Back to home

Privacy Policy

Last updated: September 18, 2026

Mist is a Discord bot and companion dashboard. It runs commands in your servers, powers user-install app commands, and gives you a dashboard to manage settings and see activity. This Privacy Policy explains what data we collect, why we collect it, how long we keep it, and the choices you have over it.

By using Mist, the dashboard, or any premium subscription, you agree to the collection and use of information as described here.

Information we collect

We collect only the information needed to make Mist work. Most of it comes from Discord itself when you invite the bot, use a command, or sign in to the dashboard.

Discord identifiers. When Mist joins a server, we store the server (guild) ID and the IDs of users who use the bot. These are Discord snowflake IDs, which we treat as opaque identifiers. We never use them to build a profile of you outside of Mist.

Profile information. When you authorize Mist through Discord, we read your username, discriminator, avatar, and locale. We keep a copy so the dashboard can show who you are and so command logs can attribute actions to a user.

Messages processed for commands. When you run a message-prefix command, we receive the message text so the command can execute. We use the arguments to run the command and then discard the raw message. We do not read or store messages that are not command invocations.

Economy data. Mist provides economy features such as wallets, banks, and balances. We store the balances, transaction history, and related items you create or earn through these commands.

Command usage analytics. We record which commands run, when, in which server, and by which user, along with whether they succeeded and how long they took. This helps us find broken behavior, measure reliability, and understand what features people actually use.

Dashboard account data. When you sign in to the dashboard, we create an account tied to your Discord ID and store your dashboard settings and preferences.

OAuth tokens. When you connect your Discord account to the dashboard, Discord issues us tokens with the user_connections scope. We encrypt these tokens at rest with AES-256-GCM and use them only to keep your connection valid. We do not use them for anything else.

Misty AI assistant

The dashboard includes Misty, an AI assistant. When you send a message to Misty, we send your prompt, the recent conversation, and the relevant server data the assistant needs to answer (such as activity counts or the settings you asked about) to a third-party language-model provider to generate a response.

We do not use your prompts or Misty conversations to train any model. Our model providers are configured so that data sent through their API is not used to train their models.

By using Misty, you agree that we may process and review your prompts and the assistant's replies, including through the provider, to operate the feature, keep it safe, and improve it. We do not sell this data or use it for advertising.

Misty only accesses data for the server you have open, through the same permission checks as the rest of the dashboard. We keep AI usage counters to enforce the free and premium limits described in the Terms of Service.

Why we collect it

We use the information we collect for three purposes: to operate the bot, to operate the dashboard, and to improve the product.

Operating the bot means running commands you ask for, storing the economy and moderation state those commands manage, and enforcing permissions and cooldowns. Operating the dashboard means signing you in, showing your servers, and applying the settings you change.

Improving the product means analyzing command usage and failure rates so we can fix bugs, remove broken features, and decide what to build next. We look at this data in aggregate, not to observe any individual user.

We do not use your data to advertise to you, and we never sell it.

Storage, security, and encryption

Mist stores data in three places: a PostgreSQL database for durable records, a Redis cache for hot configuration, cooldowns, and rate limits, and Cloudflare R2 for error storage and autopost or image service files.

PostgreSQL holds the long-term truth: economy balances, command usage events, server settings, and your dashboard account. Redis holds short-lived values that need to be fast and is not a source of truth for anything that matters.

OAuth tokens are encrypted at rest using AES-256-GCM. We also use encryption in transit: all communication with Discord, the dashboard, and our servers runs over TLS.

We follow standard security practices: secrets live in encrypted environment storage, access to production databases is limited to the minimum set of people and services, and we review access when people leave the project. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Data retention

We keep data only as long as it serves a purpose. Command usage events and message events are kept for a rolling period so the dashboard and analytics stay useful, after which they are deleted or aggregated.

Redis entries expire automatically based on their type. Cooldowns and rate limits expire in seconds or minutes. Guild and user caches are rebuilt as needed and are not permanent records.

Economy balances, server settings, and your dashboard account are kept for as long as you continue to use Mist. If you remove the bot from a server or delete your account, we delete the data tied to that server or account as described below.

Backups may contain older copies of data for a short recovery window. We delete backups according to a regular rotation and never treat them as an indefinite archive.

Data sharing

We do not sell, rent, or trade your data to anyone. We share data only in the following limited ways.

Discord. Mist necessarily exchanges data with Discord to function: commands, messages, and server state are sent to and received from the Discord API. That data is subject to Discord's own terms and privacy policy.

Service providers. We use infrastructure providers to host the database, cache, object storage, and servers that run Mist. These providers process data on our behalf under our instructions and do not use it for their own purposes.

Legal requests. We may disclose information if the law requires it, such as in response to a valid subpoena or court order, or to protect the rights, property, and safety of Mist, our users, or the public.

Data deletion and export

You can delete most of your data yourself. Removing Mist from a server deletes that server's settings and economy state. You can delete your dashboard account from the dashboard settings, which removes your account and associated data.

To request deletion or an export of your data, contact us at the address below. We will confirm it is really you, then fulfill deletion requests within 30 days and export requests within the same window.

Some data may remain in backups for a short time after deletion, as described in the retention section, and we keep aggregate, de-identified statistics that no longer identify you.

Minors

Mist is not directed at children, and we do not knowingly collect personal information from anyone under the age of 13. Discord requires users to be at least 13 years old, and our Terms require the same.

If you believe a child under 13 has provided us personal information, contact us at the address below and we will delete it as promptly as we can.

Your rights

Depending on where you live, you may have rights over your data, including the right to access it, correct it, delete it, restrict or object to its processing, and receive a copy in a portable format.

To exercise any of these rights, contact us at the address below. We respond to verified requests within 30 days. We may ask for information to confirm your identity before acting.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where practical, notify you through the dashboard or Discord.

Your continued use of Mist after changes take effect means you accept the updated policy. If you do not agree, you can stop using Mist and delete your data.

Contact us

If you have questions about this Privacy Policy or how we handle your data, you can reach us by joining our support server and messaging the team, or by emailing [email protected]. We read and respond to privacy questions ourselves, not through automated replies.