Privacy Policy
Last updated: 23 July 2026
This Privacy Policy explains how Blaze ("Blaze", "we", "us", "our") collects, uses, shares, protects and deletes data across the Blaze platform: the Blaze Bot Discord application, the Blaze Siteswebsite builder, and the Blaze dashboard and HQ (collectively, the "Services"). It applies to server administrators and staff who sign in to Blaze, and to the end users of the Discord servers and websites operated with our tools.
1. Controller and processor roles
For the personal data of your end users that flows through our tools — for example ticket messages processed by Blaze Bot, or form submissions and moderation records processed by Blaze Sites — you (the server administrator) act as the data controller and Blaze acts as your data processor. For account, authentication, billing and usage data of administrators and staff, Blaze acts as the data controller.
2. Data we collect
- Discord account data: when you sign in with Discord OAuth2 we receive your Discord user ID, username, avatar, the servers (guilds) you manage, and — where you grant the
emailscope — your email address (used for billing and account notices). We never receive or store your Discord password. - Ticket conversations (Blaze Bot): messages sent inside support tickets on your server are stored so the AI can generate suggestions and so your staff can review transcripts.
- Website & community data (Blaze Sites): the pages you build, and data your visitors submit — such as form submissions, applications/appeals, and moderation or player records you choose to manage — stored per site.
- Knowledge base content: articles and suggestions you create, stored per server.
- Billing data: plan, subscription status and billing email. Card details are handled directly by our payment processor (Stripe) and are never stored by Blaze.
- Usage metrics: aggregated, anonymised counts (e.g. AI token usage per server per day) for billing and abuse prevention.
- Session data: server-side sessions with a secure, HTTP-only cookie. We do not use third-party tracking cookies.
3. How we use data
- To provide AI-powered ticket triage, suggested responses and the website builder.
- To display dashboards, analytics and history to authorised staff.
- To enforce usage limits, billing and abuse prevention.
- To improve the Services using aggregated, anonymised analytics only.
We do not sell your data, and we do notdisclose data obtained through Discord's API to any advertising network, data broker, or other advertising or monetisation service. We also do notuse message content obtained through Discord's API to train machine-learning or AI models; ticket content is used only to retrieve relevant knowledge and generate a response for your own server.
4. Sharing and sub-processors
We share data only with the sub-processors needed to operate the Services — our managed database and hosting provider, our payment processor (Stripe), and the AI provider(s) that generate ticket suggestions. Ticket content is transmitted to an AI provider only to produce a response for your server. Some providers may process data outside the EU/EEA (for example, in the United States); such transfers rely on appropriate safeguards such as Standard Contractual Clauses. We may also disclose data where required by law or to protect our legal rights.
5. Data retention and deletion
Ticket data and AI responses are retained according to your plan:
- Free plan: 15 days
- Blaze+: 90 days
- Blaze++: 2 years
- Enterprise plan: custom
After the retention period, ticket data is automatically deleted by a scheduled retention process that runs daily. Knowledge base articles and site content are retained until you delete them; the age-based retention schedule above continues to apply. Removing a Blaze product from your server stops any further collection. In line with Discord's Developer Terms, we delete data obtained through Discord's API upon your request or Discord's request, when it is no longer needed for the functionality you enabled, and within seven (7) days following termination of the relevant end user's account. If we ever receive Discord API data in error, we will delete it promptly.
6. Your rights
Subject to applicable law (including the GDPR for EU/EEA users), you may:
- Access: request a copy of the data we store about you or your server.
- Rectification: correct inaccurate data.
- Erasure: request deletion of your data ("right to be forgotten").
- Portability: request your data in a machine-readable format.
- Withdraw consent: remove the Blaze product from your server at any time to stop further collection.
Administrators and staff can export or delete their account data from the Blaze dashboard. End users of a Blaze-powered server or site, and anyone who wishes to exercise a right, can contact us at [email protected] and we will action verified requests.
7. Security
We use commercially reasonable, industry-standard safeguards to protect data against unauthorised access, including encryption in transit (HTTPS/TLS), encryption at rest for data stored in our managed database, encryption of stored third-party access tokens, CSRF protection, parameterised SQL queries, and secure HTTP-only session cookies. Access to production data is restricted to authorised personnel.
8. Credentials
Blaze authenticates exclusively through Discord's official OAuth2 flow. We will never ask you or your users for a Discord password, authentication token, or other login credentials, and you should never share those with us or anyone claiming to be us.
9. Children
The Services are not directed to children. We do not knowingly collect data from anyone under 13, or under the minimum digital-consent age in their jurisdiction. If you believe a child has provided us data, contact us and we will delete it.
10. Discord
Blaze is not affiliated with, endorsed by, or sponsored by Discord. Our use of Discord's API is subject to Discord's Developer Terms of Service and Developer Policy, and your use of Discord is subject to Discord's own Terms of Service and Privacy Policy.
11. Changes
We may update this Policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, communicated in-product.
12. Contact
For any privacy question or request, email [email protected]. See also our Terms of Service.