Skip to content
Sentinel
HomeFeaturesPricingSupport
Add Sentinel
HomeFeaturesPricingSupportAdd Sentinel

Legal

Privacy Policy

Sentinel’s Privacy Policy for the current pre-launch/private-alpha stage.

Pre-launch draft

This document applies to Sentinel’s development/private-alpha stage. Certain operator, contact, hosting and retention details will be completed before public or commercial launch.

Draft — private alpha / pre-launch
Effective date: [EFFECTIVE DATE]

This Privacy Policy explains how Sentinel processes personal information when providing its Discord-based staff, moderation and ER:LC management services.

Sentinel is currently operated under the Sentinel project name.

Certain formal operator, hosting, contact and retention details will be completed before Sentinel enters public or commercial operation.

Data controller/operator: [OPERATOR DETAILS — TO BE COMPLETED BEFORE PUBLIC/COMMERCIAL LAUNCH]
Privacy contact: [PRIVACY CONTACT EMAIL]

Sentinel is designed to minimise unnecessary collection of personal information and to use privacy-protective defaults where practical.

1. Scope

This Policy applies to personal information processed through:

  • the Sentinel Discord application;
  • Roblox account verification;
  • ER:LC integrations;
  • staff-management features;
  • moderation and punishment features;
  • observed playtime features;
  • Sentinel web services; and
  • the Sentinel website where applicable.

This Policy does not govern independent processing performed by Discord, Roblox, ER:LC or other third-party services.

2. Information Sentinel May Process

The information Sentinel processes depends on the features enabled by a community.

Sentinel does not necessarily collect every category below about every user.

Discord information

Sentinel may process:

  • Discord user IDs;
  • Discord guild IDs;
  • Discord channel IDs;
  • Discord role IDs;
  • relevant Discord permissions;
  • membership and role information required for Sentinel features;
  • guild configuration; and
  • identifiers required to perform commands, permissions checks and administrative actions.

Stable Discord IDs are used so Sentinel can identify relevant users, servers, channels and roles even where display names change.

Roblox identity information

Sentinel may process:

  • Roblox user IDs;
  • Roblox usernames;
  • links between Discord user IDs and Roblox user IDs;
  • information necessary to establish or verify those links; and
  • limited Roblox account information needed for Sentinel functionality.

Punishment subjects are stored using their immutable Roblox user ID rather than relying only on a changeable username.

Roblox verification information

Sentinel uses official Roblox authentication together with Sentinel’s Discord identity-verification process.

During verification, Sentinel may process temporary authentication and security information required to complete and protect the flow.

This may include temporary state used for protections such as:

  • OAuth state validation;
  • PKCE;
  • nonce validation; and
  • identity-link protection.

Temporary verification material is used only as required to complete or secure the verification process.

ER:LC information

Where a community connects Sentinel to ER:LC, Sentinel may process information made available through the relevant ER:LC interfaces, which may include:

  • Roblox user IDs;
  • Roblox usernames;
  • ER:LC roster membership;
  • team information;
  • callsign information where available;
  • server/player information; and
  • observations used for playtime calculations.

Available information may change if ER:LC or its APIs change.

Staff-management information

Sentinel may process records such as:

  • staff shifts;
  • shift start and end times;
  • shift types;
  • break information;
  • leave-of-absence records;
  • reduced-activity records;
  • administrative adjustments;
  • staff-management actions; and
  • related audit information.

Moderation and punishment information

Sentinel may process:

  • Roblox ID of the punishment subject;
  • Roblox username information used to identify or display that account;
  • punishment type;
  • reason;
  • responsible staff member;
  • timestamps;
  • evidence references where supplied;
  • administrative modifications; and
  • related audit records.

The relevant Discord community is responsible for the moderation decision itself.

Roblox avatar confirmation

When preparing a punishment, Sentinel may retrieve a Roblox avatar or headshot so the staff member can confirm they selected the intended account.

The avatar/headshot is used for confirmation.

Sentinel does not store the retrieved avatar image as part of the punishment record.

The punishment subject is stored using the Roblox account’s immutable user ID.

Playtime information

Where enabled, Sentinel may process:

  • observations that a Roblox account appears on an ER:LC roster;
  • accumulated observed playtime;
  • information required to continue an active observation;
  • reward eligibility; and
  • configured Discord reward roles.

Playtime tracking is disabled by default.

An authorised community administrator must enable it.

Observed playtime is an estimate derived from Sentinel’s observations and may not be a complete record of all time spent in a server.

Configuration information

Sentinel may store:

  • enabled modules;
  • channel configuration;
  • role configuration;
  • permission settings;
  • logging destinations;
  • playtime settings;
  • reward configuration;
  • ER:LC integration settings;
  • staff settings;
  • punishment settings; and
  • other guild-specific Sentinel configuration.

ER:LC credentials

Where a community connects Sentinel to ER:LC, Sentinel may store credentials needed for that connection.

Supported ER:LC credentials are encrypted at rest.

Sentinel is designed so these credentials:

  • are not displayed back through ordinary Sentinel interfaces;
  • are not intentionally included in Discord logs; and
  • are not intentionally written to application logs.

Only systems requiring the credentials to perform authorised ER:LC operations should use them.

Technical and security information

Sentinel may process limited technical information required to:

  • operate the service;
  • diagnose errors;
  • enforce permissions;
  • investigate abuse;
  • detect security problems;
  • maintain audit trails; and
  • keep the service reliable.

This may include:

  • timestamps;
  • internal record identifiers;
  • operation results;
  • error information; and
  • security-relevant events.

Sentinel does not use this section as permission to collect unrelated behavioural or device information.

If Sentinel later introduces analytics, cookies or other tracking that materially changes the information collected, this Policy will be updated where required.

3. Information About People Who Did Not Directly Use Sentinel

Some Sentinel features may process limited information about people who did not personally issue a Sentinel command.

Examples include:

  • ER:LC roster members;
  • users observed for playtime where a community has enabled that feature;
  • Roblox users who are the subject of a punishment record; and
  • people identified in administrative records.

Sentinel limits this processing to information relevant to the feature being provided.

A person does not become bound by Sentinel’s Terms solely because a community processes information about them through Sentinel.

4. Why Sentinel Uses Information

Sentinel may use information to:

  • provide requested bot functionality;
  • identify Discord users, guilds, channels and roles;
  • enforce permissions;
  • manage staff operations;
  • maintain administrative records;
  • provide moderation-record functionality;
  • verify Discord-to-Roblox identity links;
  • retrieve ER:LC information;
  • calculate observed playtime where enabled;
  • assign configured playtime rewards;
  • protect ER:LC credentials;
  • secure authentication flows;
  • maintain guild isolation;
  • prevent fraud and unauthorised access;
  • investigate technical failures;
  • maintain service reliability; and
  • comply with applicable legal obligations.

Sentinel does not sell personal information.

Sentinel does not use personal information for third-party behavioural advertising.

5. Legal Basis for Processing

The lawful basis applicable to Sentinel’s processing depends on:

  • the purpose of the processing;
  • the category of information;
  • the person affected;
  • the final operator arrangement; and
  • applicable law.

The complete lawful-basis mapping will be finalised before public or commercial launch.

[FINAL LAWFUL-BASIS MAPPING — TO BE COMPLETED BEFORE PUBLIC/COMMERCIAL LAUNCH]

Sentinel will not rely on consent where consent is not an appropriate or valid basis.

6. Children and Young People

Discord and Roblox communities may contain users under the age of 18.

Sentinel is therefore designed with privacy-protective defaults and data minimisation in mind.

Examples include:

  • playtime tracking being disabled by default;
  • limiting collection to data required for enabled features;
  • using stable platform IDs rather than requiring unnecessary profile information;
  • treating ER:LC credentials as sensitive security information;
  • not using behavioural advertising; and
  • avoiding unnecessary disclosure of personal information.

Additional safeguards may be introduced where appropriate before broad public availability.

7. Community Configuration

Discord communities decide which Sentinel features to enable and which authorised staff members may use them.

This affects what Sentinel processes for that community.

For example, a community may choose whether to:

  • enable playtime tracking;
  • connect an ER:LC server;
  • configure staff roles;
  • create punishment records;
  • configure operational logging; or
  • enable staff-management modules.

Communities are responsible for using Sentinel appropriately and configuring permissions carefully.

Sentinel remains responsible for the obligations that apply to Sentinel’s own processing.

8. Sharing and Disclosure

Sentinel does not sell personal information.

Information may be disclosed where reasonably necessary to:

  • return information to authorised members of the relevant Discord community;
  • communicate with Discord, Roblox or ER:LC to perform an enabled integration;
  • operate Sentinel using infrastructure or service providers;
  • investigate abuse or security incidents;
  • protect Sentinel, its users or others; or
  • comply with valid legal obligations.

Access inside a Discord community is controlled by Sentinel features and community-configured permissions.

9. Service Providers

Sentinel may rely on infrastructure providers for services such as:

  • application hosting;
  • databases;
  • networking;
  • monitoring; or
  • related operational systems.

The final production provider list has not yet been selected.

[PRODUCTION HOSTING / INFRASTRUCTURE PROVIDERS — TO BE COMPLETED WHEN FINALISED]

Sentinel will update this Policy where required once those providers are confirmed.

10. International Data Transfers

The countries in which Sentinel’s production infrastructure and providers will operate have not yet been finalised.

[INTERNATIONAL TRANSFER ARRANGEMENTS — TO BE COMPLETED AFTER PRODUCTION PROVIDERS ARE SELECTED]

Where applicable, Sentinel will implement appropriate safeguards required by law.

11. Data Retention

Sentinel does not currently publish fixed retention periods for every category of information because the final production retention schedule has not yet been adopted.

Sentinel intends to retain information only for as long as reasonably necessary for purposes including:

  • providing an active feature;
  • maintaining historical or administrative records;
  • maintaining security and audit information;
  • resolving disputes or abuse reports;
  • complying with legal requirements; and
  • protecting the integrity of Sentinel systems.

Different types of information may require different retention periods.

Guild removal

When Sentinel is removed from a Discord guild, its current architecture:

  • disables active tracking;
  • clears active playtime observations; and
  • removes the guild’s stored encrypted ER:LC connection.

Removing Sentinel does not necessarily delete all historical information immediately.

For example, accumulated historical playtime totals or historical administrative records may remain where stored separately from the active connection.

Sentinel will not promise automatic deletion until such behaviour is actually implemented.

Final retention schedule

The production retention schedule, including applicable periods or retention criteria, will be completed before public or commercial launch.

[FINAL RETENTION SCHEDULE — TO BE COMPLETED BEFORE PUBLIC/COMMERCIAL LAUNCH]

12. Security

Sentinel uses technical and organisational safeguards intended to protect information against unauthorised access, alteration, disclosure or loss.

Current safeguards include measures such as:

  • guild-isolated data handling;
  • permissions checks;
  • authentication safeguards;
  • encryption of stored ER:LC credentials;
  • protections around Discord-to-Roblox account linking;
  • restricted handling of credentials;
  • audit controls; and
  • safeguards intended to prevent stale or replaced ER:LC connections from being treated as current.

No online service can guarantee absolute security.

Security issues should be reported privately through:

[SECURITY CONTACT / REPORTING METHOD]

13. Removing Sentinel and Disconnecting Integrations

An authorised administrator may stop active use of Sentinel by removing it from a Discord server.

Where functionality is available, administrators may also disconnect ER:LC integrations.

Stopping an active integration does not automatically imply immediate deletion of every historical record.

See the Data Retention section above.

14. Your Privacy Rights

Depending on applicable law and the circumstances of processing, individuals may have rights relating to their personal information.

These may include rights to request:

  • access;
  • correction;
  • deletion in certain circumstances;
  • restriction in certain circumstances;
  • objection in certain circumstances; and
  • portability where applicable.

Not every right applies to every category of processing.

Privacy requests should be sent to:

[PRIVACY CONTACT EMAIL]

Sentinel may require enough information to verify identity before disclosing, altering or deleting information.

Where a record was created through a Discord community, Sentinel may also need to distinguish between Sentinel’s responsibilities and those of the relevant community.

15. Complaints

Privacy questions or complaints should be sent to:

[PRIVACY CONTACT EMAIL]

The applicable supervisory authority and complaint details will be completed once Sentinel’s legal operator arrangements are finalised.

[SUPERVISORY AUTHORITY DETAILS — TO BE COMPLETED BEFORE PUBLIC/COMMERCIAL LAUNCH]

16. Automated Actions

Sentinel may automatically perform configured technical actions, such as assigning a Discord role when a configured playtime threshold is reached.

Sentinel does not independently decide whether someone should receive a community punishment based on automated profiling.

Moderation and punishment decisions are made by the relevant community staff.

If Sentinel later introduces automated processing with significant effects on individuals, this Policy will be updated before or when that processing begins where required.

17. Changes to This Policy

This Policy may change as Sentinel develops.

Material changes may be communicated through:

  • the Sentinel website;
  • the Sentinel Discord service;
  • the support Discord; or
  • another appropriate method.

The effective date at the top identifies the current published version.

18. Third-Party Services

Sentinel interacts with services operated independently by third parties, including Discord, Roblox and ER:LC-related services.

Those services maintain their own privacy practices.

Sentinel does not control how third-party services process information outside Sentinel.

19. Contact

Questions, privacy requests or concerns may be directed to:

Sentinel
[OPERATOR DETAILS — TO BE COMPLETED BEFORE PUBLIC/COMMERCIAL LAUNCH]
[PRIVACY CONTACT EMAIL]

© 2026 Sentinel
TermsPrivacy