Overview
ChevLink Cyber ("Cyber", "the bot", "the Service") is a Discord security and community-protection service. To protect communities, it processes information about Discord servers and the people in them — and, where linked, associated Roblox accounts. This policy describes that processing in detail.
This Privacy Policy forms part of, and should be read together with, the ChevLink Cyber Terms of Use.
Key principle. Cyber is built for the security and moderation of communities. We process the minimum data needed to detect threats, enforce rules, and operate the shared CRN Network — and we do not sell personal data.
Who We Are
ChevLink Technologies ("ChevLink", "we", "us", "our") develops and operates ChevLink Cyber and the wider ChevLink platform. For the data described in this policy, ChevLink acts as a data controller or data processor depending on the activity, as explained in Section 7.
Our services are available globally to Discord communities. Contact details for privacy enquiries are in Section 18.
Scope of This Policy
This policy applies to ChevLink Cyber in all the forms it is delivered:
- the ChevLink Cyber Discord bot, its commands, and its automated protection modules; and
- the ChevLink Cyber tools provided through the CRN Director dashboard at
crnsecure.com/director— including the Screen tab and any other surface that queries or displays Cyber data.
It also covers information we observe when our staff review a community for compliance (Section 8). It does not cover other ChevLink products (such as PRC or Aegrix), which have their own policies.
Data We Collect
We group the data Cyber processes by category. "Persistent" data is stored on our servers (a Supabase/PostgreSQL database and encrypted state files); "Transient" data is processed to deliver a feature and not retained beyond what that feature needs; "Memory only" data is held briefly in memory and discarded.
4.1 Community & configuration data
| Data element | Purpose | Storage |
|---|---|---|
| Discord server (guild) ID and name | Identifying the community and its configuration | Persistent |
| Channel and role IDs (logs, notifications, verification, staff) | Routing alerts and determining permissions | Persistent |
| Protection settings (anti-raid/anti-nuke levels, lockdown, filters, network-ban opt-in, verification) | Operating the Service per your configuration | Persistent |
| ERLC server key (if Roblox integration is enabled) | Authenticating ERLC API requests; stored encrypted | Persistent (encrypted) |
4.2 Member & account data
When members join or are looked up (for example via /user info or a background check), Cyber may process:
| Data element | Purpose | Storage |
|---|---|---|
| Discord user ID, username, display name, avatar | Identification, risk assessment, enforcement, logging | Transient / as needed |
| Account age, badges, system flags, default-avatar status | Alt-account and risk detection (background check) | Transient |
| Linked Roblox account (ID, username, created date, banned status, verified badge, groups, friend/follower counts, badge count, username history) | Background checks and cross-platform risk scoring | Transient |
| Risk signals and scores (including signals exchanged with our Horizon risk service) | Threat detection and prioritisation | Memory / as needed |
| Account links recorded by staff (Discord main↔alt; Discord↔Roblox) | Investigation and enforcement context | Persistent |
4.3 Activity & content processed for safety
| Data element | Purpose | Storage |
|---|---|---|
| Message links/URLs (and a hash of each) | Malicious-link scanning; verdict caching | Cached verdicts |
| Message content that triggers the word filter | Enforcement and a violation record for repeat-offence thresholds | Persistent (violation log) |
| Image/attachment URLs and automated classifier scores (NSFW, scam, child-safety) | Detecting and removing harmful imagery | Transient (see §10) |
| Invite codes, their creators, and join events (who invited whom, when) | Invite tracking and raid attribution | Persistent (capped) |
| Server structure snapshots (roles, channels, permissions) | Anti-nuke restore (latest backup only) | Persistent (latest only) |
4.4 Enforcement & audit data
| Data element | Purpose | Storage |
|---|---|---|
| Network ban records (user ID, reason, category, issuing staff, evidence reference, related message IDs, timestamp) | Cross-community enforcement and accountability | Persistent |
| Service ban records (user or server, reason, timestamp) | Removing abusive users/servers from the Service | Persistent |
| Roblox network bans (Roblox ID, reason, linked Discord ID) | Enforcement on connected ERLC servers | Persistent |
| Threat "Radar" entries and action/audit logs | Threat tracking and an accountability trail of staff actions | Persistent |
4.5 What we do not collect
- We do not collect passwords, account credentials, payment-card numbers, or government-ID numbers.
- We do not use advertising cookies, ad networks, or cross-site tracking.
- We do not sell or rent personal data.
- We do not read or store the full content of ordinary messages that do not trigger a safety feature.
How We Use Your Data
- Providing the Service — running anti-raid, anti-nuke, automod, link/scam/NSFW/child-safety scanning, verification, backups, and recovery.
- Threat detection & risk scoring — background checks, alt-account and compromised-account detection, and invite/raid attribution.
- Enforcement — issuing and enforcing network bans and service bans, and maintaining accountable records and appeals.
- The CRN Network — sharing ban and threat-intelligence data between participating communities (Section 9).
- Safety & legal compliance — detecting illegal content and meeting our legal obligations, including child-safety reporting (Section 10).
- Security & improvement — protecting and improving our detection systems, using aggregated, de-identified signals and samples. We do not use this to build advertising profiles.
Legal Basis for Processing (GDPR)
If you are in the UK, the EEA, or a jurisdiction with equivalent law, we rely on the following bases under Article 6 of the UK/EU GDPR:
Legitimate interests — Art. 6(1)(f)
Most processing relies on our and our users' legitimate interest in keeping online communities safe — detecting raids, scams, and exploiters, enabling effective moderation, and operating a cross-community enforcement network. We have weighed these interests against data subjects' rights and consider them not overridden, given that processing is limited to what is necessary for security and that members' reasonable expectation in a moderated community is that activity is monitored for safety.
Contract — Art. 6(1)(b)
Processing of a community's configuration data is necessary to provide the Service to the administrator who installed it.
Legal obligation — Art. 6(1)(c)
We process and retain certain data to comply with legal obligations, including mandatory child-safety reporting and responding to lawful requests from authorities.
Special category & criminal-offence data — Art. 9 & 10
Where child-safety scanning processes content that may constitute special-category or criminal-offence data, we do so only as strictly necessary for reasons of substantial public interest (the safeguarding of children) and to comply with legal obligations, with appropriate safeguards, as permitted under the UK Data Protection Act 2018 and equivalent EU law.
US residents
For US residents, we process personal information consistent with applicable federal and state law, including the California Consumer Privacy Act/CPRA. We do not "sell" or "share" personal information as those terms are defined under California law. See Section 15.
Data Controller vs. Data Processor
You, as controller
For the activity and personal data of members within your community, the community (acting through its administrators) is generally the data controller, and ChevLink acts as your processor, processing that data on your configured instructions. As controller, you are responsible for having a lawful basis and for informing your members (see the Terms of Use).
ChevLink, as controller
ChevLink is an independent controller for data where we determine the purpose and means — in particular CRN Network enforcement records, cross-community threat intelligence, the security of our own Service, and aggregated service-improvement data.
Administrators' responsibility. By adding Cyber, you confirm you are entitled to deploy automated moderation in your community and will inform your members that the server uses automated security tooling that processes their activity for safety.
Compliance Reviews — Data We Observe
As described in the Terms of Use, ChevLink and authorised CRN Staff reserve the right to join and review a community using the Service to verify compliance with our Terms and policies.
During such a review, we may observe information available within the server, including channels, messages visible to a member, server configuration, and how the Service is being used (for example, whether investigative features such as /user info are being misused, or whether the server is a genuine community).
We process information observed during reviews only for compliance, safety, security, and enforcement purposes; our legal basis is our legitimate interest in protecting communities and the integrity of the CRN Network. We retain only what is necessary to record the outcome of a review or to support an enforcement action, and handle it in accordance with this policy.
Network Bans & Enforcement Records
The CRN Network allows a ban issued in one participating community to be enforced across others. Because this creates persistent records linking a user to a moderation action, we address it specifically.
What is stored
A network ban record may include the user ID, the reason and category, the issuing staff member, a reference to evidence, related message IDs, and a timestamp. Service bans and Roblox network bans store comparable details. See Section 4.4.
How it is shared
Ban and threat data may be shared with participating communities and synchronised to the CRN website and, for Roblox bans, to connected ERLC servers, so that enforcement is consistent across the network.
Challenging a record
If you believe a record about you is inaccurate, you may appeal through the appeals process, contact the issuing community, or contact us to exercise your rights under Section 15. We will investigate and correct or remove demonstrably inaccurate records.
Child Safety & CSAM Reporting
Automated reporting. Cyber includes automated child-safety scanning of imagery. Where content is confirmed as known child sexual abuse material (CSAM), we remove it, take enforcement action, and automatically report it to the US National Center for Missing & Exploited Children (NCMEC) CyberTipline. A report may include the relevant account, server, and content identifiers. We cooperate with NCMEC and competent authorities as required by law.
Suspected-explicit imagery flagged by automated classifiers (for example, adult-content detection) is removed and surfaced to staff for review; image URLs are handled in restricted, staff-only contexts and are not posted into general community channels. We retain only the minimum necessary to action and, where applicable, report an incident. This processing is carried out for the safeguarding reasons described in Section 6.
Third-Party Services
To deliver the Service, Cyber shares limited data with the providers below. We are not responsible for their practices; review their policies independently.
| Provider | What is shared | Purpose |
|---|---|---|
| Discord | Server, member, and message data via the Discord API | The platform the Service runs on |
| Supabase / hosting (Vultr, US) | The persistent data described in Section 4 | Database and server hosting |
| VirusTotal | URLs (and hashes) found in messages | Malicious-link scanning |
| Microsoft Azure (PhotoDNA) | Image references for hash matching | Known-CSAM detection |
| Google Cloud Vision | Image references | Explicit-content classification |
| NCMEC CyberTipline | Incident reports (account, server, content identifiers) | Mandatory child-safety reporting |
| Roblox & ERLC (PoliceRoleplayCommunity) APIs | Roblox IDs/usernames; ban sync to ERLC servers | Roblox integration and enforcement |
| Roblox link providers (Bloxlink, RoWifi, RoVer) | Discord/Roblox identifiers | Resolving linked Roblox accounts |
| ChevLink Horizon | User/guild IDs and risk signals | Predictive risk intelligence |
| CRN platform (crnsecure.com) | Ban and enforcement data | Cross-community enforcement & Director tools |
We do not engage advertising networks or sell data to any third party.
International Data Transfers
Our infrastructure is located in the United States. If you are in the UK, the EEA, or another jurisdiction with transfer restrictions, your data may be transferred to and processed in the US. Where we transfer personal data internationally, we rely on appropriate safeguards such as the UK/EU Standard Contractual Clauses where applicable, and we minimise the volume of persistent personal data transferred. Data sent to Discord, Roblox, and other providers is subject to those services' own transfer arrangements.
Data Retention
| Data category | Retention | Deletion trigger |
|---|---|---|
| Ordinary message content (no safety trigger) | Not stored | Immediate |
| Link-scan verdicts (cache) | Short-lived cache (hours), plus a malicious-URL record | Cache expiry |
| Word-filter violation records | Retained for audit; a 30-day rolling window drives repeat-offence thresholds | On account/community deletion or erasure request |
| Invite join events | Capped per server (most recent retained) | Automatic rotation |
| Ban-message references | Up to ~90 days | Automatic pruning |
| Server backups | Latest snapshot only | Overwritten each cycle |
| Community configuration | While the server remains registered | Bot removed / community deleted |
| Network/service/Roblox ban records & audit logs | Retained while needed for enforcement and accountability | Ban removed or verified erasure request |
On a verified erasure request (see Section 15), we delete the associated persistent data within 30 days, except where we must retain it to comply with a legal obligation or to establish, exercise, or defend legal claims (for example, certain safety and enforcement records).
Security Measures
- Encryption in transit for connections to external services, and validation of certificates.
- Encryption at rest for sensitive secrets such as ERLC server keys; secrets are never stored in plaintext or logged.
- Minimal persistence — most data is processed transiently and discarded.
- Server hardening — firewalling, restricted SSH-key access, and least-privilege practices.
- Access control — staff tiers and permissions limit who can take sensitive actions.
No method of transmission or storage is completely secure. In the event of a breach affecting your personal data, we will notify affected parties and regulators as required by law.
Your Rights
Depending on your jurisdiction, you may have some or all of the rights below. To exercise them, contact us (Section 18); we respond within 30 days, free of charge, unless a request is manifestly unfounded or excessive.
Request a copy of the personal data we hold about you and how it is used.
Request deletion of your data where we have no overriding legitimate interest or legal obligation to retain it.
Request correction of inaccurate data, including ban records.
Object to processing based on legitimate interests; we will stop unless we have compelling grounds.
Request that we limit processing to storage only, pending a dispute or objection.
Receive certain data in a structured, machine-readable format where applicable.
California (CCPA/CPRA)
California residents may request to know and delete personal information, opt out of sale/sharing (we do not sell or share), and exercise these rights without discrimination. To submit a request, contact us and state you are a California resident.
Children's Privacy
Discord requires users to be at least 13 (or older where local law requires). Because Discord and Roblox communities may include minors, Cyber may process data referencing individuals under 18, and in some jurisdictions under 16 (the GDPR child-consent threshold).
Cyber does not collect data directly from individuals or build advertising profiles. The persistent records that may reference a minor are moderation and safety records created by community administrators or by our safety systems. We do not knowingly build profiles of children beyond what is necessary for safety and enforcement. Parents or guardians who believe a minor's data has been incorrectly retained may contact us (Section 18) and we will investigate promptly. Child-safety incidents are handled as described in Section 10.
Changes to This Policy
We may update this policy to reflect changes to the Service, the law, or our practices. When we make material changes, we will update the "Last updated" date and, where appropriate, provide notice. Your continued use of the Service after changes take effect constitutes acceptance. Previous versions are available on request.
Contact Us
For privacy enquiries or data-subject requests relating to ChevLink Cyber, contact us using the details below. Please use the indicated subject line so your request is routed correctly. We aim to respond within 3 business days for general enquiries and 30 days for formal requests.
| Operator | ChevLink Technologies |
| Privacy | privacy@chevlink.com |
| Website | chevlink.com |
| Subject line | Use "Cyber Privacy" |
If you are in the UK or EEA and are not satisfied with our response, you may lodge a complaint with your data-protection authority — for example, the UK Information Commissioner's Office (ico.org.uk) or your national supervisory authority.
This policy should be read together with the ChevLink Cyber Terms of Use.