Privacy policy
Revised: 27 July 2026
This policy explains how LunaPhoebe [legal business name] ("Scrump", "we", "us", or "our") handles information when you use the Scrump Discord app, scrumpbot.com, its dashboards and APIs, subscriptions, music services, moderation and safety tools, and related features (together, the "Services"). Questions and privacy requests can be sent to [email protected].
Discord server owners and managers choose which Scrump features to enable and how those features are configured. That choice affects which information Scrump receives and stores in a server. Some records are therefore connected to a Discord server and its managers as well as to an individual user.
Information Scrump receives and stores
Discord identity, account, and server information
When you use Scrump or sign in with Discord, we may receive and store:
- Discord user IDs, usernames, global and server display names, email address, avatar hash, and whether an account is a bot.
- Discord OAuth access tokens and their expiry time. Access tokens are encrypted before they are stored.
- Server IDs, names, icons, owner IDs, preferred locale, feature flags, and member counts.
- Channel and role IDs and names, role permissions, channel permission overwrites, application commands, command permissions, and Discord AutoMod rule configuration.
Messages and feature content
Scrump does not store ordinary message content. It does process message events and stores content when an enabled feature needs that content to work. Depending on the feature, this can include message text, links, attachments, embeds, author or submitter IDs, server/channel/message IDs, timestamps, and configuration supplied by users or server managers.
Examples of stored feature data include confessions and their submitter IDs, reminders, bookmarks, quotes, sticky messages, starboard, role menus, giveaways and their entries, levelling activity and XP, reputation and relationship features, language preferences, user and server blocklists, public-leaderboard choices, and configured moderation or AutoMod messages. Scrump also processes text submitted for translation, but does not store that text. A feature may display content anonymously to server members proving it to moderators through configured logs.
Statistics, moderation, and safety information
- Statistics: hourly counts of messages, joins, leaves, and voice minutes associated with server, channel, and user IDs, plus daily and weekly aggregates. Message text is not part of these activity counters.
- Moderation: target and moderator IDs, action, reason, duration, source, timestamps, Discord audit-log references, revocation or redaction history, and aggregate moderation metrics.
Automated safety systems may analyse images and text to flag or block suspected scams or unsafe media under rules chosen by server managers. Server managers can review configured moderation outcomes, and concerns can be raised through the contact address above.
Music information
Music features may store searches, playlists and descriptions, playlist shares, requester and contributor IDs, user and server song blocklists, DJ role and player settings, queue and player snapshots, voice-channel membership needed to control playback, and listening history.
Website, authentication, and analytics information
- OAuth transaction records, hashed browser-binding values, hashed session identifiers, session creation and last-seen times, and revocation state.
- Aggregate website route, request method, response status, error, and latency metrics, along with page and dashboard categories.
- First-party product events such as invite clicks, dashboard sign-ins, initial feature configuration, protection events, plan-limit events, pricing views, checkout starts, subscription assignment, and retention. An event may include a Discord user ID, server ID, bounded campaign source, and limited event metadata when needed to understand product use.
- Dashboard changes and audit records containing the acting user, server, action, target, outcome, and configuration snapshots before or after a change.
Scrump does not load third-party behavioural analytics or advertising scripts. We use the first-party operational and product measurements described above to run and improve the Services, we do not share our metrics with any third parties, advertisers, or partners.
Purchases and subscriptions
We store records as needed to administer paid plans and trials, including Stripe customer, checkout, product, price, subscription, and invoice references; status; amount and currency; hosted invoice links; assigned server; purchaser and beneficiary IDs; and trial information. Stripe processes payment methods, billing details, tax information, and fraud signals. Scrump does not store or ever access your full payment-card number or card security code.
How we use information
We use information to:
- provide Discord commands, dashboards, music, safety, moderation, statistics, and community features;
- authenticate users, check server permissions, maintain sessions, and prevent unauthorised changes;
- operate subscriptions, trials, invoices, entitlements, and support;
- detect abuse, scams, security incidents, fraud, and violations of applicable rules;
- maintain high availability, diagnose failures, measure performance, and recover service state;
- understand feature adoption and improve the Services; and
- comply with law, enforce our terms, and establish or defend legal claims.
Where data-protection law requires a lawful basis, we rely as appropriate on performance of our agreement with you, our legitimate interests in operating and securing Scrump, consent for optional choices, and compliance with legal obligations. We balance legitimate interests against the rights and expectations of affected users.
Who can see information
Information submitted in Discord may be visible to server members, moderators, or managers according to Discord permissions and the feature's configuration. Examples include leaderboards, quotes, giveaway entries or winners, role menus, starboard posts, moderation history, confessions, and safety-review information. Server managers can also access configuration and aggregate server data through authorised dashboards.
Do not submit information through a public or server-visible feature unless you are comfortable with the audience configured for that feature. To change a server-controlled record, you may need to contact the server's managers as well as Scrump.
Service providers and disclosures
We disclose information only as needed to operate a requested feature, administer the Services, protect users, or meet legal requirements. Providers and recipients include:
- Discord: identity, OAuth, server membership and permissions, interactions, messages, media, moderation actions, and other Discord data required by enabled features.
- Stripe: customers, checkout, subscriptions, invoices, payment methods, tax, fraud prevention, and billing administration.
- Music and lyrics providers: Spotify, Tidal, Deezer, and Apple Music. Scrump sends searches, public provider links, track identifiers, and track metadata as needed to find catalogue records, lyrics, or playable media.
- Google Translate: text submitted for translation, including text extracted from an image, is sent for translation.
- TikTok: usernames submitted to the TikTok lookup feature are requested from TikTok.
- Infrastructure providers: hosting, databases, caches, file storage, network delivery, monitoring, and other operational suppliers may process information on our behalf.
We may also disclose information where reasonably necessary to comply with law or valid legal process, protect a person or the Services, investigate abuse or fraud, enforce agreements, or complete a merger, financing, acquisition, or transfer of the Services with appropriate safeguards.
Retention
Retention depends on the type of record and why it exists. The following validity and cleanup periods are implemented in the Services as of the revision date:
- OAuth transactions: valid for 10 minutes. Expired transactions and transactions consumed more than 10 minutes earlier are removed when a new OAuth transaction is created.
- Website sessions: valid for no more than 14 days and invalid after 7 days without use. Expired sessions and sessions revoked more than 24 hours earlier are removed when a new website session is created.
- Hourly statistics and hourly moderation or security rollups: Maximum 2 years as required by the feature or server configuration.
- Completed dashboard mutations and dashboard audit records: 90 days.
- Music service events and ordinary player snapshots: about 15 minutes. Persistent queue snapshots expire after 30 days.
Moderation archives may remain after a user erasure request with user IDs and reasons removed. Safety evidence may remain where necessary to protect servers and other users. Billing references and limited pseudonymous records may remain to meet accounting, fraud-prevention, trial-eligibility, dispute, or legal requirements.
Security
Scrump uses technical and organisational measures intended to protect information. These include encrypting stored Discord OAuth tokens, hashing OAuth state and website session identifiers, permission checks, secure production cookies, CSRF protections, bounded caches and payloads, and restricted administrative access.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or obtain a copy of personal information, and to object to certain processing or withdraw consent. You can also change optional feature settings, remove content where a feature provides that control, sign out to revoke the current website session, or ask a server manager to change server-controlled records.
To make a request, email [email protected] from an address or Discord account we can use to verify the request. Describe the Discord user ID and relevant server or feature. We may need additional information to verify identity and authority. Active paid entitlements may need to be cancelled, transferred, or ended before erasure so that billing and beneficiary access can be resolved.
An erasure request does not always delete every row. Where continued retention is justified, Scrump may remove or replace identifiers and content instead. The erasure process can preserve a keyed pseudonymous erasure log, trial-eligibility marker, erased subscription or invoice references, anonymised statistics, and redacted audit or safety records. These retained records are not used to recreate a deleted Scrump profile.
You may complain to the data-protection authority where you live. We would appreciate the opportunity to address the concern directly first.
Children
The Services are intended for people who meet the minimum age in our Terms of Service and the rules applicable to their Discord account. We do not knowingly solicit personal information from children. If you believe a child has provided information in violation of those requirements, contact us so we can investigate and take appropriate action.
International processing
Scrump and its providers may process information in countries other than the one where you live. Those countries may have different data-protection laws. Where required, we use appropriate legal mechanisms and safeguards for international transfers.
Changes to this policy
We may update this policy when the Services, providers, or legal requirements change. The revised date at the top identifies the current version. Material changes may also be announced through the website, Discord, or another appropriate service notice.
Contact
For privacy questions or requests, email [email protected].