Privacy Policy
LAST UPDATED 3 OCTOBER 2026
Alya is a personal, non commercial project run by one person. There are no adverts, no analytics, no third party trackers, and nothing is sold or shared with anyone. What follows is the complete list of what gets stored.
What the bot stores
When you post an Instagram or TikTok link in a server where Alya is present, it records:
- Your Discord user ID and the server ID, which are numbers rather than names
- A count of how many links you have posted, split between Instagram and TikTok
- The date of your most recent post, used to track daily streaks
- The hour of day you posted, in UTC, kept only as a running tally per hour
- Links you save with the Save button, stored as URLs against your user ID, capped at fifty
- Your Discord client language setting, recorded when you use a slash command
What it does not store
- Your messages, or any message content beyond the link itself
- Your display name, avatar or email, or your username outside the technical log described below
- Your IP address, location, or device information
- Any video or image file, beyond the seconds it takes to pass one to Discord
- Direct messages, or anything from channels it cannot see
Why the hour and the language
Discord does not tell bots where anyone is. Those two signals together allow a rough guess at which part of the world a group of people is in, which powers the activity chart. It is an estimate accurate to roughly a country, never a precise location, and the resulting figures are only ever shown as group totals.
Profile, emoji and server tools
?pfp, ?bnr, ?emoji and ?sticker show images Discord already makes visible to the server. They are fetched when asked for and never saved. ?copy downloads an emoji image only for the moment it takes to add it to your server. ?copy and ?purge also leave an entry in your server's own audit log, under the name of whoever ran them, so moderators can see who did what. Messages removed by ?purge are deleted by Discord and are not kept anywhere.
Technical log
To diagnose problems, the bot keeps a running technical log on the same private server. When it stages a link, or someone uses ?copy or ?purge, the log line includes the Discord username and user ID involved, and the server or channel it happened in. The log is used for nothing else, is never shared, and older entries are deleted automatically once it reaches its size limit.
The dashboard
Logging in to the dashboard uses Discord's own login. Discord shares your user ID, username, display name, avatar and the list of servers you are in. Alya keeps your ID, names, avatar and only the servers you can manage, for up to seven days or until you log out, so the dashboard knows who you are. The key Discord issues for the login is handed straight back and never stored. A cookie holds your session, and only a scrambled form of it is kept on the server. When you change a server's settings, the change is written to the technical log with your username, so a server's managers can find out who changed what.
A server's welcome message, its chosen channel, and any GIF or image uploaded for it are stored on the same private server until a manager changes or removes them. The welcome is posted in that server when someone joins. It can show their name, avatar, the date they joined, when their Discord account was made and their member number, all of which Discord already shows to the server. Nothing about the new member is stored for it.
Scam protection
Only in servers where a manager has switched it on. To spot one account posting the same link or image across several channels, Alya keeps a scrambled fingerprint of each recent message that contains a link or an image, together with where it was posted, in memory for about ninety seconds. Nothing of it is written to disk. When she acts, the report she sends to the chosen manager's DMs, or to a chosen channel, includes the member's name and ID and a copy of what they posted, and the action is written to the technical log and to the server's audit log.
Suggestions on this site
Anything you submit through the suggestion form is public, including the name you attach, so do not put anything private in it. To stop one person voting repeatedly, your connection address is hashed with a secret value and only that hash is kept. The address itself is never written to disk and the hash cannot be reversed back into one.
Where it lives
Everything sits in plain files on a single private server, readable only by its owner. There is no external database and no third party service holding a copy. Backups are kept on the same machine for fourteen days.
Third parties
To make a link playable, the bot passes the public post address to an embed service such as kkinstagram or tnktok, which fetches the video. Those services are independent and have their own policies. Nothing about you is sent to them, only the address of the post being shared. /furi sends the phrase you type to GIF sources such as Tenor and public image boards, again with nothing about you attached. ?translate sends the text being translated to Google Translate, or to MyMemory if Google is unavailable. Text typed in English letters may also go to Google's input tools, to be written in its own script first. Nothing else about you or the message is sent, and translations are not saved. Fonts are loaded from Google Fonts.
Removing your data
Message @cinnamon.ron on Discord with your user ID and everything tied to it will be deleted. No reason required. Removing the bot from a server does not delete existing records on its own, so ask if you want that done too.
Children
Discord requires users to be at least thirteen, or older where local law says so. This project is not aimed at anyone below that age.
Changes
If this policy changes, the date at the top changes with it. There is no mailing list to notify, so check back if it matters to you.