Whale Connect privacy policy
Effective 9 September 2026. Discord application ID: 1295454766477873283.
This policy covers Whale Connect. The bot operator is Ruadhan, the maintainer of these Seasonal Tokens community bots. Contact info@seasonaltokens.io about your data, support, or a concern about the bot. Other independently operated community bots have their own policies.
What the bot does and what data it uses
Whale Connect verifies a public wallet address you provide and assigns community roles based on public Seasonal Tokens balances.
- Your Discord user ID, the public wallet address you supply, the verification transaction hash during verification, and the managed roles and their assignment timestamps.
- Public balances and transaction receipts on Ethereum and Polygon are checked to verify the address and maintain roles. No wallet private key or seed phrase is requested.
The bot processes commands you deliberately invoke and the information needed to respond. It does not request access to ordinary server message content or track your online status or activities. Direct messages and messages explicitly mentioning a bot may be available to that bot under Discord's normal API rules.
How data is used and shared
Data is used to provide the stated bot features, operate and secure the service, handle requests, and resolve contest or account issues. We do not sell Discord data, supply it to advertisers or data brokers, or use Discord message content to train AI or machine learning models.
Your wallet address and transaction hash are queried through Infura blockchain RPC services; Discord IDs are not needed in those blockchain queries. The assigned roles are visible according to server permissions and can indicate a holdings range. Authorized bot administrators can inspect wallet links, and sensitive lookups and exports are delivered privately. Public blockchain activity remains public.
Discord processes commands and bot responses. The infrastructure host, Contabo, provides the server hosting the bots and their records. Authorized operators and service providers may access data as needed to operate or secure the service. We may also disclose information when legally required. Public messages and information you choose to publish can be copied by other people.
Retention
- The active Discord-to-wallet link and managed role timestamps are kept while the role verification service is used or until a verified deletion request. Superseded address-owner mappings expire after 30 days.
- Verification replies are processed to complete the request; new operational logs do not retain their text or wallet identifiers. Discord retains the original DM conversation according to its own controls.
- New diagnostic logs are minimized and rotated. Operational log files are kept for at most 30 days. Older bot logs and local historical archives are held in restricted encrypted storage during the cleanup transition and scheduled for removal by 9 October 2026.
- Privacy requests remain pending until resolved; completed request records are removed after 90 days. Records are deleted sooner when no longer needed or following a verified deletion request, unless a specific legal retention requirement applies.
Discord messages, downloaded reports held by their recipients, and public blockchain records are outside the bot database. We cannot erase a public blockchain or another person's copies. We will explain any concrete limitation when handling your request. If a backup is restored, completed deletion requests must be applied again before the restored data is used.
Your choices and rights
Use /privacy for this policy, /mydata to request a copy of your records, and /deletedata confirm:True to request deletion. These commands record your request for the operator; deletion is not instantaneous. Stop using the bot if you do not want new participation records created.
You can also email info@seasonaltokens.io with the bot name and your Discord user ID, or the request reference shown by the bot. Do not send passwords, bot tokens, private keys, seed phrases or identity documents. We may ask you to confirm the request from the relevant Discord account to protect your records.
We normally respond to access, correction and deletion requests within 30 days. Deleting records can remove saved scores, queued choices, account links or role eligibility. Where applicable, you may also request restriction or portability, object to processing, withdraw consent for optional features, or complain to your local data protection authority. Necessary processing provides the features you request; service security and support are based on the operator's legitimate interests. Optional wallet and account links are established at your request and can be withdrawn.
Security and policy changes
Bot database snapshots and the retained bot data files on the simulator host are stored on an encrypted filesystem. Decryption keys are restricted to the host administrator. Access controls restrict application files and credentials; the database listens on loopback. Simulator links and score submissions use HTTPS. Encryption does not make a running server immune to compromise.
We investigate security reports, limit access during an incident, and notify Discord and affected users as required. Material changes will be described in an updated policy and the bot command guide. This page itself uses no analytics, advertising or tracking scripts; the web server may retain ordinary access and security logs.