SaferChatAI
Back
Privacy

Privacy Policy

Last updated: March 26, 2025

This Privacy Policy explains how SaferChatAI (the "Bot" or "Service") collects, uses, and protects your personal data. We process data in accordance with the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), and all other applicable data protection laws.

1. Data Controller

Responsible for data processing:

Anton Eitenbichler
Dreiheiligenstraße 9
6020 Innsbruck
Austria

Email: [email protected]

2. What SaferChatAI Does

SaferChatAI is a Discord bot that helps moderate communities by analyzing messages for potentially harmful content. The bot uses artificial intelligence (AI) to detect toxicity, hate speech, self-harm language, NSFW content, spam, and piracy.

The bot is installed by Discord server administrators. When active on a server, it processes messages sent by users in that server.

3. What Data We Collect

3.1 Discord User Data

  • Discord User ID: Your unique numerical Discord identifier
  • Username: Your Discord display name
  • Server ID (Guild ID): The unique identifier of the Discord server
  • Channel ID: The identifier of the channel where a message was sent
  • Timestamp: Date and time when a message was created

3.2 Message Content

  • Text content: The full text of messages that are analyzed
  • Conversation context: Previous messages in the conversation may be analyzed to understand context

3.3 Moderation Data

  • Detected category: Classification of the message (e.g., toxicity, hate speech, self-harm, NSFW, spam, piracy)
  • Confidence score: AI's confidence level in its assessment
  • Moderation actions: How server moderators responded (Delete, Warn, Timeout, False Positive)
  • Feedback data: False positive reports used to improve accuracy

3.4 What We Don't Collect

We do not collect IP addresses, device information, or other technical connection data beyond what is necessary for the bot to function through Discord's API.

Important Warning About Sensitive Data:

We do not intentionally collect special categories of personal data under GDPR Article 9 (health data, racial or ethnic origin, political opinions, religious beliefs, biometric data, etc.). However, because users can write anything in their messages, such sensitive data could be included.

Do not include sensitive personal data in your messages. If you do include such data, it may be processed as part of the moderation system. By using servers where SaferChatAI is active, you acknowledge this risk.

4. Why We Process Your Data

4.1 Content Moderation

Purpose: To detect and report potentially harmful content to server moderators.

Legal basis: Legitimate interest (GDPR Article 6(1)(f)). Our legitimate interest is providing server administrators with an effective moderation tool to create safer communities. Server administrators have a legitimate interest in protecting their communities from harassment, hate speech, and other harmful content.

4.2 AI Analysis and Context Understanding

Purpose: To analyze messages using AI that considers conversation context, reducing false positives compared to simple keyword filtering.

Legal basis: Legitimate interest (GDPR Article 6(1)(f)). Context-aware moderation benefits both server operators and users by reducing incorrect flags.

4.3 Storage of Flagged Content

Purpose: To store messages flagged as problematic for moderator review and documentation.

Legal basis: Legitimate interest (GDPR Article 6(1)(f)). This allows moderators to review and respond to potential violations, and provides accountability for moderation decisions.

4.4 System Improvement

Purpose: To use feedback (especially false positive reports) to improve AI accuracy and adapt to specific community cultures.

Legal basis: Legitimate interest (GDPR Article 6(1)(f)). Improving accuracy benefits all users by reducing false flags.

4.5 Crisis Intervention

Purpose: To detect self-harm language and provide crisis resources to users while alerting moderators.

Legal basis: Legitimate interest (GDPR Article 6(1)(f)) in connection with protecting vital interests. This serves to protect users' physical and mental wellbeing.

5. Who We Share Data With

5.1 OpenAI

To perform AI-powered content analysis, we use services from OpenAI, L.L.C. (San Francisco, California, USA). Messages that need analysis are sent to OpenAI's API for processing.

Data transmitted: Message text, context messages, technical metadata.

Purpose: AI-powered content analysis.

Data retention by OpenAI: According to OpenAI's published policies, API data is retained for 30 days for abuse monitoring and is not used to train AI models. This policy may change - refer to OpenAI's documentation for current information: https://openai.com/policies/data-processing-addendum/

International transfer: See Section 6.

5.2 Discord Inc.

SaferChatAI operates as a Discord bot, meaning it relies on Discord's platform infrastructure. Discord Inc. (San Francisco, California, USA) processes user data independently as the platform operator.

Note: Discord's data processing is governed by Discord's own privacy policy, available at: https://discord.com/privacy. We do not control how Discord processes data and are not responsible for their data practices.

5.3 Server Administrators and Moderators

Server administrators and moderators can access flagged messages and moderation data through the moderation dashboard. They are responsible for their own use and handling of this data on their servers.

5.4 Hosting and Infrastructure Providers

We use third-party hosting services to operate our infrastructure. These providers act as data processors and are contractually obligated to process data only according to our instructions.

5.5 Legal Authorities

We may disclose data to law enforcement or government authorities when legally required or to protect our legal rights.

5.6 No Other Sharing

We do not sell, rent, or otherwise share your personal data with third parties beyond what is described above.

6. International Data Transfers

6.1 Transfers to the USA

Data processed through OpenAI and Discord is transferred to servers in the United States. The USA is considered a third country without an adequacy decision from the European Commission under GDPR Article 45.

Legal basis for transfer: OpenAI and Discord are certified under the EU-U.S. Data Privacy Framework (DPF), which the European Commission recognizes as providing adequate protection for data transfers to the USA.

6.2 Risks

Despite protective measures, there is a residual risk that U.S. authorities may access data under certain circumstances. We have assessed this risk and believe the transfer is lawful given the protections in place and the limited scope of processing.

7. Automated Decision-Making and AI Processing

7.1 Use of Artificial Intelligence

SaferChatAI uses artificial intelligence (Large Language Models) to automatically analyze message content. The AI assesses whether a message potentially violates community guidelines and categorizes it.

7.2 Automated Decisions

By default, SaferChatAI does not make automated moderation decisions. It reports potentially problematic content to server moderators, who then make human decisions.

Optional auto-delete: Server administrators can optionally enable automatic deletion of flagged messages. When this feature is enabled, messages may be deleted immediately upon detection without human review. This is not the default setting.

No other automated actions (warnings, timeouts, bans) are performed by the bot. These decisions are always made by human moderators.

7.3 AI Limitations

AI analysis is not perfect. False positives (incorrect flags) and false negatives (missed violations) can occur. The AI considers message content and conversation context to improve accuracy.

7.4 Right to Human Review

You have the right to request human review of any AI decision and to express your perspective. Contact the server moderators or us at the address in Section 1.

8. How Long We Keep Your Data

8.1 Non-Flagged Messages

Messages that the system considers harmless are not permanently stored. They are processed in real-time for analysis and then discarded.

8.2 Flagged Messages

Messages flagged as potentially problematic are stored in our database for up to 90 days from the time they are flagged, unless:

  • They are deleted earlier by moderators, or
  • Legal retention requirements apply

After 90 days, flagged messages are automatically deleted from our systems.

Note: Flagged messages are also posted to the server's moderation channel on Discord. These messages remain in Discord according to Discord's own retention practices and the server's settings. We do not control deletion of messages within Discord channels.

8.3 Data at OpenAI

According to OpenAI's published policies, API data is retained for 30 days and then automatically deleted. This policy is set by OpenAI and may change - refer to their current documentation.

8.4 Aggregated Statistics

Aggregated, anonymized statistics (e.g., number of flagged messages per category, false positive rates) may be stored permanently as they cannot identify individuals.

9. Security Measures

We implement appropriate technical and organizational measures to protect your personal data:

9.1 Technical Measures

  • Encryption: All data transmissions use encrypted connections (TLS/SSL)
  • Access control: Access to systems and databases is protected by authentication and authorization
  • Logging and monitoring: Security events are logged and monitored
  • Backups: Regular backups ensure data recoverability
  • Network security: Firewalls and network security measures protect against unauthorized access

9.2 Organizational Measures

  • Data processor agreements: Contracts with all data processors per GDPR Article 28
  • Confidentiality: All personnel with data access are bound by confidentiality obligations
  • Regular security reviews: Systems are regularly reviewed and updated
  • Incident response: Procedures exist for responding to data breaches per GDPR Articles 33 and 34

10. Your Rights

Under GDPR, you have comprehensive rights regarding your personal data. You can exercise these rights at any time by contacting us at the address in Section 1.

10.1 Right of Access (Article 15 GDPR)

You have the right to obtain confirmation of whether we process your personal data and, if so, to receive information about that data and additional details about the processing.

10.2 Right to Rectification (Article 16 GDPR)

You have the right to request correction of inaccurate personal data and completion of incomplete data.

10.3 Right to Erasure (Article 17 GDPR)

You have the right to request deletion of your personal data when:

  • The data is no longer necessary for the purposes it was collected
  • You withdraw consent and there is no other legal basis
  • You object to processing and there are no overriding legitimate grounds
  • The data was unlawfully processed
  • Deletion is required to comply with a legal obligation

The right to erasure does not apply when processing is necessary for exercising the right of freedom of expression, complying with legal obligations, or establishing, exercising, or defending legal claims.

10.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request restriction of processing when:

  • You contest the accuracy of the data (for the duration of verification)
  • Processing is unlawful but you prefer restriction to deletion
  • We no longer need the data but you need it for legal claims
  • You have objected to processing (pending verification of legitimate grounds)

10.5 Right to Data Portability (Article 20 GDPR)

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller, where processing is based on consent or contract and carried out by automated means.

10.6 Right to Object (Article 21 GDPR)

You have the right to object at any time to processing of your personal data based on legitimate interest (GDPR Article 6(1)(f)).

If you object, we will no longer process your data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.

How to exercise this right: If you do not want your messages analyzed on servers where SaferChatAI is active, you should leave those servers or request that the server administrator remove the bot. Individual opt-out from processing while remaining on the server is not currently possible.

10.7 Right to Withdraw Consent (Article 7(3) GDPR)

Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

10.8 Right to Lodge a Complaint (Article 77 GDPR)

You have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us is:

Austrian Data Protection Authority
Barichgasse 40-42
1030 Vienna
Austria

Phone: +43 1 52 152-0
Email: [email protected]
Website: https://www.dsb.gv.at

You may also contact the supervisory authority in your country of residence or workplace.

11. Important Notices

11.1 User-Generated Content Risks

SaferChatAI processes content freely written by users. We have no control over what information users include in their messages. While our system is designed to detect problematic content, we cannot guarantee that all potentially harmful or privacy-sensitive content will be identified.

Important reminders:

  • Do not include sensitive personal data (health information, religious beliefs, political opinions, etc.) in messages
  • Do not share confidential or private information you don't want analyzed
  • Be aware that all messages on servers with SaferChatAI active may be processed for moderation

11.2 Discord Platform Processing

SaferChatAI is a Discord bot and uses Discord's platform as its technical foundation. Use of Discord is subject to Discord Inc.'s Terms of Service and Privacy Policy. We have no control over Discord's own data processing.

Discord Inc. processes your data as an independent controller. Information about Discord's data processing is available in their privacy policy: https://discord.com/privacy

11.3 Children and Minors

Our service is not directed at persons under 16 years of age. We do not knowingly collect personal data from children under 16. Discord's minimum age requirement is 13 years (in the EU: 16 years or with parental consent).

If you are a parent or guardian and believe your child has provided us with personal data without consent, please contact us immediately so we can delete it.

11.4 No Profiling for Advertising

We do not create user profiles for advertising or marketing purposes. Data processing is solely for the moderation and system improvement purposes described in this privacy policy.

12. Changes to This Privacy Policy

We reserve the right to update this privacy policy to reflect changes in legal requirements, technical developments, or changes to our service. The current version is always available on our website.

For significant changes affecting your rights, we will notify you appropriately (e.g., through a notification on Discord or our website). We recommend reviewing this privacy policy regularly.

The effective date of this privacy policy is stated at the beginning of this document.

13. Contact

For questions about processing of your personal data, to exercise your rights, or for data protection inquiries, please contact:

Anton Eitenbichler
Dreiheiligenstraße 9
6020 Innsbruck
Austria

Email: [email protected]

We will respond to your request promptly and within one month of receipt. In complex cases, this period may be extended by up to two additional months, and we will inform you of any extension and the reasons for it.

SaferChatAI

© 2025 SaferChatAI · All rights reserved

  • Legal Notice (Impressum)
  • Privacy Policy
  • Terms of Service

SaferChatAI · Innsbruck, Austria