Vellum Privacy Policy

Effective: 12 June 2026 · Contact: privacy@vellumbot.xyz

Vellum ("we", "us") is a Discord bot and web dashboard for managing Discord communities and ER:LC (Emergency Response: Liberty County) private servers, operated from Norway. This policy explains what we collect, why, how long we keep it, and your rights. We've kept it in plain language on purpose — if anything is unclear, email us.

Vellum is an independent third-party tool. It is not made by or affiliated with Police Roleplay Community (PRC), Roblox, or Discord.

1. What we collect, and why

DataWhy we have itWhere it comes from
Discord server (guild) IDs, channel/role IDs, and your module settingsTo run the features you configureYou, via the bot and dashboard
Your Discord user ID, username, and avatarSign-in and showing who did whatDiscord OAuth when you log in
Discord ↔ Roblox account linksVerification: connecting your Discord identity to your Roblox identityYou, when you verify (Roblox OAuth or profile code)
ER:LC server data: player lists, join/leave logs, kill logs, command logs, mod calls, emergency callsLive panels, maps, logs, shifts, and automations for your serverThe PRC API, using the server-key a server owner provides
Moderation records (warnings, kicks, bans, notes) and shift recordsThe core record-keeping your staff team uses Vellum forCreated by your server's staff
Audit log (who changed which setting, when)Accountability for server adminsGenerated by Vellum
Automation flows and their run logsSo you can build and debug automationsYou
Technical logs and error reportsKeeping Vellum reliableGenerated automatically; scrubbed of secrets

We deliberately do not: read or store Discord message content beyond what a feature you enabled shows (e.g. a logging module posts an edit log — we store what we posted, nothing more); sell or share data for advertising; or collect anything "just in case."

ER:LC server-keys are encrypted (AES-256-GCM, envelope encryption) the moment they reach us, are never shown again, never logged, and never sent to your browser.

2. Legal bases (GDPR)

3. How long we keep things

4. Your rights

You can, at any time:

Server owners can export their entire server's data at any time. No lock-in is a product principle, not just a legal one.

5. Who else touches the data (processors)

We self-host Vellum's core on our own infrastructure in Norway. Supporting services:

ServiceUsed for
CloudflareNetworking/CDN in front of our services; encrypted backups (R2)
VercelHosting the web dashboard
DiscordThe platform itself (their privacy policy)
RobloxVerification lookups (their privacy policy)
PRC APIER:LC server data, fetched with your server's key
SentryError reporting (scrubbed of personal data and secrets)

Where processors are outside the EEA, transfers rely on standard contractual clauses or equivalent safeguards.

6. Security

TLS everywhere; secrets and server-keys encrypted at rest; access limited to the operator; no inbound ports on our origin (tunnel-only); audit logging. If a breach affects you, we will notify affected users and servers and the relevant authorities without undue delay (and within 72 hours where GDPR requires), and we notify PRC where their data is involved.

7. Age

Vellum is for users who meet Discord's minimum age (13, or higher where local law says so). We do not knowingly collect data from children below that age.

8. Changes

We'll announce material changes in our Discord server and on the dashboard before they take effect, with the effective date updated above.