Legal
Privacy Policy
This policy explains what data Docket collects, why, and how it is stored and used. Docket is operated by Nøyra Labs.
1. What we collect
When you sign in with Discord, we receive and store the following from Discord's OAuth API:
- Discord user ID — your unique account identifier
- Username and display name — shown in the dashboard
- Avatar URL — displayed in the app bar and author row
- Email address — requested at OAuth scope, used for account verification only; not shared with third parties
When you connect a Discord server (guild), we also access and temporarily cache:
- Guild IDs, names, and icons — to populate your guild list
- Channel and role lists — to power ticket type configuration
- Guild member permissions — to verify you hold owner or administrator rights
Ticket data created through the Docket Discord bot is stored in our database and includes:
- Discord user IDs of the ticket creator, closer, and status updaters
- Ticket opening reason and closure reason
- Thread ID and message IDs within the ticket thread
- Ticket status history with timestamps
- A reference path to the stored transcript file
We also collect technical data as part of normal web service operation:
- Server access logs — IP addresses, request paths, HTTP methods, and timestamps, retained for up to 90 days for security monitoring and debugging
2. How we collect it
- Discord OAuth 2.0— when you click "Sign in with Discord", we initiate a PKCE authorization flow. Temporary state and code-verifier values are stored in short-lived cookies and deleted after the callback completes.
- Session cookie — after sign-in we store a cryptographically signed session cookie (HMAC-SHA256) containing your Discord profile and access token. This cookie expires when you sign out or your Discord token expires.
- Discord bot — ticket data is written to our database by the Docket bot when users interact with bot commands and buttons inside your Discord server.
We do not use tracking pixels, advertising SDKs, or third-party analytics scripts.
3. How we use it
- Authenticating you and verifying your guild administrator status
- Displaying your servers and their configuration in the dashboard
- Storing and retrieving ticket records, statuses, and transcripts
- Generating formatted ticket IDs based on your configured number format
We do not sell, rent, or share your personal data with third parties for marketing purposes.
Under UK GDPR, we process your personal data on the following lawful bases: contract performance — processing necessary to operate the service for your guild; and legitimate interests — security monitoring, fraud prevention, and service reliability.
4. Data storage and security
All data is stored in AWS infrastructure in the eu-west-2 (London) region:
- Database — ticket configuration and ticket records are stored in a managed relational database with all connections encrypted in transit.
- Transcripts — closed ticket transcripts are uploaded as JSON files to AWS S3 (Amazon Simple Storage Service) and are accessible via unique per-ticket URLs. Older transcripts are automatically transitioned to S3 Infrequent Access storage to reduce costs while remaining fully accessible. Transcript links are posted to the ticket thread on closure.
- Caches — guild, channel, and role lists are held in short-lived server-side memory caches and are never persisted to disk.
5. Data retention
Ticket records and transcripts are retained indefinitely unless you request deletion. Guild configuration is retained for as long as your server uses Docket. Session cookies expire with your Discord access token or when you sign out, whichever is sooner.
To request deletion of your data or a guild's data, contact us using the details below.
6. Third-party services
- Discord— authentication and bot operations. Subject to Discord's Privacy Policy.
- Amazon Web Services (AWS)— hosting, database, and transcript storage in the eu-west-2 (London) region. Subject to AWS's Privacy Policy. Data stored in the UK may be transferred to EEA countries under the UK's adequacy regulations, which permit free data flows between the UK and EU.
7. Your rights
Docket is available to Discord users worldwide and is operated from the United Kingdom. We comply with UK GDPR as our primary data protection framework. Regardless of where you are located, you may contact us to access, correct, export, or request deletion of your personal data. UK and EEA residents have specific enforceable rights under UK GDPR and EU GDPR respectively; users in other jurisdictions may also have rights under their local laws. We will respond to all requests within 30 days.
8. Changes to this policy
We may update this policy as the product evolves. When we make material changes, we will update the effective date at the top of this page. Continued use of Docket after changes are posted constitutes acceptance of the revised policy.
Questions about this policy? Email us at legal@noyralabs.com.