Privacy
How Kordyn handles data
This page describes the current technical data flows. Operator contact details and the final legal wording must be completed before a public commercial launch.
Technical draft · August 2026
Data used by the service
Kordyn processes Discord account identifiers, manageable server identifiers and the configuration you save. Member activity is only stored when an enabled module needs it, for example message counts for XP or ticket metadata for support. Optional Reaction XP never stores message content or emoji; its anti-replay ledger keeps guild-bound SHA-256 event, message and reactor hashes, recipient mode/count and timestamps, while the normal member XP ledger identifies the credited recipient. Live Counters receives aggregate member, role, voice, boost, emoji and sticker totals only; its refresh ledger stores counter/channel IDs, rendered aggregate names and finite retry state, never member IDs, Presence history, message content, emoji names or sticker names. Ticket support teams store Discord role and team identifiers only; ticket snapshots freeze those identifiers for access and routing without copying role membership or message content. On-call schedules store configured weekdays, times, timezone and explicitly selected Discord member IDs. Current coverage is resolved transiently and Kordyn does not retain attendance, presence or response history. Ticket service-hours configuration stores administrator-selected timezone, recurring time windows, local-date exceptions, bypass role IDs, mode and closed message. A member's roles and the open/closed decision are checked transiently when a ticket is requested and are not logged or retained. Saved ticket replies are administrator-authored configuration. Their delivery ledger contains scoped identifiers and status only, while usage analytics keep an aggregate count and last-used time without the staff member's identity or a rendered message copy. Dashboard Reply Bridge text is transferred transiently to Discord and is not stored by Kordyn; its 90-day replay ledger contains a SHA-256 hash, scoped identifiers and finite delivery state, but no body or operator identity. Ticket ownership history stores finite claim, release and handoff transitions with optional actor/from/to Discord IDs, but no ticket text, reason, display name or role membership; public dashboard responses omit internal operation keys.
Welcome DM Guide
A server manager may turn the existing single join DM into a bounded embed with administrator-authored title, body and footer, the existing optional public HTTPS image and up to five labels plus Discord text-channel IDs. Kordyn derives every button URL from the current server and selected channel; arbitrary external URLs are not accepted. The buttons are Discord link buttons without an interaction ID, so Kordyn receives and stores no click or channel-view event. This feature adds no member record, delivery history or recipient message content. Free, Grace and Premium activate the first 1/3/5 saved links; downgrade overage remains stored but is not delivered. Deleted-channel repair removes stale links. Blocked DMs prevent only that best-effort greeting and never change the remaining join actions. Existing server export and irreversible server deletion cover the configuration JSON. Public production activation stays disabled until live desktop/mobile Discord, blocked-DM, deleted-channel, permission, downgrade and burst drills pass.
Native Onboarding Studio v1
A native Discord server manager may import and update the server's official Community Onboarding configuration. Kordyn stores only manager-authored revision snapshots containing enabled/mode state, prompt and option copy, emoji metadata and referenced Discord channel/role IDs, plus SHA-256 before/after fingerprints, finite lifecycle/error state and timestamps. It never requests or stores a member's onboarding answers, chosen roles, channel choices, completion state, profile, message content or click/view history. Every apply refetches live Discord state, rejects a stale fingerprint, requires Manage Server and Manage Roles, permits only current assignable non-management roles, and enforces Discord's seven-default/five-publicly-writable readiness rule before enabling. Kordyn records the Discord-confirmed response, including newly assigned prompt/option IDs. If final persistence fails after Discord changes, it attempts exact restoration; unresolved compensation is explicitly marked for manual recovery. Free/Grace/Premium show the newest 3/25/100 revisions, retain terminal revisions for 7/90/365 days and allow rollback for 24 hours/7 days/30 days. Server export includes revision lifecycle metadata and fingerprints but excludes configuration snapshots and channel/role IDs; server deletion cascades all revisions. Public production activation stays disabled until live Community enablement, desktop/mobile editing, manual Discord drift, newly assigned IDs, permission revocation, PostgreSQL restart/multi-replica, compensation, retention, export and deletion drills pass.
QOTD Discussion & Response Lab v1
When a server manager enables Question of the Day discussions, Kordyn creates one public Discord thread from each QOTD message and observes only the first human message each member sends in that exact thread during the following 24 hours. Kordyn never stores response text, attachments, embeds, reactions, usernames, display names or sentiment. Durable response rows contain the server/publication relation, response time and separate HMAC-SHA-256 pseudonyms for member and message replay protection; neither pseudonym is returned by the dashboard or server export. Publication rows contain the manager-authored question snapshot, rotation index, local date, destination/message/thread IDs, finite prepare/claim/retry/error state and timestamps. The private manager dashboard and server export expose aggregate unique-responder counts and sanitized publication lifecycle only; these are observational metrics and make no causal claim. Free/Grace/Premium retain 14/90/365 days and 14/90/365 rows; public discussion threads remain available on Free, while Grace/Premium add custom archive duration and slowmode. Member-data deletion recomputes the member pseudonym and deletes matching responses; server deletion cascades all publication and response rows. Enforced Discord nonces, an idempotent thread lookup, external-ID checkpoint, tenant lock and atomic publication/config finalization suppress duplicates; incomplete compensation becomes a visible manual-recovery state. Public production activation stays disabled until live Discord permission, desktop/mobile, crash-after-send, PostgreSQL multi-replica, downgrade/renewal, retention, export and deletion drills pass.
Member Milestone Roles v1
A server manager may configure delayed add or remove actions for safe Discord roles. Free, Grace and Premium activate the first 3/10/25 saved rules with maximum delays of 7 days/365 days/10 years; downgrade overage remains stored but plan-paused. For bounded existing-member reconciliation, Kordyn processes at most 250 Discord members per request and transfers only server identity, member Discord ID, bot flag and exact joined_at time through the authenticated internal boundary. It transfers no username, display name, role-membership snapshot, Presence detail or message content, and bots are excluded. The existing durable job row retains server, member, rule, target-role, action, exact join and finite claim/retry timestamps. A unique exact-join key prevents duplicates, and execution refetches membership plus current role safety so rejoined members and managed, above-bot, moderation or server-management roles are skipped. Member-data deletion removes that member's jobs, server export includes the scoped identifier/timing rows and server deletion cascades them. Public production activation stays disabled until live large-guild paging, privileged-intent, permission drift, multi-replica PostgreSQL, downgrade, renewal, export and privacy-deletion drills pass.
Native Community Role Invites v1
A native Discord server manager may create one official role-bearing Community Invite for a selected text channel. Free, Grace and Premium allow 1/3/10 safe roles, maximum lifetimes of 24 hours/7 days/7 days and use caps of 5/25/100. Kordyn refreshes the current plan and Discord resources, requires Create Instant Invite plus Manage Roles and rejects managed, above-bot, moderation, audit-log, server, channel, webhook or role-management roles. The complete invite URL is returned in the successful response exactly once and is not retained in PostgreSQL, audit metadata, application logs, analytics or server export. The content-free audit event contains only server/channel context, role IDs, lifetime, use cap and demo/live mode; if that write fails after Discord creation, Kordyn attempts to revoke the invite. Kordyn stores no recipient, click, acceptance or role-assignment result and does not connect invitation volume to roles, coins or giveaways. Public production activation stays disabled until live desktop/mobile acceptance, expiry/use-cap, permission/hierarchy drift, plan, concurrent-create, compensation and redaction drills pass.
Recurring Native Polls v1
A server manager may store administrator-authored native poll schedules containing a name, Discord text-channel ID, question, two to ten answers, duration, multiple-choice setting, IANA timezone, local hour and weekdays. Free/Grace/Premium activate 1/5/25 schedules and the first 1/3/7 weekdays per schedule; downgrade overage stays saved but is plan-paused or runtime-clamped. Kordyn stores each resulting poll's authored question and answers plus a content-bounded delivery snapshot, schedule fingerprint, server/channel/message identifiers, finite retry/error state and timestamps. Terminal delivery metadata is physically bounded to 30 days/100 rows, 90 days/500 rows or 365 days/5,000 rows. Discord exclusively collects and presents votes, voter identities and results; Kordyn does not request or store ballots, voter IDs or result totals. Leased claims, a unique server/run key and Discord nonce deduplication prevent duplicate publication across retries and replicas. Server export includes configuration and retained content-bounded records, and server deletion cascades them. Public production activation stays disabled until live Discord desktop/mobile, DST, permission drift, crash-after-send, multi-replica, downgrade, export and deletion drills pass.
Giveaway Campaigns v1
A server manager may save administrator-authored one-time or weekly giveaway campaigns containing a name, Discord text-channel ID, prize, description, duration, winner count, optional XP reward, bounded role/age eligibility, IANA timezone, local hour, weekdays or an exact start time. Free/Grace/Premium activate 1/5/25 campaigns; Free supports one-time starts, while Grace/Premium support weekly recurrence with the first 3/7 weekdays. Downgrade overage remains saved but is plan-paused or runtime-clamped. Kordyn stores the campaign configuration, each resulting giveaway and a content-bounded delivery snapshot, SHA-256 campaign fingerprint, server/channel/message identifiers, finite retry/error state and timestamps. Terminal delivery metadata is physically bounded to 30 days/100 rows, 90 days/500 rows or 365 days/5,000 rows. Existing giveaway entries remain unique by server, giveaway and member; this scheduler adds no recipient, invite, click or tracking record and never changes member odds based on plan. Leased claims, a unique server/run key and enforced Discord nonce converge retries and replicas on one publication; active-capacity deferral does not consume a failure attempt. Server export includes configuration and retained records, member deletion continues to remove that member's entries and server deletion cascades campaign data. Public production activation stays disabled until live Discord desktop/mobile, DST, permission drift, crash-after-send, multi-replica, downgrade/renewal, capacity, export and deletion drills pass.
Recurring Event Series v1
A server manager may save a finite administrator-authored Event Planner template containing event copy, external or voice location, Discord channel and bounded role IDs, first start, duration, IANA timezone, weekly/biweekly/monthly frequency, occurrence count, capacity and reminders. Free/Grace/Premium activate 1/5/25 series, allow 4/26/104 occurrences and publish 7/14/30 days ahead; downgrade overage remains stored but is plan-paused or runtime-clamped. Every published occurrence becomes an independent native Discord Scheduled Event plus Kordyn RSVP/waitlist/reminder tree. Kordyn stores the template, resulting event attribution and a bounded delivery snapshot with SHA-256 run/fingerprint, server/resource/external IDs, finite lease/retry/error state and timestamps. The scheduler adds no attendee, click, Presence or message-content record; member identity remains only in the existing RSVP rows and member deletion removes those rows. A unique guild/run key, token lease, current plan/template/resource revalidation, deterministic visible native-event marker, independent external-ID checkpoints and enforced panel nonce converge retries and replicas on one publication. Terminal delivery metadata is physically bounded with Event Planner history to 30/90/365 days and 25/100/500 rows. Server export includes templates and retained deliveries without claim tokens; server deletion cascades them. Public production activation stays disabled until live Discord desktop/mobile, DST/month-end, permission drift, crash/checkpoint, multi-replica, downgrade/renewal, capacity, export and deletion drills pass.
Event Commitment Window v1
A server manager may optionally save one fixed Event Planner RSVP cutoff. Free stores no cutoff; Grace/Premium allow up to 7/30 days before start, and recurring cutoffs must remain after the plan's publication time. At the server-derived boundary Kordyn disables new Going, Maybe, roster selection and slot changes, while only a member with an existing Going, Maybe or Waitlist response may still cancel. That late cancellation never promotes another member. Kordyn stores one nullable bounded minute value on the event/series and one content-free transition timestamp used to refresh the public panel once. It adds no attendee table, click history, message content, Presence, Gateway intent, Discord subscriber import or external provider. Existing RSVP identity, replay, member deletion, event retention, server export and server deletion rules remain unchanged. Downgrade overage is retained and future series publication is plan-paused. Public production activation stays disabled until live exact-boundary desktop/mobile, two-replica, restart, replay, no-promotion, downgrade, retention, export and deletion drills pass.
Event Check-in Desk v1
A server manager may optionally enable a fixed self check-in window opening at event start and closing at the earlier of event end or the configured boundary. Free enables none, Grace up to two hours and Premium up to twelve hours. Only a member with a confirmed Going RSVP or filled roster slot may press the public Discord check-in button; Maybe, Waitlist and Declined are rejected. Kordyn stores one unique server/event/member check-in containing the existing Discord member ID and bounded display name, the interaction ID, and check-in/creation timestamps. The manager dashboard receives only retained, plan-bounded rows and never exposes member IDs; member-facing event lists expose only that member's own checked-in state plus aggregate count. Kordyn does not monitor voice presence, message content, screenshots, PINs, location, devices or Scheduled Event subscribers. Exact interaction/member repeats remain idempotent without double counting. Member deletion erases that member's rows, event retention and event/server deletion cascade them, and server export includes retained check-ins. Downgrade overage blocks new check-ins and plan-pauses future series publication. Public production activation stays disabled until live Discord desktop/mobile, exact-boundary, concurrent-click, restart, downgrade, retention, export and deletion drills pass.
Event Feedback Pulse v1
A server manager may optionally enable a post-event feedback window. Free enables none, Grace up to 72 hours and Premium up to 720 hours. Exactly at event end, only a member with a confirmed Going RSVP or filled roster slot may submit one final 1–5 star rating; Maybe, Waitlist, Declined and unregistered members are rejected. Kordyn stores one unique server/event/member row containing the existing Discord member ID, interaction ID, integer rating and timestamps, but no display name, free text, message content, attachment, voice activity, location, device data or inferred sentiment. Exact interaction/member repeats return the first stored rating without double counting, including after closure or downgrade. The public panel exposes only response count. Manager analytics expose anonymous response rate, and average/distribution only from three responses; no individual rating or identity is shown. Server export is event-aggregate-only and applies the same three-response threshold. Member deletion removes that member's row and refreshes the panel; event retention and event/server deletion cascade all rows. Downgrade overage blocks new responses and plan-pauses future series publication. Public production activation stays disabled until live Discord desktop/mobile, exact-boundary, concurrent-click, threshold, restart, downgrade, retention, export and deletion drills pass.
Event Waitlist Promotion Inbox v1
Whenever Event Planner automatically promotes a member from a FIFO waitlist before event start, Kordyn creates one private transactional Discord notification on Free, Grace and Premium. The RSVP promotion and unique delivery row commit in the same database transaction. Kordyn stores server, event and recipient Discord IDs, a random delivery key, finite status/attempt/lease metadata, optional DM channel/message IDs, bounded fixed error information and timestamps. A stable Discord nonce, two-minute claim leases and at most five attempts make delivery restart- and replica-safe. Discord 403/404 becomes terminal blocked, an undelivered row becomes terminal dead at event start, and Kordyn never falls back to a public channel. The DM contains administrator-authored event title, time, location and an event link, but no other attendee, waitlist position or analytics. Dashboards and server export are event-aggregate-only and exclude recipient IDs, delivery/claim secrets, DM IDs and error text. Kordyn stores no display name, reply, click/open receipt, message content, device, IP history, Presence or Scheduled Event subscriber list. Member deletion erases that member's rows; event retention and event/server deletion cascade them. Public production activation stays disabled until live Discord desktop/mobile, blocked-DM, crash-after-send, lease-expiry, multi-replica, retry-exhaustion, event-start, retention, export and deletion drills pass.
Event Cancellation Inbox v1
When a manager cancels a Draft or Published Event Planner event, Kordyn atomically stores the local Cancelled state, queues idempotent native Discord Scheduled Event deletion when applicable, stops pending reminders, releases owned attendee-role references and creates one unique private transactional notification for every current Going, Maybe or Waitlist RSVP on Free, Grace and Premium; Declined and absent members receive nothing. Each notification stores server, event and recipient Discord IDs, a random delivery key, finite status/attempt/lease metadata, optional DM channel/message IDs, bounded fixed error information and timestamps. Native cleanup stores bounded status, attempt timing, an ephemeral claim token and deletion time. Independent two-minute leases and at most five attempts prevent either path from blocking the other; DMs use a stable Discord nonce, native Discord 404 means already deleted, DM 403/404 becomes terminal blocked and Kordyn never falls back publicly. The DM contains administrator-authored event title, original time, planned location, an event link and a transactional explanation, but no other attendee, roster, waitlist position, role, analytics, custom reason or marketing text. Dashboard and server export are event-aggregate-only for cancellation notifications and exclude recipients, delivery/claim secrets, leases, DM IDs and error text; native claim secrets are also excluded. Kordyn stores no display name, reply, message content, click/open receipt, device, IP history, Presence or Scheduled Event subscriber list. Member deletion erases that member's RSVP and delivery rows; event retention and event/server deletion cascade them. Public production activation stays disabled until live Discord desktop/mobile, manual-native-delete, blocked-DM, crash-after-send, lease-expiry, multi-replica, retry-exhaustion, retention, export and deletion drills pass.
Event Change Inbox v1
Before a published event starts, a current server manager may change its bounded title, description, external or voice location, start/end time, standard capacity, RSVP cutoff, check-in/feedback windows and reminder settings on every plan. Announcement channel, published roster-slot structure and attendee access roles remain immutable; roster capacity is fixed and standard capacity cannot fall below current Going RSVPs. Kordyn atomically increments an optimistic event version, refreshes the RSVP panel, recalibrates undelivered reminders, creates a content-bounded before/after revision and queues one private transactional notice for each current Going, Maybe or Waitlist member; Declined and absent members receive nothing. Rapid undelivered revisions are superseded and coalesced. Native Discord synchronization and member DMs use independent two-minute leases and at most five attempts; a deterministic visible marker recovers or recreates a manually deleted Scheduled Event, DMs use a stable nonce, 403/404 becomes terminal blocked and no public fallback is used. The DM exposes only relevant old/new title, time, location, capacity and bounded setting summaries plus an event link, never another attendee, role ID, waitlist position, custom reason or analytics. Kordyn stores server/event/version, changed-field flags, administrator-authored snapshots and finite retry metadata; notification rows additionally contain recipient and optional DM IDs. Dashboard and export expose notification aggregates only, and export excludes snapshots, recipient/DM IDs, delivery/claim secrets, leases and error text. Member deletion erases that member's delivery rows; event retention and event/server deletion cascade revisions and deliveries. Public production activation stays disabled until live Discord desktop/mobile, rapid-edit, manual-delete recovery, blocked-DM, crash/checkpoint, multi-replica, retry-exhaustion, downgrade, export and deletion drills pass.
Event Calendar Bridge v1
Every newly published Event Planner event receives one opaque individual iCalendar capability URL on every plan. Grace and Premium may additionally create one private subscribable server feed returning at most 50/250 retained published, completed or cancelled events per refresh. Calendar files contain administrator-authored event copy, time, location, stable event UID, cancellation state and the native Discord event link; they contain no attendee identity, RSVP choice, roster or waitlist counts, member roles, analytics or Discord subscriber list. The feed uses a 256-bit random bearer token. Kordyn stores only its SHA-256 digest, final four display characters, version and creation time; the complete URL is returned once, can be rotated or disabled, is excluded from normal route logging, audit and export, and returns a neutral 404 when unknown, revoked, disabled or plan-paused. Server export removes both the feed digest and individual event slugs. The feature creates no click, download, calendar-client, IP-history, OAuth-token or external-provider record. Existing event retention removes old capabilities and server deletion removes all remaining calendar state. Public production activation stays disabled until live Apple/Google/Outlook desktop/mobile, proxy-log redaction, rotation race, downgrade/renewal, migration, export and deletion drills pass.
Event Access Roles v1
A server manager may select existing safe Discord roles for confirmed Event Planner attendees. Free supports none, Grace one and Premium three roles per event or recurring template. Only Going and a filled roster slot create access references; Maybe, Waitlist and Declined never grant access. Kordyn stores content-free server, event, member and role identifiers plus finite ownership, lease, retry, error-code and timestamp metadata. One aggregate ownership row reference-counts a member/role pair across events. If the member already had a role, Kordyn records it as observed and never removes it; an owned role is removed only after the final event reference disappears. Decline, waitlist transition, cancellation, completion and privacy deletion release references, while promotion creates them for the promoted attendee. Adds freshly require Manage Roles and an existing non-managed role below Kordyn; cleanup continues after downgrade while new paid grants pause. Export strips claim secrets, event and server deletion cascade the ledgers, and member deletion first releases owned Discord roles before erasing identity. The feature stores no message content, Presence, Scheduled Event subscriber list, click history or access-use analytics. Public production activation stays disabled until live permission, hierarchy, shared/manual role, promotion, crash, multi-replica, downgrade, export and deletion drills pass.
Channel Autopilot · Auto Threads
A server manager may configure normal text or announcement channels so an eligible new Discord message creates a public thread and/or is published. Kordyn receives only bounded server, channel and message identifiers, channel/source class, event time and a transient display label; it never receives or stores the message body, embeds or attachments. Normal text-thread templates allow only {channel} and {date}, and new durable delivery snapshots omit the member display label. The retained metadata contains the effective rule, rendered non-member text-thread name, finite retry/error state, optional publish time and Discord thread ID. Free runs one human-only text auto-thread or announcement auto-publish rule; Grace/Premium run 5/20 rules and may add source filters, safe name/archive/Slowmode customization and announcement discussions. Downgrades retain saved configuration while applying the safe Free runtime and pausing excess rules. Server export includes retained configuration and content-free delivery metadata; server deletion cascades it. Public production activation stays disabled until live Discord permission, desktop/mobile, bot/webhook, retry, downgrade, export and deletion drills pass.
Bluesky Alerts v1
A server manager on Grace or Premium may save a public Bluesky handle and deliver alerts for new original posts through the existing Social & Alerts workspace. Kordyn uses only Bluesky's fixed cached public AppView and requests no password, app password, OAuth token or write access. Configuration stores the canonical public handle and DID plus optional public display metadata/follower total. Provider post text, facets, embeds and media remain transient and are neither copied into Discord nor stored, audited, logged or exported. Kordyn accepts only non-reply, non-repost AT URIs authored by the resolved DID and skips !hide, !no-unauthenticated, porn, sexual, nudity and graphic-media labels. Discord receives administrator-authored template text, public profile presentation, a neutral event title and a derived bsky.app post link. The content-free delivery ledger stores only scoped provider/event/channel IDs, finite status/error metadata, optional Discord message ID and timestamps under the existing 7/30/90-day Free/Grace/Premium cleanup; guild deletion cascades it. Public production activation stays disabled until live AppView, label/opt-out, custom-domain, Discord, retry, multi-replica, downgrade, export and deletion drills pass.
Creator Live Role v1
A server manager may configure a safe cosmetic role while Discord reports that a human member is streaming. The bot accepts only Discord's Streaming activity with a credential-free HTTPS Twitch or YouTube URL, then reduces it to one Boolean before calling Kordyn's API. Stream URL, title, game, activity state and provider metadata are never transferred to the API or retained in PostgreSQL, logs, audit metadata, analytics or server export. Free/Grace/Premium activate 1/5/10 total Presence Role rules; Grace and Premium may restrict a streaming rule to members who already hold one selected creator role. The existing ownership ledger stores only guild, member, rule and target-role IDs plus timestamps/status, never adopts a manually held role and releases only a role proven to be Kordyn-owned. Target roles with moderation or server-management permissions are rejected on save and against a fresh bot-side safe-role list before every new assignment. Member-data deletion removes that member's grants and guild deletion cascades them. Public production activation stays disabled until live Twitch/YouTube, desktop/mobile Discord, linked-account absence, privileged-intent approval, permission/hierarchy drift, reconnect, downgrade, export and deletion drills pass.
Event Log Routing v2
A server manager may group selected finite Server Event Log types into at most fifteen ordered Discord text-channel routes. The existing main channel remains the destination for every unassigned event and receives one attempt if a routed delivery fails. Stored route configuration contains only a bounded route ID, text-channel ID and event-type names. Gateway payloads, optional message text, actors and delivery attempts remain transient and are not inserted into Kordyn's audit, analytics or message tables. Free/Grace/Premium activate the first 0/5/15 saved routes; downgrade overage remains stored and plan-paused. Deleting a route channel removes only that route and returns its events to the main fallback. Existing server export and irreversible deletion cover the configuration JSON. Public production activation stays disabled until live desktop/mobile Discord, permission fallback, deleted-channel, downgrade/renewal and burst drills pass.
Community Tags v2
A server manager may enable selected Discord roles to create simple shared text tags through `/tag create`, then let the creator edit or delete their own tag. Kordyn stores the server, tag name, optional description, member-authored text and timestamps. Ownership is stored only as a server-bound application-secret HMAC, never as a raw member Discord ID; that key is omitted from dashboard responses, logs and server export. Current roles and manager permission are checked transiently on every write. Community tags cannot use placeholders, embeds, automatic triggers, reactions, private replies, execution scopes or mass mentions. Running a tag posts its retained text publicly in Discord with mention parsing disabled. Free/Grace/Premium allow 1/3/10 active creator roles and 1/3/10 owned tags per member; every tag also consumes the shared 5/20/50 custom-response allowance. Downgrade overage remains retained and runnable but blocks new over-limit creation. A manager dashboard edit intentionally converts the tag into manager-owned configuration and erases member ownership. Member-data deletion removes that member's owned tags; server export includes policy and tag content with only a Boolean ownership marker, and server deletion cascades policy, tags and usage rows. Public production activation stays disabled until live desktop/mobile Discord, PostgreSQL multi-replica, downgrade, deleted-role, export and privacy-deletion drills pass.
Saved Music Playlists
A current Discord server manager or configured Music DJ may create a persistent server playlist. Kordyn stores the server ID, playlist name and version plus each track's order, a credential-free HTTPS reference or bounded search string, bounded title, optional author, source class, duration, stream flag and timestamps. It stores no media bytes, encoded Lavalink track, requester/member Discord ID or vote ledger in the playlist. List and detail responses remain tenant-scoped; every mutation rechecks the current Community Studio state, manager/DJ access and authoritative plan. Free/Grace/Premium allow 3/10/50 playlists and activate the first 25/100/500 tracks per playlist; downgrade overage remains visible but cannot be played or expanded. Playback sends no more than 25 references per request to the operator-managed Lavalink node. Advanced Music Controls separately keep only a 10/50/250-track plan prefix in bot memory for the current process. Those session rows contain a safe replay reference and bounded display metadata, never a member/requester ID, encoded track or media; replay resolves exactly one current result and restart clears the complete session history. Server export includes only the persistent server-authored playlist records, and irreversible server deletion cascades every playlist and track. Public production activation stays disabled until live Discord/Lavalink source-expiry, concurrent-edit, advanced-control, downgrade, export and deletion drills pass.
Saved Playlist AutoDJ
A current server manager or configured Music DJ may activate AutoDJ from the plan-active prefix of one saved server playlist. The bot process then keeps one bounded in-memory snapshot containing the playlist ID and name, the existing safe track references and bounded display metadata, shuffle order, cursor, activation time and attempt/queue counters. It stores no member/requester Discord ID, encoded Lavalink track or media and writes no AutoDJ state to PostgreSQL, analytics, audit records or server exports. When the queue is empty, Kordyn freshly resolves at most five references; failed references count against the cap. Free/Grace/Premium allow 0/25/250 reference attempts per activation. One process accepts at most 500 active AutoDJ snapshots and 25 concurrent reference resolutions. Stop, an ineligible downgrade, a matching playlist edit through the bot, node loss, player destruction, guild removal, shutdown or restart clears the snapshot; tracks already placed in the normal queue may continue after AutoDJ is stopped. An already-running snapshot is not a durable copy and may remain in memory until one of those boundaries if the persistent playlist is changed elsewhere. Live Discord/Lavalink, dashboard-edit, expiry, downgrade, capacity and restart drills remain ready.
Private current-track lyrics
When an operator explicitly enables Lyrics and the active Lavalink node reports the LavaLyrics plugin, a member in Kordyn's current voice channel may request one private current-track snapshot. Kordyn sends only the fixed Lavalink session/guild route and the node authorization header to that operator-managed node; it does not send an encoded track in the URL. The provider response is limited to 256 KiB and eight seconds, validated, reduced to source/provider labels plus at most 8/16/30 Free/Grace/Premium lines and 3,400 rendered characters, and discarded after the private reply. Synchronized lyrics are centered around the current player position. A track or node-session change discards a delayed result. Kordyn writes no lyrics text, provider payload, query, track title, member ID or cooldown to PostgreSQL, analytics, audit records, structured logs or server exports. The bot process temporarily keeps only a 10-second member/server cooldown, capped at 10,000 entries, and allows at most 20 concurrent requests; expiry, player/server removal, node loss, shutdown or restart clears relevant memory. Provider credentials, licensing, regional rights and source configuration remain the deployment operator's responsibility. Live provider, licensing, desktop/mobile, rate-limit, track-race, node-loss and restart drills remain ready.
Music Fair Queue
Kordyn limits one member to 5/25/100 current plus upcoming tracks on Free/Grace/Premium. The count is derived transiently from the requester Discord ID already attached to each active in-memory track; Fair Queue creates no additional member ledger, PostgreSQL row, analytics dimension, audit event or server-export field. Direct Play, private Search selection, History Replay and saved-playlist playback reject a full member before source resolution and recompute server/member capacity under one guild operation fence before queue mutation. AutoDJ tracks contain no member requester and do not consume a member allowance. A downgrade does not stop or delete admitted tracks, but future additions remain blocked until the member's derived count falls below the new limit. Private Queue and Now Playing responses show only the invoking member's own count. Player destruction, server removal, shutdown or restart removes the underlying queue/requester metadata. Live simultaneous-admission, independent-member, downgrade and production-node soak remain ready.
Music sound profiles and retention
Sound Profiles and Stay Connected are session-only controls. Kordyn keeps only the selected fixed preset name and an absolute retention expiry in the bot process; it stores neither value in PostgreSQL, analytics, audit exports or server exports. Fixed profiles are applied by the operator-managed Lavalink node and do not add media storage or member identifiers. Free/Grace/Premium expose 2/4/7 profiles and at most 0/60/1,440 minutes of empty-player retention per activation. Stay Connected never renews itself, auto-rejoins voice or survives player destruction, guild removal, shutdown or bot restart. A current music interaction rechecks the authoritative plan and clears an ineligible profile or removes/clamps a downgraded retention window. Production audio, expiry, downgrade and restart drills remain ready.
Private music search and queue tools
A private `/music search` sends the bounded query transiently to the operator-managed Lavalink node. Kordyn then keeps at most five credential-free HTTPS references or bounded search strings plus bounded title, optional author, source class, duration and stream flag for two minutes in bot memory. The session also temporarily contains a random nonce, the requesting Discord member ID, server ID, original voice-channel ID and expiry so one menu can be actor-, tenant- and voice-bound. It stores no raw query, encoded Lavalink track or media and never enters PostgreSQL, analytics, audit or server exports. A new search replaces that member's old menu; one valid selection consumes it and freshly resolves one safe reference. Expiry, player destruction, server removal, shutdown or restart clears it. Previous uses the separately documented safe session history, while Clear and Skip-to create no new stored data. Live expiry, source-drift and concurrent-control drills remain ready.
Purpose and separation
Data is used to authenticate administrators, operate configured modules and diagnose service errors. Every server-scoped record is tied to its Discord guild ID and protected by central authorization checks.
Moderation Case Navigator
Authorized server staff may project existing retained moderation cases into a private Discord Components V2 response through `/case list`, `/case view` or `/case tempbans`. This creates no new database record. The response may show the existing subject and moderator Discord IDs, case number, action, status, bounded current reason, timestamps, expiry, safe execution status/code and a current HTTPS evidence link. Rendered mentions cannot ping. Component IDs contain only finite routing state, actor and optional subject Discord IDs, page and case number—never a reason, evidence link, display name or raw error. Each interaction rechecks the invoking moderator's current Discord permission and module state. An authorized manager may correct a reason or evidence link in the dashboard; Kordyn never overwrites the original case and instead appends at most 20 revisions with changed-field flags, the current staff Discord ID, a required private correction note, idempotency key and timestamp. Discord and the account-bound Appeal Portal receive only the resulting current reason/evidence and revision. The Appeal Portal never receives correction notes, correcting staff identity or idempotency keys, and its stale-action fingerprint changes with the revision. Guild export includes retained correction rows. Deleting the case subject cascades its journal, deleting the correcting staff member clears that actor ID, and server deletion removes all rows. Existing moderation retention remains authoritative. Public production activation stays disabled until desktop/mobile Discord, stale-state, PostgreSQL multi-replica, export/deletion and permission-revocation drills pass.
Ban Appeal Portal
A Discord-authenticated account may open `/appeals` without current server membership or management permission. Kordyn returns only that exact account's retained, successfully executed ban and temporary-ban cases and its own appeal status. The response includes the server name, case number, action, reason, optional HTTPS evidence, timestamps and the appellant-authored explanation/evidence. It omits appellant/member/moderator identifiers, internal idempotency keys, staff assignment and the private staff decision note. OAuth `identify` proves account identity; it does not restore server access. One appeal is accepted per case through a stale-action fingerprint and transactionally serialized, account-bound write. Staff acceptance or denial never automatically unbans or restores access. After acceptance, a manager may separately type `RESTORE`; Kordyn stores a dedicated unban moderation case before contacting Discord and records success, failure or an already absent ban. Best-effort DMs may provide the portal link, terminal outcome or successful access restoration, but blocked DMs never change case, appeal or unban state. Existing moderation retention, guild export, member-data deletion and guild deletion remain authoritative and can remove the case, appeal and linked re-entry record. The appeal and core re-entry integrity paths are included on Free, Grace and Premium because access to an appeal is not a paid feature. They remain ready until live banned-account OAuth, blocked-DM, desktop/mobile, multi-replica PostgreSQL, export and privacy-deletion drills pass.
Reminder Inbox v2
A member may create a personal channel reminder with `/remind set` or the message-context action Apps → Remind me. For a message-context reminder, Kordyn stores the server, member, channel and source-message Discord IDs, but never copies the selected source message, its author, attachments or embeds. The member-authored reminder note, due time, optional finite repeat interval/count, delivery version, Snooze count, bounded attempt/error state, optional Kordyn delivery-message ID and lifecycle timestamps are retained. Delivery is visible in the selected channel and mentions only its owner; it is not a private DM. Done and Snooze component IDs bind the reminder, owner and exact delivery version and contain no note or source content. Every action rechecks the current member, module and plan, and a stale button cannot act twice. The manager dashboard projects aggregate/status metadata only and omits note content, member, channel/source-message and worker-claim data. A server export includes the retained member-authored note and scoped Discord IDs, but excludes worker claim tokens and leases. Member-data deletion removes that member's reminders and server deletion cascades every reminder. Free/Grace/Premium physically retain terminal rows for at most 7/30/90 days and 50/500/5,000 rows; active reminders remain until terminal. Delivery uses leased atomic claims, Discord nonce deduplication and at most five attempts, but deleted channels, missing permissions or outages may delay or prevent it. Public production activation stays disabled until live desktop/mobile Discord, stale-button, deleted-source, permission, PostgreSQL multi-replica, downtime, retention/export and privacy-deletion drills pass.
AI Image Studio
A member may select a Discord message and open Apps → Create AI image. The selected text is prefilled only into an actor-bound private modal and is not sent externally until the member explicitly reviews and submits it. Kordyn then sends the bounded prompt transiently to OpenAI for pre-moderation and one low-quality safety-filtered image; Discord identifiers are minimized and an HMAC safety pseudonym is used. Kordyn stores neither selected text, prompt, image, filename, moderation categories nor provider payload. A content-free replay row retains server, interaction and actor Discord IDs, UTC period, status, included/Flex source, aspect, prompt character count, model, output byte count or bounded error code and timestamps. Server export omits actor/interaction IDs, member deletion removes matching rows, server deletion cascades them, and terminal metadata is physically limited to 30 days and 5,000 rows. Failed or stale operations refund their included unit or Flex Credit exactly once. The result is private and mention-free. Public production activation stays disabled until live OpenAI, Discord and multi-replica PostgreSQL drills pass.
Growth Pulse
When a native Discord server manager enables Growth Pulse for one selected channel, Kordyn transiently inspects a response from the allowlisted DISBOARD application to verify that a member manually ran `/bump` and that the provider reported success. Provider message and embed content never leaves the Bot process, is never sent to Kordyn's API and is never stored. The durable event stores only server, provider, channel and source-message IDs, an optional last-bumper Discord ID, bump/due timestamps, finite delivery/attempt/error state, an optional Kordyn reminder-message ID and lifecycle timestamps. Administrator configuration additionally stores the enabled state, selected channel and mention mode, an optional role ID, bounded reminder template and optional IANA-timezone quiet hours. Kordyn never runs `/bump`, uses no selfbot, stores no listing content or ranking and makes no growth or placement claim. Free/Grace/Premium physically retain terminal metadata for at most 7/90/365 days and 25/500/5,000 rows; active reminders are retained until terminal. A newer bump cancels an older pending reminder. Member-data deletion nulls the matching bumper ID, server export includes sanitized events without worker claim tokens, and server deletion cascades all records. Discord receives the configured reminder; DISBOARD supplies the original success response and is otherwise independent from Kordyn. Public production activation stays disabled until live provider-response, Discord-permission, downtime, quiet-hour, PostgreSQL multi-replica and privacy-deletion soak tests pass.
AFK Return Inbox
A native Discord server manager must first enable AFK return callbacks, and an AFK member must separately opt in for each AFK session through `/afk set callbacks:true`. A member who mentions that AFK member may request one return notification and, on Grace or Premium, leave one private note for that session. Kordyn stores server, AFK-member and requester Discord IDs, the exact AFK-session timestamp, callback kind, finite delivery/attempt/error state, expiry/due/delivery timestamps and an optional Discord DM message ID. Private-note content is limited to 300 characters and stored only as AES-256-GCM ciphertext while waiting or retrying; ciphertext and plaintext are excluded from dashboard responses, logs and server export. The API decrypts content only immediately before the DM and erases it after delivery, terminal failure, cancellation, expiry, downgrade, feature disable or session replacement. Free/Grace/Premium allow 25/100/250 callbacks per session, wait at most 7/14/30 days and physically retain content-free terminal metadata for at most 7/30/90 days and 25/250/1,000 rows. Delivery uses bounded five-attempt leased claims and Discord nonce deduplication, but blocked DMs or Discord outages can prevent or delay delivery. Member-data deletion removes rows where the member is either AFK target or requester; guild deletion cascades all rows. Public production activation stays disabled until live blocked-DM, retry, downgrade, PostgreSQL multi-replica and privacy-deletion soak tests pass.
Dedicated Custom Bot
A native Discord server owner may voluntarily connect the raw token of a separate customer-created bot application. Kordyn uses that token to request the current bot user and application identity from Discord, then stores only an AES-256-GCM ciphertext plus server ID, application/bot IDs, username, optional Discord avatar URL, credential revision, connecting owner Discord ID and timestamps. The raw token is accepted once, never returned to the dashboard, never written to normal logs and deliberately excluded—together with its ciphertext—from server exports. An authenticated Dedicated runtime may decrypt the token through a private no-store bootstrap; retained runtime state contains bounded instance/application/bot identifiers, observed target-server IDs, command-sync/heartbeat timestamps and a finite error code. Heartbeats recheck the current Premium entitlement, credential revision, identity and single target server. Rotation resets all runtime observations; disconnect deletes the credential but cannot revoke it at Discord, so the owner must reset it in the Developer Portal as well. Member-data deletion nulls matching connector attribution without deleting server configuration; server deletion cascades the complete credential. The regular Kordyn bot remains installed by design as the dashboard and resource-synchronization control plane.
Rewards Store
When a member buys a virtual server reward, Kordyn stores the server, member, configured item ID and an immutable snapshot of its administrator-authored name, description, virtual-coin price, fulfillment type and optional Discord role ID. The purchase also stores a finite prepared, pending-review, fulfilled or refunded status, attempt/error metadata, optional reviewing staff Discord ID and timestamps. A private idempotency key and short-lived random delivery claim prevent duplicate debits and multi-runtime role delivery; both are excluded from browser responses and server exports. Role delivery checks the live member and Discord role hierarchy. A Discord failure refunds the exact virtual-coin debit once; if the role was already assigned before an API interruption, reconciliation completes the existing reservation instead of refunding it. Manual rewards require an explicit manager decision; rejection restores the full virtual-coin price. Terminal purchase history is physically limited to 30 days/100 rows on Free, 90 days/500 rows during Grace and 365 days/2,000 rows on Premium. Member-data deletion removes that member's purchases and accounts and clears matching reviewer attribution; server export includes sanitized purchase receipts, and server deletion cascades the complete store ledger. Rewards are virtual guild benefits only, have no cash value or real-money purchase path, and staff must describe and fulfill manual rewards lawfully.
Economy Role Payday v1
A native Discord server manager may configure an ordered Role Payday list containing a manager-authored rule ID and name, Discord role ID, positive fixed virtual amount, interval and enabled state. When a member privately opens or collects `/economy view:payday`, the Bot fetches that member's current Discord roles and passes their IDs transiently across the authenticated internal boundary; every due matching active rule stacks. Current role IDs are not retained as a membership snapshot, and Kordyn stores no role/display name, message content, channel, command-option history or public salary post. A claim row contains only server, member and rule IDs plus latest claim and update times; the existing Economy account and sanitized `role_income` ledger retain the resulting virtual balance. PostgreSQL commits account credit, per-rule cooldown and ledger entries atomically. Free/Grace/Premium activate 3/10/25 ordered rules with minimum effective intervals of 24/6/1 hours. Downgrade deletes nothing: overage plan-pauses and too-fast intervals clamp at runtime. Export includes configuration, minimized claims and sanitized transactions; member-data deletion removes claims, account and applicable transactions, while server deletion cascades all rows. Currency has no cash value, purchase or cash-out path; automatic mass payroll, negative or percentage payouts, deductions and public announcements are not provided. Public production activation stays disabled until live Discord desktop/mobile, PostgreSQL multi-replica, restart, downgrade, export and deletion drills pass.
Economy Chat Rewards v1
A native Discord server manager may opt in to Chat Rewards, choose ordered current text-channel IDs, a fixed positive virtual amount and a cooldown. The Bot accepts only a normal human message or reply with at least four trimmed characters or an attachment and excludes bots, webhooks and system messages. It derives one eligibility Boolean inside the Bot and adds only that field to Kordyn's existing content-free Message Activity envelope. The shared envelope retains its existing bounded identity/channel metadata for XP and other configured modules, but sends no message content, excerpt, attachment data or embed. The Chat Rewards resolver receives and stores no display name or channel name. Kordyn sends no public reward response. Free/Grace/Premium activate 1/5/25 channels with minimum effective cooldowns of 60/20/5 minutes and 10/50/250 rewards per member per Economy-local day. Downgrade deletes nothing: ordered overage plan-pauses and too-fast cadence clamps at runtime. PostgreSQL serializes each server/member, checks cooldown, daily cap and replay, then commits account credit and one `chat_reward` ledger row atomically. That row contains server/member IDs, amount, resulting balance, timestamp and a private message-derived idempotency key, but no metadata or channel ID. Manager responses and server export remove the raw key; normal pruning replaces it with a server-scoped hash containing no member, channel, amount or raw message ID. Member-data deletion removes account and applicable transactions, and server deletion cascades all data. Currency remains virtual with no purchase, cash-out or real-money path. Public production activation stays disabled until live eligible/ineligible Discord events, desktop/mobile, PostgreSQL multi-replica, restart, local-day, downgrade, retention, export and deletion drills pass.
XP Access Rules v1
A native Discord server manager may configure one ordered role denylist or non-empty allowlist that applies to Message, Voice and Reaction XP. Free/Grace/Premium activate the first 3/10/25 saved current Discord role IDs; downgrade overage remains stored and plan-paused, while removal stays available and over-limit additions fail. The Bot already supplies each event member's current role IDs through Kordyn's authenticated XP activity boundary. XP Access Rules evaluates those IDs transiently and stores only the server policy; it creates no member-role snapshot, denial ledger, message content, attachment, emoji, Presence or channel history. A restricted Reaction recipient is filtered independently from any other configured recipient. An empty allowlist, duplicate or unavailable role is rejected. Deleted-role repair removes a stale ID and resets an emptied allowlist to the safe default empty denylist. Manual manager XP corrections remain outside this organic-activity policy. Existing server export and irreversible server deletion cover the configuration; member-data deletion needs no additional path because this feature stores no member-specific record. Public production activation stays disabled until live Discord role-change/deletion, Message/Voice/Reaction, desktop/mobile, restart, downgrade, multi-replica, export and deletion drills pass.
Economy Wealth Leaderboard & Privacy Center v1
A member may privately view the server's visible virtual-currency accounts and their own current position through `/economy`; authorized server managers receive the same derived ranking in the private dashboard. A sparse preference stores only the server ID, member Discord ID, a visibility boolean and its update time. With no preference row, an account is visible by default. The ranking is derived on demand from current virtual balances and stores no snapshot, display name, message content, channel, role, command-option history or public Discord post. Hidden accounts are removed before sorting, ranking and plan truncation; other viewers receive only an aggregate hidden-account count, while the hidden member can still privately see their own visibility, balance and position. Free/Grace/Premium expose at most 10/25/100 ranked accounts, but visibility control is included on every plan. Opting out does not delete the account, balance or Economy Ledger, and authorized managers retain scoped integrity, support and export access to underlying economy records. Server export includes the preference; member-data deletion removes the preference and account, and server deletion cascades all preferences. Public production activation stays disabled until live Discord desktop/mobile, PostgreSQL multi-replica, restart, downgrade, privacy, export and deletion drills pass.
Economy Ledger & Integrity Center v1
Authorized server managers may inspect retained virtual-currency transactions for the stated purposes of explaining rewards, spending, transfers, refunds and settled games and detecting integrity problems. Each active row contains server, sender and optional transfer-target Discord IDs, finite kind, virtual amount, resulting balance, a private raw idempotency key, bounded operational metadata and timestamp. The authenticated manager response and server export include scoped member/target IDs, kind, amount, balance and time but exclude the raw idempotency key and all metadata. Aggregate current supply comes from current accounts; issuance, burns, transfer volume and game net cover only the retained window and are not real-money, accounting or causal claims. Free/Grace/Premium physically retain at most 14/90/365 days and 250/2,500/25,000 rows. Before pruning, Kordyn atomically stores only a guild-scoped SHA-256 digest of the idempotency key and original time, with no member, target, amount, balance, kind or raw interaction ID; this replay tombstone expires after 400 days and prevents an old interaction from paying twice. Member-data deletion removes transactions where that member is sender or target plus the account; tombstones contain no member identifier. Server deletion cascades accounts, transactions, purchases and tombstones. The currency remains virtual and guild-scoped with no purchase, cash-out, conversion or real-money wagering path. Public production activation stays disabled until multi-replica pruning/settlement, downgrade/renewal, post-prune replay, export and deletion drills pass.
Community Segments
A native Discord server manager may configure transparent rolling activity-role rules with one to three explicit conditions using message counts, eligible Voice minutes or Reaction XP events over 7, 30 or 90 days. Each condition stores separate entry/release thresholds; a rule also stores finite all/any matching and dynamic/milestone retention modes. Kordyn evaluates the existing content-free XP event ledger; it stores no message body, emoji, channel history, display name or secret member score for this feature, and the dashboard exposes only aggregate preview counts. The ownership ledger stores server, member, rule and role IDs, matched-condition count and earliest window, evaluation and role-operation state, bounded retry metadata and timestamps. Kordyn never adopts a role already present manually and removes only roles recorded as bot-owned. Paused or downgrade-locked rules make no Discord role changes; explicit deletion or dynamic release may clean up owned roles, while milestone retention deliberately keeps a previously earned owned role. Released assignments are physically retained for at most 14/90/365 days on Free/Grace/Premium. Member-data deletion removes assignments and the underlying member activity records through their existing deletion paths; server export and irreversible server deletion include the configuration and ledger. Public production activation stays disabled until live Discord/PostgreSQL hierarchy, retry, pause, downgrade and deletion soak tests pass.
Activity Streaks
A native Discord server manager may configure one to three explicit daily targets for messages, eligible Voice minutes and Reaction XP, a finite all/any match mode and an IANA server timezone. Kordyn derives streaks on demand from the existing content-free XP event ledger and stores only this server-level policy; it creates no new member score, daily member table or public leaderboard. Manual XP adjustments, bots, message bodies, emoji and channel history are excluded. The private manager response contains bounded daily counts, member ID/display name and derived current/longest streak values for at most 250/2,500/10,000 sampled members, with a truncation marker. Free/Grace/Premium use 30/180/365-day windows, 10/50/100 leaderboard rows and 1/2/3 conditions. An incomplete current local day never breaks yesterday's streak. Downgrade overage remains saved but plan-paused. Existing member-data deletion removes the underlying XP events and profile; server export includes only the policy and server deletion cascades it. Public production activation stays disabled until real PostgreSQL timezone, scale, privacy-deletion and multi-day rollover tests pass.
Supporter Intelligence
A native Discord server manager may explicitly connect Patreon through OAuth. Kordyn requests only identity, campaign, campaign-member and webhook-management scopes; it does not request Patreon email, postal address or post access. OAuth access/refresh tokens and Patreon's generated webhook secret are stored only as AES-256-GCM ciphertext and are never returned by the dashboard or included in server exports. Kordyn maps current membership status, currently entitled monthly amount, currency, charge status, pseudonymous tier keys and an optional Patreon-linked Discord ID. Raw Patreon member and tier IDs are HMAC-pseudonymized before persistence; name, email, address, profile image, payment instrument, post content and raw webhook body are not stored. The private manager dashboard exposes aggregate supporter counts, currently entitled value, Discord link/activity rates and new/churned/declined totals only. Organic correlation uses existing content-free message, eligible Voice and Reaction-XP events; it does not create a member list or secret score. Patreon remains responsible for its native Discord tier-to-role synchronization—Kordyn performs no Patreon role write. Free stores no connection; Grace/Premium allow 1/3 campaigns, 2,500/25,000 members, 90/365-day snapshots and 60/15-minute minimum sync intervals. Truncated runs never classify unseen supporters as churned. Downgrade overage remains encrypted and plan-paused. Member-data deletion removes matching Discord-linked membership rows; server export excludes credentials but includes remaining connection metadata, pseudonymous memberships and aggregates, and server deletion cascades all tenant data. Public production activation stays disabled until real Patreon credentials, PostgreSQL and multi-day provider/retry/privacy soak tests pass.
Discord Activity Operations Room
The optional Discord Activity is disabled by default and remains release ready. Starting it requires a native Discord Manage Server user. Kordyn exchanges the one-time OAuth code server-side, validates the exact Discord Activity instance with Discord using the Bot token and issues a five-minute Kordyn session bound to that user, server, channel and instance. The Discord OAuth access token is returned only to the Activity browser for SDK authentication; it and participant-presence updates remain transient and are never stored or written to normal logs. A shared room stores only the exact server, channel and Activity-instance IDs, one fixed focus value, five fixed checklist Booleans, revision and timestamps. It contains no participant/member ID, display name, message content, notes or presence history and expires physically after 24 hours. The live pulse reuses current content-free aggregate module, ticket, SLA, incident and Configuration Guardian counts without copying them into the room. Retained rooms are included in server export, and server deletion removes them.
Public service status and incidents
Kordyn's global operators may intentionally publish bounded German and English incident or maintenance titles and updates for the Web, API, Discord Bot, OAuth and Data components. This copy and its timestamps, lifecycle, impact and affected component list are public on the status page and Atom feed. The private persistence record also contains creator, publisher and update-actor Discord IDs for accountability; these identifiers are removed from every public response and feed. Operators must not place secrets, message content or unnecessary personal data in public copy. Drafts and active records are never removed by retention cleanup; completed, resolved or cancelled incidents are physically limited to the newest 100 and 365 days. This global operational history is not guild/member activity and is therefore outside guild export and member-data deletion; terminal history is removed through the stated retention lifecycle. Kordyn currently makes no uptime or SLA percentage claim from this history.
Launch Control Center
Kordyn's private global Launch Control Center combines current API dependency results, the selected billing provider's latest successfully processed webhook or Discord entitlement observation, current Bot/Worker process heartbeats, a 24-hour failed-job count and the aggregate unresolved Interaction Replay Shield count. Any external interaction effect whose final state is unknown blocks readiness instead of being repeated automatically. The underlying 30-day guild ledger stores only an allowlisted operation, SHA-256 source/request digests, finite state, fenced lease metadata and a sanitized error code—never a raw interaction or member ID, command body, Minecraft username, message, provider response or credential; it is included in guild export and removed with the guild. After a 15-minute recovery window, a global operator may terminally resolve an item only by recording effect-present/effect-absent, a safe scope label, an external SHA-256 report digest, a bounded note, operator Discord ID and timestamp. The report, its URL and target content are never stored; this private operator evidence is excluded from guild export while terminal status and resolution time remain in it, and it is deleted with the operation after 30 days or with the guild. A heartbeat stores only service and bounded instance/deployment identifiers, process/observation timestamps and a small allowlisted set of numeric, Boolean or short operational values; its service/instance row is overwritten and is not an activity history. Restore, privacy-deletion and Discord-permission drills require an explicit global operator attestation. That append-only evidence stores the check, passed/revoked outcome, operator Discord ID, deployment, a bounded non-secret scope label, SHA-256 digest of an external report, bounded note and creation/expiry timestamps. Kordyn never stores that report, its URL, credentials, tokens, Discord message content or member identity in this feature. Attestations expire after 90/90/7 days and global evidence is physically limited to 365 days and 500 newest events. It is outside guild export and member deletion; operator identifiers remain private and expire with the same global evidence lifecycle. The center cannot change public-launch environment flags or approve legal text, and it makes no uptime/SLA claim.
Flex Credits
If Discord-native consumable purchases are later published, Discord handles checkout, payment details, receipts and refunds. Kordyn observes the purchaser-bound entitlement, temporarily stores its Discord user ID so only that account can assign the pack, and stores an HMAC pseudonym for replay and ownership integrity. Assignment requires the purchaser to be a current native Manage Server user. In one transaction Kordyn credits the server wallet, records a content-free receipt/transaction ledger and removes the raw purchaser ID; only then does the Bot consume the Discord entitlement. The wallet stores balance, revocation debt and aggregate lifetime purchased, used, refunded and revoked counts. Transactions store a bounded operation key, kind, signed amount, resulting balance/debt, optional AI Assistant or Image Toolkit resource, optional receipt reference and timestamp—never prompts, responses, images, filenames, payment details or member activity. Credits are used only after the included monthly quota is exhausted; a failed AI or image operation refunds a Flex Credit idempotently. A revoked purchase removes available credits and records any already-spent remainder as debt, which later packs settle first. Server export includes the wallet, ledger and sanitized assigned receipts; server deletion removes wallet and transactions while terminal purchaser-free receipts remain only for the 365-day operational replay lifecycle. Terminal receipts and transaction history are physically limited to 365 days and 5,000 transactions per server. This feature is implemented, but no live purchase may be offered until the final operator-approved billing and refund terms are published.
Advanced Analytics and Weekly Operations Digest
Advanced Analytics stores timestamps and one-way hashed member and event identifiers, never message content. If a Premium server manager enables the Weekly Operations Digest, Kordyn stores its destination channel, local weekday and hour, IANA timezone and delivery state. For each delivery Kordyn derives aggregate counters for a frozen seven-day period and sends them to the selected Discord channel; the rendered report is not stored. The delivery ledger contains server and channel IDs, period and schedule timestamps, finite status and attempt fields, an optional Discord message ID and bounded error metadata. It is limited to 365 days and 100 rows per server. Reports contain no member names, member IDs, top-contributor list or message text. Server export includes the schedule and content-free delivery ledger, and server deletion removes both. Discord receives the report as the selected external delivery destination.
Configuration Guardian
A manual Configuration Guardian check uses the bot's live Discord view to inspect effective permissions, enabled gateway intents, configured channel and role references, and the guild command manifest. Exact IDs, missing values and repair details are returned only transiently through the private `/doctor` command and are not copied into Guardian history. The retained check contains the server ID, source, finite issue area/code/severity, optional non-identifying reference class, counts, content-free fingerprint, notification status and timestamps. It contains no member identity, message content, raw channel or role ID, missing command name or permission value. History is limited to 90 days and 100 rows per server. Premium or valid-Grace managers may store an alert channel and 6/12/24-hour schedule; only changed drift and an optional recovery are sent to that Discord channel. Server export includes the configuration and minimized checks, server deletion removes both, and deleting the destination disables scheduled alerts.
Operations Inbox
Operations Inbox derives current operational work from the server's existing installation, onboarding, finite bot-permission set, module configuration state, Configuration Guardian, Ticket SLA, Interaction Replay Shield and connected Dedicated Bot state. It stores only server, finite key/source, optional module name, severity, SHA-256 state fingerprint, finite status, occurrence count, optional internal Kordyn acknowledgement-user relation and lifecycle timestamps. It stores no localized title or description, current metric payload, Discord member/channel/role/message ID, display name, message content, ticket body, provider payload or secret. Browser responses replace internal acknowledgement attribution with a Boolean indicating whether the current actor acknowledged the item. Acknowledgement or Snooze never changes the source; a changed fingerprint reopens work and a missing source auto-resolves it. Every plan sees every current safety signal. Free/Grace/Premium physically retain resolved history for at most 7/30/180 days and 25/250/2,000 rows; active work remains, and Grace/Premium add only finite Snooze choices. Server export includes the content-free lifecycle rows, user deletion nulls attribution and server deletion cascades all rows. Public production activation stays disabled until live multi-replica PostgreSQL, Discord drift, delegated-access, deletion/export and desktop/mobile drills pass.
Setup Launchpad
Setup Launchpad reads the server's existing module switches, current plan, onboarding status and the bot's finite Discord permission set to build a live starter-pack preview. Applying a pack stores only the same module switches and onboarding flag already used by Kordyn. Its audit contains the selected preset, changed and plan-locked module names, missing permission names and an additive flag. It adds no member data, message content, channel or role identifier, and it never copies or overwrites saved module configuration.
Setup Copilot
When a native server manager explicitly submits a bounded server goal, Kordyn sends it transiently to OpenAI with provider storage disabled (`store: false`), together only with locale, plan, minimized module states and built-in starter/Blueprint metadata. No Discord server, member, channel, role or message identifier, message content or secret is included; an HMAC safety pseudonym replaces raw account identity. Kordyn stores neither the goal nor the recommendation. It retains only a server-scoped UTC monthly usage counter and content-free audit metadata such as character and recommendation counts, finite locale/preset/focus fields, model, token counts, latency, bounded outcome and successful-refund state. Managers must not enter credentials, secrets, member data or copied messages. The strict allowlisted recommendation changes only the browser preview and can never apply modules, install Blueprints or publish an Automation. Provider/subprocessor and international-transfer disclosures plus live safety, concurrency and privacy drills must be operator-approved before ready removal or public commercial launch.
Automation Blueprints
Automation Blueprints are built-in, administrator-selected workflow configuration; Kordyn does not accept executable community code. Preview processing uses the selected locale, workflow name and current channel, role or ticket-panel identifiers transiently to resolve a Draft, check readiness and create a five-minute signed token. Installing stores the server ID, Blueprint key/version/canonical digest, created Automation and version references, finite installed or rolled-back state, installer/rollback account identifiers and timestamps. The installed Workflow DSL is retained as normal administrator-authored Automation configuration; the dry-run stores no message body or member event. Member or user deletion nulls matching actor attribution without deleting server configuration, server export includes installation provenance and server deletion removes it.
Automation Webhook Connectors
A native Discord server manager may configure a public HTTPS receiver for fixed Automation events. Connector configuration stores the server, administrator-authored name, endpoint URL, enabled state, six-character secret hint, secret revision, optional creator account and timestamps. A random signing secret is returned only in the create or rotate response and is then retained only as AES-256-GCM ciphertext; neither form is included in normal logs, browser reads or server exports. Every queued delivery stores a versioned fixed JSON envelope with delivery/event/server/automation metadata, trigger type, finite retry/HTTP/error state and timestamps. It can never contain message content, display name, ticket subject, member role list, arbitrary custom JSON or custom headers. Discord member ID and channel/role/level/ticket identifiers are separately disabled by default and appear only when a manager explicitly enables the corresponding workflow disclosure. The configured receiver is an external destination controlled by the server manager. Free/Grace/Premium physically retain terminal delivery metadata for at most 7/30/180 days and 25/250/2,000 rows; pending or retrying work remains until terminal. Member-data deletion removes a matching opted-in member ID from retained envelopes, user deletion nulls creator attribution, sanitized server export includes endpoint/configuration and retained envelopes, and server deletion cascades all connector and delivery records. Public production activation stays disabled until real receiver, DNS-rebinding and multi-replica PostgreSQL soak tests pass.
Inbound Automation Webhooks
A native Discord server manager may create a secret-bearing inbound connector that lets a controlled shop, website or form request a fixed Automation trigger. Kordyn stores connector name, enabled state, six-character secret hint, secret revision, optional creator account and timestamps; the random signing secret is shown only on creation or rotation and otherwise retained only as AES-256-GCM ciphertext. Each request must include a unique external event ID, Unix timestamp and HMAC-SHA256 signature over the timestamp plus exact raw body. Kordyn never stores the raw body or external event ID: it stores an HMAC pseudonym of the event ID, a SHA-256 body digest, fixed event name, finite delivery state and retry timestamps. The optional text, number and Boolean scalars are encrypted only until processing and erased on every terminal outcome. The payload cannot contain a Discord member, role list, arbitrary object, custom header or secret, and inbound workflows may run only channel-message, outbound-webhook and delay actions. Free/Grace/Premium allow 0/3/25 runnable connectors, 0/5,000/100,000 accepted events per UTC month and physically retain terminal metadata for at most 7/90/365 days and 25/500/5,000 rows. Downgrade overage remains encrypted but plan-paused. Sanitized server export excludes secrets, event-ID pseudonyms and encrypted payloads; user deletion nulls creator attribution and server deletion cascades every connector and event. Public production activation stays disabled until real PostgreSQL multi-replica, crash-recovery and Discord execution soak tests pass.
Level Migration Concierge
When a server manager explicitly previews a level migration, Kordyn transiently processes a bounded CSV or JSON export containing Discord member IDs and XP or levels. The request is limited to 1.5 MB and 10,000 rows; one invalid row blocks the complete import. Imported names are ignored, and the raw source file is not stored. A five-minute signed token binds the manager, server, normalized source digest and exact current member/level state. Applying stores the server ID, source and format, a SHA-256 source digest, aggregate row and XP counts, applying/rollback account identifiers, timestamps and one provenance row per changed member containing the member ID, previous/applied XP and level, content-free state fingerprints and finite rollback outcome. It does not create message or Voice counts, XP events, Season history, achievements or role assignments. Free, Grace and Premium retain at most 3, 10 and 50 import records and offer 24, 168 and 720-hour rollback windows; old terminal or expired records can be pruned when new imports are created. Rollback changes only exact unchanged imported rows and leaves drifted, missing or privacy-deleted state untouched. Member-data deletion removes matching provenance rows, user deletion nulls matching actor attribution, server export includes retained provenance and server deletion removes all migration data.
Role Panel Migration Concierge
When a server manager explicitly previews a Role Panel migration, Kordyn transiently processes a bounded universal CSV or Kordyn JSON export containing administrator-authored panel copy plus Discord channel and role identifiers. The request is limited to 1.5 MB and 1,250 role-item rows; an invalid row, missing or unmanageable channel, missing or unassignable role, duplicate panel name or plan overage blocks the complete import. A five-minute signed token binds the manager, server, normalized SHA-256 source digest and exact current Role Panel, Discord resource and plan state. The raw source is never stored. Applying atomically creates unpublished Role Panel drafts and stores only source/format, digest, aggregate row/panel/item counts, applying/rollback account identifiers, timestamps and one provenance record per draft with its source key and content fingerprint. It never publishes a Discord message or assigns a member role. Free, Grace and Premium import up to 3/10/50 panels and 25/250/1,250 role items, retain 3/10/50 migration records and offer 24/168/720-hour rollback windows. Rollback deletes only an unchanged version-one draft; edited, published or missing panels remain untouched and are recorded as drifted or missing. The configuration contains no member identifier, user deletion nulls actor attribution, server export includes retained migration provenance and server deletion cascades all records.
AutoMod Migration Concierge
When a server manager explicitly previews an AutoMod migration, Kordyn transiently processes a bounded universal CSV or structured JSON export containing administrator-authored rule names, trigger terms, actions and optional Discord channel or role identifiers. The request is limited to 1.5 MB and 250 source rules; an invalid rule, duplicate name, missing or unmanageable resource, unavailable timeout permission, native Discord trigger-slot overage or plan overage blocks the complete import. A five-minute signed token binds the manager, server, source/format, normalized SHA-256 source digest and exact current Kordyn rules, live Discord AutoMod usage, Discord resources, timeout permission and plan state. The raw source is never stored. Applying atomically stores normalized rules as disabled and unsynchronized Kordyn configuration plus source/format, digest, aggregate row/rule/entry counts, applying/rollback account identifiers, timestamps and one fingerprinted provenance record per rule. It does not create or update a Discord AutoMod rule and activates no moderation action; each rule must be reviewed and saved manually. Free, Grace and Premium import up to 2/6/9 rules and 100/350/1,000 entries, retain 3/10/50 migration records and offer 24/168/720-hour rollback windows. Rollback removes only an exact unchanged rule that is still disabled and has no Discord rule ID; edited, enabled, synchronized or missing rules remain untouched and receive a finite drift or missing outcome. The migration contains no member identifier, user deletion nulls actor attribution, server export includes retained provenance and server deletion cascades all records.
Automation Migration Concierge
When a native Discord server manager explicitly previews an Automation migration, Kordyn transiently processes a bounded universal CSV or structured JSON export containing administrator-authored workflow names, triggers, conditions, actions, templates and optional Discord channel, role or ticket-panel identifiers. The request is limited to 1.5 MB and 250 source automations; malformed or unsupported semantics, duplicate names, missing or unmanageable resources, unavailable timeout permission or plan overage blocks the complete import. A five-minute signed token binds the manager, server, source/format, SHA-256 source digest and exact current Automation, Discord resource, bot-permission and plan state. The raw source and filename are never stored. Applying atomically creates only inactive version-one Automation drafts plus source/format, digest, aggregate row/automation/node counts, applying/rollback account identifiers, timestamps and one fingerprinted provenance record per draft. It activates or executes no workflow and makes no Discord change. Free, Grace and Premium import up to 2/10/50 automations and 30/150/750 workflow nodes, retain 3/10/50 migration records and offer 24/168/720-hour rollback windows. Rollback archives only an exact unchanged draft at its imported version; edited, activated, archived or missing workflows remain untouched and receive a finite drift or missing outcome. The migration contains no member identifier, user deletion nulls actor attribution, server export includes retained provenance and server deletion cascades all records.
Onboarding Experiment Studio
When a native Discord server manager starts an Onboarding Experiment, Kordyn stores the administrator-authored experiment name, two bounded public Welcome variants and/or two bounded private DM variants, fixed 50/50 allocation policy, lifecycle timestamps and optional creator/start/completion account identifiers. A joining member is assigned before Welcome delivery with a deterministic HMAC-derived A/B choice; the durable assignment stores server, experiment and Discord member IDs, variant, join/assignment timestamps, content-free delivery flags and optional activation/retention timestamps. It never stores the member's messages or builds a member score. Kordyn activation means the first eligible server message within 24 hours; retention means an eligible message between day 7 and day 14. Discord channel views are not observable and are not claimed as activation. Results use mature cohorts and show no directional signal before at least 25 eligible members per variant. Free, Grace and Premium retain at most 3/10/50 experiments, 250/2,500/25,000 assignments per experiment and physically retain assignment rows for 30/180/365 days. Member-data deletion removes assignments, user deletion nulls actor attribution, server export includes retained configuration and assignments, and server deletion cascades all records.
Activation Journey Studio
When a native Discord server manager enables Activation Journey Studio, Kordyn stores the enabled state, a bounded administrator-authored `{user}`/`{server}` template, delay, selected starting-channel ID, configuration version, optional updating account ID and timestamps. A member is enrolled only after at least one initial Welcome destination was actually delivered. The retained journey state contains server and Discord member IDs, exact join time, initial-delivery flags, configuration version, due/retry/lease state, bounded delivery outcome, optional Discord DM message ID, activation/opt-out times and retention expiry; it contains no member message text, channel-view history or hidden score. Before delivery, trusted content-free server activity cancels the follow-up. Otherwise Kordyn sends at most one transparent DM per join with a channel link, an explanation of why it was sent and a button that permanently suppresses future check-ins for that member on that server. The suppression record stores the server/member IDs, a one-way hash of the opt-out interaction and timestamps. Dashboard results are aggregate only and label the 24-hour post-delivery rate as observational rather than causal. Free, Grace and Premium allow 100/2,500/25,000 enrollments per UTC month and physically retain journey rows for at most 14/90/365 days; paid plans add custom copy and timing. Member-data deletion removes journey and suppression rows, user deletion nulls configuration attribution, server export includes retained configuration/state/suppression records and server deletion cascades all records.
Command Intelligence
For each slash interaction, Kordyn may store the server ID, a one-way SHA-256 hash of the guild-bound Discord interaction ID, one command from Kordyn's finite catalog, an invoked/blocked/failed outcome, a finite reason and UTC timestamps. Kordyn does not collect a member ID, channel ID, option value, response or message content for this feature. Smart Help Search processes the focused autocomplete text, selected command option, current member roles and permissions transiently inside the bot to return a private personal access explanation. That search text, option and derived access state are not sent to the API, logs, audit, export or an external provider; Command Intelligence can count only the ordinary finite `help` invocation. The hash prevents one Discord interaction from being counted twice. Free, Grace and Premium physically retain at most 7, 30 and 90 days and 500, 5,000 and 25,000 rows respectively. Free receives aggregate totals and five top commands; paid plans expose longer ranges and finite blocker diagnostics. Server deletion removes all rows; no member-specific deletion is required because no member identifier is stored.
Command Governance v2
A server manager may store a finite Kordyn command name, enabled state, selected role and channel IDs, exactly one all/allow/deny channel mode and an optional cooldown duration. Kordyn enforces this policy at runtime in addition to Discord's native permissions and does not claim to update Discord application-command permission overwrites. Current member roles, channel and parent-thread context are evaluated transiently. For a configured cooldown, the bot sends server, member and interaction IDs plus the API-selected bounded duration only through the authenticated internal route; Redis stores only an application-secret HMAC key and separate interaction HMAC value with a maximum one-hour TTL. Raw cooldown identifiers are not written to PostgreSQL, normal logs, audit or export. Free keeps complete role/channel governance and the global burst guard; Free, Grace and Premium activate 5, 25 and 101 custom cooldowns up to 60, 300 and 3,600 seconds. Downgrade overage remains saved but plan-paused. Deleted roles and channels are repaired from saved policies, and server deletion removes the configuration. No member-specific deletion is required for the expiring non-reversible cooldown pseudonym. Public production activation stays disabled until live multi-bot Redis, thread, outage, downgrade, deletion and privacy drills pass.
Dashboard Teams
When an authorized Manage Server user delegates dashboard access, Kordyn stores the selected member's Discord ID, saved view/manage mode, workspace scopes, enabled state and timestamps. Display name, username, avatar, current guild membership and Discord permissions are resolved transiently and are not copied into the grant. The member must still belong to the Discord server and the bot must remain installed. Revoking the seat or deleting that member's server data removes the grant; deleting the server removes all grants. Billing, installation, backups, global settings, server data operations and access administration cannot be delegated.
Organization Command Center
When a native Manage Server user creates an Organization Command Center, Kordyn stores the administrator-authored organization name, enabled state, home-server ID, linked server IDs and link/configuration timestamps. A server can be linked only while the acting account natively manages both the home server and target server and Kordyn is installed on the target; one target server can belong to only one organization. Read-only portfolio access reuses the home server's plan-bounded Dashboard Teams overview scope and never grants native Discord permissions or cross-server configuration writes. On each private dashboard request Kordyn derives aggregate server, module, permission-health, open-ticket, SLA-breach and active-incident counts plus an explainable readiness score. The derived radar is not stored and uses no member ID, member name, message content or cross-server member profile. Grace and Premium support up to 5 and 50 total servers respectively; downgrade overage remains linked but pauses. Server export includes owned organization configuration and membership references. Deleting the home server removes the organization; deleting a linked server removes its link.
Incident War Room
When an authorized server manager starts an Incident War Room, Kordyn stores the server and incident identifiers, sequence, title, severity, administrator-authored reason and resolution summary, commander ID, selected response-role and channel IDs, bounded channel names, containment and restoration state, checklist state, content-free Raid Guard signals, administrator-authored timeline notes and timestamps. The timeline also records the acting Discord ID for accountable checklist and response actions; member-data deletion replaces matching commander and actor IDs with `deleted`. Administrators should not place unnecessary personal data or message content in incident reasons, notes or summaries. Free, Grace and Premium physically retain resolved incidents for at most 7, 30 and 90 days and 10, 100 and 500 incidents respectively, with separate finite timeline limits. An active response is never removed by retention pruning. Server export includes the retained record and a verifiable report digest; server deletion removes all War Room data.
AI Moderation
When a server administrator explicitly enables AI Moderation for selected channels, the current message text is transferred transiently through Kordyn's authenticated API to OpenAI's moderation service. Kordyn does not store the message body, attachments, provider scores or arbitrary provider response. The retained incident contains server, member, channel and message identifiers, selected flagged categories, provider model, final outcome, timestamps and optional bounded error correlation. Self-harm categories are always review-only and do not authorize automatic punishment. Free, Grace and Premium retain incident history for 7, 30 and 90 days with plan-specific row limits. Member-data deletion replaces the member identifier with an incident-scoped anonymous identifier; server export includes the content-free incident and server deletion removes it. OpenAI/provider and international-transfer disclosures must be reviewed and completed by the operator before public commercial launch.
Community AI, Persona Studio and Knowledge Studio
When a member directly mentions the enabled Community AI in an approved channel, Kordyn transfers the current bounded question transiently to OpenAI with provider storage disabled and does not retain the prompt, answer or conversation history. Persona Studio personas and Knowledge Studio articles are different: they are administrator-authored server configuration and are intentionally stored until edited or the server tenant is deleted. The server export includes persona name, optional tagline, instructions and knowledge articles. Only the single active persona inside the current plan limit is transferred per request; Kordyn removes Discord identifiers, moderates its text with the current question and always presents the result publicly as a Kordyn AI persona. A persona cannot override fixed identity, safety or privacy rules, claim to be human, Discord staff, server staff or a professional authority. Over-limit personas retained after a downgrade are paused and not sent to the provider. Kordyn locally selects only matching active articles up to the plan limit and transfers their title and body as untrusted reference data. Optional source URLs must use credential-free HTTPS and are displayed but never fetched by Kordyn. Content-free audits retain only character/token counts, selected-source count, persona-active state, model, channel and latency, never the member question, generated answer, persona text or article body. Administrators should not place personal data, secrets or third-party copyrighted material in persona or article text. Provider/subprocessor and international-transfer disclosures must be reviewed and completed before public commercial launch.
Ticket Copilot
When an authorized support manager explicitly requests Ticket Copilot for an open ticket, Kordyn retrieves a plan-bounded set of recent Discord message text, replaces author identity with member/staff roles, removes Discord identifiers and excludes attachments before transferring the request transiently to OpenAI. The provider is instructed not to retain the API response (`store: false`). Kordyn does not persist the source text, summary, priority, category, review flags or reply draft; the browser result disappears on reload. Kordyn retains only a server-scoped UTC monthly usage counter and content-free audit metadata containing ticket ID, message count, truncation state, model, token counts, latency and success/failure state. Ticket Copilot cannot send messages or change a ticket; a human must separately copy or send any draft. Provider/subprocessor and international-transfer disclosures must be reviewed and completed by the operator before public commercial launch.
Tokens and sessions
OAuth tokens are handled on the server and encrypted when persisted. Browser sessions use secure cookies and expire automatically. Secret values are not placed in the client bundle or normal application logs.
Retention and deletion
Retention depends on the enabled feature and server configuration. Message contents are not stored by default. Dashboard Reply Bridge terminal delivery metadata is removed after 90 days and its internal replay ledger is excluded from server exports. Ticket ownership history is physically limited to 7 days/25 rows on Free, 90 days/250 rows during Grace and 365 days/2,000 rows on Premium. Member deletion removes or scrubs matching ticket ownership identifiers, removes that member from on-call schedules (deleting a now-empty shift) and releases a ticket if the deleted member was its current owner. Service-hours bypasses contain role IDs rather than member IDs, so they require no member-specific retention. Authorized managers can download a complete server-scoped JSON export, including administrator-authored on-call and service-hours configuration. After the bot has been removed, the Discord server owner can permanently delete the tenant data with exact-name confirmation and a separate irreversible-action acknowledgement.
Forms and applications
When a server enables a form, Kordyn stores the submitted Discord member ID, display name, bounded answers, timestamps and review status. Anonymous mode hides identity from reviewer-facing messages and the dashboard but retains the member ID privately for cooldown, duplicate protection, member-data deletion and any role action the server manager explicitly configured for an approval or rejection. A human decision first stores an exact role-action snapshot; a leased background job then rechecks the current plan, configuration, member presence, bot permission and Discord role hierarchy before applying only the missing add/remove delta. Finite attempt and non-sensitive error metadata remains visible to managers, while random claim tokens and lease expiry are excluded from browser responses and server exports. Free, Grace and Premium physically retain non-executing form history for at most 30/90/365 days and 100/500/2,000 rows; queued, processing or retrying role work remains until terminal. Member-data deletion removes that member's submissions; deleting a form or server cascades its remaining forms, answers and fulfillment state. Public production activation for Application Fulfillment stays disabled until the documented real Discord and multi-replica PostgreSQL reviewer drill passes.
Contact
Privacy contact: Required before launch. Do not publish this service commercially until the responsible operator and applicable privacy notices are complete.