1. Scope and responsibility
This Privacy Policy applies to the Horizon Management website, Discord sign-in, account setup, dashboard, server configuration pages, blogs and update notices, the connected X Systems Discord bot, and features operated through those services. In this policy, all of these are called the Service.
X Systems, a business registered in the Netherlands, operates the Service and is responsible for the account, website, infrastructure, and product data described here.
Discord server owners and administrators also make decisions about how the bot is configured inside their communities. They choose which features are enabled, which channels and roles are used, who can view records, whether ticket transcripts are created, and how long content remains in Discord. A server owner may therefore have separate responsibilities toward its members under privacy law and Discord's rules.
Plain-language summary: we do not sell personal information. We use information to operate the bot and dashboard, protect accounts and servers, provide enabled features, and respond to support or legal requests.
2. Information we process
Discord account and sign-in information
When you sign in using Discord OAuth, the dashboard requests the identify and guilds scopes. Depending on what Discord returns, we process your Discord user ID, username, global display name, discriminator where applicable, avatar, and a list of servers associated with your account. For each returned server, we may receive the server ID, name, icon, whether you own it, and your Discord permission value.
The OAuth access token is used during sign-in to request your account and server list from Discord. The current dashboard implementation does not place that Discord access token in your long-term dashboard profile. It creates a separate signed session identifier after sign-in.
Dashboard account and profile information
We store account and profile information such as your Discord ID, current Discord name and avatar URL, first and last login times, login count, signup IP address, recent login IP addresses, browser user agent, preferred-name requests, review status and reasons, notification choices, onboarding progress, legal acceptance version and time, and a limited history of profile preference changes.
Server configuration and feature records
Depending on the features a server enables, the bot may process or store server IDs, channel IDs, role IDs, member IDs, message IDs, configured text, permissions, command settings, moderation and infraction records, automod actions, ticket metadata, staff shifts, activity waves, session polls and logs, in-game or ER:LC records, verification records, welcome settings, leveling and economy records, giveaways, suggestions, feedback, counting data, sticky messages, anti-ping settings, promotions, event logs, and similar operational records.
The bot may receive Discord message content where Discord permissions and enabled features require it, for example to respond in AI tickets, run automod, maintain counting channels, process configured commands, or operate other message-based features. The bot does not need every message for every feature; processing depends on the feature and server configuration.
Technical, security, and support information
We process technical information such as IP addresses, user-agent strings, timestamps, signed session IDs, OAuth state values, CSRF tokens, request details, rate-limit activity, errors, bot API responses, login events, account bans, IP bans, session revocations, and administrative actions. Support messages and information voluntarily submitted in tickets may also be processed.
Public and third-party information
When a configured feature needs it, the Service may request public or authorized information from Discord, Roblox, ER:LC/PRC services, or other integrated services. This can include Roblox user details, server status, command logs, or related identifiers needed to perform the requested integration.
3. How the AI ticket system uses messages
Server administrators can enable an AI-assisted ticket system. When it is enabled, the bot can read messages in the relevant ticket channel and send limited ticket context to the OpenAI API so it can draft a support response or summary.
Information sent for an AI reply
For a normal AI reply, the current bot can send:
- the current message text, limited by the bot before submission;
- up to ten recent readable ticket messages selected from the recent channel history;
- attachment names shown in that recent history;
- the ticket opener ID, current user's display name and Discord ID;
- server information and support instructions configured by server administrators, including server name, owner name, server description, common support topics, extra setup information, and administrator-written training notes; and
- one image attachment when supplied, provided it is within the bot's size limit. The image is encoded for the request and sent to the AI provider for analysis.
Administrator-written “training” notes are prompt instructions used as context for that request. They do not create or retrain a private machine-learning model.
Ticket closing, transcripts, and summaries
When a ticket is closed, the bot can read the full ticket channel to build a text transcript. The transcript may include message timestamps, author names and IDs, message text, and attachment filenames. The current bot can send the most recent portion of that transcript to OpenAI to generate a short closing summary.
If the server configured a transcript channel, the full transcript file and summary may be posted there. The bot can also attempt to send the transcript and summary to the ticket opener by Discord direct message. Those copies are then stored within Discord until deleted under the server's or user's Discord settings.
OpenAI processing
OpenAI acts as a service provider for AI replies and summaries. OpenAI's current API data controls state that API data is not used to train its models by default unless the customer explicitly opts in, and that abuse-monitoring logs may be retained for up to 30 days unless a different approved control or a legal requirement applies. Provider practices can change, so you can review OpenAI's current API data controls.
Do not place passwords, authentication tokens, payment card details, government identification numbers, medical records, or other unnecessary sensitive information in an AI-assisted ticket. AI-generated replies can be incomplete or wrong and should not be treated as legal, medical, financial, emergency, or professional advice. Users can request human staff where the server supports escalation.
4. API keys, credentials, and sensitive configuration
Some integrations require a server administrator to provide a credential, such as an ER:LC private-server API key. The current bot treats the ER:LC API key as a sensitive setting.
- The key is hidden after it is saved and is not returned in normal dashboard configuration responses.
- Audit records use a redacted value instead of storing the key in readable audit history.
- The database stores the key as authenticated ciphertext rather than plain text.
- The encryption system uses a 256-bit master key, derives separate encryption and authentication keys using HMAC-SHA256, uses a fresh random 128-bit nonce, and verifies an HMAC-SHA256 authentication tag before decryption.
- When a locally generated master-key file is used, the bot attempts to create it separately from the database with owner-only file permissions.
- The key is decrypted in application memory only when the integration needs to make an authorized request.
Accuracy note: this implementation is 256-bit authenticated encryption, but the uploaded bot code does not use the AES algorithm. We therefore do not describe it as “AES-256.”
Other operator credentials, such as the Discord client secret, dashboard API token, OpenAI API key, session secret, and optional global ER:LC key, are loaded from server-side environment configuration. They are not intended to be exposed through the public dashboard.
5. Why we use information
We use information to:
- authenticate users with Discord and maintain dashboard sessions;
- show servers the signed-in user can access and enforce server, role, and owner permissions;
- save settings and operate the features enabled by a server;
- provide moderation, logging, ticketing, staff, session, verification, notification, and integration functions;
- generate requested AI-assisted ticket replies and summaries;
- send optional blog and product-update direct messages based on profile choices;
- review preferred-name requests and administer accounts;
- detect fraud, abuse, unauthorized access, spam, malicious activity, and attempts to bypass restrictions;
- diagnose failures, maintain reliability, enforce these Terms, and protect users and infrastructure; and
- comply with applicable law, preserve evidence, and respond to lawful requests.
6. Legal bases for processing
Where the GDPR or similar laws apply, we rely on one or more of the following legal bases:
- Contract: processing needed to provide the Service you or a server administrator requested, including account access, bot functions, settings, and support.
- Legitimate interests: operating and securing the Service, preventing abuse, enforcing permissions, keeping limited audit history, troubleshooting, and improving reliability. We consider the impact on users before relying on this basis.
- Consent: optional direct messages for product updates or blogs, where consent is required. You can change these choices in your profile.
- Legal obligation: processing needed to comply with law, accounting requirements, court orders, or lawful authority requests.
- Protection of rights and safety: processing reasonably necessary to establish, exercise, or defend legal claims or protect users, the public, or the Service.
The AI ticket system is used to assist communication. It is not intended to make decisions that produce legal effects or similarly significant effects on a person. Account bans, nickname reviews, moderation decisions, and other consequential actions remain subject to human or server-admin control.
7. Storage and retention
The dashboard currently stores account, profile, session, legal-acceptance, account-control, and blog/update data in server-side files. The bot stores configuration and operational records in a SQLite database. Discord stores the messages, channels, direct messages, and transcript copies created on Discord.
We keep information only for as long as reasonably needed for the purpose it was collected, subject to server configuration, legal obligations, security needs, and technical limitations. The current implementation includes the following limits or practices:
| Data | Current practice |
|---|---|
| Dashboard sessions | Normally expire after 14 days unless the operator changes the configured session duration. Expired sessions are removed from the active session store. |
| Login history | The account record keeps up to the 25 most recent login IP and user-agent entries, plus signup and last-login information. |
| Profile preference history | Limited to the 100 most recent profile log entries. |
| Administrative control history | Limited to the 250 most recent account-control actions in the current dashboard store. |
| Bot configuration audit values | By default, audit rows are limited to 5,000 per server and a maximum age of 14 days. Sensitive values such as ER:LC API keys are redacted. |
| AI ticket metadata | Ticket IDs, server/channel/user IDs, status, claim/escalation state, timestamps, and AI reply count remain in the bot database until deleted through maintenance, account/server removal, or another applicable cleanup process. The current uploaded version does not define an automatic expiry for these rows. |
| Ticket messages and transcripts | Original messages remain in Discord according to Discord and server settings. Transcript files or summaries posted to a transcript channel or sent by DM remain there until deleted by an authorized Discord user or Discord. |
| OpenAI API request data | Handled under OpenAI's then-current API data controls. OpenAI currently states that abuse-monitoring logs may be kept for up to 30 days by default, subject to exceptions. |
| Account and legal records | Kept while the account is active and afterward where reasonably necessary for security, disputes, legal compliance, or ban enforcement. A deletion action removes the main user, profile, legal-acceptance, and active-session records but may retain a limited deletion or security record. |
| Application and error logs | Kept for operational, security, and troubleshooting needs and removed or rotated when no longer reasonably needed. A single fixed retention period is not guaranteed. |
Server owners may retain records independently in Discord channels, external logs, screenshots, exports, or other tools. Requests concerning those independent copies should also be directed to the relevant server owner.
9. Service providers and international processing
We disclose information only where needed to operate the Service, follow your or a server administrator's instructions, protect the Service, or comply with law. Relevant providers and platforms can include:
- Discord: account authentication, server and permission information, bot commands, messages, channels, direct messages, attachments, and transcripts;
- OpenAI: AI-assisted ticket replies and ticket-closing summaries;
- X Systems Hosting and infrastructure providers: hosting, storage, networking, logs, backups where configured, and security operations;
- Roblox and ER:LC/PRC services: information needed for server, user, command, verification, or logging integrations when enabled; and
- professional advisers or authorities: where reasonably necessary for legal advice, claims, investigations, safety, or compliance with lawful requests.
We do not sell personal information and do not provide it to advertising partners for targeted advertising.
Some providers may process information outside the European Economic Area. Where required, we rely on applicable transfer mechanisms, contractual safeguards, adequacy decisions, or the provider's lawful transfer framework.
10. Who can see server and account records
Access depends on the record and configured permissions. X Systems personnel with a genuine operational, security, support, or legal need may access relevant account and system information. Server owners and roles authorized by the server may access settings, moderation records, staff records, tickets, transcripts, logs, and management pages made available to them.
Users in the same Discord server may see content posted in channels they can access. A ticket opener may receive a transcript by DM. Staff may receive ticket summaries or logs. Public blog and update posts are visible to website visitors. Preferred names accepted for display may appear alongside a Discord identity.
11. Security measures
We use technical and organizational safeguards intended to reduce unauthorized access, misuse, alteration, or loss. Current safeguards include signed random session identifiers, server-side sessions, HttpOnly and SameSite cookies, Secure cookies over HTTPS, OAuth state verification, CSRF protection, permission and role checks, site-owner controls, timing-safe signature comparisons, rate controls, restricted dashboard routes, audit records, secret redaction, and authenticated encryption for the stored ER:LC API key.
Security also depends on correct deployment. Operators must keep environment secrets private, use HTTPS, restrict access to the database and key files, patch dependencies, limit administrator accounts, and rotate credentials when exposure is suspected.
No internet service can guarantee complete security. You are responsible for protecting your Discord account, devices, server roles, API keys, and any content you submit. Report suspected compromise promptly and rotate affected credentials.
12. Your choices and privacy rights
You can change optional blog and product-update DM choices in your dashboard profile. You can also request correction or removal of a preferred name through available profile or support controls.
Depending on your location and the circumstances, you may have the right to be informed, access your personal data, correct inaccurate data, request deletion, restrict processing, receive portable data, object to certain processing, withdraw consent, and complain to a data protection authority. These rights are not absolute; for example, we may retain limited information where required by law, needed to protect other people, or necessary for legal claims and security enforcement.
We may ask for reasonable verification before acting on a request, especially where the request concerns Discord server records or could expose another person's information. For records controlled by a Discord server owner, we may direct you to that owner or coordinate with them.
People in the Netherlands may also contact the Autoriteit Persoonsgegevens. People elsewhere may contact their local supervisory authority.
13. Age requirements
The Service is not directed to children under 13 and may only be used by people who meet Discord's minimum age requirement in their country. That minimum may be higher than 13. Where a user is not old enough to agree to these terms independently, a parent or legal guardian must provide any consent required by applicable law.
If you believe a child is using the Service below the applicable minimum age or that information was collected without required authorization, contact us so the situation can be reviewed.
14. Changes to this policy
We may update this policy when the Service, providers, security design, law, or business practices change. Material changes may be announced through the dashboard, Discord, a service notice, or a renewed legal-acceptance step. The effective date at the top identifies the current version.
15. Contact and privacy requests
For privacy questions, access or deletion requests, complaints, or security reports, contact X Systems using the details below. Please do not send passwords, API keys, bot tokens, or other credentials in your request.