Hex Discord Bot · Data Practices

Privacy Policy

This Privacy Policy explains what information Hex processes, what it stores, why it uses that information, and what happens when features such as server statistics, weather, media handling, and voice transcription are used.

Effective: August 25, 2026 Service: Hex Discord Bot Scope: Bot data practices
Short version: Hex processes Discord data needed to perform enabled features. Its statistics system stores aggregate counters rather than message bodies. Voice-note transcription sends temporary audio to the configured transcription provider.

Contents

1. Scope

This Privacy Policy describes information processed by the Hex Discord bot and the C420.org Hex website/documentation. Discord and third-party providers have separate privacy practices for information they control.

2. Information Hex processes

Depending on which features are enabled or used, Hex may process:

  • Discord identifiers and names: guild/server IDs and names, channel IDs/names, user IDs/display names, message IDs, and permission/context information needed to run commands and features;
  • Message text temporarily: to detect supported URLs, count aggregate text statistics, route automatic features, or respond to commands;
  • Weather inputs: cities, postal codes, coordinates, or other location strings supplied to weather commands;
  • Links and public-media URLs: URLs needed for supported social-link rewriting, YouTube summaries, RSS subscriptions, deal sources, or Reddit/TikTok processing;
  • Voice-note audio: temporary copies of native Discord voice notes when transcription is enabled;
  • YouTube caption text: available caption/transcript text used to create a requested/automatic summary;
  • Deal submissions: title, price/offer, merchant/details, supporting URLs, expiration, submitter ID/name, guild/channel context, and generated deal-card files;
  • RSS subscriptions: feed URL, resolved URL, target channel, submitter ID/name, feed title/link, polling state, ETag/Last-Modified metadata, errors, and hashes of seen item identifiers;
  • Feedback submissions: title/message/category, source guild ID/name, source channel ID, submitter Discord ID/name, timestamps, workflow status, and optional administrator notes;
  • Aggregate statistics: counters and date/time buckets described below; and
  • Operational information: error details and technical logs reasonably needed to run/troubleshoot Hex.

3. How information is used

Hex uses information to provide enabled/requested functions, including weather, strain lookups, social/media processing, voice transcription, YouTube summaries, activity statistics, network leaderboards, deals, RSS broadcasts, feedback administration, per-server settings, troubleshooting, security, abuse prevention, and compliance with applicable legal obligations.

4. Server statistics and network leaderboards

Hex's statistics database is designed to store aggregate counters rather than a searchable message archive. Counters can include messages, non-empty lines, words, characters, attachments, links, mentions, replies, active days, activity by member/channel, and daily trends.

To associate counters with the correct server/user/channel, Hex stores Discord guild IDs, user IDs, channel IDs, latest known names, and date/time buckets.

Hex does not intentionally store message bodies, raw URL values, or attachment contents in its statistics database. Message text is inspected long enough to calculate the relevant counters.

Participating-server leaderboards can expose server names and aggregate activity totals/rankings to other users of Hex. The public participating-server list does not intentionally publish guild IDs or invite links. Server managers can opt out of network statistics while retaining local statistics.

5. Voice-note transcription

When enabled, Hex temporarily downloads a native Discord voice note, converts it locally to a compact audio format, and sends the converted audio to the configured OpenAI transcription endpoint so text can be produced.

  • The original voice note remains in Discord.
  • Hex deletes its temporary local source/converted audio after the transcription attempt finishes.
  • The transcript posted to Discord is then governed by Discord/server message retention and deletion behavior.

6. YouTube caption summaries

For supported YouTube URLs, Hex may use yt-dlp to obtain video metadata and an available manual/automatic caption track. Caption text is cleaned and a bounded transcript is sent to the configured OpenAI Responses API to generate a summary.

  • Normal summaries use caption text and do not require downloading the full video/audio.
  • Temporary caption files are deleted after processing.
  • The summary is posted to Discord and follows Discord's retention/deletion behavior.

7. Weather and location queries

When a user runs a weather, forecast, or radar command, the user-supplied location is sent to Xweather/Vaisala to obtain the requested data. Input may be a city, postal code, or coordinates if the user chooses to provide them.

Hex does not intentionally use weather-location input to build a location history or advertising profile.

8. Links and media processing

Hex may inspect message text for supported social links, rewrite a URL, verify an embed, temporarily retrieve publicly accessible Reddit/TikTok media, upload a replacement file to Discord, and optionally remove the original Discord message after a successful reproducible replacement.

Temporary media files are cleaned up after processing. Successfully reposted media remains in Discord under Discord's policies. Source websites/link-preview providers may receive requests from the Hex server.

9. Community deals

Deal metadata is stored persistently per Discord server so members can browse/search submissions. Stored fields include the deal data, supporting URLs, submitter Discord ID/name, guild/channel IDs, timestamps, expiration, and status.

Hex also creates a 1200×630 PNG card locally from submitted deal information. It does not need an AI image-generation service or a copied product photo for the normal deal card.

Removed deals are currently soft-deleted in the database (status changed to removed); generated thumbnail files can be deleted when a deal is removed.

10. RSS / Atom subscriptions

RSS subscription records are stored persistently so Hex can poll and broadcast future unseen items. Records can include feed/source URLs, target Discord channel ID, submitter ID/name, feed title/link, enabled state, timestamps, ETag/Last-Modified response metadata, error state, and SHA-256 hashes of seen entry identifiers.

Hex fetches the public feed publisher to obtain new entries. Feed content is posted into the configured Discord channel and is then subject to Discord/server retention. The seen-item hash history exists to suppress duplicate broadcasts.

11. Cross-server feedback

Feedback from Hex servers is pooled into a central persistent inbox. Each submission stores the feedback title/message/category, source guild ID/name, source channel ID, submitter Discord ID/name, timestamps, workflow status, and optional private administrator note.

The central inbox is intended to be browsed only by authorized administrators in the configured Club420 administration guild. A submitter can use /feedback mine to see their own submission IDs/titles/status.

12. Per-server command and feature settings

Hex stores guild-specific command rules so server managers can enable/disable supported command groups independently. Cross-server-stat participation settings are also stored so opted-out servers can be excluded from network lists/leaderboards.

13. Third-party services

Hex currently relies on or interacts with services including:

  • Discord for messages, accounts, servers, attachments, embeds, and bot interactions;
  • OpenAI API for configured voice transcription and YouTube summarization;
  • Xweather / Vaisala for weather/forecast/radar;
  • YouTube for video metadata/captions used by the summary feature;
  • public strain-information sources for strain lookup; and
  • social-media, RSS publisher, source, and link-preview services used for enabled media/link/feed features.

Those third parties control their own systems and data practices.

14. Retention

  • Voice processing files: temporary local audio is deleted after each transcription attempt.
  • YouTube caption files: temporary caption files are deleted after summary processing.
  • Media-processing files: temporary downloads are cleaned up after handling; successfully reposted media remains in Discord.
  • Weather inputs: Hex does not intentionally maintain a persistent weather-location history.
  • Statistics: aggregate activity data is persistent; current historical counters do not automatically expire.
  • Deals: deal metadata persists; removed entries are currently retained with a removed status unless data is deleted administratively.
  • RSS: subscriptions/settings and bounded seen-item hashes persist until removed/reset.
  • Feedback: submissions/status/admin notes persist until permanently deleted.
  • Command/network settings: persist until changed, reset, or deleted.
  • Operational logs: may be retained according to the bot host/server configuration for troubleshooting/security.

15. Sharing and sale of data

Hex does not sell personal data or use it for targeted advertising. Information is disclosed to third-party services only as reasonably necessary to provide enabled/requested functionality, operate/protect the service, comply with law, or respond to valid legal process.

Some information is intentionally shared inside Discord as part of the feature: for example, RSS entries in the target channel, deal listings, server-stat leaderboards, YouTube summaries, transcripts, or other bot replies.

16. Security

Reasonable technical/operational measures are used to reduce unauthorized access, loss, or misuse. RSS URL fetching includes network-safety restrictions intended to block private/local destinations. However, no internet-connected bot, host, or third-party service can be guaranteed completely secure.

17. Your choices and server controls

  • You can choose not to invoke optional commands or submit deals/feeds/feedback.
  • Server managers can disable supported command groups/features.
  • Server managers can opt out of cross-server statistics while retaining local stats.
  • Users can remove their own deal/RSS submissions where Hex provides that command; moderators can have additional controls.
  • A server administrator can remove Hex from the server.

18. Access, correction, and deletion requests

To ask about information controlled by Hex or request deletion/correction of Hex-controlled data associated with you, contact Club 420 administrators. Verification of your Discord account may be required. Requests are handled subject to applicable law, technical feasibility, security, and legitimate recordkeeping needs.

Data stored by Discord or another third-party provider generally must be addressed through that provider.

19. Minors

Hex and Club 420 are intended for adults age 18 and older. We do not knowingly operate Hex as a service directed to children. If you believe a minor's information has been improperly submitted, contact the administrators.

20. International processing

Discord and third-party providers may process information in countries other than where a user lives. Their privacy policies describe their international-transfer practices.

21. Changes to this Policy

This Policy may be updated as Hex adds/removes features, changes providers or retention practices, or as legal obligations evolve. Material revisions will be reflected by updating the effective date at the top of this page.

22. Contact

Privacy questions or requests concerning Hex-controlled data can be directed to Club 420 administrators through the C420 Discord server or through a current contact method published on C420.org.