Report Tool · Policies

Privacy Policy

How Report Tool processes reported messages, nearby context, AI assessments, and moderation records.

Effective & updated: 10 September 2026Version 1.0

At a glance: Report Tool sends reported content and nearby context to OpenAI. Reports identify the reporter and message author. Automatic warnings and timeouts may occur.

1. Scope and operator

This policy covers Report Tool, its related support, and these documentation pages. AndWhatNot Studio operates the application and is responsible for its processing described here. Contact: admin@andwhatnotstudio.com. Discord and server administrators have separate responsibilities for their platforms, communities, and copies of content.

2. Information processed and its sources

Information comes from your report command, Discord’s APIs, and the AI service. It can concern both the reporting member and people whose messages appear in the retrieved context.

3. How information is used

We use this information to route reports, explain their context, assess proposed actions, let moderators review the case, execute enabled moderation actions, and investigate errors or misuse.

We do not sell personal information, disclose Discord data to advertisers or data brokers, or use Discord message content to train our own AI models.

4. Automated assessments and actions

The current configuration permits an automatic public warning or 60-minute timeout after an approving second AI review and the configured confidence checks. Kicks, softbans, and bans are disabled. AI may make incorrect inferences about messages. Affected members can request human review from server moderators and raise concerns with AndWhatNot Studio.

5. Recipients and service providers

Authorized operators and hosting or infrastructure providers may access information needed to run, secure, and support the application. Information may also be disclosed where required by law or necessary to investigate abuse and protect rights. External services apply their own terms and data controls.

6. Storage, retention, and deletion

The bot does not maintain its own report database or general archive of channel history. Retrieved context is assembled for processing in memory. The report and action information posted in Discord persist until deleted by someone with permission or handled under Discord’s policies; the bot does not apply a scheduled report expiry.

Operational logs can contain identifiers, request and error details, and action outcomes. OpenAI’s retention is separate and depends on its API endpoint and applicable account data controls. Deleting a source message does not automatically delete a previously posted report or a provider-held copy.

Support correspondence and operational records may be retained to resolve requests, investigate failures or abuse, and meet legal obligations. We assess deletion requests against these purposes and any applicable retention requirements. Existing backups and provider-held records may require separate deletion or expiry; we do not promise immediate removal of copies outside our control.

8. Your choices and rights

Contact your server moderators for a correction, removal of a report, or human review of a warning or timeout. You can ask administrators to restrict the bot’s channel access. Not invoking /report does not prevent your messages from being included when someone else reports nearby content.

Depending on your location and the circumstances, you may request access, correction, deletion, restriction, or portability, object to processing, withdraw consent where processing relies on it, or complain to a data-protection authority. Send requests to admin@andwhatnotstudio.com, identifying the bot, your Discord user ID, and the relevant message, channel, clip, or stored fact. We may need reasonable verification; do not send passwords or account tokens.

9. Security and international processing

We use restricted service credentials and access controls to protect the service. No online system can guarantee complete security. Discord, service providers, and infrastructure may process information outside your country. Where data-protection law requires safeguards for international transfers, the relevant processing must use a lawful transfer mechanism. Contact us for information about the arrangements applicable to your data.

10. Documentation website

These documentation pages do not set tracking cookies, load analytics scripts, or require a login. The web server may log technical request information such as IP address, requested page, browser information, and time for delivery, security, and troubleshooting. Following an external link brings you under that destination’s own policies.

11. Children

The application is not directed to children under 13 or anyone below Discord’s minimum age in their country. Contact us if you believe a child’s information has been processed inappropriately.

12. Updates and contact

We may update this policy when features, data practices, or applicable requirements change. The date above identifies this version. Material changes will be communicated through an appropriate service channel where practical. Questions, requests, and complaints: admin@andwhatnotstudio.com.