Privacy Policy for RoAPI Discord Bot
Last Updated: September 2026
This Privacy Policy describes how RoAPI ("the Bot", "we", "us", or "our") collects, uses, and safeguards information when you use our Discord bot, web application, and associated developer services at roapi-bot.netlify.app.
1. Information We Collect
RoAPI collects only the minimal data required to deliver tracking, verification, developer telemetry, and automated perk fulfillment:
- Discord Account Identifiers: We store your numeric Discord User ID when you run commands (e.g.,
/setup, /purchase, /manage-trackers), link accounts, or purchase perks. We also store Discord Guild (Server) IDs, Channel IDs, and Message IDs where tracker embeds and update threads are deployed.
- Roblox OAuth 2.0 Data & Scopes: When you connect your Roblox account using official Roblox OAuth 2.0 authentication, we request the following scopes:
openid and profile: To verify your identity and retrieve your public Roblox User ID, Roblox Username, and Display Name to bind your Roblox identity to your Discord account.
user.inventory-item:read: To securely inspect your Roblox inventory and confirm your ownership of official RoAPI gamepasses (+1, +2, +3 Trackers, Premium, and Developer Tier) for automatic perk activation.
We never access, request, or store your Roblox password, private payment details, or sensitive credentials. You can revoke this authorization at any time directly through your Roblox Account Settings.
- Experience Ownership & API Key Security: We use your verified Roblox User ID to confirm your developer ownership or group administrative permissions over experiences you instrument. This ensures your Developer Tier Luau Debugger API keys are locked exclusively to your authorized Roblox Universe IDs and Place IDs, guaranteeing that your API keys can only operate within your own games and cannot be hijacked or used externally.
- Stripe Payment & Billing Metadata: All fiat purchases and subscriptions (Premium Tier, Developer Tier, Tracker Addons) are processed directly by Stripe. RoAPI never collects, handles, or stores sensitive payment details such as credit card numbers or security codes. We receive and retain only transaction metadata necessary for fulfillment: Stripe Checkout Session ID, transaction timestamp, amount paid, subscription status, product tier, and the associated Discord User ID passed via
client_reference_id. If you provide an email address at checkout, it is used solely for receipt delivery, subscription status synchronization, and manual claim matching.
- Roblox Game Data: RoAPI queries Roblox's public APIs to fetch experience statistics (such as visit counts, concurrent active players, like/dislike ratios, favorites, place versions, update timestamps, sub-places, and public metadata). This information is publicly accessible on the Roblox platform.
- Luau In-Game Debugger Telemetry (Developer Tier): For developers using our Luau Crash Reporter API, our edge backend receives runtime script error payloads (script name, line number, error message, stack trace, Place ID, and server Job ID). This telemetry is processed transiently and relayed directly to your configured Discord webhook URL. We do not store your game's proprietary source code.
- Configuration & Operational Metrics: Tracker preferences, notification settings, custom embed colors, role ping IDs, and aggregated operational performance metrics (e.g., API response times, embed update counts).
- Blacklist & Abuse Prevention: Identifiers of users, guilds, or universe IDs restricted from using the service due to abuse, fraud, or violation of these terms.
2. How We Use Your Information
We use the collected information strictly for operational, fulfillment, and security purposes:
- To operate, update, and maintain automated Roblox game tracking embeds and update threads in Discord.
- To automatically verify Roblox gamepass ownership and apply associated tracker limit upgrades via OAuth 2.0 inventory reading.
- To enforce strict Universe Locking on Developer Tier API keys, ensuring crash reporting keys only function inside games you verified ownership of.
- To fulfill, manage, and synchronize Stripe subscriptions, one-time perks, and tracker limits automatically without manual intervention.
- To relay game crash reports and performance alerts directly to developer-designated Discord channels.
- To enforce fair usage policies, prevent duplicate claim abuse, and safeguard bot infrastructure.
- To communicate transaction confirmations and subscription status updates via Discord direct messages.
3. Third-Party Services & Data Sharing
We do not sell, rent, or monetize your personal information. Data is shared only with trusted infrastructure providers essential to our operations:
- Discord: To execute bot commands, post tracker embeds, manage update threads, and send direct message notifications.
- Roblox Corporation: We interact with Roblox's public APIs to retrieve game statistics and utilize Roblox's official OAuth 2.0 service for secure identity linking.
- Stripe: Payment processing is handled by Stripe. Your payment card information is governed by Stripe's Privacy Policy.
- Cloudflare: Our backend routing, OAuth callbacks, and primary database operate on Cloudflare Workers and Cloudflare D1 distributed edge infrastructure.
- Legal & Safety Compliance: We may disclose information if required by applicable law, court order, or to prevent fraud, unauthorized access, or attacks against our systems.
4. Data Storage, Security & Infrastructure
All configuration data, account mappings, and fulfillment logs are stored securely in distributed Cloudflare D1 databases protected by authenticated API tokens and encrypted at rest and in transit (TLS 1.3 / HTTPS). We implement strict input validation, universe-level key authentication, and rate limiting to guard against unauthorized access.
While we employ industry-standard safeguards, no Internet transmission or cloud storage system is completely impenetrable. We continuously review our security practices to protect user data.
5. Data Retention & Account Control
We retain configuration and account association data only as long as your trackers remain active or as necessary to honor purchased lifetime perks and active subscriptions. You have the right to:
- Unlink Accounts: You can disconnect your Roblox authorization at any time via Roblox Account Settings → Authorized Applications, or unlink your Discord pairing by contacting support.
- Data Deletion: Removing a tracker deletes its stored channel and message associations. You may request permanent deletion of your stored user record, linked accounts, or debugger keys by opening a request in our Support Server.
- Subscription Management: You can cancel recurring Stripe subscriptions anytime via the Stripe billing portal or through customer support, with access continuing through the end of the paid billing period.
6. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect new features, infrastructure updates, or regulatory requirements. Material revisions will be announced in our Discord Support Server and reflected in the "Last Updated" date on this page.
7. Contact Us
For privacy inquiries, account unlinking, or data deletion requests, join our official Discord server: