Legal

Privacy Policy

Last updated: July 19, 2026

1. Scope

This Privacy Policy explains how Ghost Ticket ("we," "us," or the "Service") collects, uses, stores, and discloses information through the Discord bot, dashboard, ticket transcripts, analytics, and bug-reporting features. Discord separately processes information under its own Privacy Policy.

2. Information We Collect

Discord and account information

Ticket and server information

Dashboard, device, and security information

Bug-report information

A submitted bug report contains the report description, your Discord-linked email and account details, submission time, source, and an optional image. Image uploads are limited to validated image formats and a maximum of 100 MB.

3. Sources of Information

We receive information directly from you, from server administrators, from activity inside ticket channels, automatically from your browser or connection, and from Discord through the bot API and OAuth2 permissions you authorize.

4. How We Use Information

Where data-protection law requires a legal basis, processing may rely on providing the Service you requested, our legitimate interests in operating and securing it, consent where required, and compliance with legal obligations.

5. How Information Is Disclosed

We do not sell personal information or use it for third-party behavioral advertising. Information may be disclosed:

6. Transcript Links

Closed-ticket transcripts may be available through a web link without requiring a Discord login. Anyone who receives a working link may be able to view the transcript until it expires or is deleted. Do not forward transcript links to unauthorized people. Deleting a Discord message after transcript creation may not remove the copied content from an existing transcript.

7. Cookies and Sessions

The dashboard uses a necessary Flask session cookie to keep you signed in, maintain OAuth state, protect forms, and store account and preference data. The browser-stored session cookie may contain Discord OAuth credentials and is signed against modification; signing does not encrypt its contents. It is configured as HTTP-only and SameSite=Lax, and as Secure when the dashboard uses HTTPS. The normal session lifetime is 30 days, and sessions may be revoked earlier. We do not use advertising cookies.

8. Data Retention

Data typeTypical retention
Closed-ticket transcripts and copied attachments180 days after transcript creation, then scheduled for automatic deletion
Discord messages and attachmentsControlled separately by Discord and the applicable server
Ticket logs, analytics, claims, response times, resolutions, and ratingsUntil manually deleted or no longer needed to operate the Service
Bug reports and optional report imagesUntil reviewed and manually deleted
Login logsUntil manually deleted
Dashboard session cookieNormally 30 days, unless cleared, expired, or revoked earlier
Session recordsUntil revoked or manually deleted
User settings and server or panel configurationUntil changed or manually deleted
Ban and restriction dataUntil expiration, removal, or manual deletion, subject to security needs

We may retain information longer when reasonably necessary for security, dispute resolution, backups, or legal compliance. Automatic deletion depends on the Service running successfully.

9. Data Location and International Processing

Application records, transcripts, and bug reports are stored on the system hosting Ghost Ticket. Its location depends on the operator's hosting setup. Discord, its CDN, jsDelivr, and other infrastructure providers may process information in other countries under their own terms and policies.

10. Security

We use reasonable technical measures including signed HTTP-only session cookies, CSRF protection for form submissions, content-security and other browser headers, permission checks, session revocation, file-size limits, extension and image-content validation, and path controls. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or disclosure will never occur.

11. Your Choices and Rights

Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, or objection, and to withdraw consent where processing relies on consent. You can change dashboard preferences in Settings, revoke active sessions, leave a Discord server, or remove the app if you have the required server permission. Requests may be limited where information must be retained for security, legal obligations, or the rights of others.

To make a privacy request, email contactgtickets@atomicmail.io. Include enough information to verify your identity and identify the relevant Discord server or ticket. Discord account-level requests must be directed to Discord.

12. Children's Privacy

The Service is not intended for anyone below Discord's minimum age requirement or the higher age required in their country. We do not knowingly collect personal information from children who are not permitted to use the Service. Contact us if you believe such information has been submitted.

13. Policy Changes

We may update this Privacy Policy when features, practices, or legal requirements change. We will post the revised policy here and change the date at the top. Material changes may also be communicated through the Service where practical.

14. Contact

Privacy questions, requests, or complaints may be sent to contactgtickets@atomicmail.io.