Privacy Policy
Last updated: 25 September 2026
This Privacy Policy explains how Blaze ("Blaze", "we", "us", "our") collects, uses, shares, protects and deletes data across the Blaze platform: the Blaze Bot Discord application, the Blaze Siteswebsite builder, and the Blaze dashboard and HQ (collectively, the "Services"). It applies to server administrators and staff who sign in to Blaze, and to the end users of the Discord servers, game servers and websites operated with our tools.
Who is responsible: Blaze. Contact: [email protected]
Wherever this Policy says "Blaze", "we" or "us", it means the party named in the block above. Wherever it says "contact us", it means the address in that block.
1. Controller and processor roles
For the personal data of your end users that flows through our tools, you (the server administrator) are the data controller and Blaze is your data processor. Examples are ticket messages processed by Blaze Bot, game data fetched by the Blaze Bot connector, the feedback a player gives about your server (section 2), and form submissions and moderation records processed by Blaze Sites. For Blaze Bot, our data processing agreement sets out the terms of that processing.
Blaze is the data controller in these cases:
- account, authentication, billing and usage data of administrators and staff;
- the answers players give to Blaze Bot's feedback questions only where the player has chosen to send them to Blaze, that is, where they answered that their feedback is about the assistant (section 2). Blaze uses those for its own purpose, which is to improve the product. Where the player instead chose their own server, the answer is the server administrator's data, it is stored separately for that server alone, and Blaze is only the processor for it;
- the answers players gave before Blaze started asking who the feedback was for, that is, before 24 September 2026. Blaze did not put the question then, so those answers may be about a server rather than about the assistant, and some of them contain what the player wrote about a server's support or staff. Blaze holds them as controller, they are marked as being of unknown subject, they are still on Blaze's product feedback, and Blaze still uses them to improve the product. They are deleted two years after they were given (section 6);
- the feedback you send us from the dashboard or with Blaze Bot's
/feedbackcommand (section 2); - email addresses left on our waitlist (section 2).
2. Data we collect
- Discord account data: when you sign in with Discord OAuth2 we receive your Discord user ID, username, avatar and the servers (guilds) you manage. Where you grant the
emailscope, we also receive your email address, which we use for billing and account notices. We never receive or store your Discord password. - Ticket conversations (Blaze Bot): messages sent inside support tickets on your server are stored so Blaze can answer the ticket, hand it to your staff when needed, and let your staff review transcripts.
- Name cache (Blaze Bot): so the dashboard and transcripts can show who wrote what, Blaze keeps the public Discord profile of people who write in tickets. That profile is their username, global display name and avatar. It is the same on every server, and Blaze never stores the nickname someone uses on a particular server.
- Images in tickets (Blaze Bot): when someone attaches an image to a ticket message, Blaze stores a link to the image, not the image itself. The image stays on Discord. On Blaze++ the image is sent to our AI provider so the AI can take it into account.
- Game data (Blaze Bot connector): if you install the connector on your game server, Blaze collects game data about the person who opened a ticket and links between Discord accounts and game characters. See section 3.
- Activity statistics (Blaze Bot):a record of events on your server, such as a ticket being opened, claimed or closed, or a staff member replying. It includes the Discord IDs of the people involved and, for replies, the staff member's name. It contains no message content. It is used for the dashboard's statistics.
- Feedback from players (Blaze Bot): Blaze Bot asks the person who opened a ticket, by Discord direct message, whether they got the help they needed. It does so in two situations:
- After a manual close.When a ticket is closed with Blaze Bot's close button or close command, Blaze picks about one in four of those closes at random. Nobody is asked this way more than once every 30 days, counted across all servers. When Blaze sends such a message, it records that it did (the player's Discord ID, the server's ID and the time) to enforce the 30-day limit.
- After an automatic close.If your server uses auto-close, Blaze Bot asks after every automatic close. If the player answers "no", Blaze Bot opens a new ticket for them, with an AI summary of the old ticket for your staff. This question and the new ticket are part of the auto-close feature and work whatever the setting below.
- The player decides who receives it. Before anything is stored, Blaze Bot asks the player whether their feedback is about the server — the support they got, their case, the staff — or about the assistant, meaning how the bot answered. Apart from the one case described below, nothing is stored until they have chosen.
- Feedback about the server goes to the server.It is stored for that one Discord server, is shown to that server's staff in the Blaze dashboard, and is also posted to a Discord channel if the server has chosen one. It never reaches Blaze's own product feedback, and Blaze does not use it to improve Blaze. For this data the server administrator is the controller and Blaze is the processor (section 1). Staff of other servers cannot see it.
- Feedback about the assistant goes to Blaze.It is stored in Blaze's own product feedback and used to improve Blaze. Blaze is the controller for it (section 1).
- The one answer the player is not asked about. After an automatic close, a player who answers that they still need help is not asked the question: they need help, and Blaze Bot opens the new ticket straight away. That answer — that the ticket was not resolved — is treated as feedback about the server and goes to the server, never to Blaze.
- Before the question is even asked.When something happens that should lead to a feedback question later — a ticket the assistant handled, for example — Blaze notes that the player is due to be asked, with their Discord ID, the server's ID and which ticket it was about. The note is kept whether or not the question is ever put.
- What is stored either way.Their Discord ID and username, the server's ID, whether they got help, and the time. A player who did not get help can also write a comment of up to 1,000 characters, which is stored too. Feedback that goes to the server also records which ticket it was about, and whether your staff have marked it as read; feedback that goes to Blaze instead carries details about the server's plan.
- The setting.Server Config → AI & Automation → "Ask players for feedback" in the Blaze dashboard. It is on by default and covers both situations and both destinations. When it is off, no feedback message is sent after a manual close, and answers to the auto-close question are not stored at all — neither for the server nor for Blaze.
- Feedback you send us:
- In the dashboard,with the feedback button (general feedback, bug reports, praise) or by answering a short survey question. Survey questions include a 0–10 rating, or why you upgraded or cancelled. Blaze stores your Discord ID and username; the server you picked, and details about that server's plan; and what you write or choose. From the feedback button it also stores the page you were on, your browser and operating system, your last (up to 10) page visits and clicks in the dashboard, and a screenshot if you attach one. For survey questions it records when one was shown to you and whether you answered or dismissed it.
- With the
/feedbackcommand in Discord. Anyone who can send messages in a server with Blaze Bot can use it. Blaze stores their Discord ID and username; the server's ID; the category they picked and their message (up to 2,000 characters); and the channel it was sent from, and their Discord language setting.
- Waitlist: before launch, blaze-bot.net shows a page where you can leave your email address to hear when Blaze launches. Blaze stores the address, when you signed up, whether and when you unsubscribed, and when we sent you the launch email. It sends you a welcome email from our own mail server. The unsubscribe link in our emails marks the address as unsubscribed. The address is deleted 30 days after you unsubscribe, or 30 days after we send you the launch email (section 6).
- Website & community data (Blaze Sites): the pages you build, and data your visitors submit, such as form submissions, applications and appeals, and moderation or player records you choose to manage. It is stored per site.
- Knowledge base content: articles and suggestions you create, stored per server.
- Billing data: plan, subscription status and billing email. Card details are handled directly by our payment processor (Stripe) and are never stored by Blaze.
- Usage metrics: aggregated counts per server, such as AI token usage per server per day, used for billing and abuse prevention.
- Session data: server-side sessions with a secure, HTTP-only cookie. We do not use third-party tracking cookies. See our cookie policy.
3. The game-server connector (Blaze Bot)
The connector is an optional Blaze++ add-on that you can install on your own game server, for example a FiveM server. It lets Blaze look up game data about the person who opened a ticket, so the AI can answer questions such as "where is my car?".
- Only the ticket opener's own data. Every lookup about a player is about the person who opened the ticket. Blaze works out who that is from the Discord account that opened the ticket. Neither the AI nor the player can change it.
- Only the lookups you turn on. Each lookup your connector offers stays off until you turn it on in the Blaze dashboard. The lookups that come with the connector return:
- the player's character name, job, gang, whether they are online and when they were last seen;
- their vehicles: plate, model, condition and location;
- their cash, bank balance and items.
A further lookup reports the game server's own status (players online, capacity, uptime), which is not about any player. We also supply example lookups you can add, for example for fines, unpaid bills, deaths or housing. Any lookup you add or write yourself returns whatever it is written to return.
- Read-only. Blaze only ever asks the connector to run lookups that read data, and the connector refuses to run anything else. The lookups Blaze supplies only read data and never change anything on your game server. If you write lookups of your own, you control what they do.
- Sent to the AI, then deleted.The result of a lookup is sent to our AI provider (Anthropic) together with the ticket, so the AI can write its reply. Blaze deletes the result, and what the AI asked for, from its database as soon as Blaze has read them. If something goes wrong before that, an hourly clean-up deletes them once they are more than an hour old. A record is kept of which lookup ran, for which ticket and game character, when, and whether it worked. That record is deleted after 30 days. The AI's reply is part of the ticket and may repeat what the lookup found. It is kept and deleted with the ticket (section 6).
- Link between Discord and game character.To know who a ticket opener is in the game, Blaze stores a link between a Discord account and a game character's identifier.
- How links are created. While the connector is running, it reports a link for every player who loads into your game server with a Discord account connected to the game. Blaze can also ask the connector for the link of someone who has opened a ticket, and keeps a note of whom it has asked so it does not ask too often. Those notes are deleted after 30 days.
- When a link is deleted. Once the player has not been seen on your game server for 90 days.
- When Blaze Bot is removed. All links for your server are deleted: straight away if Blaze Bot is running, otherwise the next time it starts (with one exception, see section 6).
- The connector runs under your control. It runs on your own game server, so removing Blaze Bot from Discord does not stop it. As long as it keeps running, it keeps reporting links to Blaze. To stop it, do one of these:
- remove the connector from your game server;
- beforeyou remove Blaze Bot, download the connector again on the Blaze dashboard's Connectors page (Blaze++). This creates a new key and cuts off the old one. The dashboard only lets you manage servers Blaze Bot is in, so after removal this option is gone;
- ask us to disconnect it.
- If your connector stops. The hourly clean-up runs when your connector contacts Blaze. The 30-day and 90-day deletions also run once a day on their own, so they still happen after you uninstall the connector. Anything the hourly clean-up has not reached is deleted with the lookup record after 30 days.
4. How we use data
- To answer support tickets on your server with AI (Blaze Bot replies in the ticket itself), and to hand a ticket to your staff when the AI cannot resolve it.
- To look up game data about a ticket opener, where you have installed the connector (section 3).
- To run the website builder.
- To display dashboards, analytics and history to authorised staff.
- To enforce usage limits, billing and abuse prevention.
- To improve the Services, using usage statistics, the feedback you send us, and the feedback players have chosen to send to Blaze about the assistant (section 2). Feedback a player has addressed to their own server since we started asking is not used for this: we only store it for that server and show it to that server's staff. The answers players gave beforewe started asking were never separated in that way; they are on Blaze's product feedback and are still used for this purpose until they are deleted (sections 1 and 6).
We do not sell your data, and we do not disclose data obtained through Discord's API to any advertising network, data broker, or other advertising or monetisation service. We also do notuse message content obtained through Discord's API to train machine-learning or AI models. Ticket content is used only to retrieve relevant knowledge and generate a response for your own server. The same applies to game data from the connector.
5. Sharing and sub-processors
We use the sub-processors below to operate the Services, and each of them receives only the data it needs:
| Sub-processor | What it does for Blaze | Where | Safeguard for transfers outside the EU/EEA |
|---|---|---|---|
| Anthropic PBC | AI provider. For Blaze Bot it receives ticket content, relevant knowledge-base content, images on Blaze++ and connector lookup results, and writes the reply. For Blaze Sites it receives what you send to the editor's AI assistant. | United States | Standard Contractual Clauses, in Anthropic's data processing addendum |
| Stripe | Payments. It receives the Discord IDs of the server and of the person paying, and what that person enters at checkout. It never receives ticket content or game data. | May be processed in the United States | EU–US Data Privacy Framework and Standard Contractual Clauses, in Stripe's data processing agreement |
| Hetzner Online GmbH | Hosting. Blaze's server, including its databases and backups, is in Hetzner's data centre in Falkenstein, Germany. | Germany | Not needed (EU) |
| Cloudflare, Inc. | Network and security. All traffic to Blaze's websites and API passes through Cloudflare, which decrypts it in order to forward it to our server. | Worldwide network; may be processed in the United States | EU–US Data Privacy Framework and Standard Contractual Clauses, in Cloudflare's data processing addendum |
Ticket content and game data are sent to the AI provider only to produce a response for your server.
Other services your browser contacts.The Blaze dashboard's code and fonts come from our own server. Some content is loaded by your browser directly from the service that hosts it, and that service then receives your IP address:
- Discord (cdn.discordapp.com): profile pictures, server icons and emoji shown in the dashboard. Discord is the platform your server runs on, not a sub-processor of ours, and handles this under its own privacy policy.
- Cloudflare Turnstile (challenges.cloudflare.com): if we switch on the anti-bot check on our waitlist page, your browser loads it from Cloudflare. Our server then confirms the result with Cloudflare and sends your IP address along.
- Images you link to yourself, for example in embed previews or bot profile settings. These are loaded from wherever they are hosted.
- Blaze Sites. Websites built with Blaze Sites can load fonts from Google Fonts; images from Unsplash in our templates; and videos or streams the site owner embeds, for example from YouTube or Twitch. These are loaded directly from those services.
Apart from the above, we disclose data only where required by law or to protect our legal rights.
6. Data retention and deletion
Tickets (Blaze Bot).A ticket is kept for as long as it is open and its channel still exists on Discord. After a ticket is closed, it is deleted once your plan's retention period has passed, counted from when it was closed:
- Free plan: 15 days
- Blaze+: 90 days
- Blaze++: 2 years
- Enterprise: as agreed
A ticket also counts as closed when its channel is deleted, or when its Discord server removes Blaze. If Blaze Bot is running, it is closed at that moment. If Blaze Bot was offline, it is closed when Blaze Bot next starts.
One exception: if Blaze Bot appears to have been removed from an unusually large share of servers at the same time, it treats that as a fault on our side rather than as removals. It then closes nothing and deletes nothing on that basis until we have checked it by hand.
The retention period that applies is the one for your current plan. If you move to a plan with a shorter period, closed tickets older than that period are deleted. When a ticket is deleted, its messages, the image links in them, Blaze's AI replies, its transcript, and the notes, ratings and knowledge-base suggestions made from it are deleted with it. An automatic process looks for tickets to delete every day.
Everything else.The table below lists everything else Blaze Bot keeps about you, your server or your players, and for how long. "Your plan's period" means the ticket periods above. An automatic process deletes what has expired every day.
| What | How long |
|---|---|
| Your server's audit log, and the run history of your automations | Your plan's period, counted from each entry |
| Activity statistics (section 2), the daily totals behind them, and AI usage per server per day | 2 years |
Feedback: players' answers about their own server or about the assistant, answers from before we asked who they were for (section 1), feedback you send us from the dashboard or with /feedback, and the record of which players were due to be asked or were sent a feedback message, and of which survey questions you were shown | 2 years after it was given. Feedback about a server is also deleted earlier on that server's instruction. |
| Announcements you send with Blaze Bot | 2 years after they were sent, or after they were made if they could not be sent. Scheduled ones are kept until they are sent. |
| Your votes on our roadmap | 2 years |
| Beta invitations: the email address, the code, and the Discord ID that used it | 2 years after the invitation |
| Referrals that never led to a payment | 2 years |
| Your referral code | 2 years after it was made or last used |
| Discount codes that were never used | 2 years after they expired, or after they were last changed if they do not expire |
| Payment records: discount codes that were used and what they gave, referral rewards and the referrals behind them, and your consent to start straight away during the withdrawal period | 5 years after the end of the year of the payment they document, as Danish bookkeeping law requires, also if you ask us to delete your data. A referral reward we have not yet credited is kept until it is. |
| Records of actions on Blaze that are not tied to one server, such as an account deletion | 5 years after the end of the year they were made in |
| The name cache (section 2) | As long as a ticket or dashboard permission we still keep shows the person's name. After that, 90 days after they last opened or wrote in a ticket. |
| Your server's emoji, copied from Discord | 90 days after they were last fetched |
| Connector data | As in section 3: lookup results within about an hour, lookup records and notes after 30 days, links after 90 days without being seen |
| Waitlist email addresses | While you are subscribed. Then 30 days after you unsubscribe, or 30 days after we send you the launch email. |
| Dashboard permissions you give staff and roles | Until you remove them, or until Blaze Bot is removed from your server |
| Your server's name, and the fact that Blaze Bot is in it | Until Blaze Bot is removed from your server |
| Sign-in sessions | About a week after your last visit |
| Your server's settings and plan, ticket panels and categories, automations and commands, knowledge base, announcement templates and connector setup | Until you delete them, or ask us to, and at the latest 12 months after Blaze Bot is removed from your server (see below) |
| Reviews you publish | Until you delete them, or ask us to |
| Blaze Sites content | Until you delete it, or ask us to |
It is our copy that is deleted. Anything Blaze Bot has already posted on Discord, or sent to someone's Discord inbox, stays there.
Backups (Blaze Bot). The Blaze Bot database is backed up once a day to the same server. Each backup is deleted at the next successful daily backup once it is 14 days old. Data deleted from Blaze Bot is therefore also gone from our backups about two weeks later. If backups fail for a while, older backups are deliberately kept until a new one succeeds.
Application logs. Our server keeps technical logs of what Blaze Bot does. They can contain:
- Discord user and server IDs, and ticket IDs;
- short extracts of AI replies and ticket messages (up to 200 characters). An AI reply can repeat what a connector lookup found.
Routine logs are kept for about 14 days. Error logs are kept as the last 14 log files for each service, which can reach back several months. Deleting a ticket or an account does not remove it from these logs.
Removing Blaze. Removing a Blaze product from your server stops us from collecting any more data through Discord. When Blaze Bot is removed:
- your server's open tickets are closed and then deleted under the rules above;
- the connector's links for your server are deleted (section 3);
- the dashboard permissions you gave staff and roles on your server are deleted;
- 12 months later, we delete everything we still hold for your server, even where the table above gives a longer period.
Dashboard permissions and connector links are deleted when Blaze Bot is removed. Adding Blaze Bot back does not bring them back.
If you add Blaze Bot back before the 12 months are up, nothing else is deleted, and the 12 months start again if you remove it later. Nothing is deleted on this basis while you still pay for a subscription for that server. If an unusually large number of servers falls due on the same day, we check them by hand before deleting. Two kinds of data are kept anyway:
- payment records, for the five years the law requires;
- feedback sent to Blaze, for its own two years: players' answers about the assistant, answers from before we asked who they were for, feedback you send us from the dashboard or with
/feedback, your votes on our roadmap, and our notices to you about that feedback.
A connector still running on your game server keeps reporting links until you stop it (section 3).
Discord data.In line with Discord's Developer Terms, we delete data obtained through Discord's API when you or Discord ask us to, and when it is no longer needed for the functionality you enabled. The periods above are how we do that. Anyone can ask us to delete their data (section 7). If we ever receive Discord API data in error, we will delete it promptly.
7. Your rights
Subject to applicable law (including the GDPR for EU/EEA users), you may:
- Access: request a copy of the data we store about you or your server.
- Rectification: correct inaccurate data.
- Erasure:request deletion of your data (the "right to be forgotten"). Payment records are kept for the five years Danish bookkeeping law requires (section 6).
- Portability: request your data in a machine-readable format.
- Withdraw consent: remove the Blaze product from your server at any time to stop further collection through Discord. If you use the connector, also stop it on your game server (section 3).
Download and deletion in the dashboard. Administrators and staff can download and delete their own account data from the Blaze dashboard.
- The download covers the tickets, messages, knowledge-base contributions, flows, reviews, permissions, AI feedback and billing ownership linked to your Discord account, and your last 1,000 audit-log entries.
- Deleting removes your Discord ID but keeps the text. Your Discord ID is replaced with a placeholder in tickets, messages, knowledge-base articles and suggestions, flows and the audit log. The text of those messages and articles is kept, so the server keeps its support history.
- Deleting also removes you as assigned staff and as billing owner, and deletes your reviews, permissions, AI feedback and sessions.
- Deleting does not cover the name cache, activity statistics, feedback answers (about the assistant or about a server), connector data or application logs. Each of these is deleted on its own schedule in any case (section 6). To have any of it removed sooner, ask us — for feedback about a server, ask that server.
End users of a Blaze-powered server or site, and anyone who wishes to exercise a right, can contact us at the address under Who is responsible above, and we will act on verified requests.
If you are in the EU/EEA and believe we handle your data unlawfully, you also have the right to complain to your data protection supervisory authority. In Denmark that is Datatilsynet, datatilsynet.dk.
8. Security
We protect data with these safeguards:
- encryption in transit: HTTPS/TLS between your browser (or your game server's connector) and Cloudflare, and between Cloudflare and our server;
- encryption of the Discord access tokens we store;
- CSRF protection, parameterised SQL queries, and secure HTTP-only session cookies;
- separation of each customer's data by Discord server, including the feedback players give about a server: every read of it names the Discord server it belongs to. The one exception is the name cache (section 2): it holds only public Discord profile data (username, global display name and avatar), which is the same on every server, and it is shared between servers;
- a Blaze Bot database that accepts connections only from our own server, never from the internet;
- daily backups of the Blaze Bot database (section 6), on a server with two mirrored disks.
9. Credentials
Blaze authenticates exclusively through Discord's official OAuth2 flow. We will never ask you or your users for a Discord password, authentication token, or other login credentials. Never share those with us or with anyone claiming to be us.
10. Children
The Services are not directed to children. We do not knowingly collect data from anyone under 13, or under the minimum digital-consent age in their jurisdiction. If you believe a child has provided us data, contact us and we will delete it.
11. Discord
Blaze is not affiliated with, endorsed by, or sponsored by Discord. Our use of Discord's API is subject to Discord's Developer Terms of Service and Developer Policy. Your use of Discord is subject to Discord's own Terms of Service and Privacy Policy.
12. Changes
We may update this Policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, communicated in-product.
13. Contact
For any privacy question or request, write to the address under Who is responsible above. See also our Terms of Service, our cookie policy and, for Blaze Bot, our data processing agreement.