Privacy Policy
Last updated August 1, 2026
This page is maintained by the Botbuild team to explain what data Botbuild collects when you use the product, why we collect it, and how you can have it removed. It describes our current practices and is not an independent audit or certification.
1. Who we are
Botbuild ("we", "us") provides a web application that turns a written prompt into Discord bot code, simulates that bot, and optionally runs it in production on your behalf. For privacy questions, contact support@botbuild.app.
2. Data we collect
- Account data. Your email address and, if you sign in with Google, the basic profile information Google returns (name, email, avatar). Passwords are never stored by us in readable form; authentication is handled by our managed auth provider.
- Product data. The prompts you write, the bot code and configuration generated from them, your saved bots, and simulator activity.
- Discord credentials. If you deploy a bot, the application ID, public key and bot token you provide. Tokens are encrypted at rest and are only decrypted server-side to talk to Discord on your behalf.
- Billing data. Plan, credit balance, credit usage history and payment records. Card details are collected and stored by Stripe, not by us.
- Technical data. Request logs and error reports needed to keep the service running and secure.
3. How we use it
To create your account and sign you in; to generate, simulate, store and run your bots; to meter credit usage and process payments; to provide support; to detect abuse; and to improve reliability. We do not sell your data, and we do not use your prompts or generated code to train our own models.
4. Processors we rely on
- Supabase. Database, authentication and storage (data hosted in the cloud region of the project).
- Cloudflare. Application hosting and edge delivery.
- OpenAI, via our AI gateway. Processes your prompt text to generate bot code.
- Stripe. Payment processing, subscriptions and receipts.
- Discord. Receives requests only for bots you explicitly deploy.
Each processor receives only the data needed to perform its function and is bound by its own terms and security commitments.
5. Retention and deletion
Account, bot and billing records are kept for as long as your account exists. You can delete individual bots at any time from the app, which removes their code, deployment configuration and stored Discord token. To delete your entire account and associated data, email us and we will action the request within 30 days. Billing records may be retained longer where required by tax or accounting law.
6. Security
Access to your data is restricted per user through row-level database policies, so one account cannot read another account's bots, credits or payments. Discord bot tokens are encrypted before being written to the database. Incoming Discord webhook requests are verified with Ed25519 signatures before they are processed. Traffic is served over HTTPS. No system is perfectly secure, and we do not claim any external certification.
7. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, or to object to certain processing. Email support@botbuild.app and we will respond within 30 days.
8. Cookies
We use only the storage strictly necessary to keep you signed in and remember interface preferences such as panel sizes. We do not run advertising or cross-site tracking cookies.
9. Children
Botbuild is not directed at children under 13, and Discord itself requires users to be at least 13. Do not use the service if you are under this age.
10. Changes
We may update this policy as the product changes. Material changes will be announced in the app, and the "last updated" date above will change.
11. Reporting a vulnerability
If you believe you have found a security issue, email support@botbuild.app with details. Please do not publicly disclose it before we have had a chance to respond.
