MasterBot Appeal Hub

MasterBot legal

Privacy Policy

Last updated: May 28, 2026

Privacy Policy / Terms of Service

1. Introduction

MasterBot ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service, including our website, dashboard, APIs, bot hosting, and related features. The English version of this policy is the legally governing version; translations, if any, are for convenience only.

MasterBot is operated by Trolens Design (Poland). The data controller responsible for personal data processed through the Service (your MasterBot account and platform use) is Trolens Design (Poland) ("we", "us", "our"). For EU/UK privacy rights, contact us at trolensdesign@gmail.com (see Section 17).

2. Information We Collect

2.1. Information You Provide

When you register for an account or use our Service, we may collect:

  • Account information such as email address, display name, and internal user identifiers
  • Profile and preferences (for example language) and, where you sign in with a third-party account, profile details provided by that provider (such as Google, GitHub, or Discord) including avatars and public identifiers, depending on your choices and the provider's sharing
  • Bot and product data you configure: flow definitions, variables (including stored variables), node settings, message and embed content, uploaded assets where the product allows, API Request URLs and header metadata, and credentials for HTTP integrations. Most configuration is stored as you enter it so we can run your automations; selected credentials are encrypted when stored (see Section 8)
  • Communication and support data when you contact us (for example, email content and ticket metadata)
  • Billing-related identifiers processed by our payment provider (we generally do not store full card numbers on our systems; see Payment processing)
  • Discord bot tokens and application identifiers needed to run bots you add to the Service (stored securely; see Section 8)
  • Inbound webhook endpoints you create (including access credentials and, when you enable it, optional captured sample payloads for debugging)

2.2. Automatically Collected Information

We automatically collect certain technical and usage information when you use our Service:

  • Usage and product analytics needed to run and improve the Service (for example, request metadata, error rates, and feature usage in aggregated or identifiable form as needed for your account)
  • Device and client information (such as browser type, operating system, and approximate locale where relevant)
  • IP address and network identifiers for security, abuse prevention, and logging
  • Session and authentication data (for example, sign-in cookies or similar technologies required to keep you signed in, depending on your browser settings). We do not use third-party advertising or analytics cookies by default; if that changes, we will update this policy and any consent UI required by law.

2.3. Discord Account Information

When you authenticate or link a Discord account, we may receive information from Discord in accordance with Discord’s policies, such as your Discord user ID, username, and avatar, and we process Discord data needed to run your bot and flows. Separately, we may receive identifiers and event-related data as your bot acts in Discord, depending on the flows and permissions you configure.

2.4. Payments (Stripe)

Paid subscriptions and related billing are processed by Stripe (or another processor we name in checkout). When you pay, Stripe receives payment and account identification data (such as email, country, and payment method where applicable) and may process transactions according to its own terms and privacy policy. We receive limited billing metadata (for example customer and subscription identifiers, status, and invoice references) in our systems to provide access to paid entitlements. We do not store full card numbers on our own systems as part of the standard flow.

2.5. Temporary and operational data

To execute flows, rate-limit requests, and keep sessions coherent, we may process short-lived data for a limited period. This can include temporary run data, throttling state, and similar operational data. It is not intended for long-term archival of your end-user messages beyond what the product's logs surface to you in the interface.

2.6. Logs, debug, and security

We may log technical events and flow execution details for security, support, and abuse prevention. If you or users on your team use debugging features, additional execution details may be stored or displayed in the product for a period consistent with the feature (for example, flow debug output). Some security or compliance records may be retained in anonymized form after you delete your account. We aim to limit sensitive personal data in logs and restrict access to authorized staff and account members as the product's roles allow.

2.7. Collaboration and invitations

Where the Service supports real-time or asynchronous collaboration, we process collaborators' user identifiers, access grants, and invite tokens, and your browser may store pending invite or navigation state temporarily. Invitations and sharing determine who can edit or view a resource.

2.10. Referral program

If you participate in our referral program or sign up through a referral link, we process referral identifiers, attribution to the referring account, and related commission or discount metadata. We may use referral cookies or similar browser storage for up to 30 days to attribute signup correctly. See Section 11 for details.

2.11. Product analytics (Bot Analytics and Year Wrapped)

When you use Bot Analytics, Year Wrapped, or similar in-product statistics, we process aggregated usage data about your bots and flows (for example command counts, execution outcomes, session metadata, and performance metrics) to display dashboards to you. This is first-party product analytics controlled by us, not third-party advertising tracking.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our Service, including running your bots and flows
  • Process your transactions, manage subscriptions, and apply plan entitlements
  • Send transactional notices (for example security, billing, or service updates) and respond to support requests
  • Enable collaboration, sharing, and role-based access within your workspace
  • Display Bot Analytics, Year Wrapped, and similar product statistics to you
  • Operate referral attribution, commissions, and related program accounting
  • Monitor usage patterns to improve reliability, performance, and product design
  • Detect, prevent, and address technical issues, abuse, fraud, and security threats
  • Comply with legal obligations and enforce our Terms of Service

4. Legal Bases for Processing (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on the following legal bases depending on the activity:

Processing activityTypical legal basis
Account, bots, flows, collaboration, and paid entitlementsPerformance of a contract (or steps at your request before contract)
Security, abuse prevention, logging, rate limits, and service reliabilityLegitimate interests (balanced against your rights)
Tax, invoicing, and accounting recordsLegal obligation
Referral attribution at signupLegitimate interests and/or contract (program terms)
Optional marketing communications (if we offer them in the future)Consent (you may withdraw at any time)

5. Sharing, Subprocessors, and Disclosure

We do not sell your personal information. We may share information only as described below, including with subprocessors that process data on our behalf to operate the Service.

  • With your consent or at your direction (including data you send to external URLs via flows)
  • With service providers who assist us in operating the Service
  • To comply with legal obligations or respond to lawful requests
  • To protect our rights, privacy, safety, or property, and that of our users
  • In connection with a business transfer, merger, or acquisition

Typical subprocessors (user-facing)

We use the following categories of third parties. We do not publish hosting vendor names or internal architecture details:

  • Stripe - payment processing (see stripe.com/privacy)
  • Discord - platform integration and sign-in (see discord.com/privacy)
  • Google and/or GitHub - third-party sign-in when enabled (see their respective privacy policies)
  • Cloud infrastructure providers - hosting and essential service operations

This list may change as the Service evolves. See also our Subprocessor list.

6. Third-Party Services You Configure

When you configure API Request nodes, outbound webhooks, or other integrations with external URLs, we transmit payloads, headers, and data you define to those endpoints on your instructions. We are not responsible for how third-party services collect, use, or secure that data. You are responsible for having a lawful basis and complying with the policies of every service you connect to.

7. Your Bots and Discord End Users

When your bots run on Discord, we process event and message data needed to execute your flows (for example Discord user IDs, usernames, avatars, message content, roles, and channel or guild metadata), depending on the events, permissions, and nodes you configure. For that end-user processing, you are typically the data controller toward your server members and we act as a processor on your instructions. You are responsible for having a lawful basis and, where required, your own privacy notice for your bot users.

If you need a Data Processing Agreement (DPA) describing our processor role, contact us at trolensdesign@gmail.com. We will provide applicable terms on request.

8. Data Security

We implement technical and organizational measures appropriate to the risk, including secure connections for data in transit, access controls, and encryption for selected sensitive information when stored.

The following types of credentials are encrypted when stored: Discord bot tokens, API Request secrets you save in the product, and inbound webhook access credentials. Other data you provide - including flow definitions, variables, message text, URLs, webhook sample captures, and debug output - is stored and logged as needed to operate the Service. You choose what personal or third-party data those flows store, log, or transmit to external services. We do not use customer flow content to train AI or machine learning models. Backups and internal access are treated as high-sensitivity. No method of storage or transmission is 100% secure; we cannot guarantee absolute security.

9. Retention and Account Deletion

We retain account, bot, and flow data for as long as your account and the related resources exist, unless you delete them earlier. Billing and invoice records are kept as required by tax and accounting law (including records held by Stripe). Short-lived execution data expires automatically after a limited period. Application and execution logs are kept for operational, support, and security needs for a limited period and may contain metadata from your flows.

You may delete your account in the product (Profile - Delete Account). When you do, we stop your running bots and delete your account and associated content such as bots, flows, variables, secrets, and settings. Some anonymized security or compliance records may remain. Residual copies in backups may persist for a limited period before being overwritten. Payment history at Stripe is retained according to Stripe's and applicable legal requirements.

10. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information, including:

  • Access and receive a copy of your personal data
  • Rectify inaccurate or incomplete information
  • Request deletion of your personal data
  • Object to or restrict processing of your data
  • Data portability
  • Withdraw consent where processing is based on consent

To exercise these rights, contact us at trolensdesign@gmail.com or use in-product account tools where available (for example account deletion). We aim to respond within 30 days, extendable where permitted by law. We may need to verify your identity. If you are in the EU/UK, you also have the right to lodge a complaint with a supervisory authority; we ask that you contact us first so we can try to resolve the issue.

United States state privacy laws: If you are a resident of California or another U.S. state with similar privacy laws, you may have additional rights to know, delete, and correct personal information we hold about you. We do not sell personal information as defined by those laws. Submit requests to trolensdesign@gmail.com with enough detail for us to verify your account.

11. Cookies and Similar Technologies

We use cookies and similar technologies only where needed for security, sign-in, referral attribution, or essential product functionality. We do not use third-party advertising cookies by default. Treat your device and browser as part of your security boundary. You can block or clear cookies in your browser; if you do, parts of the Service may not work.

NamePurposeDurationType
Auth / session cookiesKeep you signed in and secure sessionsSession or as configuredEssential
Referral cookieAttribute signups to a referral linkUp to 30 daysFunctional
Referral cookie (pre-signup)Remember referral link before you create an accountUp to 30 daysFunctional
Browser storage (referral)Same purpose as referral cookies when your browser uses storage insteadUntil cleared by you or the browserFunctional

12. International Transfers

We use third-party infrastructure and service providers to operate the Service. Your data may be processed in countries where those providers operate. We do not publish hosting vendor names or internal architecture. Where personal data is transferred from the EEA, UK, or Switzerland to countries not deemed adequate, we use appropriate safeguards such as the EU Standard Contractual Clauses, as required, with vendors who support them.

13. Staff Access and Security Incidents

Access to our systems and customer data by our personnel is limited to what is necessary for support, abuse investigation, security, billing assistance, or legal compliance. We apply least-privilege access and do not routinely read user flow content except when needed to resolve a specific issue you report or to address abuse, fraud, or a security incident.

If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and/or relevant authorities as required by applicable law.

14. Automated Decision-Making

We do not use automated decision-making, including profiling, that produces legal or similarly significant effects concerning you. Bot automations you build run according to your own flow logic; those are under your control, not ours.

15. Children's Privacy

Our Service is not intended for users under the age of 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at trolensdesign@gmail.com.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and change the "Last updated" date. If we make material changes, we will use reasonable efforts to provide additional notice (for example in-product notice or email to the address on your account). Continued use of the Service after changes take effect may constitute acceptance, subject to your mandatory rights.

17. Contact Us

If you have questions about this Privacy Policy or want to exercise your privacy rights, contact:

Trolens Design (Poland) - operator of MasterBot

Email: trolensdesign@gmail.com

We aim to respond within a reasonable time. If you are in the EU/UK, you may also lodge a complaint with your local supervisory authority.

Terms of Service / Back to Appeal Hub