Sigil Join the server

Sigil is a Discord bot that makes QR codes. This page explains what Sigil keeps, why it keeps it, how long it keeps it, and how you get rid of it. It is written to be read, not to be skimmed past.

Sigil is operated by HappyDale Holding LLC, a Delaware limited liability company in the United States. In this policy, “we” and “Sigil” mean that company, and “you” means the person using the bot or visiting sigilbot.io.

The short version

  • We store your Discord user ID. We do not store your name or your email address.
  • We store the link you ask us to turn into a QR code, and the time you made it.
  • Free codes are wiped within 24 hours. Pro keeps your last 50.
  • Pro users can upload a logo. We convert it to a clean image and throw the original file away.
  • We never sell your data. There is no advertising in Sigil.
  • Type /sigil forget and everything we hold about you is deleted right then.

The rest of this page is the detail behind those lines.

What we collect, and why

Your Discord user ID. This is the long number Discord assigns to your account. It is not your username and it is not your email. We use it for two things: to know whether you are a Pro subscriber, and to count how many codes you have made recently so one person cannot flood the bot. Without it we would have no way to tell your Pro codes from someone else’s.

The destination you type in. When you set a link for your QR code, we hold that link so the bot can build the code, decode it, and check that the decoded result matches what you asked for byte for byte. That check is the whole point of Sigil, and it needs the original text to compare against.

A logo image, for Pro users only. If you upload a logo, we take it from Discord’s own file servers, check that it is a PNG or a JPEG, check its size and dimensions, and then re-encode it into fresh pixels. Re-encoding means we rebuild the picture from scratch, which strips out everything hidden in the file that is not the picture itself: camera model, GPS coordinates, editing history, colour profiles, anything else tucked into the metadata. The file you uploaded is discarded once the clean version exists. We keep only the cleaned image, and only so your future codes can be branded without you re-uploading it.

Timestamps. We record when a code was generated. This is how retention windows and rate limits work. A record with no time on it cannot be expired on schedule.

Your Pro settings. If you are a subscriber, we store the choices in your brand kit: which colour pair from the board, which module style, whether a frame caption is on. These are your preferences, not personal details.

What we do not collect

  • No message content. Sigil does not read your Discord messages. The /qr panel is a private form. What we see is what you type into that form and nothing else in the server.
  • No email addresses and no names. We never ask for them and Discord does not hand them to us.
  • No payment card data. If you subscribe to Pro, the card details go to a payment processor. They hold that information. We do not see your card number, and we do not store it.
  • No location data, no device fingerprinting, no tracking across other sites.
  • No scanning of your QR codes after the fact. Once a code is posted, whoever scans it goes straight to your link. That traffic never touches us, and we have no idea how many people scanned it.

How long we keep things

WhatHow long
Free-tier QR destinationsAt most 24 hours, then deleted automatically
Pro generation historyThe most recent 50 codes; older entries drop off as new ones arrive
Pro brand kit and cleaned logoFor as long as your subscription is active
Your original uploaded logo fileDiscarded as soon as the re-encoded version exists
Your Discord user IDFor as long as you use Sigil, or until you run /sigil forget

If a Pro subscription lapses, your brand kit, logo, and history are frozen for 60 days. Frozen means we stop using them and you cannot access them, but we have not erased them yet. That window exists so a failed card or a change of mind does not cost you your setup. After 60 days, that data is deleted. If you would rather not wait, run /sigil forget and it goes immediately.

Backups are the one honest exception to any deletion. If a copy of the database exists in a routine backup, your data may sit in that backup until it rotates out on its normal schedule. It is not restored into the live service, and it is not used for anything.

Deleting everything

Type /sigil forget in Discord.

That command removes everything Sigil holds tied to your Discord user ID: your ID record, your stored destinations, your history, your brand kit, and your cleaned logo. It happens immediately, not on a queue and not after a review. There is no confirmation email because we have no email address for you. There is no undo, so use it deliberately.

If you delete your data while Pro is active, your subscription itself is handled separately through the payment processor. Deleting your Sigil data does not cancel a recurring charge, so cancel the subscription too.

Other companies involved

Discord. Sigil lives inside Discord and cannot work without it. Discord operates the servers where you type commands, the file storage your logo comes from, and the account system that gives you a user ID. Your use of Discord is governed by Discord’s own privacy policy, which we do not control.

A payment processor. If, and only if, you subscribe to Sigil Pro, a payment company handles the transaction. They collect and hold your card details under their own privacy policy. We receive confirmation that a subscription is active and tie it to your Discord user ID. We do not receive your card number. We have not finalised which processor we use, and this page will name them once we do.

Hosting. Sigil runs on rented server infrastructure in the European Union. Our hosting provider stores the data on our behalf and does not use it for anything of its own.

That is the complete list. There is no analytics vendor, no advertising network, and no data broker in the chain.

We do not sell your data

We do not sell it, rent it, trade it, or hand it to anyone for marketing. Not now, and not later under a new name for the same thing. Sigil makes money one way: people pay $1.99 a month for Pro. That is the entire business model, which is exactly why we can say this plainly.

We would disclose data only if we were legally required to, for example by a valid court order. Given that the most sensitive thing we hold is a Discord user ID and a link, there is very little there to disclose.

There is no advertising inside Sigil and there never will be while it is a paid product.

Cookies on sigilbot.io

The sigilbot.io website is a static marketing site. It sets no cookies. There is no analytics script, no tag manager, no pixel, and no consent banner, because there is nothing to consent to.

Our host records ordinary server logs, such as an IP address and the page requested, for a short period. That is a normal part of serving a website and keeping it up.

If we ever add analytics, we will pick something privacy-respecting, update this page before it goes live, and say clearly what it collects.

Children

Sigil follows Discord’s rules. Discord requires users to be at least 13, or older where local law sets a higher minimum. If you are not old enough to use Discord, you are not old enough to use Sigil.

We do not knowingly collect data from children below that age. If you believe a child has used Sigil, contact us through the support server and we will delete the associated records.

Your rights

Depending on where you live, you may have formal rights over your data under laws such as the GDPR in Europe and the UK, or the CCPA and CPRA in California. In plain terms:

  • See what we hold. You can ask for a copy of your data.
  • Fix it. If something is wrong, you can ask us to correct it.
  • Delete it. Run /sigil forget. That is the full deletion, self-service, immediate.
  • Take it with you. You can ask for your data in a portable form.
  • Object or restrict. You can ask us to stop a particular use of your data.
  • Do not sell or share. We do not sell or share your data, so there is nothing here to opt out of. If that ever changed, this page would change first.
  • No retaliation. Exercising any of these rights costs you nothing and does not degrade the service.

How to exercise them: ask in our support server on Discord. We answer within 30 days, and usually much faster. Because we identify you only by Discord user ID, the request has to come from that Discord account. That is how we confirm the data is actually yours before handing it over or acting on it.

Our legal basis for processing, in GDPR terms: we hold your Discord user ID and your inputs because they are necessary to perform the service you asked for, and we apply rate limits under our legitimate interest in keeping the bot available to everyone.

Where your data lives

Sigil’s servers are in the European Union. Sigil is operated by a US company, so authorised people in the United States can access the systems to run and maintain them. Discord and any payment processor operate their own infrastructure across multiple countries under their own terms.

Security, honestly

Here is what we actually do, without the marketing language.

Uploads are restricted to PNG and JPEG. SVG files are refused outright, because an SVG can carry executable code and an image should not be able to run anything. Files are fetched only from Discord’s own content servers, so the bot never follows a link to some arbitrary address. Size and dimensions are capped. Every accepted image is re-encoded into fresh pixels with all metadata stripped, so nothing rides along inside the file.

Image rendering happens in a separate, resource-capped process, isolated from the bot itself. If a malformed file causes trouble, the trouble is contained in a process that can be killed, and it cannot reach into the rest of the system.

We store as little as we can, and we delete on a timer rather than keeping things because they might be useful someday. Data you do not hold cannot leak.

What we will not claim: we are not certified to any security standard, we do not employ a security team, and no system is unbreakable. If a breach ever affected your data, we would tell affected users through the support server and by any means the law requires, and we would say what happened rather than issue a vague notice.

Changes to this policy

If we change how Sigil handles data, we update this page and move the “Last updated” date at the top. Meaningful changes get an announcement in the support server before they take effect, not after. We will not quietly broaden what we collect and leave you to spot the diff.

Contact

Questions, requests, or anything about this policy: reach us in the official Sigil Discord server at https://discord.gg/KXJTS8U9yq.

Sigil is operated by HappyDale Holding LLC, a Delaware limited liability company.