Legal

Privacy Policy

Auth Bot Live works with a small, specific set of data: the Discord identity of a member and the TikTok profile they chose to link. This page explains exactly what that means, and how to get it removed.

Last updated October 8, 2026

01Scope of this policy

This Privacy Policy explains what Auth Bot Live collects when you invite the bot, sign in with Discord, or link a TikTok account, and what happens to that data afterwards.

Auth Bot Live is operated by VaninoLLC and serves the website at authbotlive.therealalexv.com. This policy covers the bot, the website, and the dashboard. It does not cover TikTok, Discord, or Stripe, each of which handles your data under its own privacy policy.

02Data we collect from Discord

When you sign in with Discord, we receive your Discord user ID, username, and avatar, and the list of servers you can manage where the bot is present. We use a session cookie to keep you signed in.

When a member links an account, we store the Discord user ID and the server ID the link belongs to, so the Linked role can be granted in the right place.

03Data we collect from TikTok

When a member authorizes a link, TikTok returns an open ID, an access token, a refresh token, and their expiry times. We store these so the link keeps working without asking the member to log in again.

With the approved user.info.basic scope, we also read and store the member's display name and avatar. We do not request or receive follower counts, likes, video counts, or video metadata, because the scope does not grant them.

We do not collect data about accounts a member does not own, and we do not access private messages, watch history, or non-public analytics.

04How we use this data

To verify that a Discord member owns a TikTok account.

To grant the server's Linked role when a member links, and to remove it when they unlink.

To show server administrators a list of linked members and an audit log of actions such as links, unlinks, and role changes.

There is no other use. We do not run announcements, analytics, leaderboards, or follower-count gating on this data.

05What we never do

We do not scrape TikTok. All TikTok data comes through the official Login Kit and the scope a member approved.

We do not collect follower, like, or video statistics, and we do not build leaderboards or rank members by them.

We do not post announcements or publish anything to your server on a member's behalf.

We do not sell personal data, and we do not use it for advertising or to build cross-server profiles of members.

We do not store payment card details, because payments are handled entirely by Stripe.

06Why we are allowed to process it

For members, processing is based on consent: a member chooses to link an account and approves the scope shown on TikTok's consent screen. Consent can be withdrawn at any time by unlinking or by revoking access in TikTok's settings.

For server administrators, processing is based on the contract between us (providing the dashboard and the subscription) and on our legitimate interest in operating and securing the service.

For security, fraud prevention, and legal compliance, we process limited data based on our legitimate interests and legal obligations.

07Sharing and service providers

We share data with the platforms needed to run Auth Bot Live: Discord (to grant and remove the Linked role), TikTok (to read the approved profile fields), and Stripe (to process subscriptions). Each provider processes data under its own terms.

We may share data if required by law, to protect the service from abuse, or as part of a transfer of the service, in which case this policy continues to apply.

08Retention and deletion

TikTok profile data and tokens are kept only while a link is active. When a member unlinks, or when we detect that they revoked Auth Bot Live's access on TikTok (via TikTok's authorization-removed webhook, with a token-refresh check as a fallback), the stored TikTok data for that link is deleted and the Linked role is removed.

Audit log entries are kept without TikTok profile data so server administrators retain a record of actions.

Some records, such as billing records held by Stripe, are retained as long as required for tax and accounting purposes.

09Cookies and sessions

Auth Bot Live sets a session cookie when you sign in with Discord. It is necessary for the dashboard to work, it is not used for advertising, and it is not shared with third parties.

No analytics or advertising cookies are set on the website.

10Your choices and rights

You can unlink a TikTok account at any time with /unlink or from the dashboard, which deletes the associated TikTok data and removes the role. You can also revoke Auth Bot Live's access from your TikTok account settings.

Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to certain processing, or to withdraw consent. Requests can be sent to privacy@therealalexv.com.

Server administrators can remove a server's data by removing the bot and contacting us to delete the server's records.

11Age

Auth Bot Live is not intended for anyone below the minimum age required by Discord or TikTok in their country, and never for children under 13. If we learn that a child below that age has linked an account, we will delete the data.

12Security

Tokens are stored server-side and never exposed to the browser or to other members. The website never receives secrets, and only public configuration is sent to the frontend.

Sessions are signed and set with standard protections. Access to the dashboard requires authenticating with Discord and, for a given server, holding the permission to manage it.

13Changes and contact

If this policy changes in a meaningful way, we will update the date on this page. Continued use after an update means you accept the revised policy.

Questions or requests can be sent to privacy@therealalexv.com.