ChevLink ChevLink Technologies ChevLink Cyber Terms
Legal Document

ChevLink Cyber — Privacy Policy

This policy explains exactly what data the ChevLink Cyber Discord bot and its CRN Director tools collect, how that data is used and shared, how long it is kept, and the rights you have under applicable data-protection law.

Effective date: 19 June 2026
Last updated: 19 June 2026
Applies to: ChevLink Cyber bot & CRN Director tools
Section 01

Overview

ChevLink Cyber ("Cyber", "the bot", "the Service") is a Discord security and community-protection service. To protect communities, it processes information about Discord servers and the people in them — and, where linked, associated Roblox accounts. This policy describes that processing in detail.

This Privacy Policy forms part of, and should be read together with, the ChevLink Cyber Terms of Use.

Key principle. Cyber is built for the security and moderation of communities. We process the minimum data needed to detect threats, enforce rules, and operate the shared CRN Network — and we do not sell personal data.

Section 02

Who We Are

ChevLink Technologies ("ChevLink", "we", "us", "our") develops and operates ChevLink Cyber and the wider ChevLink platform. For the data described in this policy, ChevLink acts as a data controller or data processor depending on the activity, as explained in Section 7.

Our services are available globally to Discord communities. Contact details for privacy enquiries are in Section 18.

Section 03

Scope of This Policy

This policy applies to ChevLink Cyber in all the forms it is delivered:

  • the ChevLink Cyber Discord bot, its commands, and its automated protection modules; and
  • the ChevLink Cyber tools provided through the CRN Director dashboard at crnsecure.com/director — including the Screen tab and any other surface that queries or displays Cyber data.

It also covers information we observe when our staff review a community for compliance (Section 8). It does not cover other ChevLink products (such as PRC or Aegrix), which have their own policies.

Section 04

Data We Collect

We group the data Cyber processes by category. "Persistent" data is stored on our servers (a Supabase/PostgreSQL database and encrypted state files); "Transient" data is processed to deliver a feature and not retained beyond what that feature needs; "Memory only" data is held briefly in memory and discarded.

4.1 Community & configuration data

Data elementPurposeStorage
Discord server (guild) ID and nameIdentifying the community and its configurationPersistent
Channel and role IDs (logs, notifications, verification, staff)Routing alerts and determining permissionsPersistent
Protection settings (anti-raid/anti-nuke levels, lockdown, filters, network-ban opt-in, verification)Operating the Service per your configurationPersistent
ERLC server key (if Roblox integration is enabled)Authenticating ERLC API requests; stored encryptedPersistent (encrypted)

4.2 Member & account data

When members join or are looked up (for example via /user info or a background check), Cyber may process:

Data elementPurposeStorage
Discord user ID, username, display name, avatarIdentification, risk assessment, enforcement, loggingTransient / as needed
Account age, badges, system flags, default-avatar statusAlt-account and risk detection (background check)Transient
Linked Roblox account (ID, username, created date, banned status, verified badge, groups, friend/follower counts, badge count, username history)Background checks and cross-platform risk scoringTransient
Risk signals and scores (including signals exchanged with our Horizon risk service)Threat detection and prioritisationMemory / as needed
Account links recorded by staff (Discord main↔alt; Discord↔Roblox)Investigation and enforcement contextPersistent

4.3 Activity & content processed for safety

Data elementPurposeStorage
Message links/URLs (and a hash of each)Malicious-link scanning; verdict cachingCached verdicts
Message content that triggers the word filterEnforcement and a violation record for repeat-offence thresholdsPersistent (violation log)
Image/attachment URLs and automated classifier scores (NSFW, scam, child-safety)Detecting and removing harmful imageryTransient (see §10)
Invite codes, their creators, and join events (who invited whom, when)Invite tracking and raid attributionPersistent (capped)
Server structure snapshots (roles, channels, permissions)Anti-nuke restore (latest backup only)Persistent (latest only)

4.4 Enforcement & audit data

Data elementPurposeStorage
Network ban records (user ID, reason, category, issuing staff, evidence reference, related message IDs, timestamp)Cross-community enforcement and accountabilityPersistent
Service ban records (user or server, reason, timestamp)Removing abusive users/servers from the ServicePersistent
Roblox network bans (Roblox ID, reason, linked Discord ID)Enforcement on connected ERLC serversPersistent
Threat "Radar" entries and action/audit logsThreat tracking and an accountability trail of staff actionsPersistent

4.5 What we do not collect

  • We do not collect passwords, account credentials, payment-card numbers, or government-ID numbers.
  • We do not use advertising cookies, ad networks, or cross-site tracking.
  • We do not sell or rent personal data.
  • We do not read or store the full content of ordinary messages that do not trigger a safety feature.
Section 05

How We Use Your Data

  • Providing the Service — running anti-raid, anti-nuke, automod, link/scam/NSFW/child-safety scanning, verification, backups, and recovery.
  • Threat detection & risk scoring — background checks, alt-account and compromised-account detection, and invite/raid attribution.
  • Enforcement — issuing and enforcing network bans and service bans, and maintaining accountable records and appeals.
  • The CRN Network — sharing ban and threat-intelligence data between participating communities (Section 9).
  • Safety & legal compliance — detecting illegal content and meeting our legal obligations, including child-safety reporting (Section 10).
  • Security & improvement — protecting and improving our detection systems, using aggregated, de-identified signals and samples. We do not use this to build advertising profiles.
Section 07

Data Controller vs. Data Processor

You, as controller

For the activity and personal data of members within your community, the community (acting through its administrators) is generally the data controller, and ChevLink acts as your processor, processing that data on your configured instructions. As controller, you are responsible for having a lawful basis and for informing your members (see the Terms of Use).

ChevLink, as controller

ChevLink is an independent controller for data where we determine the purpose and means — in particular CRN Network enforcement records, cross-community threat intelligence, the security of our own Service, and aggregated service-improvement data.

Administrators' responsibility. By adding Cyber, you confirm you are entitled to deploy automated moderation in your community and will inform your members that the server uses automated security tooling that processes their activity for safety.

Section 08

Compliance Reviews — Data We Observe

As described in the Terms of Use, ChevLink and authorised CRN Staff reserve the right to join and review a community using the Service to verify compliance with our Terms and policies.

During such a review, we may observe information available within the server, including channels, messages visible to a member, server configuration, and how the Service is being used (for example, whether investigative features such as /user info are being misused, or whether the server is a genuine community).

We process information observed during reviews only for compliance, safety, security, and enforcement purposes; our legal basis is our legitimate interest in protecting communities and the integrity of the CRN Network. We retain only what is necessary to record the outcome of a review or to support an enforcement action, and handle it in accordance with this policy.

Section 09

Network Bans & Enforcement Records

The CRN Network allows a ban issued in one participating community to be enforced across others. Because this creates persistent records linking a user to a moderation action, we address it specifically.

What is stored

A network ban record may include the user ID, the reason and category, the issuing staff member, a reference to evidence, related message IDs, and a timestamp. Service bans and Roblox network bans store comparable details. See Section 4.4.

How it is shared

Ban and threat data may be shared with participating communities and synchronised to the CRN website and, for Roblox bans, to connected ERLC servers, so that enforcement is consistent across the network.

Challenging a record

If you believe a record about you is inaccurate, you may appeal through the appeals process, contact the issuing community, or contact us to exercise your rights under Section 15. We will investigate and correct or remove demonstrably inaccurate records.

Section 10

Child Safety & CSAM Reporting

Automated reporting. Cyber includes automated child-safety scanning of imagery. Where content is confirmed as known child sexual abuse material (CSAM), we remove it, take enforcement action, and automatically report it to the US National Center for Missing & Exploited Children (NCMEC) CyberTipline. A report may include the relevant account, server, and content identifiers. We cooperate with NCMEC and competent authorities as required by law.

Suspected-explicit imagery flagged by automated classifiers (for example, adult-content detection) is removed and surfaced to staff for review; image URLs are handled in restricted, staff-only contexts and are not posted into general community channels. We retain only the minimum necessary to action and, where applicable, report an incident. This processing is carried out for the safeguarding reasons described in Section 6.

Section 11

Third-Party Services

To deliver the Service, Cyber shares limited data with the providers below. We are not responsible for their practices; review their policies independently.

ProviderWhat is sharedPurpose
DiscordServer, member, and message data via the Discord APIThe platform the Service runs on
Supabase / hosting (Vultr, US)The persistent data described in Section 4Database and server hosting
VirusTotalURLs (and hashes) found in messagesMalicious-link scanning
Microsoft Azure (PhotoDNA)Image references for hash matchingKnown-CSAM detection
Google Cloud VisionImage referencesExplicit-content classification
NCMEC CyberTiplineIncident reports (account, server, content identifiers)Mandatory child-safety reporting
Roblox & ERLC (PoliceRoleplayCommunity) APIsRoblox IDs/usernames; ban sync to ERLC serversRoblox integration and enforcement
Roblox link providers (Bloxlink, RoWifi, RoVer)Discord/Roblox identifiersResolving linked Roblox accounts
ChevLink HorizonUser/guild IDs and risk signalsPredictive risk intelligence
CRN platform (crnsecure.com)Ban and enforcement dataCross-community enforcement & Director tools

We do not engage advertising networks or sell data to any third party.

Section 12

International Data Transfers

Our infrastructure is located in the United States. If you are in the UK, the EEA, or another jurisdiction with transfer restrictions, your data may be transferred to and processed in the US. Where we transfer personal data internationally, we rely on appropriate safeguards such as the UK/EU Standard Contractual Clauses where applicable, and we minimise the volume of persistent personal data transferred. Data sent to Discord, Roblox, and other providers is subject to those services' own transfer arrangements.

Section 13

Data Retention

Data categoryRetentionDeletion trigger
Ordinary message content (no safety trigger)Not storedImmediate
Link-scan verdicts (cache)Short-lived cache (hours), plus a malicious-URL recordCache expiry
Word-filter violation recordsRetained for audit; a 30-day rolling window drives repeat-offence thresholdsOn account/community deletion or erasure request
Invite join eventsCapped per server (most recent retained)Automatic rotation
Ban-message referencesUp to ~90 daysAutomatic pruning
Server backupsLatest snapshot onlyOverwritten each cycle
Community configurationWhile the server remains registeredBot removed / community deleted
Network/service/Roblox ban records & audit logsRetained while needed for enforcement and accountabilityBan removed or verified erasure request

On a verified erasure request (see Section 15), we delete the associated persistent data within 30 days, except where we must retain it to comply with a legal obligation or to establish, exercise, or defend legal claims (for example, certain safety and enforcement records).

Section 14

Security Measures

  • Encryption in transit for connections to external services, and validation of certificates.
  • Encryption at rest for sensitive secrets such as ERLC server keys; secrets are never stored in plaintext or logged.
  • Minimal persistence — most data is processed transiently and discarded.
  • Server hardening — firewalling, restricted SSH-key access, and least-privilege practices.
  • Access control — staff tiers and permissions limit who can take sensitive actions.

No method of transmission or storage is completely secure. In the event of a breach affecting your personal data, we will notify affected parties and regulators as required by law.

Section 15

Your Rights

Depending on your jurisdiction, you may have some or all of the rights below. To exercise them, contact us (Section 18); we respond within 30 days, free of charge, unless a request is manifestly unfounded or excessive.

Access

Request a copy of the personal data we hold about you and how it is used.

Erasure

Request deletion of your data where we have no overriding legitimate interest or legal obligation to retain it.

Rectification

Request correction of inaccurate data, including ban records.

Object

Object to processing based on legitimate interests; we will stop unless we have compelling grounds.

Restriction

Request that we limit processing to storage only, pending a dispute or objection.

Portability

Receive certain data in a structured, machine-readable format where applicable.

California (CCPA/CPRA)

California residents may request to know and delete personal information, opt out of sale/sharing (we do not sell or share), and exercise these rights without discrimination. To submit a request, contact us and state you are a California resident.

Section 16

Children's Privacy

Discord requires users to be at least 13 (or older where local law requires). Because Discord and Roblox communities may include minors, Cyber may process data referencing individuals under 18, and in some jurisdictions under 16 (the GDPR child-consent threshold).

Cyber does not collect data directly from individuals or build advertising profiles. The persistent records that may reference a minor are moderation and safety records created by community administrators or by our safety systems. We do not knowingly build profiles of children beyond what is necessary for safety and enforcement. Parents or guardians who believe a minor's data has been incorrectly retained may contact us (Section 18) and we will investigate promptly. Child-safety incidents are handled as described in Section 10.

Section 17

Changes to This Policy

We may update this policy to reflect changes to the Service, the law, or our practices. When we make material changes, we will update the "Last updated" date and, where appropriate, provide notice. Your continued use of the Service after changes take effect constitutes acceptance. Previous versions are available on request.

Section 18

Contact Us

For privacy enquiries or data-subject requests relating to ChevLink Cyber, contact us using the details below. Please use the indicated subject line so your request is routed correctly. We aim to respond within 3 business days for general enquiries and 30 days for formal requests.

OperatorChevLink Technologies
Privacyprivacy@chevlink.com
Websitechevlink.com
Subject lineUse "Cyber Privacy"

If you are in the UK or EEA and are not satisfied with our response, you may lodge a complaint with your data-protection authority — for example, the UK Information Commissioner's Office (ico.org.uk) or your national supervisory authority.

This policy should be read together with the ChevLink Cyber Terms of Use.