PRIVACY POLICY
The scripturealone.net website and the custom Discord bots operated by Fully Awakened Ministries for the Scripture Alone community
Effective date: July 18, 2026
Scope — what this covers, and how to read it
This document has two parts with different legal characters:
- The Privacy Policy is a notice. It explains how Fully Awakened Ministries processes personal data and the lawful bases we rely on. It is not something you "agree" to by contract; it informs you.
- The Terms of Service are a contract governing your use of our services.
It applies to the online services Fully Awakened Ministries operates for the Scripture Alone community: our website at scripturealone.net, our custom, self-hosted Discord bots, and our Scripture Alone Radio stream. Broadly, our bots fall into two groups: a moderation and community-features bot (referred to in this document as Catherine), and a set of private, staff-controlled audio bots that stream audio into listen-only voice channels. For security reasons we do not publish a detailed inventory of our bots or the underlying software they run on.
What this does not cover. Third-party bots hosted and operated by other companies — for example Dyno, Carl-bot, ProBot, or YAGPDB — are governed by their own policies. Third-party services we link to (Discord, PayPal, Spreadshop, Google, audio sources) each have their own policies too.
Assent. These Terms govern use of the Services. For interactions that matter contractually — submitting a form, using bot features — we obtain affirmative acceptance. For ordinary browsing of the website or listening to the radio, these Terms apply as notice, to the extent they are enforceable without a separate agreement; we do not claim that merely viewing a page or hearing the stream forms a contract. The Privacy Policy applies as notice regardless, and special-category processing stands on the lawful bases in Section 4, not on passive conduct. We also provide conspicuous in-server notices for logging and automated moderation.
1. Plain-language summary
- Fully Awakened Ministries is the data controller for the personal data described here.
- Most bot data is ordinary Discord information (user IDs, usernames, server/channel/role IDs, timestamps). Catherine stores the most — moderation records, voice join/leave history, activity counts, and virtual-economy balances — in local databases and in Discord staff-log channels.
- Some features send data to outside services: automated image moderation to OpenAI; the translate command to DeepL; forum search to OpenAI; website form submissions to Google Forms; donations via PayPal; merchandise via Spreadshop.
- Our website uses no analytics or ad-tracking cookies and serves its own fonts. The one exception is our Podcast page, which embeds a Spotify player that connects you to Spotify when the page loads (see Sections 3.8 and 5).
- Our forms collect sensitive information (religious beliefs, and for the mentor application, gender) — provided voluntarily to apply. Self-harm support tickets may contain mental-health information. We treat both with extra care (see Sections 3.7 and 4).
- We do not sell your data, and we do not use it for advertising.
- You have rights over your data, including access and deletion — see Section 10.
- The audio bots keep no user database — only per-server playback settings and staff-created playlists (keyed by server, not user), plus routine operational logs. A transient in-memory member cache they use for permission checks is not saved to disk.
2. Who we are (the data controller)
The website, bots, and radio are operated by Fully Awakened Ministries ("we", "us", "our"), a Texas-based religious nonprofit ministry recognized by the IRS as a 501(c)(3) church (federal EIN 46-2466880), which runs this Discord community. For any privacy question, data-rights request, or complaint, use our contact form at scripturealone.net/contact.
We are generally the controller of the data we collect to operate these services. Some providers we use are independent controllers for their own parts (notably Discord, PayPal, Spreadshop, and Google) and are responsible for their own processing under their own policies. Discord Inc. provides the underlying platform and is an independent controller for the account and message data you create on Discord; this policy covers only what our services do with data, not Discord itself.
3. What data we process
3.1 Account and technical identifiers
Standard Discord identifiers: your user ID, username and server nickname, the server (guild) ID, channel and role IDs, message IDs, and event timestamps. Discord provides these automatically when you interact with a server the bot is in. In addition, where a bot uses the Server Members Intent (see Section 3.10), it may receive and transiently cache member and role information for members of the server generally — not only those who interact with it — in order to resolve permissions and run member-dependent features. That cache is held in memory and is not written to disk.
3.2 Message content
Some Catherine features process message text:
- Word filtering. The filter and translate components scan message text against a configured word list to enforce community rules, and may delete matching messages. The check happens in the moment and does not keep a stored copy of your message — but see Section 3.6 for moderation records that can quote content.
- Translation. When you use the translate command, the text you submit is sent to DeepL (see Section 5).
- Forum search. The forum "tag search" sends your search query text to OpenAI when a local keyword match does not resolve it.
- Activity counting. The role-stats feature counts messages and reactions and stores counts and first-activity locations, not message content.
- Command input. Text you pass to a command is processed to run that command; some commands log the command and its arguments to a staff channel (see Section 3.6).
3.3 Images
Automated image moderation sends the URLs of images you post and, where enabled, user avatar images, to OpenAI's moderation service to classify them, and then acts on the result (see Section 6 for what "acts on" means and how to appeal). It does not store the images; it may log the action (who, when, categories flagged) to a staff channel.
3.4 Voice-channel activity
Voice logging records when users join, leave, or switch voice channels — user ID, event type, before/after channel IDs, timestamp — in a local database, and can reconstruct historical events from a Discord log channel's message history. Used for moderation and aggregate reporting.
3.5 Moderation, engagement, and economy records
- Staff audit: moderation actions — acting moderator ID, target user ID, action, any reason text, timestamp — including actions attributed by reading server audit logs and command messages.
- Core moderation (cases, warnings, mutes, ban records): target, responsible staff, reason, timestamps. Anti-nuke monitors the rate of sensitive admin actions.
- Engagement: message/reaction counts, first-activity and per-channel activity; last-seen time; badge assignments.
- Virtual economy: in-server virtual-currency balances and transactions. This is play-money with no real-world value.
- Games: game state and scores keyed to players and server.
3.6 Records from Discord that may contain your content
Several features create records — kept in Discord staff channels — that can contain or quote content you posted on Discord. (For information you provide through our website forms rather than through Discord, see Section 3.8.)
- Ticket transcripts generated on close and posted to a staff log channel.
- Moderation reasons that may quote the message that prompted an action.
- Staff-audit entries derived from reading command messages.
- Voice history reconstructable from Discord log-channel messages.
- Server-event logs (joins/leaves, bans, role/nickname changes) forwarded to staff log channels.
These are records under our control even when hosted in Discord. Their storage and retention are covered in Sections 8 and 9.
3.7 Self-harm support and health-related data
Our restriction tools can open a private ticket channel (for example, the self-harm support workflow) visible only to the affected user and staff, and can generate a transcript posted to a staff log channel on close. Such a ticket may contain mental-health or crisis information, which we treat as sensitive.
Important: these tickets are not an emergency service and are not monitored by professionals; staff responses may be delayed. If you or someone else is in immediate danger, contact local emergency services or a crisis line (e.g. in the US, call or text 988). To protect a person from imminent harm, we may — consistent with applicable law — disclose ticket information to emergency services, a guardian, Discord, or others where we reasonably believe it is necessary to prevent serious harm. When a ticket is opened we present a clear notice and require a separate, affirmative "I explicitly consent…" control before any sensitive content is collected; we rely on that explicit consent for the mental-health information you choose to share, and on vital interests only where a person is physically or legally incapable of giving consent and is at imminent risk. Access to these tickets is limited to designated staff; see Section 4 for our lawful basis and Section 9 for retention.
3.8 The website (scripturealone.net)
The website is self-hosted. Apart from the embedded podcast player described below, it uses no analytics, no advertising trackers, and no third-party cookies on our own pages, and serves its own fonts.
Information you submit through the website is provided directly by you through our web pages, not collected from the Discord platform. Even where a form asks for your Discord tag or user ID, you are typing that in yourself; at that point our website is acting as a separate service, independent of Discord, and Discord is not involved in — or responsible for — what you submit here. This is distinct from the Discord-side records described in Section 3.6.
- Web server logs. Ordinary access logs record your IP address, browser/user-agent, pages requested, and timestamps, used to run and secure the site.
- Forms. The Apply, Ban Appeal, Mentorship, Moderation feedback, and Presenter pages carry forms that — although styled to match our site — submit to Google Forms. Submitting a form sends what you enter, together with network metadata such as your IP, to Google (see Section 5). We identify you by your Discord tag / user ID, not by email or phone. A submission can include your Discord tag and user ID, age, gender, timezone, church/denominational affiliation, answers to doctrinal questions, and free-text responses.
- Sensitive information in forms. Because these forms ask about religious beliefs, a submission necessarily includes special-category data; the mentor application also asks your gender and doctrinal views, which we treat as additional sensitive information. You provide these voluntarily to apply; see our lawful basis in Section 4. Provide only what you are comfortable sharing.
- Donations use a PayPal link; see Section 5 for the donor data we receive. We never receive your card or bank credentials.
- Merchandise is sold and fulfilled by a third-party Spreadshop store.
- Scripture Alone Radio (self-hosted) logs listener connection data such as IP address and the stream requested, to deliver audio and count listeners.
- Embedded podcast player. Our Podcast page embeds a Spotify player. When that page loads, your browser connects directly to Spotify to display it, which lets Spotify receive your IP address and device/browser information and set its own cookies in the player, under Spotify's own privacy policy (see Section 5). The Apple Podcasts, YouTube, Amazon Music, and Podchaser buttons on that page are ordinary outbound links and send nothing until you click them.
3.9 The audio (music) bots
The audio bots are private, staff-controlled utilities that stream audio into listen-only voice channels. Their data handling is deliberately minimal:
- No Message Content Intent. We do not request Discord's privileged Message Content Intent, so the bots cannot read ordinary, non-addressed messages. Staff control them with @mention commands in a restricted staff channel; to parse such a command the bot necessarily processes the content of that directly addressed message, which Discord permits without the privileged intent. We do not retain those command messages except as they may appear in routine operational logs (below).
- Minimal persistent storage. On the bot host, each bot persists only per-server playback settings (e.g. repeat mode, keyed by server ID), routine operational logs, and staff-curated playlists consisting strictly of public-domain media or authorized, self-generated content designated solely for internal bot playback. It keeps no user database and no message archive. Operational logs may record limited operational detail — such as the command processed, the requesting user, and errors — used only for debugging and kept only for the operational-log retention period (Section 9). Nothing is sent to third parties except the audio-source lookups in Section 5.
- Transient member cache. Via the Server Members Intent, the underlying library keeps an in-memory cache of the server's members and their roles, used to confirm that the person issuing a command holds a permitted staff role. This cache is held in memory only and is not written to disk (see Section 3.10).
- No audio recording. The bots play outbound audio only; they do not record or store anything spoken or played in voice channels.
- Private, not public. Each bot has Discord's "Public Bot" setting disabled and runs only in our server; it cannot be added elsewhere, and is not available for purchase or commercial use.
3.10 Discord Gateway Intents
Discord "privileged intents" control what a bot may receive. For transparency and to match the intent requests we file with Discord:
- The audio bots request the Server Members Intent as their only privileged intent, and rely on the guild-member cache to resolve the invoking user's roles for permission checks; without it the software will not start. They do not request the Message Content Intent and cannot read ordinary message content.
- Catherine requests the Message Content Intent, because moderation and word-filtering must inspect message text (Sections 3.2–3.6), and the Server Members Intent for member-dependent moderation (role automation, join/leave handling, and acting on non-invoking members).
4. Lawful bases for processing
Where the GDPR or UK GDPR applies (for example, to users in the EEA or UK), we rely on the following Article 6 bases, and — for sensitive data — the following Article 9 conditions. US state privacy laws may treat religious beliefs and similar data as "sensitive" and require opt-in consent even where a nonprofit is otherwise exempt.
| Processing | Article 6 basis | Article 9 (special-category data) |
|---|---|---|
| Moderation, anti-abuse, and safety logging; web/radio security logs; the member cache used for permission checks; engagement records | Legitimate interests (Art 6(1)(f) — operating a safe community), balanced against your rights | Not deliberately collected; any incidental special-category content is minimized (see the note below) |
| Running a feature you request (commands, games, translation, audio, the technical transmission of a form) | Contractual necessity (Art 6(1)(b)) — necessary to provide the feature you asked for | — |
| Reviewing, evaluating, deciding, and retaining applications (Apply / Mentorship / Presenter) — ordinary fields such as Discord ID, age, timezone, and non-special-category written answers | Legitimate interests (Art 6(1)(f) — assessing and selecting volunteers/mentors) | Special-category answers are covered by the explicit-consent rows below or the incidental-data note |
| Religious-belief and doctrinal answers in the Apply / Mentorship / Presenter forms | Consent | Explicit consent (Art 9(2)(a)) |
| Gender data (mentor form) | Consent | Not for gender alone. If an answer reveals another Article 9 category (e.g. sexual orientation or health), Art 9(2)(a) applies only where the separate explicit-consent control specifically covers that category; otherwise we minimize, redact, or delete it under the incidental-data note below |
| Ban-appeal and moderation-feedback form responses | Legitimate interests (handling appeals and feedback) | — |
| Self-harm / mental-health ticket content | Consent; and vital interests in an emergency | Explicit consent (Art 9(2)(a)); vital interests (Art 9(2)(c)) only where a person is incapable of giving consent and at imminent risk |
| Donation and accounting records | Legitimate interests (and legal obligation where a law that applies to us requires it) | — |
| Legal demands and legal claims | Legal obligation (Art 6(1)(c)) for a compulsory demand recognised under applicable law; legitimate interests (Art 6(1)(f)) to establish or defend legal claims | Art 9(2)(f) where sensitive data is involved in a legal claim |
Notes on the sensitive-data bases:
- Where we rely on explicit consent for sensitive data, withdrawal stops further processing (without affecting what was already done); we do not fall back to another Article 9 condition if you withdraw. You may decline to provide it, though we may then be unable to process that application.
- We rely on the religious-nonprofit condition (Art 9(2)(d)) only where its conditions are met — a qualifying nonprofit, our legitimate activities, our members or regular contacts, appropriate safeguards, and no disclosure outside the organisation without your consent — and not as an automatic substitute for consent.
- We do not use consent as the basis for unavoidable moderation, because server participation would make that consent not freely given.
- Our filtering, moderation, tickets, appeals, feedback, and application free-text responses may incidentally encounter special-category data (e.g. religious or health statements) that we did not solicit. Our default is to minimize, redact, or delete such content rather than rely on it, and we do not use it for profiling. Where a specific situation genuinely requires processing it, we identify and rely on the Article 9 condition applicable at that time (for example, your explicit consent, or Art 9(2)(f) for a genuine legal claim); we treat no single condition as a universal basis, and where none applies we remove the content.
5. Third-party recipients
Some features send data to outside parties. The table shows each recipient, its role, and what is sent; each recipient's own privacy policy (on its website) governs its own processing. "Independent controller" means that party decides its own purposes; "processor" means it processes on our behalf under our instructions and a processing agreement.
| Recipient | Role | Data sent | Purpose / notes |
|---|---|---|---|
| Discord (Discord Inc., US) | Independent controller (platform) | Bot interactions and any records we keep in Discord channels | Platform operation. Only Discord-based activity transits Discord — donations, merch, and website forms do not. |
| OpenAI (US) | Processor | Image/avatar URLs (image moderation); forum query text (forum search) | Content moderation; semantic search |
| DeepL (Germany/EU) | Processor | The text you submit to translate | On-demand translation |
| Google (Google Forms/Sheets, US) | Processor for the form content we collect under our account; independent controller for Google's own service/security processing | Form submissions (see 3.8) plus network metadata (e.g. IP) | Receiving applications, appeals, feedback |
| PayPal (US) | Independent controller | Payment data you give PayPal | Donations. PayPal typically shares donor name, email, amount, and transaction ID with us; we keep these for accounting/tax. We never receive your card/bank credentials. |
| Spreadshop / Spreadshirt (US/EU) | Independent controller | Your order, shipping, and payment details | Merch sales/fulfilment (handled by Spreadshop) |
| Giphy (US) | Independent controller | Your GIF search terms | GIF features |
| Audio sources (e.g. YouTube, SoundCloud, Bandcamp) | Independent controllers | The song/search you request | Audio lookup for the music bots |
| Spotify (US/EU) | Independent controller | Your IP address and device/browser information when the Podcast page loads its embedded player, plus any cookies Spotify sets in the player | Embedded podcast player on our Podcast page; governed by Spotify's own privacy policy |
For our processors (OpenAI, DeepL, and Google as to the form content it stores for us), retention and deletion follow our instructions and processing agreement, and their held data is included in our response to a valid rights request. For independent controllers, their own policies govern.
We do not sell personal data and do not "share" it for cross-context behavioral advertising (as those terms are used under US state laws). We disclose data only (a) to the recipients above to provide the feature you used; (b) to our staff, who see moderation records and logs for their roles; and (c) where required by law or to prevent serious harm (Section 3.7).
6. Automated moderation and your safeguards
Two features act automatically:
- Image moderation: flagged images/avatars may be deleted, and the action logged to staff; repeat or severe cases may lead to staff moderation. Results are reviewable by staff.
- Anti-nuke: may automatically limit administrative actions that look like an attack.
These do not make decisions producing legal or similarly significant effects without the possibility of human involvement. If you believe an automated action was wrong (a false positive), you may request human review and appeal via our contact form at scripturealone.net/contact or a #modmail ticket.
7. International data transfers
We operate in the United States, and several providers (Discord, Google, OpenAI, PayPal, Giphy, Spotify) host data in the US; DeepL processes within the EU. If you are in the EEA or UK, your data may be transferred to the US. Where GDPR/UK GDPR applies, we rely on an appropriate safeguard for each recipient — for most US providers this is Standard Contractual Clauses (with the UK Addendum) and/or the provider's EU–US Data Privacy Framework certification. Ask us via our contact form at scripturealone.net/contact for current details.
8. Where your data is stored
- On our bot host: Catherine's local databases and configuration files, and local logs. Not copied to any cloud database we run.
- In Discord staff channels: ticket transcripts, moderation-reason records, staff-audit and server-event logs, and reconstructable voice history (Section 3.6). These live in Discord.
- In Google: website form submissions, in Google Forms / Google Sheets under our Google account.
- On the audio-bot hosts: per-server playback settings, staff-created playlists, and routine operational logs (which may include a processed command and the requesting user; no message archive).
- With providers: whatever each recipient in Section 5 holds — for processors under our instructions and agreement, for independent controllers under their own policies.
- Backups: operational backups may retain copies for a limited period after deletion from the live system.
9. How long we keep data
We keep data only as long as needed for the purpose, then delete or de-identify it, according to the following schedule.
| Category | Retention |
|---|---|
| Web-server, radio, and bot operational logs | Up to 30–90 days |
| Voice-activity and engagement history | Up to 12 months |
| Unsuccessful application / appeal responses | Decision + up to 6 months |
| Approved applications and accepted-applicant data (incl. religious, doctrinal, gender, age) | Duration of the mentor/presenter relationship + up to 12 months, then deleted or de-identified |
| Successful ban appeals | Resolution + up to 6 months |
| Moderation-feedback and other non-application form responses | Up to 12 months |
| Ticket transcripts (incl. self-harm) | A short fixed period after closure (e.g. 30–90 days), minimized |
| Ordinary moderation records | Duration of membership + up to 12 months |
| Ban-enforcement data | Minimal (user ID + reason) while the ban is in force |
| Economy, game, badge, and account state | Until you leave the server or request deletion, or the feature is reset |
| Audio-bot playback settings and playlists | Until changed or the server is removed |
| Donation / accounting records | As required by applicable tax/accounting law |
| Provider API inputs/outputs (OpenAI, DeepL) | Per our configured provider retention settings |
| Backups | Rotating schedule; deleted copies expire with the backup cycle |
The safety exception is narrow: an active ban may require keeping a user ID and a minimal reason; it does not justify keeping every historical message, voice event, or ticket indefinitely.
10. Your rights
Subject to applicable law, you may request to: access your data; correct it; delete it; restrict or object to processing; obtain portability; and withdraw consent where we rely on it (without affecting prior processing). We do not discriminate against you for exercising these rights. Where the GDPR/UK GDPR applies, you may also complain to your supervisory authority (in the UK, the ICO). US state-law residents may have equivalent rights and may use an authorized agent.
How to make a request. Use our contact form at scripturealone.net/contact. Because much of the data is Discord-based, include your Discord user ID. We will verify your identity proportionately (for example, confirming control of the Discord account), respond within the timeframe applicable law requires, and tell you if an exception applies. If we deny a request, you may appeal by replying to our decision at the same contact; where a US state law grants an appeal right, we will follow its process and tell you how to escalate (for example, to a state Attorney General) if we still cannot grant it.
What deletion can and cannot reach. We can delete data in Catherine's databases, records we hold in Discord staff channels, and your Google Forms responses. For our processors (OpenAI, DeepL, Google as to form content), we instruct deletion or return and include their held data in our response. Independent controllers (Discord, PayPal, Spreadshop, Giphy) delete under their own policies. Backups expire on their own cycle, and we may retain or de-identify minimal records where we have a legal obligation or an overriding safety reason (Section 9). We will not delete records in a way that would improperly expose or remove another person's data or staff-confidential material.
11. Children and young people
Discord requires users to be at least 13 (older in some countries). Our services are not directed to children under 13, and we do not intend to collect their data; because bots process activity in active channels, we cannot guarantee we never encounter it, and we will delete under-13 personal data we become aware of. Our forms collect age, gender, and religious beliefs and may be completed by users aged 13–17; we minimize and restrict access to such data, and — where required — will seek guardian involvement. If you believe a child's data has been submitted, contact us through our contact form at scripturealone.net/contact.
12. Security and breach handling
We store data on access-controlled hosting; administrative access uses key-based authentication, and service credentials (API keys, bot tokens) are kept in environment configuration, not in the bots' source. Access to sensitive forms and crisis transcripts is limited to designated staff. No system is perfectly secure and we cannot guarantee absolute security, but we take reasonable measures. If a personal-data breach occurs, we will investigate and notify affected users, regulators, or others where required by law.
13. Changes to this policy
We may update this policy. Changes apply prospectively after we post the updated version and effective date, and we will announce material changes in the community server. Where a change requires it, we will seek fresh consent rather than treating continued use as consent to new sensitive processing.
14. Contact and complaints
Privacy questions, data-rights requests, or complaints: use our contact form at scripturealone.net/contact. You may also contact your data-protection supervisory authority where one applies.