Legal / Discord application

Privacy, without the guesswork.

This policy explains what VPG Manager Bot uses, what it stores, and how league invitations and verified team-access requests are handled.

Bot privacy policyUpdated 4 October 2026
Limited purposeLeague and verified team access management.
No message surveillanceOrdinary channel conversations are not read for this service.
Your choiceInvitations require acceptance before a role is granted.

01 / Scope

Who this policy covers

VPG Manager Bot is operated by the Virtual Pro Gaming (VPG) bot administrators. It works in Discord servers where the bot has been added and configured. This page covers the bot, its commands, invitations, and its administrator panel. It does not cover the rest of noirnetwork.org, which has a separate website policy.

02 / Information

Data we use

Discord identity & access

User and server IDs, usernames, display names, server nicknames, role memberships, and relevant role and channel IDs. These let the bot identify the right manager, member, league, and server.

Actions & records

League configuration, command and button actions, invitations and responses, assignments, delivery details, and operational audit records. These support access management and troubleshooting.

Verified team access

Where enabled, team names and identifiers, the verified Main Manager’s Discord ID, team role and private-channel IDs, access requests and reviewer IDs, expiry and message-cleanup details, and team action audit records.

Admin-panel security

Administrator session and login-security records, including hashed identifiers used to limit failed sign-in attempts. The panel uses a session cookie after sign-in; the admin password is not stored as plaintext by the bot.

We do not request payment information. The co-manager service does not need to read the content of ordinary Discord channel conversations.

03 / Purpose

What the bot does with it

The bot checks which leagues a member can manage, recognizes existing co-managers where possible, creates and processes invitations, displays current access, and adds or removes configured Discord roles. It may adjust a server nickname when the relevant feature is enabled and the bot has permission. Admins use the panel to configure leagues, roles, and notification channels.

The optional team-access system lets staff verify Main Managers, creates team roles and private channels, and lets team managers approve or directly manage Co-Manager and Player access. Members can remove their own Co-Manager or Player access. This system does not change server nicknames or VPG registration, and does not link Discord accounts to VPG accounts.

An invitation is not access.A member receives a co-manager role only after accepting an invitation. They can decline instead.

04 / Visibility

Messages and who can see them

Invitation and status messages may be delivered by Discord DM. If a DM cannot be delivered, the bot may post an invitation in the fallback channel selected by that server’s administrators and mention the people involved. Anyone with access to that channel can see the message and its league and participant details. Discord roles and server nicknames are visible according to that server’s settings.

Do not use a public fallback channel if those details should stay limited to a smaller group. Server administrators control that channel’s permissions.

Team-access requests use the configured private staff or team-manager channel rather than automatic DMs. Relevant reviewers and requesters are mentioned. Server administrators can still access private channels through Discord’s permissions.

05 / Sharing

Who else handles the data

Relevant server members and administrators can see information through Discord messages, roles, nicknames, and the admin panel as described above. Discord handles information on its platform under Discord’s privacy policy. The bot’s hosting and database providers process data to operate the service. We do not sell personal information or use it for advertising.

06 / Retention

How long records remain

Configuration and assignment records are kept while needed to run the bot. An invitation normally expires after 24 hours, but its record, response, and related audit details may remain so administrators can investigate access changes, failures, or abuse. There is no fixed automatic deletion period for those records.

For the separate team-access system, unanswered requests expire after 24 hours. Completed request messages are scheduled for removal after five minutes and expired notices after three hours. Completed team request records and team action audit entries are normally deleted after 90 days; unresolved message-deletion failures are retained for retry. Team settings and verified manager records remain while needed to operate team access.

Admin sessions expire; expired or revoked session records are normally removed after seven days, and login-throttle records after two days. Access to the admin panel is restricted and sessions are protected. No online service can guarantee absolute security.

07 / Your choices

Access, correction, or deletion

You may decline an invitation or ask a server administrator to remove co-manager access. For questions about information held by the bot, or to request access, correction, or deletion, email legal@noirnetwork.org. Include your Discord user ID and the relevant server ID so we can identify the right records. Please do not include passwords or other sensitive information in your email or a public channel.

We may need to verify that the request concerns your account. Some records may need to remain while they are necessary for active access management, security, or legal obligations. If privacy law gives you additional rights, you can raise them through the same address.

Email a privacy request

08 / Updates

Changes to this policy

We may update this page when the bot or its data practices change. The date at the top shows when this version was published.