Legal
Subprocessors and Data Details
Effective Date: September 30, 2026
This page provides the detailed layer of the BabelBot privacy notice. It lists the external providers we use and gives more information about data categories and retention. A provider can act as our processor or as an independent controller, depending on its service and legal duties. Read the Privacy Policy.
For data-processing agreement requests, transfer questions, or provider concerns, contact [email protected].
Current Providers
Discord platform, bot gateway, OAuth login, server membership checks, messages, reactions, attachments, and account information required to operate BabelBot.
Data Processed
Discord account IDs, server IDs, channel IDs, message content processed in real time, attachment URLs, OAuth profile data, and permission information.
Processing Location
United States and other regions where Discord operates. Transfers outside the European Economic Area use Standard Contractual Clauses or the EU-US Data Privacy Framework where Discord is certified.
Bot and server statistics and Discord interaction use measurement.
Data Processed
Bot username, ID and avatar; server IDs, names, icons, member counts, size groups and locales. Command and component names, interaction counts and locales, server joins and leaves, user-install counts, and aggregate permission and new-member groups.
Processing Location
France for applications and databases; Europe for image hosting, according to the provider's privacy policy.
AI model routing for translation, language detection, image or media text extraction, and speech-to-text transcription.
Data Processed
Message text, selected attachment content, voice transcription payloads, target language settings, and request metadata needed to return translations.
Processing Location
OpenRouter routes AI translation, media processing, and language detection to Google (Gemini) through Google Vertex AI's EU endpoint. Translation retries and fallback requests use that same EU endpoint. Voice chat and voice note transcription use OpenAI (Whisper). Those providers receive the content OpenRouter sends them. BabelBot uses OpenRouter's standard gateway. The EU model endpoint does not guarantee that OpenRouter's gateway processing stays in the EU. Gateway processing and Whisper transcription can occur in the United States and other regions those providers use. For each transfer outside the European Economic Area, BabelBot uses Standard Contractual Clauses or an adequacy decision, including the EU-US Data Privacy Framework where the provider is certified.
Fallback text translation and language detection when AI translation is not used.
Data Processed
Message text and language settings needed to return a translation.
Processing Location
The Azure region of BabelBot's Translator resource. If that region is outside the European Economic Area, the transfer uses Standard Contractual Clauses or the EU-US Data Privacy Framework where Microsoft is certified.
Checkout, subscription management, customer portal access, invoices, tax handling, payment records, and billing webhooks.
Data Processed
Billing identifiers, customer records, subscription status, payment metadata, invoice data, tax records, and customer portal events.
Processing Location
European Union and other regions used for payment processing. When Polar processes payment data outside the European Economic Area, the transfer uses Standard Contractual Clauses or an adequacy decision.
Discord bot hosting and data storage, including Redis, PostgreSQL, and private object-storage backups. Railway also provides logs and internal networking for these services.
Data Processed
Discord message content processed by the bot, recent context, Discord and dashboard identifiers, translation feedback submitted through Discord forms, server configuration, bridge records, billing state, authentication data, operational logs, and Redis recovery backups.
Processing Location
European Union.
HTTPS delivery and protection of the website and dashboard.
Data Processed
IP address, requested URL, user agent, and security logs needed to deliver and protect the site.
Processing Location
Global network. Cloudflare, Inc. is established in the United States. Transfers outside the European Economic Area use Standard Contractual Clauses or the EU-US Data Privacy Framework where Cloudflare is certified.
Billing, account, and non-essential lifecycle emails for dashboard users and customers.
Data Processed
Email addresses, delivery metadata, and email content for billing, account, abandoned checkout, and review request messages.
Processing Location
Ireland, European Union, for email sending. Resend stores customer data in the United States, including message content, delivery logs, webhook payloads, and account records. Transfers of that stored data outside the European Economic Area use Standard Contractual Clauses or the EU-US Data Privacy Framework where Resend is certified.
| Provider | Purpose | Data Processed | Processing Location |
|---|---|---|---|
| Discord | Discord platform, bot gateway, OAuth login, server membership checks, messages, reactions, attachments, and account information required to operate BabelBot. | Discord account IDs, server IDs, channel IDs, message content processed in real time, attachment URLs, OAuth profile data, and permission information. | United States and other regions where Discord operates. Transfers outside the European Economic Area use Standard Contractual Clauses or the EU-US Data Privacy Framework where Discord is certified. |
| Discord Analytics | Bot and server statistics and Discord interaction use measurement. | Bot username, ID and avatar; server IDs, names, icons, member counts, size groups and locales. Command and component names, interaction counts and locales, server joins and leaves, user-install counts, and aggregate permission and new-member groups. | France for applications and databases; Europe for image hosting, according to the provider's privacy policy. |
| OpenRouter | AI model routing for translation, language detection, image or media text extraction, and speech-to-text transcription. | Message text, selected attachment content, voice transcription payloads, target language settings, and request metadata needed to return translations. | OpenRouter routes AI translation, media processing, and language detection to Google (Gemini) through Google Vertex AI's EU endpoint. Translation retries and fallback requests use that same EU endpoint. Voice chat and voice note transcription use OpenAI (Whisper). Those providers receive the content OpenRouter sends them. BabelBot uses OpenRouter's standard gateway. The EU model endpoint does not guarantee that OpenRouter's gateway processing stays in the EU. Gateway processing and Whisper transcription can occur in the United States and other regions those providers use. For each transfer outside the European Economic Area, BabelBot uses Standard Contractual Clauses or an adequacy decision, including the EU-US Data Privacy Framework where the provider is certified. |
| Microsoft Azure | Fallback text translation and language detection when AI translation is not used. | Message text and language settings needed to return a translation. | The Azure region of BabelBot's Translator resource. If that region is outside the European Economic Area, the transfer uses Standard Contractual Clauses or the EU-US Data Privacy Framework where Microsoft is certified. |
| Polar.sh | Checkout, subscription management, customer portal access, invoices, tax handling, payment records, and billing webhooks. | Billing identifiers, customer records, subscription status, payment metadata, invoice data, tax records, and customer portal events. | European Union and other regions used for payment processing. When Polar processes payment data outside the European Economic Area, the transfer uses Standard Contractual Clauses or an adequacy decision. |
| Railway | Discord bot hosting and data storage, including Redis, PostgreSQL, and private object-storage backups. Railway also provides logs and internal networking for these services. | Discord message content processed by the bot, recent context, Discord and dashboard identifiers, translation feedback submitted through Discord forms, server configuration, bridge records, billing state, authentication data, operational logs, and Redis recovery backups. | European Union. |
| Cloudflare | HTTPS delivery and protection of the website and dashboard. | IP address, requested URL, user agent, and security logs needed to deliver and protect the site. | Global network. Cloudflare, Inc. is established in the United States. Transfers outside the European Economic Area use Standard Contractual Clauses or the EU-US Data Privacy Framework where Cloudflare is certified. |
| Resend | Billing, account, and non-essential lifecycle emails for dashboard users and customers. | Email addresses, delivery metadata, and email content for billing, account, abandoned checkout, and review request messages. | Ireland, European Union, for email sending. Resend stores customer data in the United States, including message content, delivery logs, webhook payloads, and account records. Transfers of that stored data outside the European Economic Area use Standard Contractual Clauses or the EU-US Data Privacy Framework where Resend is certified. |
Data Details
These descriptions explain the main technical data groups. They support the summary in the Privacy Policy without listing internal database fields or infrastructure keys.
- Messages and recent context
- BabelBot can temporarily keep the current message and up to five earlier eligible messages from the same channel or thread. Context records can include limited message text, message and author IDs, and timestamps. They expire after up to 15 minutes or when newer messages replace them.
- Attachments and media
- BabelBot receives attachment URLs, file metadata, embeds, stickers, and other Discord media needed for enabled translation features. Relevant content can be sent to an AI provider. BabelBot does not keep attachment files in its primary application storage.
- Live voice and voice notes
- When voice translation is enabled, BabelBot sends the audio to OpenRouter for transcription. BabelBot does not keep the audio after the transcript comes back. The transcript is then handled like other message text.
- Server settings and opt-outs
- BabelBot stores server and channel IDs, language settings, enabled features, ignored user IDs, bridge settings, webhook configuration, and other settings selected by server administrators. BabelBot keeps these records while it remains in the server. They expire 180 days after BabelBot leaves. If BabelBot rejoins during that period, BabelBot keeps them while it remains in the server.
- Dashboard setting history
- Setting-change records can include the acting dashboard account ID or name, source, time, action, and safe before-and-after summaries. The summaries omit custom-word text, bot profile content, and bridge webhook credentials. The dashboard shows up to 500 successful entries from the last 90 days.
- Dashboard accounts
- Dashboard records can include Discord account details, email address, profile image, OAuth tokens, sessions, IP address, user agent, roles, access restrictions, and account-administration metadata.
- Usage and billing
- BabelBot stores translation totals, quota records, plan status, customer and subscription identifiers, billing events, and support records. Usage counters do not contain message text.
- Translation feedback
- When a member reports a translation from a translation embed in a Discord thread, BabelBot stores the submitted problem description, optional suggested correction, Discord and translation identifiers, locale, and timestamps. The database feedback record does not copy the original message or translated text. If configured, an optional private Discord support webhook receives the feedback, any correction, relevant identifiers, and a link to the translation. The link can let authorized maintainers open the Discord translation, subject to their server access.
- Bridges and diagnostics
- Bridge records connect source messages to translated copies so BabelBot can synchronize edits, deletions, replies, and reactions. Stored bridge and replacement records contain Discord IDs and delivery state. They do not store message text. Reply previews store the quoted author's name, a short quote, and a message link. BabelBot deletes a preview 30 days after the reply is delivered. Diagnostic records can include Discord, provider, model, outcome, timing, and error identifiers. Authorized diagnostic exports can contain current Discord message content, author data, attachment URLs, and related metadata.
- Analytics and local storage
- BabelBot self-hosts cookieless analytics and performance measurement for the website and dashboard. We do not send this analytics data to the analytics software vendor. Data can include page views, interactions, referrers, browser or device category, approximate location, and performance information. Cookies and browser storage support authentication, locale, interface preferences, and onboarding state. BabelBot does not use advertising cookies.
- Discord Analytics
- When enabled, BabelBot sends bot and server statistics and Discord interaction counts to Discord Analytics. These records include server IDs, names, icons, member counts, size groups and locales. They also include command and component names, interaction locales, server joins and leaves, user-install counts, and aggregate permission and new-member groups. We exclude member IDs, message text, command arguments, feedback text, voice audio, and transcripts. Component labels exclude message IDs, trace IDs, and retry tokens. See the Discord Analytics privacy policy at https://discordanalytics.xyz/docs/legals/privacy-policy for its data handling.
- Install and lifecycle measurement
- BabelBot records install source, server joins, setup milestones, first translation, first payment, active-server events, and removal times. It briefly uses an IP-derived rate-limit key to prevent automated install-link abuse.
- Recovery backups and logs
- Recovery backups can contain server settings, billing state, bridge records, recent context, traces, and cached dashboard authentication data. Operational logs can contain request metadata, Discord identifiers, provider results, and error information.
Retention Details
| Data group | Current retention |
|---|---|
| Recent message context | Kept for up to 15 minutes. |
| Bridge synchronization records | Bridge and replacement records store Discord IDs and delivery state. They do not store message text. New records have no age-based expiry. Existing Redis bridge records keep their original expiry, normally 30 days after creation. Reply previews store the quoted author's name, a short quote, and a message link. BabelBot deletes a preview 30 days after the reply is delivered. |
| Recent translation records | A 48-hour history. The records expire after 72 hours without new activity. |
| Daily usage aggregates | 180 days after the last update. |
| Translation feedback | The database record is scheduled for deletion 90 days after submission. Copies in internal support tools follow the retention rules for those tools. |
| Install and lifecycle measurement | Eligible for deletion after 13 calendar months. |
| Accounting records | At least seven years where Dutch tax law requires it. |
| Monthly usage totals | 13 calendar months after the recorded month ends. |
| Saved target language | 180 days after the member last sets or uses it. |
| Server setup and billing records | Kept while BabelBot remains in the server. They expire 180 days after BabelBot leaves. Rejoining during that period removes this expiry. |
| Dashboard setting history | The dashboard shows up to 500 successful entries from the last 90 days. BabelBot deletes the underlying record after 90 days. |
| Email limits and cancellation reason records | Email event and cancellation reason records expire after 400 days. Monthly abandoned-checkout email limits expire 62 days after the recorded month ends. |
| Sign-in storage | BabelBot uses the expiry supplied by the sign-in service. If that expiry is missing or invalid, the record expires after 30 days. |
| Removal tasks | Records used to finish removing deleted channels and webhooks expire after 30 days. Translation thread deletion records expire 365 days after the scheduled deletion time. |
| Admin-requested troubleshooting files | BabelBot deletes an admin-requested troubleshooting file 30 days after the export, or 90 days after the related support request closes, whichever is later. |
| Recovery backups | BabelBot creates a Redis backup every 15 minutes. It keeps every backup for 2 days. It then keeps one backup per hour through day 14, one per day through day 90, and one per month through day 365. Backups expire after 365 days. Deleting data from the live service does not delete the same data from existing backups. That data remains until each backup expires. BabelBot uses backups only to restore the service. |
| Dashboard accounts and sessions | Kept while the account remains active or while needed for security, fraud prevention, recovery, support, billing, and legal duties. Expired sessions can be removed earlier. |
| Operational logs | Traces and logs are kept for 15 days. Metrics are kept for one month. |
Updates and Objections
BabelBot may update this page when subprocessors change. Where required by law or a signed data-processing agreement, BabelBot will provide notice before adding a new subprocessor and will consider timely objections related to data-protection risk.