Privacy Policy
Last updated: July 19, 2026
1. Scope
This Privacy Policy explains how Ghost Ticket ("we," "us," or the "Service") collects, uses, stores, and discloses information through the Discord bot, dashboard, ticket transcripts, analytics, and bug-reporting features. Discord separately processes information under its own Privacy Policy.
2. Information We Collect
Discord and account information
- Discord user ID, username, display name, avatar, and email address made available through OAuth2
- Discord servers, channels, roles, permissions, and member details needed to display and operate configured features
- OAuth access and refresh credentials used to maintain an authenticated dashboard session
Ticket and server information
- Ticket messages, form answers, uploaded attachments, participant IDs, channel or thread IDs, and timestamps
- Ticket status, claim details, first-response time, resolution time, closer, close reason, ratings, and support activity
- Panel, role, channel, limits, compact-mode, auto-close, logging, mention, moderation, and other server configuration
- Ticket bans and account or IP restrictions, including reason, administrator, and expiration where provided
Dashboard, device, and security information
- IP address, browser user-agent, login time, session identifier, session activity, and revocation status
- Saved nickname, language, theme, and other account preferences
- Security events and diagnostic information generated when the Service fails or detects abuse
Bug-report information
A submitted bug report contains the report description, your Discord-linked email and account details, submission time, source, and an optional image. Image uploads are limited to validated image formats and a maximum of 100 MB.
3. Sources of Information
We receive information directly from you, from server administrators, from activity inside ticket channels, automatically from your browser or connection, and from Discord through the bot API and OAuth2 permissions you authorize.
4. How We Use Information
- Authenticate users and determine dashboard and Discord permissions
- Create, route, manage, claim, close, and automatically close tickets
- Generate and serve transcripts and preserve locally copied transcript attachments
- Provide ticket counts, first-response and resolution statistics, ratings, and supporter rankings
- Save server configuration and user appearance or language preferences
- Review bug reports, troubleshoot failures, secure the Service, enforce restrictions, and prevent abuse
- Comply with applicable legal obligations and protect users, the Service, and third parties
Where data-protection law requires a legal basis, processing may rely on providing the Service you requested, our legitimate interests in operating and securing it, consent where required, and compliance with legal obligations.
5. How Information Is Disclosed
We do not sell personal information or use it for third-party behavioral advertising. Information may be disclosed:
- To authorized server administrators, support roles, ticket participants, and dashboard users according to configured permissions
- To Discord through its API and to Discord's CDN when avatars or Discord-hosted content are requested
- To jsDelivr, which delivers the Chart.js and Lucide browser libraries used by the dashboard
- To the hosting provider or system operator as necessary to run, secure, back up, and maintain the Service
- When required by law or reasonably necessary to protect rights, safety, security, and integrity
6. Transcript Links
Closed-ticket transcripts may be available through a web link without requiring a Discord login. Anyone who receives a working link may be able to view the transcript until it expires or is deleted. Do not forward transcript links to unauthorized people. Deleting a Discord message after transcript creation may not remove the copied content from an existing transcript.
7. Cookies and Sessions
The dashboard uses a necessary Flask session cookie to keep you signed in, maintain OAuth state, protect forms, and store account and preference data. The browser-stored session cookie may contain Discord OAuth credentials and is signed against modification; signing does not encrypt its contents. It is configured as HTTP-only and SameSite=Lax, and as Secure when the dashboard uses HTTPS. The normal session lifetime is 30 days, and sessions may be revoked earlier. We do not use advertising cookies.
8. Data Retention
| Data type | Typical retention |
|---|---|
| Closed-ticket transcripts and copied attachments | 180 days after transcript creation, then scheduled for automatic deletion |
| Discord messages and attachments | Controlled separately by Discord and the applicable server |
| Ticket logs, analytics, claims, response times, resolutions, and ratings | Until manually deleted or no longer needed to operate the Service |
| Bug reports and optional report images | Until reviewed and manually deleted |
| Login logs | Until manually deleted |
| Dashboard session cookie | Normally 30 days, unless cleared, expired, or revoked earlier |
| Session records | Until revoked or manually deleted |
| User settings and server or panel configuration | Until changed or manually deleted |
| Ban and restriction data | Until expiration, removal, or manual deletion, subject to security needs |
We may retain information longer when reasonably necessary for security, dispute resolution, backups, or legal compliance. Automatic deletion depends on the Service running successfully.
9. Data Location and International Processing
Application records, transcripts, and bug reports are stored on the system hosting Ghost Ticket. Its location depends on the operator's hosting setup. Discord, its CDN, jsDelivr, and other infrastructure providers may process information in other countries under their own terms and policies.
10. Security
We use reasonable technical measures including signed HTTP-only session cookies, CSRF protection for form submissions, content-security and other browser headers, permission checks, session revocation, file-size limits, extension and image-content validation, and path controls. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or disclosure will never occur.
11. Your Choices and Rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, or objection, and to withdraw consent where processing relies on consent. You can change dashboard preferences in Settings, revoke active sessions, leave a Discord server, or remove the app if you have the required server permission. Requests may be limited where information must be retained for security, legal obligations, or the rights of others.
To make a privacy request, email contactgtickets@atomicmail.io. Include enough information to verify your identity and identify the relevant Discord server or ticket. Discord account-level requests must be directed to Discord.
12. Children's Privacy
The Service is not intended for anyone below Discord's minimum age requirement or the higher age required in their country. We do not knowingly collect personal information from children who are not permitted to use the Service. Contact us if you believe such information has been submitted.
13. Policy Changes
We may update this Privacy Policy when features, practices, or legal requirements change. We will post the revised policy here and change the date at the top. Material changes may also be communicated through the Service where practical.
14. Contact
Privacy questions, requests, or complaints may be sent to contactgtickets@atomicmail.io.