Legal Codex · Document II
Privacy Policy
- We never sell your data, and we run no advertising.
- Bots read messages only in channels server staff designate, and no bot tracks your online status.
- Most data you give us yourself: tickets, suggestions, event entries, and game IDs for verification.
- Feedback collected at MOONTON's request is shared with MOONTON staff; a few staff workflows use Google Sheets or OpenAI, and nothing else leaves our systems.
- Want your data corrected or deleted? Email [email protected] or open a support ticket in the official MLBB server.
- Discord's and MOONTON's own privacy policies also apply on their platforms — this document covers just our bots, the ones listed in the Bot Directory.
1Who we are and what this covers
This Privacy Policy describes how the MLBB Community Bot Development Team ("we", "us", "the Team") — independent contractors engaged by MOONTON Games — handles personal data when you interact with the Discord bots we operate in official Mobile Legends: Bang Bang ("MLBB") community servers.
This policy covers every bot we operate, including bots added after this policy's effective date. "Our bots" means the bots hosted by the Team for the global MLBB and Magic Chess: Go Go community servers. Some of them (Harper, for example) are also deployed in official regional MLBB servers — for role synchronisation, staff work, and so members who prefer a regional server can use them there — and this policy follows our bots wherever they are deployed. Bots hosted by a regional server's own team are not ours, even where they serve a similar purpose, and are covered by whatever documents that team publishes. The authoritative list of covered bots — with each bot's purpose and the Discord permissions it uses — is the Bot Directory, regenerated from each bot's live manifest; a bot that is not in the directory is not covered. This policy is published by the Team in its own name; it is not a MOONTON document.
For everything this policy describes, the Team is the responsible party: we decide how bot data is collected, stored, and shared, we answer the requests in Section 7, and we carry the notification duties in Section 8. Where a feature collects community feedback for MOONTON, MOONTON's use of what it receives is covered by its own privacy policy (linked below); requests about data our bots hold always come to us. You can reach the Team at [email protected] without joining any Discord server.
This policy governs only the processing our bots perform. Two further documents independently apply to you and are unaffected by anything written here: Discord's Privacy Policy, which governs everything Discord itself collects on its platform, and the Mobile Legends: Bang Bang Privacy Policy published by MOONTON, which governs your game account data. By using the Service you are also subject to Discord's Terms of Service and the Mobile Legends: Bang Bang Terms of Service, as set out in our Terms of Service. We encourage you to read all four.
This website (legal.mlbb.dev) sets no cookies, runs no analytics, and makes no third-party requests. It collects no data about visitors at all.
2What we collect
Depending on a bot's function, it may process data in the following categories. Each bot's entry in the Bot Directory lists exactly which categories apply to that bot.
2.1 Discord identifiers
Your Discord user ID, username, and display name, used to attribute actions such as tickets, event entries, suggestions, and moderation records to the right member.
2.2 Roles & membership
Role assignments, join/leave events, and booster status, used for automatic role synchronisation and staff activity statistics.
2.3 Messages in designated channels
Some bots read message content, but only in specific channels designated by server staff — for example moderation-log channels, feedback and review channels that MOONTON staff ask us to monitor (such as early-access or special-package discussion channels, where player responses inform product review), or game channels where a bot must read typed answers (such as trivia). Bots never read your direct messages except in conversations you deliberately start with a bot (for example a modmail thread or an event submission prompt).
2.4 Support tickets & appeals
The text and attachments you submit in support tickets, modmail conversations, and ban appeals, so staff can review and respond to your request.
2.5 Suggestions & feedback
Free-text suggestions and feedback you actively submit through forms, pop-up modals, or direct-message prompts.
2.6 Game identifiers
Your MLBB Game ID and Server ID, collected during account verification, tournament registration, or event participation.
2.7 Moderation records
Logs of deleted or edited messages, member reports, and moderation actions in servers where a moderation bot is deployed, used to keep official servers safe.
2.8 Uploaded files & media
Images and files you upload as part of event submissions, design requests, or staff announcements handled by a bot.
2.9 AI-assisted processing
A limited subset of submitted content (for example suggestion text) may be processed by OpenAI's API to help staff triage and summarise it. Per OpenAI's API terms, this data is not used to train their models. Bots that do this are marked in the directory.
2.10 Staff workflow sync
Limited records (such as schedules or suggestion lists) are synchronised to private Google Sheets used by staff for coordination.
What we never collect
No bot tracks your online/offline status or activity presence. No bot reads messages outside its designated channels. No bot collects payment information, email addresses, or precise location, and nothing comes from outside Discord except the game identifiers you provide yourself. (If you email us for a request under Section 7, we use your address only to correspond about that request.)
3About Discord's privileged permissions
Discord requires bots to declare three "privileged gateway intents" — special permissions reviewed by Discord itself. Because they matter for your privacy, here is how we use them:
| Intent | What it allows | Our policy |
|---|---|---|
| Server Members | Seeing the member list and member join/leave/role changes. | Enabled only for bots that perform role synchronisation, verification, ticket lifecycle handling, or staff statistics. Each such bot's justification is shown in the directory. |
| Presence | Seeing members' online status and current activity. | Disabled fleet-wide. No bot we operate uses presence data. |
| Message Content | Reading the content of messages in server channels. | Enabled only for bots whose features require reading messages in designated channels (moderation logging, ticket relays, staff-requested feedback channels, live trivia). All other bots use slash commands and forms, which do not require this intent. |
4Why we process data
We process data only for the following purposes:
- Server safety and moderation — logging deleted/edited messages, handling reports, enforcing server rules, and producing staff activity statistics.
- Member support — operating ticket, modmail, and ban-appeal systems and keeping records of how requests were resolved.
- Community features — verification and role synchronisation, events, games, giveaways, tournaments, and utility commands you invoke.
- Product feedback for MOONTON — collecting suggestions, surveys, and player responses in designated feedback channels at MOONTON's request, so the MLBB team can act on community input.
We do not use your data for advertising, profiling, or automated decisions with legal effect, and we never sell it.
Where a data-protection law such as the EU GDPR applies to you, these purposes rest on the following legal grounds. Features you actively use — tickets, verification, events, commands — are processed because that is necessary to provide what you asked for, under our Terms of Service. Moderation and security records rest on the legitimate interest of keeping official servers safe. Feedback and survey submissions rest on your consent: you give it by submitting, and you can withdraw it at any time by asking us to delete the submission. Disclosures required by law rest on legal obligation.
6How long we keep data
We keep personal data only as long as the feature it serves requires:
- Event and game data (entries, points, submissions) — for the duration of the event, then archived briefly for prize resolution and deleted.
- Suggestions and feedback — while the campaign or review programme they belong to is active.
- Tickets, appeals, and moderation records — retained while they are needed for server safety and record-keeping, in line with each server's moderation policy.
- Verification and account links — while your link is active; removed when staff unbind it at your request or when you leave permanently.
- Retired bots — when a bot is retired, its stored data is deleted after a short wind-down period.
7Your rights and choices
Wherever you are in the world, we honour the following for data our bots hold:
- Access — ask what data we hold about you and receive a copy.
- Correction — have inaccurate data (for example a mistyped Game ID) corrected.
- Deletion — have your data deleted, except records we must keep for server safety or legal reasons (we will tell you if an exception applies).
- Objection / withdrawal — stop participating in any optional feature at any time. Some opt-outs are direct commands (for example cancelling an event registration); unbinding a verified game account is handled by staff on request rather than by a self-service command, because free rebinding would make it easier to claim a Game ID that is not yours or to evade moderation.
To exercise any of these, email [email protected] or open a support ticket in the official MLBB Discord server and state your request; we may ask you to confirm your identity, for example via your Discord account or the Game ID on file. The email route works even if you have left the server, are banned, or no longer have a Discord account. We respond within 30 days. If you are in a region with a data-protection authority, such as the EU or the UK, you also have the right to lodge a complaint with that authority. If you delete your Discord account, Discord's own deletion processes apply to your identity on the platform, and identifiers held by our bots become orphaned and are removed during routine cleanup.
8Security
Bot data is stored on private, access-controlled infrastructure administered by the Team. All connections to Discord and third-party services are encrypted in transit, and access to stored data is limited to the Team members who need it to operate a bot. We apply industry-standard security practices throughout, and we deliberately do not publish the details of our security setup. No method of storage is 100% secure; if we become aware of a breach affecting your data, we will promptly notify Discord as the Discord Developer Terms of Service require, inform affected individuals and the relevant data-protection authority where the law requires it, and announce the incident to affected communities through the official servers.
9Children
The Service is not directed at children below Discord's minimum age (13, or higher where local law requires). We do not knowingly collect data from users below that age; if we learn we have, we will delete it. If you believe a child is using the Service, report it via a support ticket or to Discord Trust & Safety.
10Changes to this policy
We may update this policy from time to time. The current version and effective date are always displayed at the top of this page, and material changes will be announced in the official MLBB servers. Adding or retiring a bot in the Bot Directory does not by itself amend this policy, provided the bot's processing stays within the categories described here; a bot requiring a new category of processing will trigger a policy update first.
11Contact
For privacy questions and data requests, email [email protected] — it reaches the developers directly, without going through server staff, and requires no Discord membership. If you email us, we use your address only to correspond about your request.
You can also join the official MLBB Discord server (discord.gg/mobilelegendsbangbang) and open a support ticket. Tickets are triaged by server staff, and privacy requests are escalated to the developers responsible for the bot in question.