country to use Discord and the Bot. If you believe the Bot has processed data relating to a child who is not permitted to use the service, please contact us using the details above.
Changes To This Privacy Policy
We may update this Privacy Policy when the Bot, our processing practices, or legal requirements change. Changes take effect when the revised policy is posted on this page. We will update the date above and, where appropriate, provide additional notice of material changes.