Bastion Privacy Policy
Effective date: September 29, 2026
Operator: William Kurtz, operating as BVNGER ("BVNGER," "we," or "us")
Privacy contact: legal@bvnger.dev
This policy explains how the current Bastion Discord bot, Windows control panel, and locally run Owner Edition licensing API handle information. Bastion is installed and run by a Discord server owner on their own Windows computer. The owner chooses the server settings, who may use staff features, and how long to keep records within their control. BVNGER does not currently operate a hosted Bastion dashboard, subscription service, or customer server backup service.
This policy covers Bastion's handling of information. Discord's own services and data practices are governed by Discord's Privacy Policy. A server owner may have a separate privacy notice for their community.
Information Bastion accesses and creates
Depending on enabled features and Discord permissions, Bastion may access:
- Server and member information: server, channel, role, permission, and member identifiers; names and display names; role memberships; and join events. Bastion uses this information to configure the bot, assign roles, display the member directory, enforce access rules, and create server structure snapshots.
- Messages and support tickets: message content in channels where the bot has access, when needed for the word filter and ticket features. The word filter checks messages and edits for blocked language. When it removes a message, Bastion records the action but does not save the removed message text in its moderation log. A ticket transcript, created when staff archives or deletes a ticket, includes ticket messages, author names and IDs, timestamps, and attachment links. It is posted as a file in the server's restricted ticket log channel.
- Reports and moderation records: a member's
/reportreason, reporter and subject IDs and names, staff notes, warnings, timeout, kick or ban reasons, action history, status, and timestamps. These records are available in the owner's local control panel. Staff may also choose to post moderation records to a configured Discord log channel. - Onboarding, audit, and recovery records: join and role assignment results; staff or bot action history; settings backups; and server structure snapshots. Structure snapshots include server settings, channel names and topics, roles, permissions, and Discord IDs. They do not include message bodies or a member directory.
- Local configuration and diagnostics: the owner's selected settings, Discord bot token, and crash reports. The token is encrypted for the current Windows user. Other local records and exported files are written as ordinary files; Bastion does not encrypt them itself. A crash report may contain technical details from an error, so owners should review it before sharing it.
- Manual licensing records: if BVNGER runs the Owner Edition licensing API, it stores a key hash and suffix, a customer label entered by BVNGER, the stated total price and term, issue and expiration times, status, and the random installation ID provided during activation. It does not receive a Discord bot token or payment card details. The Owner launcher's API admin token is encrypted for the current Windows user; the API's license file is an ordinary local file. A raw license key is shown only when issued or replaced and is not stored by the API.
Bastion does not currently use advertising trackers or sell Discord data. The Windows app may fetch an image from a URL selected for an announcement preview; that request goes to the host of the selected image.
Why Bastion uses this information
Bastion uses the information above to operate the features the owner enables: tickets, moderation, member reports, onboarding, role selection, announcements, access checks, audit history, diagnostics, and server structure comparison. It exchanges data with Discord to read permitted server activity and carry out requested actions. It does not use Discord message content to train AI models.
For people in regions where a legal basis is required, the basis depends on the activity and the role of the server owner. The owner is responsible for choosing an appropriate basis and providing any required community notice for the features they enable. Contact the server owner about a specific server's use of Bastion. BVNGER can be contacted about this policy at the address above.
Where information is stored and who can see it
The bot token, configuration, moderation, onboarding, audit, backup, snapshot, and crash-report files are stored on the owner's computer, generally under the current Windows user's %LOCALAPPDATA%\BVNG3R folder. The owner controls access to that computer and any copies or exports they make. The current Windows control panel is for the owner; authorized staff may see records in Discord channels that the owner permits them to access. Ticket transcripts are posted to Discord's ticket log channel, with access controlled by the server's Discord permissions. Discord processes data sent through its platform.
The current Bastion software does not automatically upload local Discord server records to BVNGER. The licensing API currently runs locally on BVNGER's computer. If BVNGER later hosts it for customer activation, an updated policy will describe the resulting transfer and retention before that service launches. If an owner sends BVNGER a support request or diagnostic file, BVNGER receives the information they choose to provide and uses it to respond and troubleshoot. Owners should remove tokens and unnecessary personal information before sending files.
We may disclose information we actually receive when required by law or when necessary to address security or abuse. We do not sell Discord API data or share it with advertising networks or data brokers.
Retention and deletion
- Local moderation history keeps up to 1,000 entries, onboarding history up to 250 entries, and audit history up to 2,000 entries. The oldest entries are replaced as these limits are reached; there is no automatic time-based deletion for these files.
- Structure snapshots are kept according to the owner's selected count (5, 10, 20, or 50 in the control panel; 20 by default). Settings backups and exported audit files remain until the owner deletes them. Bastion keeps up to 20 local launcher crash reports.
- Ticket channels and their messages remain on Discord until removed. When Bastion archives a ticket, the resulting transcript remains in the server's ticket log channel until an authorized person deletes it there. Attachment links in transcripts may continue to point to files held by Discord.
- Removing Bastion from a server stops future bot processing there but does not itself erase existing local files, exported copies, Discord messages, or transcripts. The owner must delete those separately, subject to applicable law and Discord's own retention practices.
- Manual licensing records in the local Owner Edition API remain until BVNGER deletes the API data file; the current Owner UI can revoke or replace keys but does not delete license history.
We expect owners to keep records only while needed for the enabled features or legal obligations and to honor valid deletion requests. A record may also exist in an owner's separate backups or exports, which they must address separately.
Your choices and requests
If Bastion is used in a Discord server you belong to, contact that server's owner or moderators to ask about its settings, obtain a copy of information they control, correct a record, or request deletion. They operate the installation and control its local files and Discord log channels. You may also email legal@bvnger.dev with a privacy question or request; include the server name or ID and enough information for us to identify the relevant operator, but do not send your password or bot token. BVNGER may need to direct you to the server owner because it does not hold the local records.
Where applicable law grants additional rights, such as access, correction, deletion, objection, or complaint to a regulator, those rights remain available. We and the server owner will assess requests under applicable law and Discord's platform rules.
Security and international use
Bastion encrypts the bot token for the current Windows user and uses Discord permissions for access to ticket and log channels. The owner is responsible for protecting their computer, Windows account, Discord credentials, staff permissions, and backups. Other Bastion local records are not encrypted by Bastion. No system is completely secure.
Discord may process information in locations described in its own policy. Local Bastion files remain wherever the owner stores or backs them up. BVNGER's support communications may be processed in the places where BVNGER and its communications provider operate; request details at legal@bvnger.dev.
Children and changes
Bastion is intended for use on Discord by people who meet Discord's minimum age requirements. Server owners should not configure it to collect information from people who are too young to use Discord or to solicit sensitive personal information in tickets or reports.
We may update this policy as Bastion changes. We will revise the effective date and make the current version available where Bastion is distributed. We will also link it in Bastion's Discord Developer Portal entry when the policy is published. Material changes will be communicated through those channels before they take effect when required by law.
Contact
William Kurtz, operating as BVNGER
legal@bvnger.dev
