Privacy Policy

Last updated: 25 September 2026. This is a starting template, not legal advice — have it reviewed before relying on it (especially if you have users in the EU/UK, California, or other jurisdictions with specific data-protection requirements).

What we collect

  • From Discord: your Discord user ID, username, and avatar (via Discord's OAuth login), and, for a server owner, the guild's ID, name, and icon.
  • Your server list: when you sign in to the dashboard, the list of Discord servers you're in and your permissions there, so we can show which servers you can manage. We don't store this list — it's fetched when you open the dashboard.
  • A Discord access token: issued by Discord when you sign in, used only to fetch that server list. It's encrypted before being stored and is discarded when your session ends (after 24 hours or when you sign out).
  • Roster and department data: whatever a server's admins enter — ranks, callsigns, assigned member IDs and names, certifications, department role IDs, question text, application answers, leave-of-absence dates and reasons.
  • Uploaded files: SOP documents uploaded to a department, stored as-is.
  • Billing data: handled directly by Stripe. We store a Stripe customer/subscription ID, not your card details.
  • A session cookie: to keep you signed in. It contains a random token, not your Discord credentials.

How we use it

To run the service: authenticate you, apply Discord role changes you or your server's admins request, show rosters/applications/leave requests to the right people, and process payments. We don't sell your data.

Who we share it with

  • Discord — to authenticate you and to read/write roles, nicknames, and member data your server's admins configure RostR to manage. Being placed on a roster can change your Discord nickname in that server (to your callsign and last name) and the roles you hold there.
  • Stripe — to process payments for paid plans.
  • Render — our hosting provider, which runs the application and database.

Data retention

Roster, application, leave, and document data is kept for as long as your server uses RostR. A server owner can delete a department (and everything in it) from the dashboard at any time. To request deletion of all of your server's data, contact our support Discord.

Your choices

You can remove the RostR bot from your Discord server at any time via Discord's own server settings. A server owner can also request account/data deletion through our support Discord.

Contact

Questions about this policy: our support Discord.