Privacy Policy
Last updated 15 August 2026
This policy describes what DemonBot and Velvet Inferno staff collect, why, and what we do with it. It covers the website, the staff console, and the Discord bot that talks to the guild.
Who holds the data
Velvet Inferno staff operate DemonBot. Application tickets, staff accounts, and feed lists live in the database attached to this app. Discord also holds whatever you post in the guild — that is Discord’s data, under Discord’s privacy policy.
What we collect
Depending on how you use DemonBot:
Applications. Discord username, Discord user ID when we can resolve it, the name you give us, your answers, age confirmation, referral, and the ticket thread that follows.
Holding chat. Messages you send in the holding channel or intake thread may be copied onto your ticket so staff can read them in one place.
Feed suggestions. Platform, handle or URL, your Discord username, and an optional reason.
Staff accounts. Email and password (password stored hashed), or the identity Google or X gives us when you sign in that way. Display name. Role (owner, admin, reviewer).
Authenticator lock. A TOTP secret and hashed emergency codes, only if you turn the lock on. We never store the six-digit codes themselves.
Audit log. Who approved, denied, invited, or changed settings, and a short note of what they did.
Bot connection. Encrypted Discord bot token and worker key, guild and role IDs, so the worker can act in the server. Not shown to reviewers.
We do not ask for payment details, government ID, or precise location. We do not sell lists of members.
Why we collect it
To decide who comes in, and to tell you if you do not.
To keep unverified people in holding until staff finish a ticket.
To announce creators staff have chosen.
To let staff sign in, invite each other, and lock the desk.
To have a record when someone grants a role or issues a ban.
Who sees it
Staff with a console login can see applications, tickets, feeds, and the audit ledger. Reviewers cannot change Discord settings or the bot token. The Discord bot posts and reads in the guild you configured — holding, intake, and announce channels — so anyone in those channels can see what the bot posts there.
Sign-in through Google or X is handled by the Grok auth broker. We receive an identity, not your Google or X password. Discord receives whatever the bot sends (roles, DMs, bans, channel messages) when simulation is off.
Hosting may be on a cloud provider (the live site and, if you run it, an AWS worker). Those providers process data to keep the service up. We do not sell your information or use it for ads.
How long we keep it
Applications, tickets, denials, and audit lines stay until staff delete them or the project is taken down. Staff accounts stay until the owner removes them. Authenticator secrets stay until you disable the lock. If we shut DemonBot down, we delete the database we control. Discord may still have messages and bans in the guild.
Your choices
Do not apply if you do not want a ticket on file.
Ask staff to close or redact a ticket. They will consider it.
Staff can disable their authenticator with a current code.
If you are in the EU/UK or another place with access rights, write staff and ask what we hold on you. We will answer from the ledger we actually have — we cannot edit Discord’s copy of a ban or a DM.
Children
DemonBot is 18+. We do not target children. If you believe a minor applied or joined, tell staff. We will remove the application and ban the account from Velvet Inferno.
Security
Passwords are hashed. Bot tokens and worker keys are encrypted at rest. Staff can require an authenticator after login. No setup is perfect. Do not put secrets in an application answer.
Changes
The date at the top is the current version. If we start collecting something new in a material way, we will update this page.
Contact
Privacy questions go to Velvet Inferno staff in Discord, or the contact they publish on the community site. Read the Terms of Service for how the gate itself works.