Yamiko
All documents
DocumentsPrivacy Policy

Privacy Policy

How the Yamiko bots handle members’ data: what they keep, why, who can see it and for how long.

Revised October 5, 2026

In short

  • The bots keep what the server needs to run: moderation, newcomer checks, the staff team, events and giveaways.
  • We don’t sell data, don’t share it with ad networks and don’t use AI to make decisions about people.
  • The bots’ main databases are stored on an encrypted disk.
  • We keep data while it is needed. Voice activity is deleted automatically: after 35–60 days, and support statistics once a quarter.
  • To see, correct or delete your data, email yamikostaff@proton.me.

This is a plain-language summary. The full text below is what legally applies.

1. Who we are

The Yamiko bots are run by Leonid (the Yamiko project, Russia), “we” below. We decide what data the bots need and are responsible for how it is processed.

This policy covers the project’s eight bots, the internal systems connected to them — the Staff API and a private admin panel — and the Yamiko websites. Each bot’s page describes exactly what it keeps; those pages are part of this policy.

Discord is a separate company. Its privacy policy applies alongside ours, and we are not responsible for how Discord itself processes data.

2. What data we get

The bots run on Discord servers and see what Discord allows them to see:

  • your Discord ID, username, display name, server nickname and avatar link;
  • server events: joining, roles, voice channels and time spent in them, moderation actions;
  • what you send through the bots yourself: staff applications, appeals, reports, “Milosti” letters, event orders, reviews;
  • for staff members, data about their work on the team: branches, ranks, warnings, leave, activity requirements and payouts.

The bots don’t store chat conversations in their databases. There is one exception: Moderator Bot copies deleted and edited messages into private moderation logs on the Discord server. The bots don’t record voice.

3. Why we need data

  • moderation and server security: sanctions, appeals, reports, protection against mass destructive actions;
  • newcomer checks: who joined and through which invite, entry bans and keys;
  • running the staff team: recruitment, warnings, leave, activity tracking and payouts;
  • events, giveaways, voice rooms and creative activities;
  • restoring the server and the bots after failures.

We process data because these features don’t work without it and because we have a legitimate interest in protecting the server and its members. If the law requires your consent for any processing, we will ask for it separately.

Data isn’t used for advertising, isn’t sold and isn’t passed to data brokers. We don’t build profiles of members outside the server and don’t use AI to make decisions about people.

4. Who can see the data

  • Server staff, within their Discord permissions: logs, applications and cards are visible only in channels they have access to.
  • Us, as the operator of the bots.
  • Services and specialists who help us run the bots: server hosting, email, development tools, including tools that use artificial intelligence. They get access only to what a task requires and act on our instructions.
  • Discord, since the bots run on its platform.
  • Public authorities, only where the law requires it.

Some information is shown on the server by its very nature: everyone in the channel sees a “Milosti” letter, and a branch’s staff see the decision on an application.

5. Where and how data is stored

Data is stored on the project’s server. The bots’ main databases and files sit on an encrypted disk (AES-256); the key is kept separately from the data and only the server administrator can access it. The internal Staff API accepts requests only from the server itself.

Backups are kept on the same server, access to which is restricted.

No one can rule out risk entirely, but we take every reasonable step to protect data. If a breach affects you, we will tell you as the law requires.

6. How long we keep data

We keep data while it is needed for the feature it was collected for. The period depends on the kind of data:

  • Sanctions, entry bans, blacklists and warnings: while the restriction is in force and afterwards, for as long as moderation needs the history — for appeals, tracking repeat violations and protecting the server.
  • Staff data: while you are on the team and after you leave, for as long as it is needed to keep track of work, handle repeat applications and resolve disputes about payouts.
  • Newcomer checks (joins, invites, keys, reviews): for as long as they are needed to spot returning accounts and stop entry bans from being bypassed.
  • Voice activity is deleted automatically: after 60 days for staff and events, after 35 days for giveaway conditions. Support team statistics are reset every quarter.
  • Giveaways: for as long as they are needed to confirm results and resolve disputes.
  • The note of which site button brought you to the server (Discord ID, invite and time) is deleted after 90 days; only daily counts remain.
  • Your website account (a Discord account linked in the “Anime of the day” game) is deleted together with its whole game history after 180 days without signing in, or when you ask.
  • Copies of messages in moderation logs stay in private Discord channels for as long as moderation needs them.
  • Backups: copies of the bots’ data — the last seven, about a week; copies of the server structure — for as long as they are needed for recovery.

When data is no longer needed, we delete it. If a bot stops operating, we delete its data too.

7. Your rights

You can:

  • find out what data the bots keep about you and get a copy of it;
  • correct inaccurate data;
  • ask us to delete data;
  • object to processing or ask us to restrict it;
  • use any other rights your country’s law gives you, including complaining to a supervisory authority.

How to send a request is explained on the Data deletion page. We may ask you to confirm that the account is yours; this protects your data from requests made by someone else.

Deleting data does not lift restrictions on the server: a restriction role or a ban stays in place in Discord. A sanction can only be lifted through an appeal.

8. Age

Discord can be used from the age of 13, or older in some countries. If we learn that the bots have kept data about a child below that age, we will delete it.

9. Yamiko websites

The Yamiko websites are the home page (www.yamiko.ru), documents (docs.yamiko.ru), the status page (status.yamiko.ru) and the staff area (staff.yamiko.ru). The documents and status page don’t ask you to sign in and don’t set cookies. The home page works without signing in too and sets a cookie only if you sign in yourself — more on that below. None of the sites use analytics counters or advertising pixels. The home page shows public server data from Discord: the member count and upcoming events, and the game pages show how often each game was played and how many people joined, without names. Fonts are loaded from these same sites.

In the “Anime of the day” game without signing in, the page sends the site only the numbers of the anime you pick, to check the answer; your tries live in the page address itself and the site doesn’t save them. Signing in is optional: with Discord (sign-in goes through the staff area, and Discord gives us only your ID, name and avatar) or with a personal link the events bot gives you with /anime-day — it is valid for 15 minutes and works once. After you sign in, one shared Yamiko sign-in cookie is set for 30 days: it is signed and can’t be read by scripts on the page. Your browser sends it to every site on yamiko.ru, but only the home page and the staff area read it — so signing in on one of them signs you in on the other. The site keeps your Discord ID, name and avatar, your tries and solves of the day, your personal reward keys and endless-mode stats — for your streak, profile and reward. The site draws your profile card itself and loads your avatar from Discord’s servers for it. You can sign out with the “Sign out” button in your profile or in the game — it signs you out of both the home page and the staff area.

The staff area is for staff members: after signing in with Discord, a person sees their own records in the Staff API — branches, activity quota, warnings, payouts and leave — and can’t change anything in them. Staff Admin and branch administrators also see the Management section: the rosters of their branches (this week’s quota, leave, warnings), leave, quota-change and recruitment requests, and the staff action log — and can do the same as in the /staff panel in Discord: add to a branch, change rank, remove from a branch, give and remove warnings, decide on requests. The staff bot checks permission for every action by Discord roles, and the action goes to the log and the Discord log marked “staff area”. When you sign in, Discord gives us only your ID, name and avatar; we don’t receive your email or messages. We revoke the Discord access token right after sign-in and don’t store it. To keep you signed in, the site sets its own sign-in cookie for 7 days and the shared Yamiko sign-in cookie for 30 days (see above): both are signed and can’t be read by scripts on the page. If you are already signed in on the home page, the staff area knows you by the shared cookie, with no second sign-in. A temporary 10-minute cookie also protects sign-in. Your avatar in the staff area is loaded from Discord’s servers.

The sites run on our own server and are delivered through the Cloudflare network, which processes technical request data, such as your IP address, to deliver pages and protect the sites from attacks, under its own policy. We don’t keep visit logs ourselves. The site counts clicks on the buttons that lead to our anime project yamianime.com: only how many times each button was clicked per day — no cookies, IP addresses or other data about you; yamianime.com itself receives nothing from us. The buttons that lead to the Discord server use separate invites, so we can see how many people came from the site and through which button (see Staff Bot for details).

10. Changes to this policy

We may update this policy, for example when the bots gain new features. The revision date is shown at the top of the page. We will announce significant changes in advance on the Yamiko server or on this page.

The Russian text is the primary version; translations are provided for convenience. Where this policy conflicts with mandatory law or Discord’s rules, those prevail.

Questions and data requests

Email us for data requests, questions about these documents or complaints.

yamikostaff@proton.me