QuranBot operates on a privacy-first, data-minimization principle. We process only what is strictly necessary for core
functionality. This policy aligns with standard data protection practices.
No message content or voice data storage
No sale or commercial use of personal data
User-controlled data deletion
Definitions & Scope
Service: QuranBot, a Discord bot providing Quran recitation, Islamic radio, and azkar automation.
Personal Data: Any information relating to an identified or identifiable natural person, as understood
under applicable data protection frameworks.
Processing: Any operation performed on data, including collection, storage, use, or deletion.
Scope: This policy applies to all data processed by QuranBot in connection with its operation on
Discord. It does not cover third-party platforms (e.g., Discord itself) or external content providers.
Welcome to QuranBot. We are committed to transparent, minimal data handling. This policy
outlines what we collect, how we process it, and your rights.
1. Information We Collect
We collect only the minimum data required for core functionality:
Server Identifiers: Guild ID and Owner ID for configuration mapping
User Metadata: Discord-provided identifiers (User ID, Username) strictly for functionality.
Channel References: Channel IDs for voice and azkar automation
Playback State: Current playback mode and reciter selection per guild
Control Preferences: Admin/everyone toggle and UI navigation state
Support Data: Voluntary feedback submitted via the in-bot form
Basic Telemetry: Aggregated, anonymized command counts for stability monitoring
Admin Access Logs: Timestamped records of administrative actions by authorized developers
2. What We DON'T Collect
We explicitly do not collect, store, or process:
Message content, attachments, or voice data beyond functional triggers
Sensitive personal data (email, phone, IP address, real name)
Payment information (the bot is free and open-source)
Biometric data, browsing history, or cross-application tracking
User message history, DMs, or private conversations
Audio recordings or transcriptions of voice channel activity
3. Legal Basis for Processing
All processing is grounded in minimal, purpose-limited bases:
Contractual Necessity: Processing required to execute bot commands and manage server configuration
Legitimate Interest: Maintaining bot stability and preventing abuse via basic rate limits
Explicit Consent: Voluntary feedback submission and public statistic opt-ins
Compliance: Minimal retention required for essential service operation
4. How We Use Information
Collected data powers only essential operations:
Operating core functions: Quran streaming, radio playback, and azkar automation
Saving guild settings for automatic restoration after bot restarts
Managing voice connections and playback state across multiple guilds
Responding to voluntary feedback submitted via the in-bot form
Improving performance through basic, anonymized usage metrics
Executing automated maintenance tasks at regular intervals
Publishing general, aggregated statistics on platforms like Top.gg
Developer Admin Panel: Authorized developers may access aggregated, non-personal data strictly for
maintenance, support, and security purposes.
5. Data Retention
We enforce strict, minimal retention periods:
Voluntary feedback data is retained only until the reported issue is resolved, then purged. Unresolved data is
retained for a defined period before permanent deletion.
Guild setup data persists only while the bot remains in the server
Basic usage metrics are aggregated and anonymized after a defined period
Local backups are destroyed after successful delivery
Data for departed guilds is automatically cleaned through maintenance cycles
Admin access logs are retained for a defined audit period, then automatically purged
6. Children's Privacy
Age Requirement: Users must meet Discord's minimum age requirement (13+), in compliance with COPPA and
Discord's Terms of Service . We rely on Discord's age verification and do not
independently verify ages. We do not knowingly collect data from users under 13.
7. Third-Party Services
We do not sell, rent, or trade your data. Third-party integrations are strictly functional:
Discord API for platform interaction and voice management
Firebase for persistent storage of guild settings
Redis for fast-access state management
Lavalink for audio streaming (processing streams only)
mp3quran.net for Quran recitations and radio lists
aladhan.com for prayer time data
GitHub Pages for hosting static resources
Top.gg for aggregated, anonymized statistics
Third-party services have
their own privacy policies. We recommend reviewing them separately.
8. Security Measures
We implement essential technical and organizational protections:
All API communications use HTTPS with certificate validation
Database access is restricted to authorized bot operations via security rules
Sensitive credentials are loaded securely via environment variables
Input validation is applied to all user-submitted data
Automated safeguards, rate limiting, and cooldowns prevent abuse and excessive usage
Developer Admin Access Controls: Server-side verification on every admin interaction; no
client-side bypass possible. Access is strictly limited to authorized developers.
9. Automated Processing
The bot performs essential background operations at regular intervals:
Azkar messages to configured channels
Radio stream health checks for playback reliability
State persistence for guild data
Automated backups for data integrity
Memory cleanup routines to release unused resources
Statistics updates for aggregated usage metrics
All automated tasks can be disabled per-guild by removing the bot
10. Your Rights
You retain control over your data:
Access: Request a summary of stored data for your guild
Deletion: Request immediate deletion via our
Discord Support Server
or the in-bot complaint system
Opt-Out: Disable automated features by adjusting channel settings
Correction: Update inaccurate guild settings through bot commands
All requests are processed within a reasonable timeframe
11. Developer Admin Access
The QuranBot Developer Admin Panel is restricted to explicitly authorized developers.
Access is controlled via secure server-side verification.
Verification: Every admin interaction triggers a secure server-side check. Access is denied if the
requesting user ID is not authorized
Audit Logging: All admin actions are logged with timestamp, user ID, and operation. Logs are
retained for a defined audit period, then purged
Revocation: Developer access can be immediately revoked by updating the authorized ID list
Security Assurance: Verification is implemented entirely server-side. Client-side manipulation
cannot bypass this check. All admin interactions are securely verified before execution .
12. International Transfers
Data may be processed on servers located in regions such as the United States or EU, depending on infrastructure
providers. We ensure transfers comply with applicable data protection requirements.
13. Contact & Updates
We may update this policy to reflect improvements or regulatory changes:
Material changes will be announced via the bot support channel or in-bot notifications
Continued use after updates constitutes acceptance of revised terms
Previous versions may be requested via the in-bot system
Users may be contacted via Discord DMs only in response to user-initiated requests