Privacy policy
Legal

Privacy policy

What data Marin keeps, why, who can see it and how long it stays. No fine print.

Updated on 14 sections · 38 articles

Contents
  1. 1Before we start
  2. 2What we keep and why
  3. 3Messages and the AI assistant
  4. 4Verification
  5. 5What we never collect
  6. 6How long we keep things
  7. 7Who can see your data
  8. 8Services we use
  9. 9The website and cookies
  10. 10Your rights and how to use them
  11. 11Minors
  12. 12Security
  13. 13Changes to this policy
  14. 14Contact

Before we start

Art. 1.1

What this policy covers

This policy applies to everything Marin does:

  • The Discord bot, in any server it's in.
  • This website, including the docs and the privacy request center.
  • The web dashboard and the web ticket view, where you sign in with your Discord account.
  • The verification portal some servers use.
Art. 1.2

What it doesn't cover

What Discord does with your data is up to Discord and is explained in its privacy policy. It also doesn't cover each server's own rules or what other bots next to Marin do.

Art. 1.3

Who runs Marin

Marin is an independent project built and maintained by its creator. You can see who that is on the creator page. When this page says "we", it means whoever runs Marin.

We're not a big company and we don't pretend to be one. Marin is not affiliated with Discord, Roblox or the creators of The Strongest Battlegrounds.

Art. 1.4

Your server decides, Marin carries it out

Each server's staff choose which modules to turn on, how to set them up and which sanctions to apply. Marin does what the server configured and keeps what that requires.

So if you disagree with a ban, a warn or a rejected verification, talk to that server's staff first. We can delete your data, but we can't undo a decision another server made.

What we keep and why

Art. 2.1

This is the full table. If something isn't listed here, Marin doesn't keep it.

DataWhere it comes fromWhat forRequired?
Discord IDs: yours, the server's, channels and rolesDiscord, when you use a command or a module acts on youKnowing whose profile, case or ticket is whoseYes. Marin can't work without IDs
Server settingsStaff, from /setup or the web dashboardMaking Marin do what the server choseYes, for each active module
Player profile: name, Roblox username and ID, region, record and phaseYou or staff, when the profile is created or editedLeaderboard, score, ranking and challengesOnly if you have a profile
Results, phases and spotsStaff, with /score, /phase, /addspot and similarBoards and set and phase historyPart of those modules
Moderation cases, temporary bans and blacklistStaff, or the automatic limits the server set upHistory, lifting bans when they expire and giving roles backOnly if the server uses moderation
Tickets, transcripts and applicationsYou, when you open a ticket or applyLetting staff help you and keeping a recordOnly if you use them
Verification dataThe verification portal, when you submit itHelping staff catch alt accountsOnly if you verify
Questions to the assistant and recent channel messagesYou, when you use >ask or an AI ticket; the channel, if the AI is onLetting the assistant answer with contextOnly if the server turns on the AI
Security dataDiscord's audit log, joins and role changesStopping attacks and restoring the serverOnly with Marin Security
Your web sessionDiscord, when you sign in to the dashboard or the ticket viewKnowing who you are and which servers you can manageOnly if you sign in
Privacy requestsYou, from the request centerHandling them and keeping a record that we didOnly if you make one
Art. 2.2

Profiles and Roblox

When you create a profile or someone uses /scan or /headshot, Marin asks Roblox's public API about that user and gets back their ID, display name, public bio, creation date and avatar. /scan also asks how many public friends and groups the account has, and whether Roblox marked it as verified or banned, to show the account signals. That answer stays in memory only, for 10 minutes, so the lookup isn't repeated; what /scan shows is not saved.

We will never ask for your Roblox password. If the server requires proof that the account is yours, you do it by putting a phrase in your Roblox bio, nothing else.

Art. 2.3

Deleted messages and >snipe

When someone deletes or edits a message, Marin keeps a copy in memory for 10 minutes: author, channel, the text before and after, and the time. For the first 2 minutes anyone in that server can see it with >snipe. None of this is written to the database; when the bot restarts, it's gone.

Art. 2.4

Marin Security

In servers with Marin Security, Marin keeps a backup of the server's structure so it can be restored after an attack: name and icons, roles, channels and permissions, AutoMod rules, events, emojis and stickers, webhooks (without their tokens), invites, the ban list with reasons and, for each member, their nickname, roles and whether they're timed out.

There's a single backup per server and it's replaced with every copy. Incidents (who did what and which punishment was applied) are also recorded for 30 days, and role changes for 90 days.

There's only one list shared across servers: bots that took part in a raid or a nuke. It only includes bot accounts, never people.

Messages and the AI assistant

Art. 3.1

What happens when a server turns on the AI

This is the most sensitive thing Marin does, so let's get straight to it.

If an administrator turns on the assistant (>ask), Marin starts saving the messages people write in the channels it can read. For each message it keeps the author's display name at that moment (not their ID), the text and the date. Bot messages and AI ticket channels are left out.

Each question to the assistant goes with the channel's last 12 messages, and the assistant can search them if someone asks about a recent conversation. These messages delete themselves after 7 days. If the server turns the assistant off, Marin stops saving messages within a minute.

Art. 3.2

What else the assistant keeps

  • The conversation, for 2 hours, so you can reply to Marin and keep talking. If there were images, a small, lower-quality copy is kept. Videos, audio and voice messages aren't kept: only a note that they were there.
  • Server notes the assistant decides to save (a recurring problem, a decision), for 30 days and up to 500 per server. It only uses them with people who could see the channel they came from.
  • A usage log for 90 days: date, server, the first 140 characters of the question and whether there were errors. Your ID isn't stored there; an encrypted code is kept instead.
  • The web dashboard assistant keeps the last 30 messages of your conversation. Images you attach aren't stored.
  • If someone keeps trying to get around the assistant's rules, they're locked out for 24 hours. And if someone uses it to harass people, we can tell it to ignore that person; that instruction stays until we remove it.
Art. 3.3

What gets sent to Google

The assistant runs on Google's Gemini API. To answer, Marin sends it your question, the images, GIFs, videos, audio and voice messages you attach or link (up to 4 per message), the channel's recent messages and the server data the assistant looks up (channels, roles, profiles, leaderboard). In an AI ticket, the ticket conversation is sent. Application summaries are only sent if the server turned them on; they're off by default.

A GIF is sent as a few separate images. Videos and audio over 14 MB are uploaded to Gemini's file service just for that answer, and Marin deletes them as soon as it's done; if that deletion failed, Google removes them on its own after 48 hours. Smaller ones travel inside the same request and aren't kept on Google as a file.

Depending on the service tier, the Gemini terms allow Google to use what's sent to improve its products, including human review.

Bottom line: don't tell the assistant anything you wouldn't want someone else to read.

Art. 3.4

Images and GIFs Marin makes

If you ask Marin to put text on an image or turn it into a GIF, the editing happens on our own server, not at Google. Gemini only reads your request to understand what you want. The result is posted in the channel as a normal Discord file and we don't keep another copy.

If you then reply to that image to ask for another change, it's sent to Gemini like any attached image. Only edit images you have the right to use, and don't use them to impersonate someone or to mock anyone.

Art. 3.5

What the AI isn't

The assistant makes mistakes. It can make things up or misread a question. Don't use its answers as medical, legal or financial advice, and don't treat it as your server's official word: staff always make the decisions. If an AI answer affected you and you want a person to review it, ask your server's staff or open a ticket in our support server.

Verification

Art. 4.1

What the portal collects

Some servers ask you to verify through a web portal before giving access. The link lasts 30 minutes and works once. When you submit it, Marin keeps:

  • Your Discord ID, the server ID and your Roblox username and ID, and whether the Roblox account was checked with a phrase in its bio or you only told us which one it is.
  • The creation dates of your Discord and Roblox accounts.
  • What kind of connection you're on according to public lists (regular, VPN, proxy, Tor or data center), which company runs that network and which country that company is registered in. We don't know or keep where you are.
  • Technical details of your browser in readable form: browser and system family (without the exact version), device type, resolution, language and time zone.
  • Whether those details agree with each other and with the request itself, and whether the browser says it's an automated tool.
  • Codes made with a secret key from your IP, the portal cookie and a description of your device. Those codes can't be turned back into your IP or used to identify your device outside Marin.
  • Your answers to the server's questions.

On top of that, each portal step (creating the link, looking up your Roblox account, submitting) leaves a short entry with the same codes, to spot bursts of attempts. That entry is deleted after 30 days.

Art. 4.2

The portal cookie

The portal sets its own cookie called "marin_vid". It holds a signed random identifier, only Marin's server can read it (the page's JavaScript can't) and it's only sent to the portal. It's used to recognise the same browser in future verifications in the same server. It lasts 180 days and changes value every 90. It isn't for ads and it isn't used outside the portal.

If you delete or block it, you can still verify. A cookie alone is never enough to turn you down, and sharing a browser with someone at home isn't treated as suspicious on its own.

Art. 4.3

How the connection is checked

Your IP isn't sent to any outside service. Marin downloads free public lists of Tor exits, VPN ranges, proxies and data centers, plus the public table that says which company runs each range, and compares your IP with that copy on its own server. These lists aren't perfect: some networks may be missing or listed by mistake, which is why staff see the result as an indicator, with the certainty it actually has.

iCloud Private Relay is recognised separately and isn't treated as a VPN.

Art. 4.4

What it's for and who sees it

It helps staff spot alt accounts and people trying to come back after a ban. Marin gathers the indicators and says whether the account looks like an alt and why, but it doesn't decide: approving or turning someone down is always done by a staff member. Matches are only looked up inside that server, never in others.

Sharing a network with your family, school or workplace, or using the same phone model as someone else, isn't an accusation. Those cases are marked as shared and staff see them that way.

The result and its reasons show up on a card inside your verification ticket or thread, which you and staff can see. It may name another account in the server that looks like yours, but it never shows your IP or technical details about your connection or device. If you ask for a copy of your data, your review is included, without other people's data. If you think you were turned down by mistake, ask the server's staff to review it.

Art. 4.5

How long it's kept

WhatHow long
The full review180 days, then it deletes itself
The short attempt history30 days
The portal linkWorks for 30 minutes; the record is deleted after 6 hours
The "marin_vid" cookie180 days in your browser, changing value every 90
Your raw IPNot stored

What we never collect

Art. 5.1
  • Passwords. You sign in with Discord and we never see your password. We don't ask for your Roblox one either.
  • Direct messages. Marin doesn't read or keep what you send it by DM.
  • Everything written in your server. Recent messages are only kept if the server turned on the AI, and they're deleted after 7 days.
  • Your raw IP. In verification it's compared with public lists on our own server, and after that only a code made with a secret key is left.
  • Payment details. The website doesn't charge you or ask for cards.
  • Voice, camera, contacts or exact location.
  • Advertising or tracking cookies.
Art. 5.2

And what we don't do with what we have

  • We don't sell or rent data. To anyone.
  • We don't show ads or build advertising profiles.
  • We don't train AI models on your data.
  • We don't hand one server what you have in another.
  • We don't cross data between servers, except for the raid-bot list and the assistant's 24-hour lockout.

How long we keep things

Art. 6.1

A lot of what Marin keeps has an expiry date and deletes itself. The rest stays while the server uses it.

DataHow longWhat happens next
Recent messages for the assistant7 daysDeleted automatically
Conversation with the assistant2 hoursDeleted automatically
Videos and audio over 14 MB sent to GoogleUntil the answer is doneMarin deletes them; if that fails, Google removes them after 48 hours
Assistant notes30 daysDeleted automatically
AI usage log90 daysDeleted automatically
Assistant abuse lockout24 hoursLifted automatically
Verification portal link30 minutesStops working and is deleted
Verification review180 daysDeleted automatically
Deleted messages for >snipe10 minutes, in memory onlyGone
Roblox lookups10 minutes, in memory onlyGone
Discord and Roblox profiles shown on the creator pageUp to 30 minutes, in memory onlyGone
Discord, Roblox and Spotify images the website servesUp to 6 hours, in memory onlyGone
Creator page "mrn_cv" cookie12 hours in your browserExpires on its own
Security and raid incidents30 daysDeleted automatically
Role change history90 daysDeleted automatically
Server backupOne per serverEach copy replaces the last one
Website visit stats120 daysDeleted automatically
Dashboard or ticket view session12 hoursYou have to sign in again
Data copy you requested7 daysThe download link expires
Privacy requests365 days after they're closedDeleted
Profiles, results, cases, tickets, applications, approved verifications and settingsWhile the server needs themStaff delete them, or we do if you ask
Art. 6.2

If Marin leaves a server

Removing Marin from a server doesn't automatically delete what was already stored. If it's invited back, the setup is still there. If you want it deleted, ask as explained in section 10.

Who can see your data

Art. 7.1
WhoWhat they can seeWhat they can't see
Other server membersWhat Marin posts in channels: your profile, spots, results and announcementsYour moderation cases, your tickets and your verification data
Your server's staffDepending on their permissions: cases, tickets from their panels, applications, verification reviews and change historyWhat you have in other servers and your IP
Whoever runs MarinTechnical access to the database to keep the service running, fix problems and handle requests. Only when neededYour passwords, your DMs and your raw IP, because we don't have them
ProvidersOnly what they need to do their part (section 8)Everything else

We don't share data with anyone else, unless a law requires it.

Services we use

Art. 8.1

Marin doesn't run on its own. These services receive data because it couldn't do what it does without them:

ServiceWhat forWhat it receives
DiscordIt's where Marin lives, and the website sign-inEverything Marin does goes through Discord
Google, Gemini APIThe AI assistantWhat section 3 describes
RobloxPublic Roblox account dataThe Roblox username or ID being looked up
RenderHosts the bot and the websiteBot and website traffic
MongoDB databaseStores what this policy describesAll stored data
PlausibleVisit stats, without cookiesPage, referrer, browser and approximate country; it doesn't store your IP
LanyardThe Spotify status on the creator page, only if the bot can't see itOnly the creator's Discord ID; nothing about whoever visits the page

The creator page has its own rules, explained in section 9.

Art. 8.2

Data outside your country

These services have servers in different countries, mainly in the United States and Europe. That means your data may be processed outside the country you live in.

The website and cookies

Art. 9.1

Cookies

The website only sets cookies when you sign in with Discord, open the verification portal or visit the creator page, and they're the ones needed for that to work:

CookieWhat forLasts
Web dashboard sessionKnowing who you are and which servers you can manage. It's signed, the page's JavaScript can't read it and the Discord permission inside is encrypted12 hours
Ticket view sessionShowing you your ticket transcripts12 hours
"marin_vid", from the verification portalRecognising the same browser in future verifications in the same server. Only the server can read it and it's only sent to the portal (more detail)180 days
"mrn_cv", from the creator pageNot counting your visit twice. It only says you were already counted; it carries no identifier and the page's JavaScript can't read it12 hours

We don't use advertising or tracking cookies.

Art. 9.2

Fonts and images

The website's fonts are served from our own server, not from Google or any other service. The same goes for the Discord pictures shown on the creator page and on "About": Marin delivers them.

Art. 9.3

What's stored in your browser

Your browser remembers the language and theme (light or dark) you picked and, in the dashboard, the last server you opened. While the tab is open, it also keeps a random visit ID to count visits without cookies and, on the creator page, the music volume you picked. All of that stays on your device and you can clear it from your browser whenever you want.

Art. 9.4

Visit stats

We count visits in two ways, neither with cookies. Our own counter keeps the page, what kind of site you came from, whether you're on a computer, tablet or phone, and the browser family; it doesn't keep your IP. We also use Plausible, which doesn't use cookies either. If your browser has Do Not Track turned on, our counter doesn't record your visit.

Art. 9.5

The creator page

The creator page is the personal profile of the person who makes Marin. This is what happens when you open it:

  • Visit counter. We keep a single total number. We don't keep your IP, your browser or a list of who came in. So you aren't counted twice, the page sets the "mrn_cv" cookie for 12 hours; it only says you were already counted.
  • The creator's status and music. It shows their Discord profile and status and, if they're listening on Spotify, the song. If the bot can't see that status, our server asks Lanyard for it using only the creator's Discord ID.
  • Testers. The creator picks who to show by entering their Discord ID. The public avatar and name are requested from Discord when the page opens and held in memory for a few minutes; they aren't saved in the database. If you're listed there and would rather not be, ask the creator or write to us and we'll remove you.
  • Images and music. Discord, Spotify and Roblox images are downloaded by our server and delivered to you from Marin's website, so they load even if your network blocks those sites, and those services don't receive your IP. Only if our server can't deliver them does your browser request them directly. If the creator added an image, video or song linked from another site, it loads from that site, which does receive your IP. The music doesn't play until you tap the page.

Your rights and how to use them

Art. 10.1
RightWhat you can ask for
AccessA copy of what Marin keeps about your account, in a file you download
CorrectionThat we fix something that's wrong
DeletionThat we delete your data. If something can't be deleted, we tell you what and why
RestrictionThat we stop using something while an issue is looked into
QuestionsAnything about your data
Art. 10.2

How to ask

Go to the request center with your Discord account, pick what you need and you're done. We ask you to sign in for a simple reason: that's how we know the account is yours and nobody can request someone else's data. You can also follow your request's status from there.

If you prefer, open a ticket in our support server.

Art. 10.3

Timing

We answer in the same place you made the request. We won't promise a deadline we can't keep: if something is going to take a while, we'll tell you why. If you asked for a copy, the download link lasts 7 days.

Art. 10.4

Depending on where you live

Some laws, like the GDPR in Europe, Brazil's LGPD or some US state privacy laws, give you extra rights or let you complain to your country's data protection authority. We respect them the same way: you ask for them the same way.

Minors

Art. 11.1

To use Marin you need to meet Discord's minimum age: 13, or older if your country requires it.

The AI features are a different story: the Gemini API terms require being over 18. If you're younger, don't use the assistant or AI tickets.

If we find out someone under the minimum age gave us data, we delete it.

Security

Art. 12.1

The website runs on HTTPS. Sessions are signed and the page's JavaScript can't read them, the permission Discord gives us at sign-in is stored encrypted, and your IP and device details are only stored as encrypted codes. Database access is limited to whoever runs Marin.

No system is a hundred percent secure and we won't tell you otherwise. If something happens that affects your data, we'll announce it in the support server as soon as possible, with what we know and what we're doing about it.

Changes to this policy

Art. 13.1

When Marin changes, this page changes with it. The date of the last update is always at the top. If a change is important, we announce it in the support server before it applies, whenever possible.

Contact

Questions about your data?

Ask us in the support server, or request a copy or deletion of your data from the requests page.