This document is written for Adhi Studio’s current product and infrastructure. If a feature materially changes, this page will be updated to reflect the new practice.
Scope and our role
This Privacy Policy explains how the operator of Adhi Studio (“Adhi Studio,” “we,” “us,” or “our”) handles personal information when you use our website, editor, APIs, and related services (the “Service”). It does not govern Discord, Vercel, Turso, external websites, or other services that operate under their own privacy policies.
Information we collect
Discord account information
When you sign in, Discord provides the account identifier, display name or username, email address, avatar, and OAuth account data needed to maintain the connection, which can include access and refresh tokens, scope, and expiry information. We request only theidentify and email OAuth scopes.
Bot and server connection information
When you connect a bot, we process its token, bot identifier, username, avatar, application identifier, public key, server and channel identifiers and names, permissions, and verification time. Bot tokens are encrypted before database storage and are never included in data exports.
Content and activity
We store projects, versions, personal templates, component settings, mention preferences, interaction actions, message payloads, Discord message and channel identifiers, emoji import source and destination identifiers, send timestamps, account settings, and security or audit events generated through use of the Service. Source emoji images are fetched from Discord’s CDN and sent to the selected Discord server; we do not keep a separate asset copy after that operation.
Uploads
For uploaded media or files, we store the file with Vercel Blob and store metadata in Turso, including its public URL, path, filename, media type, size, alternative text, owner, and creation time.
Technical information
Our hosting and security providers may process IP address, request metadata, browser and device information, timestamps, error details, and rate-limit data needed to deliver and protect the Service. We do not currently use behavioural advertising trackers.
Where information comes from
- Directly from you when you edit content, upload files, configure a bot, or contact us.
- From Discord when you authorise sign-in or request bot, server, channel, and message operations.
- Automatically from the Service and its infrastructure when you sign in, save, send, upload, or use security-sensitive features.
How we use information
We use information to:
- authenticate you and maintain secure sessions;
- save, version, preview, validate, export, and delete your work;
- connect your authorised bot, discover available channels, and send or update messages at your request;
- store and serve uploads referenced by your message components;
- process configured interactions and record delivery history;
- prevent abuse, enforce limits, diagnose errors, and protect accounts and infrastructure;
- respond to support, legal, or security requests; and
- maintain and improve reliability, accessibility, and product design.
Legal bases
Where data-protection law requires a legal basis, we process information as needed to provide the Service and perform our agreement with you; for legitimate interests such as security, fraud prevention, support, and product reliability; with consent where we specifically ask for it; and to meet legal obligations or protect legal rights. You may withdraw consent at any time, but this does not affect earlier lawful processing.
Public uploads and Discord delivery
Uploaded assets use public, hard-to-guess URLs so Discord can retrieve and render them. Anyone who receives or discovers such a URL may be able to access the asset. Do not upload confidential information, private keys, passwords, tokens, identity documents, or content that should remain access-controlled.
Messages sent to Discord are then controlled by Discord and the destination server. Account deletion in Adhi Studio cannot recall or delete copies already delivered to Discord.
Retention and deletion
We keep account and Service data while your account is active and as needed to provide the features you use. Security, audit, transaction, and legal records may be retained longer where reasonably necessary to prevent abuse, resolve disputes, comply with law, or establish legal claims. Rate-limit records expire after their operational window.
You can delete your account from Settings. The deletion flow removes your database account and associated projects, versions, templates, messages, connections, actions, sessions, and upload records, and requests deletion of associated Vercel Blob objects. Limited copies may remain temporarily in provider backups or logs until their normal expiry. Discord messages already sent remain on Discord until removed there by an authorised user or bot.
Security
We use measures designed for the sensitivity of the information, including encrypted bot-token storage, HTTP-only production session cookies, account-scoped database queries, origin checks on mutating requests, rate limits, validation, and redaction of public errors. No system is perfectly secure. Protect your Discord account and bot credentials, use least-privilege bot permissions, and rotate a bot token immediately if you suspect exposure.
Your choices and privacy rights
Settings lets you download a JSON export of core profile, project, template, send, upload metadata, connection metadata, and interaction data. Bot tokens are excluded. You can also delete your account and associated Service data there.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, or to complain to a data-protection authority. To make a request that cannot be completed in Settings, email itz.adhi206@gmail.com. We may need to verify your identity and may retain information where law permits or requires it.
International processing
The Service and its providers may process information in countries other than your own. Those countries may have different data-protection laws. Where required, we rely on recognised transfer mechanisms or other lawful safeguards used by us or our service providers.
Children
The Service is not directed to anyone below Discord’s minimum permitted age or the minimum age required by local law. We do not knowingly collect personal information from a child who is not permitted to use the Service. If you believe this has happened, contact us so we can investigate and delete the information where appropriate.
Changes and contact
We may update this Policy as the Service, law, or providers change. We will update the effective date above and, for material changes, provide additional notice where appropriate. The revised Policy applies prospectively from its stated effective date.
Privacy questions or requests may be sent to itz.adhi206@gmail.com. For the rules governing use of the Service, see our Terms of Service.