Privacy policy
What data Marin keeps, why, who can see it and how long it stays. No fine print.
Contents
Before we start
What this policy covers
This policy applies to everything Marin does:
- The Discord bot, in any server it's in.
- This website, including the docs and the privacy request center.
- The web dashboard and the web ticket view, where you sign in with your Discord account.
- The verification portal some servers use.
What it doesn't cover
What Discord does with your data is up to Discord and is explained in its privacy policy. It also doesn't cover each server's own rules or what other bots next to Marin do.
Who runs Marin
Marin is an independent project built and maintained by its creator. You can see who that is on the creator page. When this page says "we", it means whoever runs Marin.
We're not a big company and we don't pretend to be one. Marin is not affiliated with Discord, Roblox or the creators of The Strongest Battlegrounds.
Your server decides, Marin carries it out
Each server's staff choose which modules to turn on, how to set them up and which sanctions to apply. Marin does what the server configured and keeps what that requires.
So if you disagree with a ban, a warn or a rejected verification, talk to that server's staff first. We can delete your data, but we can't undo a decision another server made.
What we keep and why
This is the full table. If something isn't listed here, Marin doesn't keep it.
| Data | Where it comes from | What for | Required? |
|---|---|---|---|
| Discord IDs: yours, the server's, channels and roles | Discord, when you use a command or a module acts on you | Knowing whose profile, case or ticket is whose | Yes. Marin can't work without IDs |
| Server settings | Staff, from /setup or the web dashboard | Making Marin do what the server chose | Yes, for each active module |
| Player profile: name, Roblox username and ID, region, record and phase | You or staff, when the profile is created or edited | Leaderboard, score, ranking and challenges | Only if you have a profile |
| Results, phases and spots | Staff, with /score, /phase, /addspot and similar | Boards and set and phase history | Part of those modules |
| Moderation cases, temporary bans and blacklist | Staff, or the automatic limits the server set up | History, lifting bans when they expire and giving roles back | Only if the server uses moderation |
| Tickets, transcripts and applications | You, when you open a ticket or apply | Letting staff help you and keeping a record | Only if you use them |
| Verification data | The verification portal, when you submit it | Helping staff catch alt accounts | Only if you verify |
| Questions to the assistant and recent channel messages | You, when you use >ask or an AI ticket; the channel, if the AI is on | Letting the assistant answer with context | Only if the server turns on the AI |
| Security data | Discord's audit log, joins and role changes | Stopping attacks and restoring the server | Only with Marin Security |
| Your web session | Discord, when you sign in to the dashboard or the ticket view | Knowing who you are and which servers you can manage | Only if you sign in |
| Privacy requests | You, from the request center | Handling them and keeping a record that we did | Only if you make one |
Profiles and Roblox
When you create a profile or someone uses /scan or /headshot, Marin asks Roblox's public API about that user and gets back their ID, display name, public bio, creation date and avatar. /scan also asks how many public friends and groups the account has, and whether Roblox marked it as verified or banned, to show the account signals. That answer stays in memory only, for 10 minutes, so the lookup isn't repeated; what /scan shows is not saved.
We will never ask for your Roblox password. If the server requires proof that the account is yours, you do it by putting a phrase in your Roblox bio, nothing else.
Deleted messages and >snipe
When someone deletes or edits a message, Marin keeps a copy in memory for 10 minutes: author, channel, the text before and after, and the time. For the first 2 minutes anyone in that server can see it with >snipe. None of this is written to the database; when the bot restarts, it's gone.
Marin Security
In servers with Marin Security, Marin keeps a backup of the server's structure so it can be restored after an attack: name and icons, roles, channels and permissions, AutoMod rules, events, emojis and stickers, webhooks (without their tokens), invites, the ban list with reasons and, for each member, their nickname, roles and whether they're timed out.
There's a single backup per server and it's replaced with every copy. Incidents (who did what and which punishment was applied) are also recorded for 30 days, and role changes for 90 days.
There's only one list shared across servers: bots that took part in a raid or a nuke. It only includes bot accounts, never people.
Messages and the AI assistant
What happens when a server turns on the AI
This is the most sensitive thing Marin does, so let's get straight to it.
If an administrator turns on the assistant (>ask), Marin starts saving the messages people write in the channels it can read. For each message it keeps the author's display name at that moment (not their ID), the text and the date. Bot messages and AI ticket channels are left out.
Each question to the assistant goes with the channel's last 12 messages, and the assistant can search them if someone asks about a recent conversation. These messages delete themselves after 7 days. If the server turns the assistant off, Marin stops saving messages within a minute.
What else the assistant keeps
- The conversation, for 2 hours, so you can reply to Marin and keep talking. If there were images, a small, lower-quality copy is kept. Videos, audio and voice messages aren't kept: only a note that they were there.
- Server notes the assistant decides to save (a recurring problem, a decision), for 30 days and up to 500 per server. It only uses them with people who could see the channel they came from.
- A usage log for 90 days: date, server, the first 140 characters of the question and whether there were errors. Your ID isn't stored there; an encrypted code is kept instead.
- The web dashboard assistant keeps the last 30 messages of your conversation. Images you attach aren't stored.
- If someone keeps trying to get around the assistant's rules, they're locked out for 24 hours. And if someone uses it to harass people, we can tell it to ignore that person; that instruction stays until we remove it.
What gets sent to Google
The assistant runs on Google's Gemini API. To answer, Marin sends it your question, the images, GIFs, videos, audio and voice messages you attach or link (up to 4 per message), the channel's recent messages and the server data the assistant looks up (channels, roles, profiles, leaderboard). In an AI ticket, the ticket conversation is sent. Application summaries are only sent if the server turned them on; they're off by default.
A GIF is sent as a few separate images. Videos and audio over 14 MB are uploaded to Gemini's file service just for that answer, and Marin deletes them as soon as it's done; if that deletion failed, Google removes them on its own after 48 hours. Smaller ones travel inside the same request and aren't kept on Google as a file.
Depending on the service tier, the Gemini terms allow Google to use what's sent to improve its products, including human review.
Bottom line: don't tell the assistant anything you wouldn't want someone else to read.
Images and GIFs Marin makes
If you ask Marin to put text on an image or turn it into a GIF, the editing happens on our own server, not at Google. Gemini only reads your request to understand what you want. The result is posted in the channel as a normal Discord file and we don't keep another copy.
If you then reply to that image to ask for another change, it's sent to Gemini like any attached image. Only edit images you have the right to use, and don't use them to impersonate someone or to mock anyone.
What the AI isn't
The assistant makes mistakes. It can make things up or misread a question. Don't use its answers as medical, legal or financial advice, and don't treat it as your server's official word: staff always make the decisions. If an AI answer affected you and you want a person to review it, ask your server's staff or open a ticket in our support server.
Verification
What the portal collects
Some servers ask you to verify through a web portal before giving access. The link lasts 30 minutes and works once. When you submit it, Marin keeps:
- Your Discord ID, the server ID and your Roblox username and ID, and whether the Roblox account was checked with a phrase in its bio or you only told us which one it is.
- The creation dates of your Discord and Roblox accounts.
- What kind of connection you're on according to public lists (regular, VPN, proxy, Tor or data center), which company runs that network and which country that company is registered in. We don't know or keep where you are.
- Technical details of your browser in readable form: browser and system family (without the exact version), device type, resolution, language and time zone.
- Whether those details agree with each other and with the request itself, and whether the browser says it's an automated tool.
- Codes made with a secret key from your IP, the portal cookie and a description of your device. Those codes can't be turned back into your IP or used to identify your device outside Marin.
- Your answers to the server's questions.
On top of that, each portal step (creating the link, looking up your Roblox account, submitting) leaves a short entry with the same codes, to spot bursts of attempts. That entry is deleted after 30 days.
The portal cookie
The portal sets its own cookie called "marin_vid". It holds a signed random identifier, only Marin's server can read it (the page's JavaScript can't) and it's only sent to the portal. It's used to recognise the same browser in future verifications in the same server. It lasts 180 days and changes value every 90. It isn't for ads and it isn't used outside the portal.
If you delete or block it, you can still verify. A cookie alone is never enough to turn you down, and sharing a browser with someone at home isn't treated as suspicious on its own.
How the connection is checked
Your IP isn't sent to any outside service. Marin downloads free public lists of Tor exits, VPN ranges, proxies and data centers, plus the public table that says which company runs each range, and compares your IP with that copy on its own server. These lists aren't perfect: some networks may be missing or listed by mistake, which is why staff see the result as an indicator, with the certainty it actually has.
iCloud Private Relay is recognised separately and isn't treated as a VPN.
What it's for and who sees it
It helps staff spot alt accounts and people trying to come back after a ban. Marin gathers the indicators and says whether the account looks like an alt and why, but it doesn't decide: approving or turning someone down is always done by a staff member. Matches are only looked up inside that server, never in others.
Sharing a network with your family, school or workplace, or using the same phone model as someone else, isn't an accusation. Those cases are marked as shared and staff see them that way.
The result and its reasons show up on a card inside your verification ticket or thread, which you and staff can see. It may name another account in the server that looks like yours, but it never shows your IP or technical details about your connection or device. If you ask for a copy of your data, your review is included, without other people's data. If you think you were turned down by mistake, ask the server's staff to review it.
How long it's kept
| What | How long |
|---|---|
| The full review | 180 days, then it deletes itself |
| The short attempt history | 30 days |
| The portal link | Works for 30 minutes; the record is deleted after 6 hours |
| The "marin_vid" cookie | 180 days in your browser, changing value every 90 |
| Your raw IP | Not stored |
What we never collect
- Passwords. You sign in with Discord and we never see your password. We don't ask for your Roblox one either.
- Direct messages. Marin doesn't read or keep what you send it by DM.
- Everything written in your server. Recent messages are only kept if the server turned on the AI, and they're deleted after 7 days.
- Your raw IP. In verification it's compared with public lists on our own server, and after that only a code made with a secret key is left.
- Payment details. The website doesn't charge you or ask for cards.
- Voice, camera, contacts or exact location.
- Advertising or tracking cookies.
And what we don't do with what we have
- We don't sell or rent data. To anyone.
- We don't show ads or build advertising profiles.
- We don't train AI models on your data.
- We don't hand one server what you have in another.
- We don't cross data between servers, except for the raid-bot list and the assistant's 24-hour lockout.
How long we keep things
A lot of what Marin keeps has an expiry date and deletes itself. The rest stays while the server uses it.
| Data | How long | What happens next |
|---|---|---|
| Recent messages for the assistant | 7 days | Deleted automatically |
| Conversation with the assistant | 2 hours | Deleted automatically |
| Videos and audio over 14 MB sent to Google | Until the answer is done | Marin deletes them; if that fails, Google removes them after 48 hours |
| Assistant notes | 30 days | Deleted automatically |
| AI usage log | 90 days | Deleted automatically |
| Assistant abuse lockout | 24 hours | Lifted automatically |
| Verification portal link | 30 minutes | Stops working and is deleted |
| Verification review | 180 days | Deleted automatically |
Deleted messages for >snipe | 10 minutes, in memory only | Gone |
| Roblox lookups | 10 minutes, in memory only | Gone |
| Discord and Roblox profiles shown on the creator page | Up to 30 minutes, in memory only | Gone |
| Discord, Roblox and Spotify images the website serves | Up to 6 hours, in memory only | Gone |
| Creator page "mrn_cv" cookie | 12 hours in your browser | Expires on its own |
| Security and raid incidents | 30 days | Deleted automatically |
| Role change history | 90 days | Deleted automatically |
| Server backup | One per server | Each copy replaces the last one |
| Website visit stats | 120 days | Deleted automatically |
| Dashboard or ticket view session | 12 hours | You have to sign in again |
| Data copy you requested | 7 days | The download link expires |
| Privacy requests | 365 days after they're closed | Deleted |
| Profiles, results, cases, tickets, applications, approved verifications and settings | While the server needs them | Staff delete them, or we do if you ask |
If Marin leaves a server
Removing Marin from a server doesn't automatically delete what was already stored. If it's invited back, the setup is still there. If you want it deleted, ask as explained in section 10.
Who can see your data
| Who | What they can see | What they can't see |
|---|---|---|
| Other server members | What Marin posts in channels: your profile, spots, results and announcements | Your moderation cases, your tickets and your verification data |
| Your server's staff | Depending on their permissions: cases, tickets from their panels, applications, verification reviews and change history | What you have in other servers and your IP |
| Whoever runs Marin | Technical access to the database to keep the service running, fix problems and handle requests. Only when needed | Your passwords, your DMs and your raw IP, because we don't have them |
| Providers | Only what they need to do their part (section 8) | Everything else |
We don't share data with anyone else, unless a law requires it.
Services we use
Marin doesn't run on its own. These services receive data because it couldn't do what it does without them:
| Service | What for | What it receives |
|---|---|---|
| Discord | It's where Marin lives, and the website sign-in | Everything Marin does goes through Discord |
| Google, Gemini API | The AI assistant | What section 3 describes |
| Roblox | Public Roblox account data | The Roblox username or ID being looked up |
| Render | Hosts the bot and the website | Bot and website traffic |
| MongoDB database | Stores what this policy describes | All stored data |
| Plausible | Visit stats, without cookies | Page, referrer, browser and approximate country; it doesn't store your IP |
| Lanyard | The Spotify status on the creator page, only if the bot can't see it | Only the creator's Discord ID; nothing about whoever visits the page |
The creator page has its own rules, explained in section 9.
Data outside your country
These services have servers in different countries, mainly in the United States and Europe. That means your data may be processed outside the country you live in.
The website and cookies
Cookies
The website only sets cookies when you sign in with Discord, open the verification portal or visit the creator page, and they're the ones needed for that to work:
| Cookie | What for | Lasts |
|---|---|---|
| Web dashboard session | Knowing who you are and which servers you can manage. It's signed, the page's JavaScript can't read it and the Discord permission inside is encrypted | 12 hours |
| Ticket view session | Showing you your ticket transcripts | 12 hours |
| "marin_vid", from the verification portal | Recognising the same browser in future verifications in the same server. Only the server can read it and it's only sent to the portal (more detail) | 180 days |
| "mrn_cv", from the creator page | Not counting your visit twice. It only says you were already counted; it carries no identifier and the page's JavaScript can't read it | 12 hours |
We don't use advertising or tracking cookies.
Fonts and images
The website's fonts are served from our own server, not from Google or any other service. The same goes for the Discord pictures shown on the creator page and on "About": Marin delivers them.
What's stored in your browser
Your browser remembers the language and theme (light or dark) you picked and, in the dashboard, the last server you opened. While the tab is open, it also keeps a random visit ID to count visits without cookies and, on the creator page, the music volume you picked. All of that stays on your device and you can clear it from your browser whenever you want.
Visit stats
We count visits in two ways, neither with cookies. Our own counter keeps the page, what kind of site you came from, whether you're on a computer, tablet or phone, and the browser family; it doesn't keep your IP. We also use Plausible, which doesn't use cookies either. If your browser has Do Not Track turned on, our counter doesn't record your visit.
The creator page
The creator page is the personal profile of the person who makes Marin. This is what happens when you open it:
- Visit counter. We keep a single total number. We don't keep your IP, your browser or a list of who came in. So you aren't counted twice, the page sets the "mrn_cv" cookie for 12 hours; it only says you were already counted.
- The creator's status and music. It shows their Discord profile and status and, if they're listening on Spotify, the song. If the bot can't see that status, our server asks Lanyard for it using only the creator's Discord ID.
- Testers. The creator picks who to show by entering their Discord ID. The public avatar and name are requested from Discord when the page opens and held in memory for a few minutes; they aren't saved in the database. If you're listed there and would rather not be, ask the creator or write to us and we'll remove you.
- Images and music. Discord, Spotify and Roblox images are downloaded by our server and delivered to you from Marin's website, so they load even if your network blocks those sites, and those services don't receive your IP. Only if our server can't deliver them does your browser request them directly. If the creator added an image, video or song linked from another site, it loads from that site, which does receive your IP. The music doesn't play until you tap the page.
Your rights and how to use them
| Right | What you can ask for |
|---|---|
| Access | A copy of what Marin keeps about your account, in a file you download |
| Correction | That we fix something that's wrong |
| Deletion | That we delete your data. If something can't be deleted, we tell you what and why |
| Restriction | That we stop using something while an issue is looked into |
| Questions | Anything about your data |
How to ask
Go to the request center with your Discord account, pick what you need and you're done. We ask you to sign in for a simple reason: that's how we know the account is yours and nobody can request someone else's data. You can also follow your request's status from there.
If you prefer, open a ticket in our support server.
Timing
We answer in the same place you made the request. We won't promise a deadline we can't keep: if something is going to take a while, we'll tell you why. If you asked for a copy, the download link lasts 7 days.
Depending on where you live
Some laws, like the GDPR in Europe, Brazil's LGPD or some US state privacy laws, give you extra rights or let you complain to your country's data protection authority. We respect them the same way: you ask for them the same way.
Minors
To use Marin you need to meet Discord's minimum age: 13, or older if your country requires it.
The AI features are a different story: the Gemini API terms require being over 18. If you're younger, don't use the assistant or AI tickets.
If we find out someone under the minimum age gave us data, we delete it.
Security
The website runs on HTTPS. Sessions are signed and the page's JavaScript can't read them, the permission Discord gives us at sign-in is stored encrypted, and your IP and device details are only stored as encrypted codes. Database access is limited to whoever runs Marin.
No system is a hundred percent secure and we won't tell you otherwise. If something happens that affects your data, we'll announce it in the support server as soon as possible, with what we know and what we're doing about it.
Changes to this policy
When Marin changes, this page changes with it. The date of the last update is always at the top. If a change is important, we announce it in the support server before it applies, whenever possible.
Contact
- Requests about your data: request center.
- Questions and reports: support server.
No results
Try another word or the article number.
Questions about your data?
Ask us in the support server, or request a copy or deletion of your data from the requests page.