BotFrame
Builder AI Templates Guides Docs Pricing
Join the beta

Privacy Policy

This policy explains how information is processed when you visit, use, build with, deploy through, or purchase access to BotFrame, including uses for AI and service development.

Last updated 7 August 2026

1. Scope and terminology

This policy applies to the BotFrame product and hosted service, including botframe.dev, app.botframe.dev, the editor, simulator, APIs, hosted runtime, AI-assisted features, account services, and support communications.

“BotFrame” is the product and brand. References to “we”, “us”, or “our” mean the individual Supplier who owns and provides the BotFrame product and the service providers acting on the Supplier’s behalf.

Discord, Paddle, AI providers, infrastructure providers, and other third parties have their own privacy practices and may act independently for some processing.

2. Information we collect and process

Account and Discord identity information

BotFrame uses Discord OAuth for customer sign-in. When you authorise BotFrame, we may receive and store your Discord user ID, username, global display name, avatar identifier, email address, whether Discord reports the email as verified, and login, account-link, or revocation timestamps.

Projects, workflows, revisions, and simulator data

We process information created in or supplied to the Service, including project names and descriptions, workflow documents and revisions, revision metadata, simulator worlds and suites, tests and results, release and deployment state, prompts, configuration, generated material, plan and entitlement information, and related project metadata.

Discord application credentials

When you connect a Discord application, we may store a Discord bot token and technical identifiers such as application IDs, bot user IDs, public keys, route identifiers, validation state, and credential version information. Bot tokens are intended to be stored in encrypted form and are not intentionally displayed back to you in full after storage.

Discord server, interaction, and runtime data

To deploy and operate customer bots, BotFrame may process Discord server, channel, member, user, interaction, command, message, and event data required by the workflow you configured. Depending on permissions and workflow design, this may include server IDs and names, icon identifiers, reported member counts, user or channel IDs, command options, interaction values, message content, execution inputs and outputs, delivery status, error information, runtime events, and related metadata.

AI feature and model-development data

When you use AI-assisted or automated features, we may process prompts, instructions, project context, workflows, simulator material, schemas, generated outputs, feedback, evaluations, and other information relevant to the request. We may also select eligible Customer Content and service interactions for testing, evaluation, research, model development, fine-tuning, benchmarking, safety work, quality review, and improvement of BotFrame or related AI and machine-learning systems.

Billing and subscription information

Paid purchases are processed by Paddle.com as reseller and Merchant of Record. We may receive billing-related identifiers and status information needed to provision access, such as a Paddle customer or subscription identifier, plan tier, subscription status, transaction state, and billing-period information. We do not receive or store full payment-card numbers for Paddle transactions.

Technical, security, usage, and session information

We and our providers may process IP addresses, request headers, timestamps, browser or device information, session identifiers, security signals, service logs, rate-limit information, usage counters, feature interactions, performance telemetry, errors, diagnostics, abuse indicators, and other operational information.

Support, feedback, and waitlist information

If you contact us or provide feedback, we process the contact details and content you provide. If BotFrame operates a beta, launch, or other waitlist, we may collect the email address and associated submission metadata.

3. How we use information

We may use information to authenticate users; provide accounts; save and process projects; validate, simulate, deploy, and run Discord bots; deliver Discord actions; enforce plan limits and entitlements; provide AI-assisted features; provision subscriptions; provide support; prevent fraud and abuse; secure systems; investigate incidents; diagnose faults; monitor performance; perform analytics; enforce our Terms of Service; comply with law; and protect the Supplier, customers, Discord users, Paddle, service providers, and third parties.

We may also use eligible information to research, design, develop, test, train, fine-tune, evaluate, benchmark, monitor, and improve BotFrame, related software, automated decision systems, machine-learning models, and AI systems. This may involve automated processing, human review, annotation, quality evaluation, or the creation of datasets and derived statistics.

We may create and use aggregated, statistical, or de-identified information for product development, analytics, capacity planning, security, research, benchmarking, commercial planning, and other lawful purposes. Where information is no longer personal information under applicable law, we may retain and use it without the restrictions that apply to identifiable personal information.

We do not sell personal information for money and do not currently use BotFrame account or project data for cross-context behavioural advertising.

4. Customer Content and AI/model training

Customer Content may be used to develop and improve AI and machine-learning systems. Subject to applicable law, eligible material may include prompts, workflows, workflow revisions, simulator documents, configuration, generated outputs, feedback, evaluations, and other content or interactions processed through BotFrame.

Training and evaluation may occur on systems operated by us or through service providers. Content may be filtered, sampled, transformed, labelled, reviewed, aggregated, or de-identified before or during those processes. We do not promise that all eligible training material will be fully anonymised before processing, although we may apply minimisation, filtering, or de-identification where appropriate.

We do not intend to use authentication secrets such as Discord bot tokens, passwords, private keys, or full payment-card information as model-training content. Customers should nevertheless avoid placing secrets or unnecessary sensitive information into prompts, workflows, logs, messages, or other content that may be processed by AI features.

If we provide an opt-out or similar control, the control applies only within its stated scope and generally on a prospective basis. Subject to applicable law, opting out later does not require us to reconstruct or retrain existing models, remove information already reflected in model parameters or derived datasets, or delete de-identified or aggregated information.

Where applicable privacy law requires consent, a specific notice, another lawful basis, or additional safeguards for a particular use of personal information, we will rely on the basis or process required by that law. This policy does not purport to override mandatory privacy rights.

5. Discord end-user data and customer responsibilities

Customers decide what their Discord applications do, which permissions they request, which servers they join, and which workflows they deploy. Customers are responsible for determining whether their collection and use of Discord end-user information is lawful and for providing notices, obtaining permissions or consent, and meeting other obligations that apply to their use case.

BotFrame may process end-user information to execute configured workflows, deliver actions, maintain service state, secure the platform, detect abuse, diagnose errors, investigate incidents, and perform other processing described in this policy. Customers should not configure bots to collect sensitive, confidential, or unnecessary personal information unless they have determined that doing so is lawful and appropriate.

If a customer causes third-party personal information to be submitted to BotFrame, the customer is responsible for having authority to do so. We may restrict, delete, quarantine, or decline to process data that creates material privacy, security, compliance, or operational risk.

6. AI and other service providers

BotFrame currently uses OpenAI infrastructure for some AI-assisted generation. When an AI feature is invoked, relevant prompts and project context may be sent to OpenAI for processing. We may add, replace, or remove AI providers and may use different providers for generation, evaluation, moderation, embeddings, model development, or other AI-related functionality.

Third-party providers process information under their own contracts, privacy terms, and technical controls. Their permitted use of data may differ by service, configuration, or contract. We will make disclosures required by applicable law when a provider change materially affects how personal information is handled.

7. Other service providers and disclosures

We may disclose information where reasonably necessary to operate, secure, develop, support, finance, transfer, or protect the Service; complete transactions; comply with law; enforce rights; investigate misconduct; or respond to legal process. Categories of recipients may include:

  • Amazon Web Services, for production application, database, runtime, storage, and infrastructure hosting;
  • Cloudflare, for website delivery, network security, and related infrastructure;
  • Discord, for customer authentication and operation of customer-controlled Discord applications;
  • OpenAI and other AI providers, for AI-assisted features and other AI-related processing described in this policy;
  • Paddle, as reseller and Merchant of Record for paid transactions, subscriptions, tax, payment support, cancellations, disputes, and refunds;
  • email, monitoring, analytics, security, infrastructure, development, support, and professional-service providers;
  • prospective or actual purchasers, successors, advisers, financiers, or counterparties in connection with a sale, transfer, financing, restructuring, or change in ownership or operation of BotFrame; and
  • courts, regulators, law-enforcement bodies, payment partners, rights holders, or other parties where disclosure is required by law or reasonably necessary to protect rights, safety, security, or service integrity.

8. Legal bases where required

Where laws such as the UK GDPR or EU GDPR require a legal basis, processing may be based on performance of a contract or steps requested before a contract; legitimate interests in operating, securing, developing, improving, and protecting the Service; compliance with legal obligations; consent where required; or another basis available under applicable law.

The legal basis can vary by category of information and purpose. A statement in this policy does not mean that every listed basis is used for every processing activity.

9. Cookies, sessions, and similar technologies

BotFrame uses session storage and similar technologies needed to authenticate users, protect requests, maintain account state, enforce security, remember essential settings, and operate the Service. Infrastructure providers may also use cookies, identifiers, or similar signals for security and network protection.

If non-essential analytics, advertising, or tracking technologies are introduced, we will provide notices or controls where applicable law requires them.

10. Retention, downgrade, deletion, and backups

Retention periods vary by data type, account status, plan, operational need, legal requirements, security needs, storage constraints, and whether information has been incorporated into backups, logs, analytics, datasets, or models. We do not promise a fixed retention period for Customer Content unless a separate written commitment expressly provides one.

When an account becomes inactive, a paid entitlement expires, a subscription is downgraded, a project exceeds its current plan, or access is suspended or terminated, we may immediately or later delete, archive, restrict, compact, de-identify, or make inaccessible data that is no longer required to provide the current entitlement. We may offer a grace period or recovery path, but we are not required to do so unless applicable law requires it.

Deletion from active systems does not necessarily result in immediate deletion from backups, security records, logs, fraud-prevention records, legal records, derived analytics, evaluation datasets, or model parameters. Backups are maintained for operational purposes and may be rotated or overwritten on schedules we determine.

Subject to applicable law, de-identified, aggregated, statistical, or model-derived information may be retained indefinitely. Information incorporated into trained model parameters or inseparable derived datasets may not be practically removable, and we do not promise to retrain models in response to account deletion unless required by applicable law.

Transaction and subscription records may be retained for accounting, tax, fraud prevention, chargebacks, disputes, compliance, or other legal purposes even after account closure.

11. Security

We use technical and organisational measures intended to reduce the risk of unauthorised access, alteration, disclosure, and loss. Measures may include encrypted transport, access controls, secret management, separation of customer resources, logging, and encryption of stored Discord bot tokens.

No online service, storage system, encryption scheme, backup process, or third-party provider can guarantee absolute security or availability. You are responsible for securing your Discord account, devices, and application credentials and for rotating credentials when appropriate.

12. International processing

BotFrame and its providers may process information in countries other than the country where you or a Discord end user is located. Where applicable law requires a transfer mechanism or safeguard, we will use a mechanism or safeguard available to us under that law.

13. Privacy requests and choices

You may contact privacy@botframe.dev about personal information associated with your BotFrame account. We will honour access, correction, deletion, portability, objection, restriction, withdrawal, or similar rights where applicable law grants that right and the request is valid.

We may verify identity, limit a response to information we can reasonably identify, decline or narrow requests where a legal exception applies, and retain information where permitted or required for security, fraud prevention, legal claims, compliance, backups, or other lawful purposes. This policy does not create contractual privacy rights beyond those provided by applicable law and the express commitments stated here.

Where processing is based on consent, withdrawal generally affects future processing and does not automatically invalidate prior lawful processing. Where applicable law permits, de-identified, aggregated, model-derived, or inseparable information may continue to be used after a request.

For information processed independently by Paddle, Discord, OpenAI, or another third party, you may need to exercise rights directly with that party.

14. Children and younger users

BotFrame customer accounts are not intended for anyone below Discord’s applicable minimum age. Customers who are not legally able to enter into an applicable agreement or paid transaction without authorisation must obtain the required authorisation.

Customer bots may interact with Discord users who are minors. Customers are responsible for configuring their bots and processing end-user information in a manner appropriate for their audience and compliant with law and Discord policy.

15. Changes to this policy

We may update this policy as BotFrame develops, processing purposes change, providers change, or legal requirements evolve. The revised version will be posted here with a new “last updated” date. Additional notice will be provided where applicable law requires it.

16. Contact

Privacy questions and valid rights requests can be sent to privacy@botframe.dev. General account or product support is available at hello@botframe.dev.

Do not send Discord bot tokens, passwords, private keys, payment credentials, or other authentication secrets by email.

BotFrame

Build, test, publish, and host your Discord bots with visual workflows.

ProductBuilderAI builderTemplatesPricing
ResourcesGuidesDocumentationHosting
CompanyAboutContactPrivacyTermsRefunds
© 2026 BotFrameVisual Discord bot builder and managed hosting