Privacy Policy
Last updated: 2026-07-21.
Overview
This Privacy Policy explains what data AntiLink collects, how it is used, how long it may be kept, and what choices you have.
By inviting AntiLink to a Discord server, using AntiLink commands, accessing the AntiLink dashboard, redeeming premium, or otherwise using the service, you agree to this Privacy Policy and the AntiLink Terms of Service.
AntiLink operates on Discord and depends on Discord's platform, APIs, bot gateway, permissions system, and OAuth system. Discord may separately process your Discord account, server, and platform data under Discord's own policies:
- Discord Privacy Policy
- Discord Terms of Service
- Discord Community Guidelines
- Discord Developer Terms of Service
- Discord Developer Policy
Who operates AntiLink
AntiLink is operated by its developer from Jordan.
AntiLink's hosting, servers, databases, or infrastructure may be located in Germany, the European Union, or other locations depending on operational, security, performance, and availability requirements.
Data may be processed or accessed from different locations where necessary to operate, secure, maintain, support, or improve AntiLink.
Discord gateway intents
Discord requires bots to declare which "gateway intents" (categories of real-time events) they use. AntiLink uses the minimum intents needed for its features:
- Guilds - to know which servers AntiLink is in and their basic channel and role structure.
- Guild Messages and Message Content - to read message text as messages are sent so AntiLink can detect prohibited links, phishing, and spam based on your server configuration. Non-matching content is discarded and not stored (see "Message content processing").
- Direct Messages - to deliver notices, such as a message-removed notification, to a user.
- Server Members (privileged) - requested and used only to power the optional Member Defense feature (raid and mass-join protection). This privileged intent is off unless the bot operator enables Member Defense, and even then AntiLink uses it only to receive member join events for real-time raid protection, never to download or store your server's general member list. See "Member Defense data".
AntiLink also uses standard non-privileged event categories (server moderation and bans, voice states, invites, and webhooks) to power optional features such as server-event logging, community activity insights, and webhook-abuse protection. AntiLink does not use the Presence intent and does not track member online status or activities.
What we collect
AntiLink only collects data that is needed to operate the bot, dashboard, premium system, moderation features, whitelist system, localization features, logging, security, abuse prevention, and support.
Server configuration
When AntiLink is added to a Discord server or configured by authorized users, we may store:
- Discord server ID.
- Server configuration settings.
- Protection status, such as enabled or disabled features.
- Blocking and moderation options.
- Log channel ID, if configured.
- Dashboard settings.
- Premium status.
- Premium expiry time, where applicable.
- Selected server language.
- Bot response language settings.
This data is used to make AntiLink work correctly for your server.
Whitelist data
If you configure whitelist features, we may store the whitelist entries you choose to add, including:
- User IDs.
- Role IDs.
- Channel IDs.
- Category IDs.
- URL values.
- Domain values.
- Related server ID.
- Creation or update timestamps, where applicable.
Whitelist data is used to decide what AntiLink should ignore, allow, or treat differently during moderation checks.
Moderation logs
When AntiLink detects or removes a message because of link protection, spam protection, phishing protection, or related moderation rules, we may store limited moderation log data, including:
- Discord server ID.
- Message author's Discord user ID.
- Message author's username or tag, where available.
- Channel ID.
- Detected link or domain.
- Reason for detection or removal.
- Moderation action taken.
- Timestamp of the event.
- Related configuration state, where needed for debugging or dashboard display.
Moderation logs are used to power dashboard activity views, help server staff understand moderation actions, troubleshoot issues, investigate abuse, and improve service reliability.
Member Defense data
Member Defense is an optional, off-by-default security feature that a server owner or authorized staff can enable to protect the server from raids and mass-join attacks. When a server enables Member Defense, AntiLink uses the Discord Server Members intent to receive member join events for that server so it can detect join-spikes, screen the age of newly joined accounts, and take the protective action the server has configured.
When Member Defense is enabled for a server, we may process or store:
- Discord server ID.
- Joining member's Discord user ID.
- Joining member's username or tag, where available.
- The account creation date and account age derived from the Discord user ID, used to flag very new accounts commonly used in raids.
- Join timing information, used to detect join-spikes and raids.
- The type of event, such as a raid join or a too-new account.
- The protective action taken, such as an alert, a quarantine role, a kick, or a ban, and a short technical note about that action.
- Timestamp of the event.
Member Defense data is used solely to detect and mitigate raids, mass-join attacks, and abusive new accounts, to power dashboard and log activity views, and to help server staff review protective actions. AntiLink does not use the Server Members intent to build member profiles, to download or store your server's general member list, or for advertising or analytics unrelated to security.
Message content processing
AntiLink processes message content as messages are sent in order to detect links, phishing attempts, spam links, suspicious URLs, and related violations based on your server configuration.
Non-matching message content is discarded after processing and is not stored.
When a message matches AntiLink's detection rules, AntiLink may store limited log data related to that event, such as the detected link, domain, reason, author ID, channel ID, server ID, and timestamp.
AntiLink does not store full message history.
Dashboard sign-in
When you sign in to the AntiLink dashboard using Discord OAuth, Discord may provide us with limited account and server information needed to authenticate you and show the correct servers.
This may include:
- Discord user ID.
- Username.
- Global name or display name, where available.
- Avatar.
- Discord OAuth access information needed for the session.
- List of servers associated with your account.
- Your server permissions, where available or required to determine access.
This data is used to authenticate you, show the servers you can manage, verify permissions, protect restricted areas, and prevent unauthorized dashboard access.
Premium and code redemption data
If you redeem premium or use premium-related features, we may store:
- Premium code value or code identifier.
- Redemption status.
- Redeeming Discord user ID.
- Discord server ID receiving premium.
- Redemption timestamp.
- Premium expiry timestamp.
- Premium plan or feature level, where applicable.
- Abuse, fraud, chargeback, or support notes, where needed.
This data is used to activate premium, prevent code abuse, resolve support requests, detect fraud, and enforce premium rules.
Admin and team access data
If AntiLink provides owner-only, team-only, or admin-only dashboard areas, we may process and store data needed to control access, including:
- Discord user ID.
- Internal team or owner access status.
- Admin action logs.
- Premium management actions.
- Code generation, redemption, removal, or lookup actions.
- Audit timestamps.
- Security-relevant dashboard events.
This data is used for security, accountability, abuse prevention, and service administration.
Technical and security data
When you use the website, dashboard, bot, API, or support systems, we may process limited technical data, including:
- IP address.
- Browser type.
- Device type.
- Operating system.
- Request timestamps.
- Error logs.
- API request logs.
- Session identifiers.
- Security events.
- Rate-limit events.
- Abuse prevention logs.
This data is used to keep AntiLink secure, prevent abuse, investigate errors, protect infrastructure, and maintain service availability.
Localization data
AntiLink may store language preferences for the website, dashboard, bot responses, or individual Discord servers.
This may include:
- Selected website language.
- Selected dashboard language.
- Selected bot language.
- Server-specific language setting.
- User-specific language setting, where supported.
Localization data is used only to display AntiLink in the selected language and does not change the legal effect of the English version of the Terms of Service or Privacy Policy.
AI assistant data
AntiLink offers an optional AI security assistant (AntiLink AI). It is active only where a server links a paid AI Membership and a server administrator turns it on. When it is used:
- The text of a message sent to a designated AI channel, a short recent conversation history for context, and a snapshot of the server's protection settings are sent to a third-party AI provider to generate a reply. The assistant is a read-only advisor: it can explain settings and propose changes or moderation actions, but a human administrator must approve any action before it takes effect.
- Where an administrator uploads a screenshot to the dashboard AI chat, the image is processed with text recognition (OCR) so the assistant can read it.
- We store a limited conversation history per user and server so the assistant has context, and token-usage counts used to meter your AI Membership allowance and prevent abuse. Conversation history is kept for a limited period that depends on your AI Membership tier and is then deleted.
- We may store optional feedback you give on an AI reply to improve quality.
We send the AI provider only what is needed to answer and do not send your full message history. The provider processes that content under its own terms (see "Data sharing").
Server backup and restore data
Server Backup is an optional feature that a server owner or authorized staff can use to snapshot and rebuild a server's structure. When you create a backup, we store a snapshot of the parts you choose, which may include roles, channels and categories, permission overwrites, server settings, the ban list, and custom emoji and stickers. If you explicitly enable the optional message-archive option, the snapshot also stores a limited number of recent messages, including their text and the posting member's name and avatar, so they can be re-posted on restore. Backups are created and restored only by authorized server staff (restore and delete are owner-only) and are used only to snapshot and rebuild your server.
Community insights data
Community Health is an optional, off-by-default analytics feature. When a server enables it, AntiLink stores aggregate activity counts only, such as the number of messages per channel per day, periodic member-count samples, and voice-join counts. It never stores message content, and it is used only to show the server's own activity trends and post an optional summary.
Insider-threat (Anti-Nuke) data
Where a server enables the optional Anti-Nuke feature, AntiLink may store limited records of dangerous administrative actions and any resulting quarantine, including the acting user's Discord ID (attributed through the Discord audit log), the action taken, and, so a quarantine can be reversed, the roles that were temporarily removed. This is used only to detect and contain insider attacks and to let staff undo a quarantine.
Verification data
Where a server enables the optional Verify feature, AntiLink stores the verification settings (such as the verified role and any minimum account age) and checks a member's account age at the moment they verify. It does not store a general member roster.
Vote rewards data
If you vote for AntiLink on a bot-listing site (such as Top.gg), we may record your Discord user ID, your vote count and streak, and the time of your most recent vote, in order to grant a temporary supporter role and show your vote status. Vote data comes from the listing site's vote webhook.
Custom bot (white-label) data
Where a paid server is assigned a custom (white-label) bot, we store the settings needed to run it, including its application ID, presence, and description, and its bot token in encrypted form. The token is used only to operate that bot on your behalf and is never displayed back to you.
Owner announcements
If we send a server owner a transactional notice by direct message (for example about billing or a security issue), we keep a delivery log (recipient, category, and status). Server owners can opt out of these direct messages from their account preferences, and we keep an opt-out list so we can honor it.
Global blocklist
To prevent abuse, we may keep a global list of Discord user IDs that are blocked from certain AntiLink features (such as the AI assistant), together with a short reason. This is used only for abuse prevention.
Custom command data
Where a server uses the optional Custom Commands feature, we store the command definitions its staff create: the command name, the response template, the optional role action and role, whether the command is enabled, the Discord ID of the staff member who created it, and a usage counter. This is server configuration data, used only to run the commands that server configured. Running a custom command does not store the invoking message or its content.
What we do not collect
AntiLink is designed to collect only the data needed to operate the service.
We do not intentionally collect or store:
- Full message history.
- Non-matching message content.
- Private Discord messages.
- Voice chat audio.
- Voice chat recordings.
- Payment card numbers.
- Government ID documents.
- Your server's general member list or roster. AntiLink does not download or store the full member list; the optional Member Defense feature processes individual member join events in real time and stores only limited records for flagged joins (see "Member Defense data").
- Sensitive personal data unless you intentionally place it into a configuration field, support request, message, whitelist entry, or other area processed by AntiLink.
AntiLink does not use the Discord Server Members intent to collect or store your server's general member list. Where a server enables the optional Member Defense feature, the Server Members intent is used only to receive member join events for real-time raid and abuse protection (see "Member Defense data" and "Discord gateway intents").
What we do not do
We do not sell your data.
We do not rent your data.
We do not use your server data for third-party advertising.
We do not intentionally collect more Discord data than needed to operate AntiLink.
We do not store full message history for servers, except a limited recent message archive that a server owner may explicitly choose to include in an optional Server Backup (see "Server backup and restore data").
How we use data
AntiLink uses collected data to:
- Operate the Discord bot.
- Detect and block unwanted links.
- Detect phishing, spam links, suspicious URLs, and related abuse.
- Detect and mitigate raids, mass-join attacks, and abusive new accounts, and apply protective member actions such as alerts, a quarantine role, kicks, or bans where a server enables Member Defense.
- Apply server configuration.
- Apply whitelist rules.
- Provide dashboard access.
- Show recent moderation activity.
- Manage premium status.
- Redeem and validate premium codes.
- Provide localization and language settings.
- Provide the optional AI security assistant, meter AI Membership usage, and prevent AI abuse.
- Snapshot and restore a server's structure where a server uses Server Backup.
- Show a server's own aggregate activity trends where a server enables Community Health.
- Grant supporter rewards where you vote for AntiLink.
- Provide support.
- Debug errors.
- Maintain uptime and performance.
- Secure the service.
- Prevent spam, abuse, fraud, attacks, and unauthorized access.
- Enforce the AntiLink Terms of Service.
- Comply with legal, platform, or security obligations.
Legal basis for processing
Where data protection laws require a legal basis, AntiLink may process data based on one or more of the following:
- Performance of a service - to provide the bot, dashboard, premium features, whitelist features, and moderation functionality.
- Legitimate interests - to secure the service, prevent abuse, detect fraud, maintain logs, debug issues, and improve reliability.
- Consent - where you choose to authenticate with Discord OAuth, configure the bot, redeem premium, select a language, or provide information through support.
- Legal obligations - where processing is required to comply with applicable law, platform requirements, lawful requests, fraud prevention, accounting, or dispute handling.
Discord OAuth
The AntiLink dashboard uses Discord OAuth to verify your Discord identity and determine which servers you are allowed to manage.
AntiLink does not receive your Discord password.
You can revoke OAuth access from your Discord account settings.
Revoking OAuth access may prevent you from using the AntiLink dashboard until you sign in again.
Cookies and local storage
The AntiLink website and dashboard may use cookies, local storage, session storage, or similar technologies to:
- Keep you signed in.
- Remember dashboard preferences.
- Remember language settings.
- Protect sessions.
- Prevent abuse.
- Improve website functionality.
- Support security features.
You may be able to disable cookies or clear local storage through your browser settings. Some dashboard features may not work correctly if cookies or local storage are disabled.
In practice, the AntiLink sites use only essential cookies: the dashboard sign-in session, your language preference, and a cookie named antilink_consent that remembers your cookie choice itself. We use no analytics cookies, no advertising cookies, and no third-party tracking cookies of any kind.
The website shows a cookie notice on your first visit with three options: accept all, necessary only, or customize. Choosing "necessary only" is respected in a concrete way: your language preference is then kept for the current visit only (a session cookie) instead of being remembered long term. You can change your choice at any time by clearing the antilink_consent cookie in your browser, which makes the notice appear again.
Payment and third-party billing
Paid subscriptions are processed by Paddle (Paddle.com Market Limited), our Merchant of Record. Paddle handles checkout, billing, tax, and payment records on our behalf, and processes your payment information under its own policies:
AntiLink never sees or stores full payment card numbers. When you pay, we receive only what is needed to activate premium for your server, such as the server ID (or, for an AI Membership, your Discord user ID and the linked server), the plan, and a Paddle subscription or transaction reference.
Premium can also be activated with a redeem code issued by our team, which does not involve a payment processor. See the Refund Policy for how billing and refunds work.
Data sharing
AntiLink may share or disclose limited data only when necessary for the operation, security, compliance, or support of the service.
This may include sharing data with:
- Discord, where required by Discord's platform, APIs, enforcement, or safety systems.
- Hosting providers.
- Database providers.
- Security and abuse-prevention providers.
- Payment or premium access providers.
- Support platforms.
- Analytics or logging tools, if used.
- AI providers, only to generate replies for the optional AI assistant, and only the content needed to answer.
- Legal, regulatory, or law enforcement authorities, where required by applicable law.
We do not sell your data to advertisers or data brokers.
Data retention
AntiLink keeps data only for as long as reasonably necessary for the purposes described in this Privacy Policy.
Retention periods may vary depending on the type of data:
- Server configuration may be kept while AntiLink remains configured for the server.
- Whitelist entries may be kept until removed by authorized server staff or deleted through a valid request.
- Premium records may be kept as long as needed to manage premium access, prevent fraud, resolve disputes, or maintain accounting records.
- Moderation logs may be kept for dashboard activity, support, security, abuse prevention, and troubleshooting.
- Member Defense records may be kept for dashboard and log activity, support, security, abuse prevention, and troubleshooting.
- AI assistant conversation history may be kept for a limited period based on your AI Membership tier and is then deleted; AI usage counts may be kept to meter allowances and prevent abuse.
- Server backups may be kept until deleted by an authorized server owner, or pruned automatically as newer backups are created.
- Community Health activity counts may be kept to show trends over time.
- Vote records may be kept to grant supporter rewards and show vote status.
- Security logs may be kept as long as needed to protect AntiLink, investigate abuse, prevent attacks, and maintain infrastructure reliability.
- Support messages may be kept as long as needed to handle requests, maintain records, and prevent abuse.
Some data may be retained after bot removal where necessary for legitimate operational, legal, security, fraud-prevention, accounting, dispute-resolution, or abuse-prevention reasons.
Bot removal
Removing AntiLink from a Discord server stops future bot processing for that server.
Bot removal does not always immediately delete all existing records. Stored configuration, whitelist data, premium records, moderation logs, security logs, or support records may remain for a limited period where needed for security, fraud prevention, support, backups, accounting, dispute handling, or legal reasons.
You may request deletion of stored configuration, whitelists, or logs by contacting support.
Data deletion requests
To request deletion of stored AntiLink data, contact us through:
When submitting a request, include enough information for us to verify and process the request, such as:
- Your Discord user ID.
- The Discord server ID.
- The type of data you want deleted.
- Proof that you are authorized to request deletion for that server, where required.
We may refuse or limit deletion requests where we cannot verify authority, where deletion would affect another user's rights, where data must be retained for security or legal reasons, or where the request is abusive, fraudulent, or technically impossible.
Your privacy rights
Depending on your country or region, you may have rights to:
- Access personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of certain data.
- Object to certain processing.
- Restrict certain processing.
- Request a copy of certain data.
- Withdraw consent where processing is based on consent.
- File a complaint with a data protection authority, where applicable.
These rights may be limited by applicable law, security requirements, fraud prevention, Discord platform limitations, technical feasibility, or the rights of other users.
To make a privacy request, contact:
International data transfers
AntiLink may be used internationally.
AntiLink's infrastructure may be located in Germany, the European Union, or other locations. AntiLink may also be operated, accessed, supported, or maintained from Jordan or other locations.
By using AntiLink, you understand that data may be processed in countries other than your own. These countries may have data protection laws different from those in your country.
Where required by applicable law, we will use reasonable measures to protect data transferred between countries.
Security
AntiLink uses reasonable technical and organizational measures to protect data from unauthorized access, misuse, loss, alteration, or disclosure.
Security measures may include access controls, server-side protections, logging, rate limits, authentication, restricted dashboard access, and infrastructure security practices.
No online service can guarantee complete security. You are responsible for keeping your Discord account, server permissions, staff roles, and dashboard access secure.
If you believe your Discord account, server, premium code, or AntiLink dashboard access has been compromised, contact support as soon as possible.
Backups
AntiLink may maintain backups for reliability, disaster recovery, security, or operational purposes.
Deleted data may remain in backups for a limited period until those backups are overwritten or deleted according to normal backup cycles.
Backups are not used for active moderation unless restored for operational, security, or disaster recovery reasons.
Children's privacy
AntiLink is intended for use through Discord and is subject to Discord's age requirements.
AntiLink is not intended to knowingly collect personal data from children below the age required to use Discord or below the age required by applicable law in their country or region.
If you believe a child has provided personal data to AntiLink in violation of applicable rules, contact support.
Server owner and administrator responsibility
Server owners and administrators are responsible for informing their server members that AntiLink may process message content for moderation purposes and may store limited moderation logs when messages match detection rules.
Where a server enables Member Defense, server owners and administrators are also responsible for informing their members that member join events and account age may be processed for raid and abuse protection, and that protective actions such as an alert, a quarantine role, a kick, or a ban may be applied to accounts flagged during a raid or as too new.
Server owners and administrators are responsible for ensuring their use of AntiLink complies with Discord's rules, local laws, privacy obligations, and their own server rules.
Sensitive information
Do not place sensitive personal information into AntiLink configuration fields, whitelist entries, support requests, dashboard fields, or Discord messages unless you have the legal right and proper authority to do so.
Sensitive information may include, but is not limited to:
- Government identification numbers.
- Financial information.
- Medical or health information.
- Private addresses.
- Passwords or authentication tokens.
- Private keys.
- Highly confidential personal information.
AntiLink is not designed to store or process sensitive personal information.
Automated moderation
AntiLink uses automated processing to detect links, phishing attempts, spam links, suspicious URLs, and related moderation events.
Automated moderation may result in messages being removed, links being blocked, or events being logged based on your server configuration.
Where a server enables Member Defense, automated processing may also, based on that server's configuration, flag or act on members who join during a detected raid or whose accounts are very new - for example by alerting staff, assigning a quarantine role, kicking, or banning. The action mode is chosen by the server.
AntiLink may produce false positives or false negatives. Server owners and staff are responsible for choosing the Member Defense action mode, reviewing AntiLink configuration, and reviewing moderation outcomes.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
When changes are made, we may update the "Last updated" date, publish the revised Privacy Policy on the website, notify users through the dashboard, Discord server, support server, or other reasonable channels.
Continued use of AntiLink after changes become effective means you accept the updated Privacy Policy.
Contact
For privacy questions, deletion requests, support, abuse reports, premium issues, or data-related requests, contact us through: