PRISTINE

Pristine Privacy Policy

Effective date: 3 October 2026

Contact

This policy describes information handled by the Pristine website and bot. Privacy questions, access requests, corrections, and deletion requests: vexithespindex@gmail.com. Include your Discord user ID and relevant server ID so records can be located. We may need to verify your request before acting on it.

Website and manager sign-in

Manager sign-in uses Discord authorization. Pristine receives your Discord ID, display name, and avatar. An encrypted browser cookie keeps you signed in for up to 12 hours. The website is hosted by Cloudflare. Discord’s manager access token is used temporarily to retrieve your profile and is not saved in that browser cookie. Pristine does not receive your Discord password. The private website owner panel uses a separate email and password login. A salted password verifier and separate secret pepper are held in the hosting service’s protected configuration. The application does not store the owner password in website source or browser storage. An encrypted owner session cookie expires after two hours. Login attempts are limited using short-lived counters and hashed connection identifiers in the website database; these counters expire after 15 minutes and are cleaned up during later login requests. The database also stores website content, configuration, public server listings, document text, edit revision, update time, and the owner editor identifier. Every owner settings request is checked on the server.

Member verification

Member verification requests Discord’s identify and guilds.join scopes. These identify your account and permit Pristine to rejoin you to the same server shown in the consent flow. After confirming membership and assigning the configured role, the bot records the account ID, name, selected server ID, consent time, authorization tokens, token expiry, and scope. Records without matching website consent are excluded from website restoration. Authorization tokens are handled on the website server and bot host; they are not placed in browser result cookies or returned in dashboard responses. The current supplied bot stores its token records in host data files without application-level encryption. The host must be protected against unauthorized access.

Bot information and enabled features

Depending on the features enabled by a server, Pristine processes user, server, channel, role, and message IDs; timestamps; message content; settings; moderation records; ticket messages and transcripts; activity or staff statistics; and relevant attachments or links. Bot data can be saved in host data files, logs, transcripts, exports, saves, and backups. Authorized server staff can access records permitted by their roles. If external AI moderation or ticket review is enabled, relevant content may be sent to the configured provider, including Google Gemini where configured. Enabled providers depend on the operator’s bot setup. Server owners may connect their own Gemini moderation API key. That key is encrypted on the bot host, excluded from dashboard responses, and removable by the server owner. Enabling this integration sends moderated message text to Gemini. Removing the key stops future Gemini moderation requests; bot backups may retain older encrypted records.

Why information is used

Information supports authentication, access checks, server settings, enabled bot functions, member verification, consented same-server restoration, support, and diagnosing service problems. Public directory listings are visible to visitors; private management server lists and member authorization records are not published in the directory.

Other services

Discord processes authorization and API requests. Website and bot hosting providers process information needed to operate their services and may keep their own security logs. Loading Discord avatars/icons or externally hosted media sends ordinary connection information, such as an IP address and browser details, to those media providers. The legacy guide also loads Google Fonts. Pristine’s application currently has no advertising or analytics tracking integration. Providers have their own policies and practices.

Retention and controls

Website cookie limits are listed in the Cookie Policy. Bot token records, transcripts, exports, logs, and backups do not currently share an automatic deletion schedule; deletion requires operator action. Website content remains until the website owner changes or removes it. Contact the privacy email to request deletion or discuss records and backups associated with your account. Any retention that remains necessary will be explained when handling a request. You can clear website cookies, disconnect the manager session, or deauthorize Pristine in Discord’s Authorized Apps settings to prevent future use of member authorization. Revocation does not itself erase saved bot records. You can also ask your server owner about that server’s enabled features and saved records.