Legal
Terms of Service
1. Acceptance of terms
These Terms of Service (“Terms”) govern your access to and use of the BastionHub website, Discord bot application, Owner Dashboard, Staff Dashboard, and all related services (collectively, the “Service”). The Service is operated by BastionHub (“we”, “us”, or “our”).
By adding the BastionHub bot to your Discord server, signing in to the Owner Dashboard or Staff Dashboard, or using any part of the Service, you agree to be bound by these Terms. If you do not agree to these Terms, do not use the Service.
If you are using the Service on behalf of an organization, you represent and warrant that you have the authority to bind that organization to these Terms, and references to "you" and "Customer" apply to both you and that organization.
2. Eligibility
You must meet the following eligibility requirements to use the Service:
- You must be at least 13 years old (or the age of digital consent in your jurisdiction)
- You must have a valid Discord account in good standing
- You must be the owner of the Discord server to use Owner Dashboard features, or an authorized staff member for Staff Dashboard features
- You must not be prohibited from using the Service under applicable law or Discord's Terms of Service
BastionHub relies on Discord OAuth2 for identity verification. Owner authority is derived from Discord server ownership, mapped by stable Discord IDs — not from a role name inside BastionHub.
3. The Service
BastionHub provides automated Discord cybersecurity monitoring and a security/management control plane. The Service includes:
- Threat monitoring: Detection of phishing, raids, bot spam, fraud, impersonation, and staff privilege abuse in your Discord server
- Policy enforcement: Owner-defined security policies including AutoMod hardening, timeouts, and incident invite pauses
- Exposure monitoring: Breach intelligence from Have I Been Pwned for verified domains, registered emails, and usernames (Pro and above)
- Compliance and audit: Audit trails, retention controls, litigation hold, and evidence exports for eDiscovery (Pro and above)
- Server Redesign: Owner-only workspace for restructuring Discord server roles, categories, and channels (Pro and above)
- Owner Dashboard: Web-based dashboard for server owners to manage monitoring, compliance, billing, and configuration
- Staff Dashboard: Role-mapped access for authorized staff to view monitoring data and take approved actions
Discord remains the live infrastructure for Discord objects. BastionHub is the source of truth for policy, approvals, audit, and entitlements — never a silent override of Discord authority. The Service cannot grant more authority than Discord permits for the acting bot or user context.
4. Subscription plans and pricing
BastionHub offers the following subscription plans:
| Plan | Price | Scope |
|---|---|---|
| Basic | $29.99/month | One server under 500 members. Core security monitoring, 90-day retention, automated threat detection. |
| Pro | $99.99/month | One server under 500 members. Advanced privilege monitoring, exposure monitoring, evidence/archive, Server Redesign included, up to 7-year retention. |
| Enterprise | $499+/month | Multiple verified server seats, contract-defined capabilities, EU data residency, custom retention, custom DPA and SLA. |
| Standalone Server Redesign | $49.99 one-time | Single Server Redesign engagement. Included in Pro and Enterprise. |
All prices are in USD. BastionHub reserves the right to change pricing with at least 30 days' notice to existing Customers. Existing subscriptions will continue at the originally agreed price until the next renewal date.
Plan entitlements are enforced server-side based on verified billing state. Browser-side claims of payment are not sufficient to grant entitlements. Payment truth is established by verified Stripe webhooks.
5. Payment and billing
Subscriptions are billed monthly through Stripe. By subscribing to a paid plan, you authorize BastionHub to charge the subscription fee to your designated payment method on a recurring basis until you cancel.
- Payment processing: All payment card data is handled exclusively by Stripe. BastionHub never receives, stores, or processes full card numbers, CVVs, or expiration dates.
- Billing cycle: Subscriptions renew automatically on the same date each month as the original purchase.
- Failed payments: If a payment fails, BastionHub will retry per Stripe's smart retry logic. If payment cannot be collected after 3 attempts over 15 days, the subscription will be downgraded to a limited state and entitlements will be suspended.
- Taxes: You are responsible for any applicable taxes (VAT, GST, sales tax) in your jurisdiction. BastionHub may add tax to your invoice based on your billing address.
- Price changes: BastionHub will notify you at least 30 days before any price increase takes effect. You may cancel before the new price takes effect.
6. Free trial
BastionHub may offer a free trial period for new Customers. Trial terms:
- Trial duration is 14 days from the date of signup
- Trial access includes the features of the trial plan tier, subject to the same usage limits as paid subscriptions
- A valid payment method is required to start a trial. You will be charged automatically when the trial ends unless you cancel before then
- Trials are limited to one per Discord server. A server that has previously used a trial or held a paid subscription is not eligible for another trial
- At the end of the trial period, the subscription automatically converts to a paid plan unless you cancel before the trial expires
- BastionHub reserves the right to modify or discontinue trial offerings at any time
7. Refunds and cancellations
Cancellation: You may cancel your subscription at any time from the Owner Dashboard Billing page. Cancellation takes effect at the end of the current billing period. You will retain access to the Service until the end of the period you have paid for.
Refunds: Subscription fees are non-refundable except in the following circumstances:
- If BastionHub fails to provide the Service for more than 24 consecutive hours due to our own infrastructure failure, you may request a pro-rated refund for the affected period
- If you were charged in error (duplicate charge, billing bug), contact us within 60 days for a full refund of the erroneous charge
- EU consumers have a 14-day right of withdrawal under EU consumer protection law. Contact us within 14 days of purchase to exercise this right
Standalone Server Redesign purchases ($49.99 one-time) are non-refundable once the Server Redesign has been executed. If the Server Redesign has not been executed, you may request a full refund within 30 days of purchase.
8. Acceptable use policy
You agree not to use the Service to:
- Violate Discord's Terms of Service, Developer Policy, or Community Guidelines
- Violate any applicable law or regulation
- Infringe the intellectual property rights, privacy, or other rights of any person
- Attempt to gain unauthorized access to another Customer's data, the Service's internal systems, or Discord's APIs
- Use the Service to surveil, harass, or discriminate against Discord users
- Reverse engineer, decompile, or disassemble the Service (except to the extent permitted by applicable law)
- Resell, sublicense, or redistribute access to the Service without written authorization
- Attempt to bypass billing, entitlement, or rate limit controls
- Use the Service to process data from Discord servers that the bot has not been explicitly added to by the server owner
- Use the bot to read or store Discord direct message content, except when a user directly messages the bot
Violation of this Acceptable Use Policy may result in suspension or termination of your account, removal of the bot from your server, and forfeiture of any prepaid fees.
9. Discord terms compliance
BastionHub operates exclusively through Discord's official API and OAuth2. The Service does not use user tokens, self-bots, or unofficial clients. BastionHub requests Discord Administrator at install so every advertised feature executes without permission gaps. BastionHub does not grant Administrator to members through the Service.
You acknowledge that:
- Discord is a trademark of Discord Inc. BastionHub is not affiliated with, endorsed by, or sponsored by Discord
- BastionHub cannot grant more authority than Discord permits for the acting bot or user context
- BastionHub's capabilities may only restrict Discord, never expand it
- If Discord changes its API, permissions, or policies, BastionHub's functionality may be affected without prior notice
- You are responsible for ensuring your use of BastionHub complies with Discord's Terms of Service and Developer Policy at all times
10. Intellectual property rights
BastionHub's IP: The Service, including the website, bot application, software, design, text, graphics, and code, is owned by BastionHub and protected by intellectual property laws. You may not copy, modify, distribute, or create derivative works from the Service without written authorization.
Your data: You retain all rights to your Discord server data. BastionHub processes your data only as necessary to provide the Service, as described in the Privacy Policy and Data Processing Agreement. Upon termination, you can export all your data, and BastionHub will delete it within 30 days.
Feedback: If you provide feedback, feature requests, or suggestions about the Service, BastionHub may use them without any obligation to you.
11. Disclaimers
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
BastionHub does not guarantee that:
- The Service will detect every security threat or prevent every attack on your Discord server
- The Service will be uninterrupted, error-free, or secure at all times
- Exposure monitoring will identify every breach affecting your domain, email, or username (HIBP's database is comprehensive but not exhaustive)
- Discord's API will remain available or unchanged (BastionHub depends on Discord's infrastructure)
- The Service will meet your specific compliance or regulatory requirements without additional configuration
You are responsible for configuring the Service appropriately for your server's needs, including setting retention periods, defining security policies, and enabling exposure monitoring for your domains.
Third-party bots and integrations: BastionHub operates alongside any other bots, applications, and integrations you choose to install on your Discord server. BastionHub does not control, audit, or guarantee the behavior of third-party software. Actions taken by other bots, integrations, or administrators — including changes to roles, channels, permissions, AutoMod rules, invites, or server settings — can alter, impair, or override what the Service detects, enforces, or reports. BastionHub is not responsible for the acts, omissions, security practices, or data handling of third-party software, and you are responsible for vetting anything else you install on your server.
12. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL BASTIONHUB BE LIABLE FOR:
- Indirect, incidental, special, consequential, or punitive damages
- Loss of profits, data, business, or goodwill
- Damages resulting from Discord's actions, API changes, or service interruptions
- Damages resulting from your failure to properly configure the Service
- Damages resulting from security incidents on your Discord server that the Service did not detect or prevent
- Damages resulting from third-party bots, applications, or integrations installed on your Discord server — including interference with, alteration of, or disruption to the Service's monitoring, detection, or enforcement, and any data exposure, leak, or loss caused by such third-party software
BastionHub's total aggregate liability arising from or relating to these Terms or the Service shall not exceed the amount you paid to BastionHub in the 12 months preceding the claim.
The following are excluded from the liability cap:
- BastionHub's indemnification obligations under Section 13
- Breach of confidentiality obligations
- Willful misconduct or fraud
- Death or personal injury caused by negligence (where applicable by law)
For Enterprise customers with a custom contract, the liability terms in the signed contract supersede this section.
13. Indemnification
You indemnify BastionHub: You agree to indemnify and hold harmless BastionHub from and against any claims, damages, losses, and expenses (including reasonable attorneys' fees) arising from:
- Your use of the Service in violation of these Terms
- Your violation of applicable law or third-party rights
- Your violation of Discord's Terms of Service or Developer Policy
- Content or data you process through the Service
- Your failure to properly configure security policies or retention settings
BastionHub indemnifies you: BastionHub will indemnify and hold you harmless from claims that the Service infringes a third party's intellectual property rights, subject to the limitation of liability in Section 12.
14. Termination
Termination by you: You may terminate your subscription at any time by canceling from the Owner Dashboard Billing page or by removing the BastionHub bot from your Discord server. Upon termination:
- Your subscription remains active until the end of the current billing period
- You can export all your data via the Compliance Center
- BastionHub will delete all your data within 30 days of termination, unless a longer retention period is required by law
- Audit logs of the deletion are preserved for BastionHub's legal protection
Termination by BastionHub: BastionHub may suspend or terminate your access to the Service if:
- You violate these Terms or the Acceptable Use Policy
- Your Discord account is terminated or suspended by Discord
- Your payment fails and cannot be collected after 3 attempts
- BastionHub is required to do so by law or legal process
- BastionHub discontinues the Service entirely (with at least 60 days' notice and pro-rated refund)
Upon termination by BastionHub for cause (violation of Terms), no refund is provided. Upon termination by BastionHub for convenience (discontinuation of Service), a pro-rated refund of prepaid fees is provided.
15. Dispute resolution
Informal resolution: Before filing a claim, you agree to attempt to resolve the dispute informally by contacting BastionHub through the Contact page. BastionHub will respond within 30 days.
Binding arbitration: If the dispute cannot be resolved informally, you and BastionHub agree to resolve the dispute through binding arbitration administered by the American Arbitration Association (AAA) under its Commercial Arbitration Rules. The arbitration will be conducted in the United States. Judgment on the award may be entered in any court having jurisdiction.
Class action waiver: You and BastionHub agree that each party may bring claims against the other only in an individual capacity, and not as a plaintiff or class member in any purported class, consolidated, or representative proceeding.
Opt-out: You may opt out of binding arbitration by sending written notice to BastionHub within 30 days of first accepting these Terms. If you opt out, disputes will be resolved in the courts described in Section 16.
Small claims court: Either party may bring a claim in small claims court if the amount is within the court's jurisdiction, regardless of the arbitration provision.
16. Governing law and jurisdiction
These Terms are governed by the laws of the United States and the state in which BastionHub is registered, without regard to conflict of law principles. For disputes not subject to binding arbitration under Section 15, the parties submit to the exclusive jurisdiction of the state and federal courts located in that state.
For Customers located outside the United States, BastionHub will make reasonable efforts to resolve disputes in the Customer's jurisdiction where possible, but these Terms remain governed by US law.
17. Changes to these Terms
BastionHub may update these Terms from time to time. When we do, we will:
- Update the "Effective date" at the top of this page
- Provide a summary of material changes on this page
- Notify existing Customers via the Owner Dashboard or email for significant changes
- Provide at least 30 days' notice before material changes take effect
Continued use of the Service after the effective date of any changes constitutes acceptance of the updated Terms. If you do not agree to the updated Terms, you may cancel your subscription as described in Section 14.
18. Privacy and data processing
Your use of the Service is also governed by our Privacy Policy, which describes how we collect, use, and protect your data. For Pro and Enterprise customers, a Data Processing Agreement is available.
19. Severability
If any provision of these Terms is found to be unenforceable or invalid by a court or arbitrator, that provision will be limited or eliminated to the minimum extent necessary, and the remaining provisions will remain in full force and effect.
20. Entire agreement
These Terms, together with the Privacy Policy, Data Processing Agreement (if applicable), and any signed contract for Enterprise customers, constitute the entire agreement between you and BastionHub regarding the Service and supersede all prior or contemporaneous agreements, communications, and understandings.
21. Contact
For questions about these Terms, contact BastionHub through:
- The Contact page on our website
- Direct message to the BastionHub bot on Discord
Do not include passwords, API keys, Discord tokens, or other secrets in any inquiry. BastionHub will never ask you for your password or Discord login credentials.