Skip to content

Privacy Policy

Nick Aristizabal edited this page Feb 6, 2025 · 1 revision

Privacy Policy

Effective Date: 2/5/2025
Last Updated: 2/5/2025

1. Introduction

Thank you for using the Hoyolab Check-In Discord Bot ("Bot"). This Privacy Policy explains how we collect, use, and protect your data when you use our services. By using this Bot, you agree to the terms outlined in this policy.

2. Information We Collect

The Bot collects and processes the following types of data:

2.1 User-Provided Information

  • Discord Account Information: Your Discord username and ID are stored when you interact with the bot.
  • Hoyolab Cookies: Users must provide their Hoyolab authentication cookies to enable check-ins. These cookies are required to authenticate requests with the Hoyolab API.
  • Profile Nicknames & Game Data: Users may register multiple profiles under different nicknames. Each profile stores:
    • The nickname chosen by the user.
    • Associated Genshin Impact, Honkai Star Rail, or Zenless Zone Zero account UIDs, regions, levels, and nicknames retrieved from Hoyolab.

2.2 Automatically Collected Information

  • Server & User Statistics: The Bot tracks the number of registered users and servers it is active in.
  • Command Usage Data: We log the execution of commands for analytics and debugging purposes.
  • Check-in Metrics: The Bot collects statistics on the number of successful and failed check-ins.

2.3 Sensitive Data & Encryption

  • Encryption of Cookies: All user-provided cookies are encrypted before storage to prevent unauthorized access.
  • MongoDB Storage: User data, including profiles and authentication cookies, is stored in a MongoDB database, which is protected through secure access controls.

3. How We Use Your Information

The Bot uses collected data strictly for the following purposes:

  • Automating Daily Check-Ins: Your Hoyolab cookies allow the Bot to perform check-ins on your behalf.
  • Profile Management: Users can list, update, and delete their profiles as needed.
  • Bot Functionality & Improvements: We analyze command usage data to identify bugs, improve performance, and enhance features.
  • Security & Fraud Prevention: The Bot monitors check-in failures, invalid cookies, and duplicate profile attempts to maintain security.

4. Data Sharing & Third-Party Services

We do not sell, rent, or share your personal information with third parties except in the following circumstances:

  • Discord API: The Bot interacts with the Discord API to receive and process commands.
  • Hoyolab API: The Bot communicates with Hoyolab to perform check-ins.
  • Legal Compliance: If required by law, we may disclose user data to comply with legal requests or law enforcement.

5. Data Security

We take reasonable measures to protect your data, including:

  • Encryption: User authentication data (cookies) is AES-256 encrypted before being stored.
  • Restricted Access: Only authorized system processes can access the database.
  • Environment Variables: API tokens, database credentials, and encryption keys are never hardcoded and are stored securely.

6. Data Retention

  • User profiles and associated game data are retained until the user deletes their profile using the /delete {profile_nickname} command.
  • Expired cookies must be refreshed by the user, or they will no longer function for check-ins.
  • Logs and analytics data are anonymized and stored for debugging and performance improvements.

7. User Rights & Control

Users can control their data in the following ways:

  • Registering a Profile: Users voluntarily provide their Hoyolab credentials for automated check-ins.
  • Updating Credentials: Users can refresh expired cookies using the /update_profile command.
  • Deleting Data: Users can delete their profiles at any time using the /delete {profile_nickname} command. This action removes all associated data from our database.
  • Opting Out: Users can stop using the Bot and remove it from their Discord server to discontinue future registrations from their server. To completely opt out, the user must delete their profiles.

8. Changes to This Policy

We may update this Privacy Policy from time to time. If significant changes are made, we will notify users through the bot or a public update.

9. Contact Information

If you have any questions or concerns about this Privacy Policy, please contact the bot administrator in the form of an issue on GitHub.