Vellum Privacy Policy
Effective: 12 June 2026 · Contact: privacy@vellumbot.xyz
Vellum ("we", "us") is a Discord bot and web dashboard for managing Discord communities and ER:LC (Emergency Response: Liberty County) private servers, operated from Norway. This policy explains what we collect, why, how long we keep it, and your rights. We've kept it in plain language on purpose — if anything is unclear, email us.
Vellum is an independent third-party tool. It is not made by or affiliated with Police Roleplay Community (PRC), Roblox, or Discord.
1. What we collect, and why
| Data | Why we have it | Where it comes from |
|---|---|---|
| Discord server (guild) IDs, channel/role IDs, and your module settings | To run the features you configure | You, via the bot and dashboard |
| Your Discord user ID, username, and avatar | Sign-in and showing who did what | Discord OAuth when you log in |
| Discord ↔ Roblox account links | Verification: connecting your Discord identity to your Roblox identity | You, when you verify (Roblox OAuth or profile code) |
| ER:LC server data: player lists, join/leave logs, kill logs, command logs, mod calls, emergency calls | Live panels, maps, logs, shifts, and automations for your server | The PRC API, using the server-key a server owner provides |
| Moderation records (warnings, kicks, bans, notes) and shift records | The core record-keeping your staff team uses Vellum for | Created by your server's staff |
| Audit log (who changed which setting, when) | Accountability for server admins | Generated by Vellum |
| Automation flows and their run logs | So you can build and debug automations | You |
| Technical logs and error reports | Keeping Vellum reliable | Generated automatically; scrubbed of secrets |
We deliberately do not: read or store Discord message content beyond what a feature you enabled shows (e.g. a logging module posts an edit log — we store what we posted, nothing more); sell or share data for advertising; or collect anything "just in case."
ER:LC server-keys are encrypted (AES-256-GCM, envelope encryption) the moment they reach us, are never shown again, never logged, and never sent to your browser.
2. Legal bases (GDPR)
- Performance of a contract — running the features you and your server set up (Art. 6(1)(b)).
- Legitimate interest — security, abuse prevention, reliability logging (Art. 6(1)(f)).
- Consent — linking your Roblox account; you can withdraw it anytime by unlinking (Art. 6(1)(a)).
3. How long we keep things
- Server settings & records (moderation, shifts): as long as the server uses Vellum, or shorter if the server configures its own retention.
- If Vellum is removed from a server: data collection stops immediately, the server-key is deleted immediately, and all of that server's data is deleted after a 30-day grace window (so an accidental kick isn't catastrophic).
- ER:LC live data: raw snapshots are kept briefly (days); longer-term aggregates follow the server's plan.
- Verification links: until you unlink or ask us to delete.
- Backups: encrypted, rotated out within 30 days.
4. Your rights
You can, at any time:
- See and export your data (self-serve from the dashboard, or by email);
- Unlink your Roblox account;
- Ask us to delete your data — we'll anonymize your identity in server records (servers keep the fact that "a moderation action happened"; your identity is removed where the law allows);
- Correct inaccurate data, object to processing, and complain to a supervisory authority — in Norway, that's Datatilsynet.
Server owners can export their entire server's data at any time. No lock-in is a product principle, not just a legal one.
5. Who else touches the data (processors)
We self-host Vellum's core on our own infrastructure in Norway. Supporting services:
| Service | Used for |
|---|---|
| Cloudflare | Networking/CDN in front of our services; encrypted backups (R2) |
| Vercel | Hosting the web dashboard |
| Discord | The platform itself (their privacy policy) |
| Roblox | Verification lookups (their privacy policy) |
| PRC API | ER:LC server data, fetched with your server's key |
| Sentry | Error reporting (scrubbed of personal data and secrets) |
Where processors are outside the EEA, transfers rely on standard contractual clauses or equivalent safeguards.
6. Security
TLS everywhere; secrets and server-keys encrypted at rest; access limited to the operator; no inbound ports on our origin (tunnel-only); audit logging. If a breach affects you, we will notify affected users and servers and the relevant authorities without undue delay (and within 72 hours where GDPR requires), and we notify PRC where their data is involved.
7. Age
Vellum is for users who meet Discord's minimum age (13, or higher where local law says so). We do not knowingly collect data from children below that age.
8. Changes
We'll announce material changes in our Discord server and on the dashboard before they take effect, with the effective date updated above.