Data used with purpose.
This policy explains how DoxBot processes information through its Discord bot, website, League of Legends build dashboard, moderation tools, role tools, tickets, and related utilities. Effective July 23, 2026.
Who operates DoxBot
DoxBot is an independently operated service based in California, United States. It is not operated, sponsored, or endorsed by Discord or Riot Games. Privacy questions and requests can be sent to DoxToxLoL@gmail.com.
Information DoxBot processes
Discord information
- Discord user, server, channel, message, and role identifiers needed to respond to commands and maintain server configuration.
- Command names, command options, interaction identifiers, permission and role information, and limited account presentation data such as usernames or avatars when Discord supplies them.
- Moderation records, including the server, action, affected user, acting moderator, reason, time, mute role, and expiration where applicable.
- Role-management configuration, including autoroles, reaction-role mappings, staff roles, mute roles, ignored roles, and the channels or messages used for those features.
- Ticket information, including ticket owner, type, channel, status, messages included in a requested transcript, attachments or uploads submitted through a ticket, and transcript delivery records.
- Feature data voluntarily submitted or generated through configured utilities, which may include leveling totals and message counts, birthdays, VOD submissions, coaching metadata, recommendations, and matchmaking or queue preferences.
Riot and League of Legends information
- Public Riot identifiers for configured tracked accounts, including Riot IDs, regions, and internal identifiers required to retrieve supported data.
- Supported match-history fields used for analytics, such as champion, items, runes, spells, role, queue, patch, rank context, region, result, opponent, and timestamps.
- Curated player classifications and, where applicable, private Stage 5 verification records. Private verifier identifiers and coaching notes are not published.
Website and operational information
- Limited logs used for reliability, rate limiting, abuse prevention, and security, such as request time, route, response status, and sanitized error details.
- Aggregate dashboard-query details such as champion, role, rank range, patch, region, whether certain filters were used, result count, and response time. These analytics do not intentionally store IP addresses, browser identifiers, or selected player names.
How information is obtained
Information comes from Discord when a user or server administrator interacts with or configures the bot; from users who submit content; from Riot services through supported APIs; from configured public sources; and from DoxBot's hosting systems when they process requests. DoxBot does not use self-bots or request Discord account passwords, Riot passwords, bot tokens, or Riot API keys from users.
Why information is used
- Provide requested commands, build analytics, tickets, transcripts, moderation actions, role assignment, server configuration, leveling, VOD, coaching, and other enabled utilities.
- Check permissions and role hierarchy, prevent unauthorized moderation or role changes, enforce cooldowns and rate limits, and investigate abuse.
- Maintain records requested by server administrators, recover scheduled actions, diagnose failures, measure aggregate performance, and improve coverage and usability.
- Comply with applicable law and the requirements of Discord, Riot Games, and other service providers.
DoxBot does not sell personal information and does not use Discord or Riot API data to build advertising profiles.
When information is displayed or shared
Command responses and moderation or ticket records may be displayed to the requesting user, affected user, authorized server staff, configured log channels, or other server members when the command or server configuration calls for it. Ticket transcripts may be delivered to the ticket participant or an authorized log destination.
The public dashboard may display public Riot IDs, regions, player labels, approved portraits and credits, Stage 5 status, aggregate statistics, and limited contributing-game context. It does not publish Discord IDs, PUUIDs, private verification notes, API credentials, or raw Riot API payloads.
Information may be processed by service providers used to host the application, database, logs, and uploaded files; by Discord and Riot as needed to use their services; when a user or administrator directs a feature to send information to a destination; or when disclosure is legally required. Service providers are permitted to process information only for operating DoxBot. DoxBot does not otherwise share Discord API data with third parties.
Browser storage
The website stores a recent-search list and short-lived build-response cache in your browser. This information remains on that browser until it expires or is cleared through the dashboard or browser settings. Browser storage does not contain a Riot API key or Discord bot token.
Retention
- Raw Riot API payloads: up to 30 days.
- Normalized Riot match analytics: up to 24 months.
- Operational and security logs: up to 90 days.
- Short-lived ticket upload tokens: until expiration or use, subject to limited security records.
- Active mute records: while needed to carry out or recover the scheduled action.
- Server configuration, moderation cases, tickets, transcripts, role mappings, leveling records, and other Discord feature records: while the relevant feature or server relationship remains active and thereafter only while reasonably needed for administration, continuity, dispute handling, security, or legal obligations.
Information may be deleted earlier when it is no longer needed. DoxBot will delete or de-identify Discord API data when it is no longer necessary for an approved function, when Discord or the applicable user validly requests deletion, or when operation of DoxBot ends, unless retention is required by law. Backup copies may persist temporarily until overwritten through normal backup rotation.
Your choices and requests
You may ask for access, correction, or deletion of information associated with you where applicable. Server owners and authorized administrators may also request deletion of their server's configuration and operational records. Email DoxToxLoL@gmail.com with the Discord user/server ID or Riot ID involved and a description of the request. DoxBot may request reasonable verification and may need to coordinate with a server administrator. Requests are handled subject to applicable law, platform requirements, security needs, and the rights of others.
You can stop future Discord processing by no longer using commands, leaving a participating server, disabling optional features, or asking an authorized administrator to remove DoxBot. Removing the bot does not itself erase every historical moderation or ticket record; submit a deletion request when deletion is desired.
Security
DoxBot uses access controls, permission and role-hierarchy checks, HTTPS, server-side credentials, parameterized database access, rate limiting, and restricted administrative functions. No system is perfectly secure. Please report a suspected vulnerability privately to DoxToxLoL@gmail.com and do not include passwords, tokens, or API keys.
Children
DoxBot is not directed to children below the minimum age permitted to use Discord in their country. DoxBot does not knowingly collect information from anyone who is not permitted to use Discord. A parent or guardian who believes an ineligible child provided information may contact DoxBot to request deletion.
Third-party services and policy changes
Discord, Riot Games, hosting providers, and linked websites have their own privacy practices. DoxBot's policy does not replace theirs. This policy may be updated as features, laws, or platform requirements change. Material changes will be posted here with a revised effective date before they take effect when reasonably possible.
