ToolOXX
In effect from 13 August 2026. This is version 1.0.
ToolOXX keeps less than most Discord bots do, and this page is specific about which parts those are. The short version: it counts what you do, it does not keep what you say, and the one exception is the feature whose entire purpose is keeping what you wrote.
ToolOXX is run by ryo2321, an individual developer in the Netherlands, who is the data controller for it. You can DM me on Discord if you have any questions, and requests about your data are normally answered within a few days.
Everything below lives in a single database on one server in the EU. It is written when you use a feature, and not before.
| Feature | What it keeps |
|---|---|
| Levels and coins | Your Discord user ID and username, a message count, level, medal, Abysscoins, shop inventory, the servers you have been counted in, and when you were last active. |
| Quotes | The ID of the message the quote is in, the channel it is in, the author name as it was typed, who posted it, and when. |
| Starboard | The ID of the starred message, its channel, who wrote it, who starred it, and the votes cast for star of the week. |
| Story lines | The title, who is taking part, and the full text of every part, with the author and timestamp of each. |
| Moderation | The server's own list of blocked words, and warning records: who was warned, by whom, the reason given, and when. |
| Trackers | The phrase being watched, who set it up, who it watches, the running count and when it expires. |
| Linked accounts | Your numeric osu! or VNDB account ID and the username on it. Twitch notifications keep the channel names a server follows. |
| Server settings | Channel IDs, role IDs, thresholds and on or off switches for every feature the server has configured. |
Quote and starboard entries are references, not copies. The words themselves are fetched from Discord at the moment they are shown, which is why a deleted message disappears from the board on its own.
These are decisions, not oversights, and they are worth stating plainly:
Signing in creates a session that exists only in the running program's memory. It holds your user ID, username and avatar URL, nothing else, and it expires after seven days or the moment the bot restarts, whichever comes first. The cookie in your browser is a random identifier with no readable content.
The web server keeps ordinary access logs, which include the IP address the request came from. They exist to diagnose faults and to spot abuse, are not linked to your Discord account, and are rotated away after a short period.
The only thing kept in your browser's own storage is your light or dark theme choice. There are no analytics, no tracking pixels and no third party cookies anywhere on this site.
Nothing is sold, rented or handed to advertisers. Data leaves the server only when a feature has to ask somebody else a question:
Data may also be disclosed where the law actually requires it. That has never happened, and this line will change if it ever does.
Levelling data stays while your account is active and is removed on request. Quote and starboard references, story lines and server settings stay until the server or the person who made them deletes them, or until the bot is removed from the server. Warnings stay until a moderator clears them. Sessions and the anti spam hash are gone on restart.
Removing ToolOXX from a server does not automatically wipe that server's data straight away, in case the bot is added back after an accident. Ask and it will be deleted.
Under the GDPR you can ask for a copy of what is held about you, ask for it to be corrected, ask for it to be deleted, or object to it being processed at all. One message to ryo2321 on Discord is enough. Say which of those you want, and expect a reply within thirty days, usually much sooner.
Deletion is real deletion, not a flag. Be aware that it also removes your level, coins and rank, and that those cannot be restored afterwards.
If you are unhappy with how a request was handled, you can complain to your national data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens.
The site is served over HTTPS, the API is not reachable from outside the machine except through that same site, the bot runs as an unprivileged user with a restricted system profile, repeated failed logins get blocked automatically, and backups are pulled off the server rather than left sitting on it.
What we will not claim is that any of that makes it impossible to break into. Nobody can honestly promise that. If something does go wrong and personal data is exposed, affected people and the relevant authority will be told, and there will be a note on this site.
ToolOXX follows Discord's minimum age, which is 13 in most countries and higher in some. It is not aimed at children below that age. If we learn that data belongs to someone under the applicable minimum, it gets deleted.
This page changes when the bot does. The version and date at the top are always current, and anything that meaningfully affects what is stored gets a line in the patch notes on the front page rather than a quiet edit here.