Privacy Policy
Last updated 4 October 2026
What personal data Tikkora handles, why, and what you can do about it. Short version: we collect what we need to run tickets, we don’t sell data or use it for advertising, and each server’s data stays with that server.
Who we are#
Tikkora is a Discord support bot and the website at tikkora.net, operated from Sweden. For the data described here as ours, Tikkora is the data controller. You can reach us about privacy in the Tikkora community server.
Server data and our role#
When a community uses Tikkora, that server’s owners and Management decide to use it and how, so for the tickets and messages in their server they are responsible for their community’s data, and we process it on their behalf to run the service. For our own accounts, billing, security and the website, we are the controller. If you have a question about tickets in a particular server, ask that server’s staff first; we’ll help them, or you, where we can.
What we collect#
When you open or work on tickets (in Discord)
- Your Discord user ID, username and display name, and your roles in that server (to decide who can see and do what).
- What you write in tickets: form answers, messages (including edits and deletions), attachment links, staff notes, transcripts and the rating you give.
- If the server links game accounts through an integration, the link between your Discord ID and your in-game name, and the results of actions staff run.
When you use the website
- Signing in with Discord gives us your Discord ID, name and avatar. Discord also shares your email address with sign-in; it stays inside your encrypted session cookie in your browser, and we don’t store or use it.
- For actions on the dashboard, an audit record: who did what and when, with the IP address and browser (user agent) the request came from.
- Server settings, knowledge sources and anything else you set up.
When you buy a plan
- Your Discord ID linked to a Stripe customer, your plan, its status and which servers it covers, and AI usage per server.
- Payment details, billing address and tax details are collected by Stripe and Link, not by us. We only see summaries such as the plan, amounts and invoice status.
The AI assistant#
If a server turns on the assistant, ticket text and the server’s knowledge (documents, rules, solved tickets) are sent to AI models to sort tickets, draft replies, check them and search knowledge. When a ticket closes, the assistant may summarise it into a reusable “learned solution”; usernames, in-game names, emails, IPs and order IDs are removed from these summaries, and staff approve them before use. Each server’s knowledge is used only for that server. We don’t use your data to train AI models.
Why we use it#
- To provide the service (contract): running tickets, the dashboard, plans and billing.
- Legitimate interests: keeping the service secure, preventing abuse, keeping an audit trail of configuration changes, and fixing problems.
- Legal obligations: keeping billing records as accounting law requires.
We don’t sell personal data, show advertising, or use tracking or analytics tools.
Who we share it with#
We use these service providers, only for running Tikkora:
- Discord: the platform the bot runs on and the sign-in provider.
- Railway: hosts the bot and its database (EU).
- Vercel: hosts the website (EU).
- OpenRouter and the AI model providers it routes requests to: process ticket text and knowledge for the AI assistant, only on servers that turn it on.
- Stripe (including Link): payments, invoices, tax and payment support, as an independent controller for the payment.
- Integrations a server connects, such as its game server panel, when its staff run actions.
We may also disclose data where the law requires it.
Where it is stored#
The bot, its database and the website run in the EU. Some providers (Discord, OpenRouter and AI model providers, Stripe) may process data outside the EU, such as in the United States. Where they do, the transfer relies on safeguards such as the EU–US Data Privacy Framework or the European Commission’s standard contractual clauses.
How long we keep it#
- Tickets, messages, notes and transcripts are kept so servers can look back at past cases and export their history, until that server’s Management asks us to delete them. Removing the bot from a server doesn’t delete them automatically.
- Audit records are kept for as long as the server’s data is kept.
- Billing records are kept as long as accounting law requires (in Sweden, 7 years).
- Your website session lasts up to 7 days in your browser, or until you sign out.
Cookies and storage#
The website sets only the cookies needed to keep you signed in. It also remembers your light/dark theme choice in your browser’s local storage. There are no tracking or advertising cookies, so there’s nothing to consent to.
Security#
Access follows your live Discord roles and is checked on every request. Integration secrets are encrypted, website sessions are encrypted, connections use HTTPS, and dashboard actions are logged. No system is perfectly secure; if something goes wrong that affects you, we’ll tell you as the law requires.
Your rights#
Under the GDPR you can ask for a copy of your data, have it corrected or deleted, object to or restrict how we use it, and receive it in a portable format. Server Management can export a server’s complete ticket history from the dashboard at any time. To make a request, contact us in the community server; we may need to confirm it’s you, and we’ll answer within one month. You can also complain to the Swedish Authority for Privacy Protection (IMY) or the authority where you live.
Children#
Tikkora is used through Discord, which doesn’t allow users under 13 (or older, in some countries). We don’t knowingly collect data from children under those ages.
Changes#
We’ll update this policy when what we do changes; the date at the top shows the latest version. For significant changes, we’ll give notice on the website or in the community server.