Privacy Policy

Effective 5 September 2026 · Operated by Chu Đức An

Scope

Moji Debate Bot is operated from Vietnam and covers this website, the Discord bot, installation authorization, and the owner dashboard. The bot helps tournament participants access CalicoTab information through Discord. CalicoTab remains the tournament system of record. Users must meet Discord’s applicable minimum age requirements.

Data we process

  • Discord user ID, username, guild ID, role IDs, and channel or message IDs needed to operate the bot.
  • CalicoTab participant reference, display name, role, team, institution, and released draw assignments.
  • Operational delivery records such as announcement, check-in, reminder, and direct-message status.
  • Sanitized Command Log records for successful Bot Manager actions and meaningful automation transitions: Discord user/channel IDs, typed action, bounded result summary, timestamp, and delivery status. These exclude raw options, message or DM bodies, tokens, Private URLs, and meeting URLs.
  • Guild activation payment metadata: guild ID, internal payment ID, PayOS order code and payment-link ID, amount, currency, status, sanitized provider reference, and timestamps.

Authorization and cookies

  • Installation and Bot Manager command-access recovery use temporary authorization cookies to verify the return from Discord. These flows request no profile or email scope. The OAuth access token is used transiently to verify server permissions and prepare command visibility, is never stored, and is revoked on a best-effort basis after success or failure.
  • Owner dashboard sign-in separately requests Discord’s identify scope. A secure session cookie contains the owner’s Discord ID and display name and expires after eight hours; signing out clears it. Temporary sign-in cookies protect the authorization flow.

When an administrator reviews and confirms a role merge, Moji temporarily reads server members and their roles to calculate and verify transfers. Merge member lists and previews are not saved to the database, included in analytics, or logged. Successful role and permission changes remain in Discord; previews expire after five minutes or restart.

Credentials stay secret. Participant Private URL keys are never persisted. A server's CalicoTab administrator token is stored only as AES-256-GCM ciphertext in PostgreSQL and is never exposed in operational state, logs, or messages.

How we use data

We use data only to activate paid guild access, link participants, show released tournament information, update requested check-in status, publish notifications approved by the OrgComm (tournament organizers), assign configured Discord roles, and diagnose delivery failures.

Moji Debate Bot does not sell participant data, use it for advertising or targeted marketing, send promotional messages, or make automated decisions about tournament results.

How data is collected

Data is provided when you use Discord commands or buttons such as /connect, /room, /tab, and check-in workflows. The bot also receives released tournament data from the configured CalicoTab API and basic Discord context needed to respond in the correct server and channel.

Service providers

  • Discord: messaging, authorization, and server operations. Privacy policy.
  • CalicoTab: the configured tournament receives data needed for requested features and supplies tournament information. Consult your tournament’s CalicoTab policies.
  • PayOS: hosted checkout and payment confirmation. Moji Debate Bot does not receive or store bank login details or payment credentials. Privacy policy.
  • Railway: hosts the bot, dashboard backend, and database. Privacy policy.
  • Vercel: hosts this website and forwards authentication and dashboard requests to the backend. Privacy policy.

Sharing and retention

  • Stored data: We retain server credentials and operational state while the server remains configured. Unlinking stops future linked-participant delivery and role synchronization; historical delivery records may remain until server cleanup.
  • Command Log: Delivered Command Log outbox records are retained for 30 days. Unresolved records remain until resolution or server cleanup to prevent blind resend. Messages retained by Discord follow Discord's policies and administrator controls.
  • Payment metadata: Payment metadata is retained for ten years after payment as the product default for financial and support records; the operator must review that period for its jurisdiction.
  • Automatic cleanup: The bot is scheduled to leave and delete server data after 45 days without recorded activity or 90 days after setup, whichever comes first. Recorded activity restarts the inactivity timer; completing setup again restarts both timers. /setup status shows the current dates and does not reset activity.
  • Confirmed removal: Confirming /setup remove deletes the server’s stored credential and operational state, then makes the bot leave. Removing the bot also triggers cleanup. Payment metadata is excluded from operational deletion. If removal happens while the bot is offline, startup reconciliation handles the missed removal when the bot resumes.
  • Remaining records: An opaque migration marker containing no raw server ID may remain to prevent legacy data from being imported again. Deleting bot state does not delete messages or tournament records held by Discord, CalicoTab, or PayOS; those providers apply their own retention policies.

Your choices

You may ask the OrgComm to unlink your account or correct a link. The OrgComm can remove links and associated bot-managed roles. Unlinking is not a request to delete all historical records. For deletion requests, email mojidebate@gmail.com with enough information to identify your account and server, without sending credentials. Never post Private URLs in public channels.

Contact

For privacy questions, complaints, or data requests, email mojidebate@gmail.com. Moji Debate Bot does not provide a separate support server or escalation channel.