Back to home

Privacy policy

Effective from October 3, 2026 · echo-assistants.tech

This page explains, point by point, what data the Echo project processes, why, who it is shared with, how long it is kept and how to delete it. We collect what the features need in order to work, and we do not sell data.

1Who we are and what this policy covers

Echo is a Discord bot and dashboard at echo-assistants.tech, together with related services: server monitoring (monitoring.echo-assistants.tech), server stores, the Echo Deal escrow service (deal.echo-assistants.tech), a Minecraft server with its own website and launcher (minecraft.echo-assistants.tech), the Mafia and Bunker games, and our Discord server Echo Studio.

This policy applies to everyone who uses the bot on their server, signs in on the website, plays on our Minecraft server, takes part in escrow deals or simply interacts with Echo features (submits a form, votes, writes in a ticket).

By using the service, you agree to the data processing described here. If you do not agree, do not add the bot, do not sign in on the website and do not play on the server.

2Discord data and the bot

The bot receives from Discord only what it is permitted to: IDs and names of users, servers, channels and roles, server nicknames, and message text. We use this only for features that the server’s administration has enabled.

  • Server module settings: greetings, moderation and protection, tickets, forms and tests, roles and panels, voice rooms, polls, staff and shifts, logs, backups, levels, economy, alerts, verification, giveaways, auctions, birthdays (day and month only), marriages.
  • Statistics: message counts, time in voice channels and who you were there with (for the Year in review), experience and levels, nickname history, who gave whom a role, who invited whom.
  • Message text is stored only where an enabled feature needs it: logs of deleted and edited messages (text, author, attachments), transcripts of closed tickets, arguments of the server’s custom commands, the Mafia match chat, and questions to the AI assistant. Automod, filters, auto-replies and counting check text on the fly and do not store it.
  • Copies of messages that the bot posts in server channels (log channels, reports, the Starboard) remain in Discord until the server’s administration deletes them.
  • A ticket transcript opens via a link that the bot sends to the server’s administration; do not share it with outsiders.
  • The name of the game that members of a personal voice room are playing — for the room’s status; it is not stored.
  • The bot sends direct messages about events that the server’s administration has enabled: decisions on applications and forms, warnings, shifts, ticket ratings. The website sends balance receipts and decisions on reports.
  • Server economy and games: balance, bank, chips, items, businesses, marriages, participation in giveaways and auctions.
  • Mafia, Bunker and Scribbles: game profile, rating, statistics and match history; the Mafia match chat is visible on the room page until the next match on that server; reports about the game chat are stored together with the message text.
  • Staff and activity: departments, ranks, applications, reprimands, work reports and points — for your server’s HR module.
  • Responses to the server’s forms and tests, together with the submitter’s ID and the moderation decision.
  • Snapshots of the server structure (roles, channels, permissions) — for backups and restoring.
  • Your own bot (Premium): your bot application’s token is stored encrypted and used only to run Echo under your bot.
  • Discord Linked Roles: Discord access keys are stored encrypted (AES-256-GCM) together with the last values sent; once you revoke access in Discord, the keys are deleted.

3Website and sign-in

Sign-in uses Discord’s official OAuth2. We request your profile (identify), your email address (email) and the list of your servers (guilds); adding you to our server (guilds.join) is requested only if you chose auto-join yourself. The server list (name, icon, whether you are the owner) is saved for the dashboard.

We save the email address from Discord and its “verified” flag each time you sign in. We use a verified email to show your albums from the fotora.ru image host (the address is shared with fotora for this) and for account service emails: the deletion confirmation code, “your data is ready” and reminders about a scheduled deletion, and notifications about replies to your support requests. We send no marketing emails. Your email is deleted together with your account.

We have no access to your Discord password. The session is stored in an encrypted cookie (AES-256-GCM) in your browser; it contains a Discord access token used to check your permissions.

If two-factor protection is enabled, we send a one-time code to Telegram. The code is valid for 5 minutes, the number and frequency of attempts are limited, and the code is deleted after use or when it expires.

Emails sent to @echo-assistants.tech addresses (echo@, garant@ and others) are received by our own mail server. We store the sender's address and name, the subject, text, attachments and the result of the sender check (SPF, DKIM, DMARC and the IP address of the sending mail server) so that we can read the email and reply. Only the project's leadership can see these emails.

To protect your account from takeover, we record sign-ins to the site and the Minecraft dashboard (IP address, browser and operating system) and signs of compromise: reuse of a cookie after sign-out, guessing of the two-factor code, guessing of Minecraft passwords. When we see such signs, we end all sessions of the account or disable it until you contact support. Decisions and their grounds are visible only to the project leadership.

4Cookies and browser storage

We use only necessary cookies. There are no advertising or tracking cookies, and no third-party analytics. Our own page-view counter records only the page address and the day — no IP and no cookies.

  • echo_session — website sign-in, 7 days.
  • echo_clearance — browser check against bots and flooding, 2 hours; contains no data about you.
  • locale — your chosen language, 1 year.
  • Temporary cookies for signing in via Discord, VK, Telegram and for Linked Roles — up to 10 minutes.
  • echo_mc — sign-in to the Minecraft account page, 7 days; echo_deal — sign-in to the escrow service, 30 days.
  • A reaction on a bio page — 1 year, so that you don’t vote twice.
  • Browser storage (localStorage) keeps form drafts and dismissed hints; they are not sent to the server.
  • On bio pages where the author chose a Google font, your browser loads it from Google’s servers.

5Payments and balance

The balance is topped up via YooMoney and Crypto Pay (@CryptoBot in Telegram). Card and wallet details are entered on the payment service’s side and never reach us.

  • We send the payment service the amount, a label with your Discord ID and a payment description with your Discord name (or Minecraft nickname).
  • On our side we store the transaction number, amount, status, sender (YooMoney wallet number, or amount and coin for crypto) and the payment service’s notification in full.
  • Balance history: top-ups, purchases, refunds and bonuses — with the date and reason.
  • Withdrawal details (store, escrow) — for payouts; they are visible to the wallet owner and the staff who process the payout.

6Public data: monitoring, reviews, stores, bio pages

  • A server’s monitoring card (name, description, invite, tags, banner, links), “Flame” votes, views and clicks are shown publicly in the catalog.
  • A server review is public together with your Discord name and avatar; new reviews are recorded in the moderation log.
  • Clicks on a server badge are counted by a hash of the IP address; these records are deleted after 60 days.
  • Purchases and gifts in a server store are visible to the seller (the server owner); “Support the server” can be done anonymously.
  • A bio page is a public page that you fill in yourself.
  • On-site notifications (the “bell”) are stored under your ID; read ones are deleted after about 2 months.

7Echo Deal escrow

  • Account: name, public number, verified email (required), notification settings, balance, blocks.
  • Sign-in via Discord, Telegram (chat ID and @username) or VK (first name, last name and email from VK ID).
  • Deals: subject, terms, amounts, statuses, disputes and arbiter decisions.
  • Deal correspondence, including a private thread with the arbiter. The arbiter sees all the correspondence of the deal whose dispute they are handling.
  • Attachments in correspondence open via a link; do not send in them anything that must not be shown to outsiders.
  • Deal reviews are public on the participant’s page.

8Minecraft server

  • Account: nickname, password (stored only as a bcrypt hash), a link to Discord (you can’t join the game without it), registration date. We do not collect email addresses.
  • IP address at registration and sign-in, sign-in log (time, IP, AFK time); the IP also ends up in the game servers’ logs.
  • Hardware ID (HWID): the launcher computes it from the serial numbers of the drive and motherboard and from monitor, graphics card, memory and processor data — to protect against multi-accounts and ban evasion. The MAC address is not collected.
  • Game logs: actions with blocks, chests and items, chat and commands (including private messages), deaths and dropped items, money movements, positions every 5 minutes (kept for 14 days), inventory snapshots (14 days), teleports (30 days) — for handling complaints, rollbacks and detecting violations.
  • Punishments and their reasons; in-game requests are kept for 30 days after the last message, and the conversation is passed to the AI assistant for requests without nicknames.
  • Forum posts, staff applications (including age), bugs and ideas submitted from the account page; launcher crash reports (nickname, OS, error text; only the latest 500 are kept); skins and capes — you can delete them on the account page.
  • The server does not record voice chat. So that villagers and “Echo” can talk with you, speech is recognized on our server and discarded immediately. Villager voices are synthesized by fish.audio — it receives only prewritten phrases, without your nickname or your words. The voice chat mod lets players record conversations on their own computer — they are responsible for such recordings themselves.
  • You can have your account deleted on request to the server’s administration.

9AI and machine translation

Some features run on Anthropic’s Claude models. They receive only the text needed for a reply — without your IDs, email or payment data.

  • The support AI assistant on the Echo Studio server: the text of your question, the message you replied to, and in help channels also attached screenshots and text files. The question is stored on our side to track limits.
  • The setup AI assistant in the dashboard: your message and what is needed to advise on the server — channel names, roles the bot can give, and current Echo settings. The conversation is stored on our side: it is used to count free and paid requests, and the Echo team reviews requests to stop abuse. Questions to the assistant and applied plans are visible to the server's administrators in the change log.
  • “Echo” on the Minecraft server (when enabled): your nickname, your lines and the game situation — location, time, nicknames of nearby players. “Echo” keeps a short memory of each person it talks to on our side; it can be erased on request.
  • AI requests are briefly saved in service files on our server.
  • Translation on our Echo Studio server: news, the changelog, ideas, poll questions and the text of replies to direct messages are translated automatically.

10Logs and security

  • Web server logs (IP, time, page address, browser) are kept for 14 days.
  • Sign-ins to the website and the Minecraft account page are recorded in an internal log: outcome, sign-in method, name, IP and device.
  • The server is protected by BitNinja: it sees the IP addresses of incoming requests; information about attacks is kept for 3 days.
  • Rate limiting works by IP in memory and saves nothing.
  • Dashboard access is granted only after signing in via Discord and checking your permissions on the server; every action is checked against permissions.
  • Sessions are encrypted (AES-256-GCM), protective HTTP headers are in effect (CSP, HSTS and others), and a browser check runs at entry; two-factor protection via Telegram is available as an option.

11Who receives data

We do not sell data, do not show ads and do not use tracking services. Data goes only to those without whom a feature cannot work:

  • Discord — running the bot, website sign-in, bot messages.
  • Telegram — linking, two-factor protection, escrow sign-in, payment via Crypto Pay.
  • YooMoney and Crypto Pay — payments (see “Payments and balance”).
  • fotora.ru — your verified email, to show your albums.
  • Anthropic (Claude) — texts for AI features and translation.
  • VK — escrow sign-in via VK ID.
  • YouTube, RuTube and Twitch — public requests about the channels you specified for alerts; no personal data is shared.
  • fish.audio — voice synthesis for Minecraft villagers (prewritten phrases only).
  • YouTube and SoundCloud — music search for your query; MEE6, Tatsu, Amari and Lurkr — level import, if the server’s administration started it.
  • Addresses set by the server’s administration in integrations (Premium): the bot sends server events there — member ID and name, levels, purchases, tickets.
  • BitNinja — server protection.
  • We will disclose data only if required by law or by an official request from authorized bodies.

12Where and how long data is kept

Data is stored on a rented server in the Netherlands.

  • Logs of deleted and edited messages — 7 days, 90 days with Premium.
  • Ticket transcripts — 30 days, 1 year with Premium.
  • Daily statistics — 32 days, 1 year with Premium; settings change log — 31 days; server joins — 100 days.
  • Web server logs — 14 days; attack information — 3 days; badge clicks — 60 days.
  • When the bot leaves a server, that server’s data is deleted after 7 days (except the store and reports).
  • Accounts, payments, deals and game data are kept while you use the service and for as long as they are needed for settlements, disputes and protection against violations. You can delete your account yourself in your account settings — what is deleted and what is anonymized is described under “Your rights”.
  • A “Request my data” package is kept for 14 days after approval, a rejected one is deleted immediately; email confirmation codes are valid for 15 minutes.
  • Emails to the project's mailbox are kept as long as they are needed to reply; emails filed as spam are deleted after 30 days.
  • The security sign-in log is kept for 30 days; records of account blocks are kept as long as they are needed to protect against violations.

13Age

The services are intended for people who have reached the minimum age for using Discord in their country. We do not knowingly collect data from children below that age.

14Your rights

  • Get a copy of your data: your account → “Data & account” → “Request my data”. You choose the categories, the site builds a ZIP archive (a JSON file per table and a README in your language), the team checks the package so that nothing belonging to others ends up in it, and we email you. You can download the package for 14 days, after which the file is deleted. Requests are limited to once every 30 days; a rejected request doesn't count.
  • Delete your Echo account: in the same place, “Delete account”. We send a six-digit code to your verified Discord email (valid for 15 minutes, up to 5 attempts), and deletion is scheduled in 30 days — you can cancel it in your account during that time, and we send a reminder 3 days before. Deletion can't be scheduled while an escrow deal is open, a deal claim is under review, an escrow or store withdrawal hasn't been paid out, there's money on your escrow balance or a protected payment hasn't been credited.
  • On deletion we erase your profile and email, Telegram and fotora connections, bio page, badges, notifications, server and game stats, your applications, reviews, posts, ticket transcripts and message copies; your balance is forfeited with no refund, Premium stops renewing, the partnership is removed and your own bot's token is deleted.
  • Anonymized — the ID is replaced with a random one, names and texts are erased, amounts and dates remain — are payments, balance history, store orders, used promo codes, escrow deals and money: they are needed for accounting, refunds and dispute resolution. Unchanged: punishments and staff records on servers (they belong to the servers), restrictions from the project's moderation (otherwise deletion would lift a ban) and the project team's action log.
  • Deletion removes your Echo account, not your Discord account: your Discord account, server memberships and messages in channels stay. The Minecraft account is a separate game-server account; to delete it, contact the Minecraft server's support.
  • Ask us to correct your data — except for what we are required to keep for settlements and for handling violations.
  • Revoke access: remove the bot from the server, sign out of the website, unlink Telegram, revoke Linked Roles in Discord.
  • For anything else, write to support on our Discord server: discord.gg/echo-ass.
  • You can also email us at echo@echo-assistants.tech — that is also where you can ask us to delete your correspondence with us.

15Changes to the policy

We update the policy when the service changes. The current version is always on this page, with the date at the top; we announce significant changes in the news.