Legal
Privacy Policy
Summary
BastionHub is a Discord cybersecurity monitoring platform. We process Discord identifiers, server metadata, and threat detection metadata to deliver automated security monitoring for server owners.
What we collect
Discord IDs, server metadata, threat detection metadata, audit logs, billing info via Stripe
What we DON'T collect
Message bodies, passwords, payment card numbers, biometric data, DM content
Your rights
Access, delete, export, correct, restrict, object — self-service in Owner Dashboard
Where data lives
AWS US-West-2, encrypted at rest (AES-256) and in transit (TLS 1.2+)
1. Who we are
BastionHub (“we”, “us”, or “our”) is a Discord cybersecurity monitoring platform that provides automated threat detection, policy enforcement, compliance reporting, and exposure monitoring for Discord server owners. BastionHub operates as a data processor on behalf of server owners (“Customers”) who act as data controllers for their Discord community members.
BastionHub is accessible at bastionhub.io and consists of a web application (Owner Dashboard, Staff Dashboard), a Discord bot application, and server-side APIs that communicate with Discord's official APIs using OAuth2 and bot authentication.
For privacy questions or data protection requests, contact us through the Contact page or by messaging the bot directly on Discord. Do not include passwords, API keys, or other secrets in inquiries.
2. Data we process
BastionHub processes the following categories of personal data to deliver the service:
- Discord identifiers: Guild (server) IDs, user IDs, role IDs, channel IDs, and webhook IDs. These are non-reversible numeric identifiers assigned by Discord.
- Server metadata: Server names, member counts, role names, channel names, and configuration state as returned by Discord's official API.
- Threat detection metadata: Threat type (phishing, raid, bot spam, fraud, impersonation, staff privilege abuse), detection timestamp, action taken, and severity. This is metadata only — Discord message bodies, embeds, and attachments are never persisted.
- Audit log entries: Actor identity (Discord user ID and email for portal users), action type (view, export, delete, configure, verify), timestamp, target guild, and action details. Audit logs are tenant-scoped.
- Exposure monitoring findings: Breach names, breach dates, severity levels, and remediation guidance returned by Have I Been Pwned for verified domains, registered emails, and registered usernames. Individual email addresses from breach data are not stored — only breach metadata.
- Billing information: Stripe customer IDs, subscription status, plan tier, and payment events. Full payment card numbers are handled exclusively by Stripe and never touch BastionHub servers.
- Authentication data: Discord OAuth2 tokens (encrypted at rest), session cookies, and TOTP secrets for internal operator access. Passwords are never collected — BastionHub does not use password-based authentication.
- Technical data: IP addresses (for rate limiting and security alert logging), user agent strings, and request timestamps. This data is used for security monitoring and is not used for advertising or tracking.
3. Data we do NOT process or store
BastionHub is designed around data minimization. The following data is never collected, processed, or stored:
- Discord message bodies, embeds, or attachments — detection occurs in memory only
- Passwords, password hashes, or seed phrases — BastionHub does not use password authentication
- Raw webhook tokens — only webhook IDs are stored; tokens are used ephemerally and discarded
- Direct message content — except when a user directly messages the bot, in which case the message is processed in memory for the purpose of responding and is not persisted
- Payment card numbers, CVVs, or full card details — handled exclusively by Stripe
- Biometric data, health data, racial or ethnic origin, political opinions, religious beliefs, or sexual orientation
- Data from Discord servers that the bot has not been explicitly added to by the server owner
4. Legal basis for processing (GDPR Article 6)
BastionHub processes personal data under the following legal bases:
- Contract (Article 6(1)(b)): Processing Discord identifiers, server metadata, and threat detection metadata is necessary to deliver the cybersecurity monitoring service that the Customer has subscribed to.
- Legitimate interests (Article 6(1)(f)): Processing IP addresses for rate limiting, security alert logging, and fraud prevention is necessary for BastionHub's legitimate interest in protecting the service and its users from abuse and attacks.
- Legal obligation (Article 6(1)(c)): Retaining audit logs and compliance records to meet legal and regulatory obligations, including eDiscovery and litigation hold requirements.
- Consent (Article 6(1)(a)): When a server owner adds the BastionHub bot to their server via OAuth2, they consent to BastionHub processing their server's security metadata for monitoring purposes.
5. How we use your data
BastionHub uses personal data exclusively for the following purposes:
- Threat monitoring: Detecting phishing, raids, bot spam, fraud, impersonation, and staff privilege abuse in Customer Discord servers
- Policy enforcement: Applying owner-defined security policies, including AutoMod hardening, timeouts, and incident invite pauses
- Compliance and audit: Maintaining audit trails, retention controls, litigation hold, and evidence exports for eDiscovery
- Exposure monitoring: Querying Have I Been Pwned for breach intelligence tied to Customer-verified domains, emails, and usernames
- Billing and subscription management: Processing payments via Stripe, managing plan tiers, and enforcing entitlements
- Security and abuse prevention: Rate limiting, CSRF protection, tenant isolation enforcement, and security alert logging
- Service improvement: Analyzing aggregate, anonymized threat trends to improve detection rules — never individual user data
BastionHub does not use personal data for advertising, marketing, profiling, or selling to third parties. BastionHub does not train machine learning models on Discord content.
6. Subprocessors and data recipients
BastionHub engages the following subprocessors to deliver the service. Each is bound by equivalent data protection obligations. BastionHub will notify Customers at least 30 days before engaging a new subprocessor.
| Subprocessor | Purpose | DPA |
|---|---|---|
| Amazon Web Services | Cloud infrastructure and data storage (US-West-2) | AWS DPA |
| Supabase | Managed PostgreSQL database on AWS | Available on Pro tier |
| Discord Inc. | Source of Discord data via official API and OAuth2 | Discord Developer Terms |
| Stripe | Payment processing for subscription billing | Stripe DPA |
| Have I Been Pwned | Breach intelligence for exposure monitoring | HIBP API Terms |
| Vercel | Web application hosting and edge delivery | Vercel DPA |
A current list of subprocessors is maintained on our Compliance page. BastionHub does not share personal data with any other third parties.
7. International data transfers
Customer data is stored on AWS infrastructure in US-West-2 (Oregon, USA). For Customers located outside the United States (particularly EU/EEA residents), this constitutes an international transfer of personal data.
BastionHub ensures appropriate safeguards are in place through:
- Standard Contractual Clauses (SCCs) as adopted by the European Commission, where applicable
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256) for all transfers and storage
- Data Processing Agreements with subprocessors that include transfer safeguards
- EU data residency is available for Enterprise customers on request, which avoids cross-border transfers entirely
Customers who require EU-only data residency should contact BastionHub before purchasing to arrange a dedicated EU-region deployment.
8. Data retention
Retention periods are determined by the Customer's plan tier and can be adjusted by the server owner from the Owner Dashboard Settings:
| Plan | Retention period |
|---|---|
| Basic ($29.99/month) | 90 days |
| Pro ($99.99/month) | Up to 7 years (compliance archive) |
| Enterprise ($499+/month) | Contract-defined, may be unlimited |
Server owners can adjust retention periods downward and activate litigation hold from Owner Dashboard Settings. When litigation hold is active, all deletion and purge operations are paused until the hold is released by the owner.
Upon termination of the subscription, all Customer data is deleted within 30 days. The Customer can export all data via the Compliance Center before deletion. Audit logs of the deletion request are preserved for BastionHub's legal protection.
9. Security measures
BastionHub implements the following technical and organizational security measures to protect personal data:
- Encryption at rest: AES-256 managed by AWS for all stored data
- Encryption in transit: TLS 1.2+ enforced on all connections
- Tenant isolation: Every database query is scoped to the Customer's guild ID — one server cannot access another server's data
- Content-Security-Policy: Strict CSP headers on all routes preventing XSS and injection attacks
- HSTS: Strict-Transport-Security with 1-year max-age and includeSubDomains in production
- Rate limiting: All API routes enforce rate limits (10-100 requests per minute depending on sensitivity)
- CSRF protection: All mutation endpoints verify same-origin via Origin and Referer headers
- Security headers: X-Frame-Options DENY, X-Content-Type-Options nosniff, Permissions-Policy restricting camera/microphone/payment
- Access control: Server-side Prisma service role only; no browser-side database access; secrets never in frontend bundles
- Authentication: Discord OAuth2 for Owner and Staff Dashboards; TOTP-based MFA for internal operator access
- Audit logging: All significant actions (view, export, delete, configure, verify) logged with actor, timestamp, guild, and action type
- Security alerts: Automated detection of rate limit violations, CSRF failures, tenant isolation violations, and privilege escalation attempts
- Incident response: Documented 7-phase incident response plan — see Incident Response Plan
- Secrets management: API keys and secrets stored in environment variables, never committed to git or exposed to the frontend
- Fail-closed architecture: If authorization or verification fails, operations do not execute
10. Breach notification
BastionHub operates automated breach detection. Security events (rate limit violations, CSRF failures, tenant isolation violations, privilege escalation attempts) are logged to the audit trail immediately when they occur.
The Owner Dashboard exposure monitoring page displays a live green-light indicator showing the connection status to the breach intelligence provider (Have I Been Pwned), refreshed hourly.
In the event of a confirmed personal data breach, BastionHub will notify affected Customers as soon as practically possible after confirmation, including the nature of the breach, the data categories affected, the likely consequences, and the measures taken. For GDPR Article 33 compliance, BastionHub will notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach. BastionHub's automated detection ensures awareness happens quickly, not days later.
Full breach response procedures are documented in the Incident Response Plan.
11. CCPA / CPRA — California Consumer Privacy Act
BastionHub does not sell personal information to third parties, ever. Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), you have the right to opt out of any sale of your personal information. Because BastionHub does not engage in any sale or sharing of personal data, no opt-out is necessary — but this notice is provided to comply with CCPA disclosure requirements.
California residents have the following rights under CCPA/CPRA:
- Right to know: What personal data is collected, how it is used, and who it is shared with
- Right to delete: Request deletion of your personal data held by BastionHub
- Right to correct: Request correction of inaccurate personal data
- Right to opt-out of sale or sharing: BastionHub does not sell or share personal data, so this right is automatically satisfied
- Right to limit use of sensitive personal information: BastionHub does not collect sensitive personal information as defined by CPRA
- Right to non-discrimination: BastionHub will not discriminate against you for exercising your privacy rights
To exercise your CCPA/CPRA rights, server owners can use the Data Privacy & Deletion controls in Owner Dashboard Settings, or contact us through the Contact page. Requests are processed within 45 days, with a possible 45-day extension for complex requests.
If you are a Discord user (not the server owner) whose data appears in BastionHub threat metadata, you can submit a data subject request directly using our Data Subject Request form. You will need your Discord user ID and the server ID where your data appears. The server owner reviews each request and approves or denies it.
12. GDPR — Rights of EU and UK residents
Under the General Data Protection Regulation (GDPR) and the UK GDPR, EU and UK residents have the following rights regarding their personal data:
- Right of access (Article 15): Request a copy of your personal data held by BastionHub
- Right to rectification (Article 16): Request correction of inaccurate or incomplete personal data
- Right to erasure (Article 17): Request deletion of your personal data. Server owners can use the Delete all server data button in Owner Dashboard Settings to permanently remove all BastionHub data for their server.
- Right to restrict processing (Article 18): Request that BastionHub limit processing of your data in certain circumstances
- Right to data portability (Article 20): Receive your personal data in a structured, machine-readable format. The Compliance Center provides CSV and JSON export.
- Right to object (Article 21): Object to processing based on legitimate interests.
- Right to withdraw consent (Article 7): Withdraw consent for processing that was based on consent. Server owners can remove the BastionHub bot from their server at any time via Discord.
- Right to lodge a complaint (Article 77): You have the right to lodge a complaint with your local supervisory authority.
Litigation hold may pause deletion when legal action is pending. To exercise any of these rights, contact us through the Contact page or use the self-service controls in Owner Dashboard Settings. Requests are processed within 30 days.
13. Children's privacy
Discord requires users to be at least 13 years old (or the age of digital consent in their jurisdiction). BastionHub does not knowingly process personal data from children under 13. If BastionHub becomes aware that it has processed personal data from a child under 13, it will take steps to delete that data promptly.
BastionHub does not direct its services at children and does not use age-based targeting or profiling.
15. Automated decision-making
BastionHub uses automated processing for threat detection (classifying messages and events as phishing, raid, bot spam, etc.) and for security alert generation. These automated decisions do not produce legal or similarly significant effects on individuals.
Threat detection actions (such as timeouts or AutoMod hardening) are policy-based responses to security threats and are configured by the server owner. BastionHub does not make automated decisions about individuals' eligibility for services, credit, employment, or other legally significant matters.
Under GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. BastionHub's automated processing does not meet this threshold.
16. Data Processing Agreement (DPA)
A Data Processing Agreement is available for Pro and Enterprise customers. The DPA defines BastionHub as a data processor, the Customer as a data controller, and outlines subprocessor obligations, security measures, breach notification procedures, and audit rights. View the DPA.
17. Changes to this privacy policy
BastionHub may update this Privacy Policy from time to time. When we do, we will:
- Update the "Last updated" date at the top of this page
- Provide a summary of material changes
- Notify existing Customers via the Owner Dashboard or email for significant changes
- Provide at least 30 days' notice before changes take effect for material changes
Continued use of BastionHub after the effective date of any changes constitutes acceptance of the updated Privacy Policy.
18. Contact
For privacy questions, data protection requests, or to exercise your rights under GDPR, CCPA/CPRA, or other applicable privacy laws, contact BastionHub through:
- The Contact page on our website
- Direct message to the BastionHub bot on Discord
- The self-service controls in Owner Dashboard Settings
Do not include passwords, API keys, Discord tokens, or other secrets in any inquiry. BastionHub will never ask you for your password or Discord login credentials.