Privacy Policy
Inco keeps the Discord IDs it needs to deliver questions, run replies and blocks, and manage tiers. It reads your Custom Status only to pause the Free timer, and does not store that text. It does not sell your data. To ask for access or deletion, open a [Support] thread in the Mutual Hub or use /feedback.
Read the Terms of Service too.
[TODO: contact email, operator legal identity and country, concrete retention periods, and the other open gaps from the review must be resolved before publishing.]
This Privacy Policy governs the processing, retention, and deletion protocols of data gathered through your interaction with the Inco Discord Application ("the Service").
We consider user privacy fundamental. Our architectural framework is intentionally configured to minimize data gathering (Data Minimization Principle under Article 5 of the EU GDPR).
1. Data Points We Process
To execute core Q&A transmission, state tracking, and abuse prevention, the Service processes the following technical identifiers:
- Discord Snowflake IDs:
- User IDs: Processed to route anonymous communications, enforce rate-limiting ceilings, maintain two-way thread correlations, and enforce user-level blocklists (
blocked_relations). - Guild & Channel IDs: Retained strictly for bot shard allocation, command telemetry, and administrative dispatch tracking.
- Interactive Message IDs: Stored temporarily to correlate persistent UI button clicks (
timeout=None) to their underlying database dispatches.
- User IDs: Processed to route anonymous communications, enforce rate-limiting ceilings, maintain two-way thread correlations, and enforce user-level blocklists (
- Presence & Activity Metadata:
If and only if the Free Tier 3-hour timer feature is invoked, the bot evaluates the user's publicly visible Discord Custom Status text via
GatewayIntent.presencesto detect the presence of verification keywords for session pausing. This data is evaluated in memory and is never persistently stored to disk. - Anonymous Transmissions:
Text submitted within the
/askmodal interface is transmitted to the target user's Direct Message (DM) inbox. Message records are transiently stored to permit the two-way reply mechanism and sender clue inspection.
2. Categories of Data We NEVER Collect
- We do not collect real-world identities, physical locations, legal names, or banking credentials.
- We do not log or scrape public channel messages in servers hosting Inco.
- We do not monetize, market, license, or distribute your personal identifiers or message history to data brokers or advertising third parties.
3. Legal Grounds for Processing (GDPR Compliance)
We process personal technical data under the following legitimate grounds:
- Contractual Performance (Art. 6(1)(b) GDPR): Processing required to deliver requested anonymous messages and maintain active inbox tiers.
- Legitimate Interests (Art. 6(1)(f) GDPR): Processing required to prevent platform spam, deter malicious targeted cyberbullying via blocking systems, and ensure server infrastructure health.
4. Data Storage, Security & Retention Windows
- Volatile Memory & Session Records: Interaction caches and temporary memory handles are automatically pruned via routine scheduled sweeps every 5 minutes.
- Database Storage: Relational data is stored within isolated database instances with strictly controlled access credentials.
- Retention Schedule:
- Active dispatch records are systematically marked for archival and purged when no longer operationally viable.
- Recipient block relations (
blocked_relations) persist continuously to safeguard individuals from repeated abuse until manually lifted by the recipient.
5. Third-Party Disclosures & Integrations
The Service interfaces strictly with:
- Discord Inc.: Host platform providing API gateway tunnels, webhook dispatches, and Discord Native Server Subscriptions.
- Payment Gateways: Regional transaction tokens (such as TrueMoney claim URLs) are executed securely via headless network interfaces. Inco does not store or process payment card data.
6. Your Rights Under GDPR and Global Privacy Frameworks
Subject to statutory location criteria (including EU, UK, and California residents), you hold the right to:
- Right of Access (Art. 15 GDPR): Request disclosure of all Snowflake IDs and records linked to your Discord account.
- Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): Request comprehensive purging of your user configuration, inbox timers, and dispatch linkages from our storage layer.
- Right to Rectification: Update corrupted or invalid tier subscription associations.
7. How to Exercise Data Rights & Deletion
To invoke data removal or retrieve your system data footprint:
- Open a thread categorized with
[Support]within the Inco Mutual Hub, or - Execute the
/feedbackcommand detailing your erasure directive.
Requests are typically processed and purged from active production stores within 72 hours of verification.
8. Revisions to Privacy Protocols
We reserve the right to amend this Privacy Policy to reflect changing technical capabilities or evolving legal frameworks. Continued use of the Service following revisions confirms your informed acknowledgement of the updated terms.