Privacy Policy

Draft · no effective date set

Draft: not legally reviewed

This policy is an unreviewed template written to give the service a starting point. It has not been checked by a lawyer, it may be wrong or incomplete for your jurisdiction, and it must not be relied on. Ticki is not open to the public while this notice is here.

This describes what the Ticki hosted service at ticki.gg, operated by [legal entity not configured], would collect and why. It is written to match what the software actually does today.

Who is responsible for what

A server administrator decides to install Ticki and configures what it collects through ticket forms. For the data inside your server's tickets, the server operator is the controller and we are the processor acting on their instructions. For dashboard accounts and service operation, we are the controller.

[Placeholder: if the service is offered to users in the EU/UK, a data processing agreement, a lawful basis table, transfer mechanism and a named contact are required. Confirm with counsel before launch.]

What we store

  • Account: your Discord user id, username, avatar and (if your Discord account has one) email, plus the OAuth tokens needed to list the servers you can manage. Identity is the Discord id, never the email.
  • Server configuration: ticket types, forms, panels, staff groups and permissions, workflows, notification rules, SLA policies and localisation overrides.
  • Ticket and modmail content: messages sent in ticket channels and modmail conversations, the answers submitted in ticket forms, and files attached to them. Attachments are copied from Discord's CDN so they survive in transcripts.
  • Transcripts: a stored copy of a conversation once it closes, including participant names and avatars at that time.
  • Operational records: an audit log of dashboard actions, job and delivery logs for integrations, AI usage counts, and server logs.

What we do not do

  • We do not sell personal data or share it with advertisers.
  • We do not use your messages or transcripts to train AI models.
  • We do not read messages outside ticket channels, modmail conversations, and the channels you point the bot at.

Third parties

  • Discord: the platform the service runs on. Everything Ticki sees comes from there.
  • AI providers: only when a server enables AI features. Ticket content needed for the reply is sent to the configured provider, either on Ticki's key or on the server's own key.
  • Integrations you configure: outgoing webhooks and connectors send ticket events to endpoints you choose. What happens to the data there is governed by that endpoint's own policy.
  • Hosting and storage [hosting provider and region to be named before launch]

Secrets

API keys you supply (AI provider keys, integration credentials) are encrypted with a per-secret key that is itself wrapped by a master key held outside the database. The dashboard is write-only for these: after saving, only a fingerprint is shown, and the plaintext is never returned to the browser.

How long we keep things

  • Transcripts: for the retention window of the server's plan. After that they stop being readable, and they are deleted for good after a further grace period.
  • Configuration: until you delete it, or until the bot is removed from the server and the purge job runs.
  • Audit and delivery logs [retention period to be decided]

Your rights

Depending on where you live you may have the right to access, correct, export or erase your personal data, and to object to some processing. Ticki supports export and erasure requests for a Discord user; ask a server administrator, or contact us directly.

Erasing a member's data removes their messages from stored transcripts. It cannot remove anything from Discord itself.

Contact

Privacy questions and data requests: [contact email not configured]