Privacy Notice & Cookie Policy

Part A explains how UBITS processes personal information, Part B covers cookies, and Part C sets out the details specific to Modu.

Effective 12 September 2026 · Last updated 30 September 2026

Want to see or change the cookies on this device? Open cookie settings.

Part A: Privacy notice

1. Who is responsible for your data?

The data controller is:

UBITS LIMITED
Company number: 16156587
Privacy contact: [email protected]

Where required by applicable law, UBITS will appoint and publish details of an EU representative or other privacy representative.

2. What information may we collect?

Depending on how you use UBITS, we may collect:

Account information

  • username;
  • email address;
  • account identifiers;
  • password credentials in appropriately protected form;
  • profile information;
  • age or age-assurance information where required.

Community information

  • posts;
  • comments;
  • messages;
  • voice-chat information;
  • images;
  • videos;
  • uploaded files;
  • reactions;
  • reports;
  • moderation records; and
  • other User Content.

Technical information

  • IP address;
  • device information;
  • browser type;
  • operating system;
  • approximate location derived from technical information;
  • log information;
  • session information;
  • security information; and
  • information about how you use the Services.

Transaction information

If paid services are introduced, we may process:

  • transaction identifiers;
  • billing information;
  • subscription information;
  • purchase history; and
  • payment status.

Payment-card details may be processed directly by third-party payment providers rather than stored by UBITS.

3. How do we use personal information?

We may use information to:

  • provide the Services;
  • create and maintain accounts;
  • communicate with users;
  • provide community functionality;
  • moderate content;
  • investigate reports;
  • prevent fraud;
  • protect security;
  • investigate abuse;
  • improve the Services;
  • provide customer support;
  • administer competitions;
  • process payments;
  • comply with legal obligations;
  • establish or defend legal claims;
  • analyse usage;
  • send marketing where legally permitted; and
  • operate and develop our business.

4. Lawful bases

Depending on the circumstances, our lawful bases may include:

  • performance of a contract;
  • compliance with a legal obligation;
  • legitimate interests;
  • consent; and
  • protection of vital interests where applicable.

Where we rely on consent, you may withdraw consent at any time, without affecting processing that took place before withdrawal.

5. Legitimate interests

Where we rely on legitimate interests, these may include:

  • operating the community;
  • maintaining security;
  • preventing fraud;
  • moderating harmful activity;
  • improving functionality;
  • defending legal claims;
  • protecting users; and
  • managing the business.

We will balance those interests against your rights and freedoms.

6. User-generated content and moderation

User-generated content may be processed to:

  • publish it to other users where you choose to do so;
  • operate chat and community functionality;
  • enforce community rules;
  • investigate reports;
  • prevent abuse;
  • comply with legal obligations; and
  • protect users.

Moderation systems may include automated tools and, where appropriate, human review.

7. Automated decision-making and profiling

Where UBITS uses automated decision-making that produces legal or similarly significant effects, we will provide the safeguards required by applicable law.

Where applicable, users may have rights concerning:

  • meaningful information about the logic involved;
  • human intervention;
  • expressing their point of view; and
  • challenging the decision.

We will not rely on solely automated decision-making where prohibited by applicable law.

8. Artificial intelligence

If UBITS uses AI systems, information may be processed by those systems depending on the particular feature. Section 26 describes the AI processing in Modu.

UBITS will not use personal information to train third-party AI models unless there is an appropriate lawful basis and users have been given the information required by applicable law.

9. Who may receive personal information?

We may share information with:

  • hosting providers;
  • cloud service providers;
  • software providers;
  • security providers;
  • moderation providers;
  • analytics providers;
  • customer-support providers;
  • payment providers;
  • professional advisers;
  • insurers;
  • regulators;
  • law-enforcement agencies where legally required; and
  • companies involved in a corporate transaction.

Service providers will only receive information appropriate for the services they provide.

10. International transfers

Some providers may process information outside the UK or European Economic Area.

Where applicable, UBITS will use an appropriate lawful transfer mechanism, such as:

  • adequacy regulations;
  • UK International Data Transfer Agreements;
  • UK Addendum to EU Standard Contractual Clauses;
  • EU Standard Contractual Clauses; or
  • another legally recognised safeguard.

Further information may be obtained by contacting us.

11. Retention

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, unless a longer period is required by law.

Different categories may have different retention periods.

12. Security

We use appropriate technical and organisational measures designed to protect information against:

  • unauthorised access;
  • accidental loss;
  • destruction;
  • alteration;
  • disclosure; and
  • other unlawful processing.

No internet system is completely secure.

13. Your UK data-protection rights

Subject to applicable law, you may have rights to:

  • access your personal information;
  • correct inaccurate information;
  • request deletion;
  • restrict processing;
  • object to processing;
  • receive portable information;
  • withdraw consent;
  • object to direct marketing; and
  • challenge certain automated decisions.

Requests should be sent to:

[email protected]

We may need to verify your identity.

14. Complaints

Please contact us first so that we can investigate your concern.

From 19 June 2026, organisations are subject to new statutory requirements concerning data-protection complaints under the Data (Use and Access) Act 2025. UBITS will maintain a complaints process appropriate to its obligations.

You may also complain to the Information Commissioner's Office (ICO) if you believe your data-protection rights have been infringed.

15. Children

Where children are likely to access a service, UBITS will consider:

  • the UK Children's Code / Age Appropriate Design Code;
  • age assurance;
  • privacy-by-design;
  • default privacy settings;
  • parental controls where appropriate;
  • children's rights and interests;
  • profiling restrictions;
  • geolocation controls; and
  • targeted advertising restrictions.

16. Data protection by design

UBITS will consider privacy and data protection from the design stage of products, features and systems.

This includes AI, moderation, analytics, advertising, community functionality and new features.

17. What are cookies?

Cookies and similar technologies may store or access information on your device.

We use them only where permitted by applicable law.

18. Essential technologies

Some technologies are necessary to:

  • authenticate users;
  • maintain security;
  • remember essential settings;
  • maintain sessions;
  • prevent fraud; or
  • provide functionality requested by the user.

These may be used where legally permitted without consent.

19. Analytics

Where analytics technologies are not strictly necessary, UBITS will obtain consent where required.

Analytics may help us understand:

  • traffic;
  • feature usage;
  • errors;
  • performance; and
  • user journeys.

Modu uses Google Analytics 4, the same property as ubits.tech, only after you accept analytics in the cookie banner or on the Cookie settings page. It receives the pages you visit (with identifiers removed from their addresses), how you arrived, your device and browser type and approximate location. We do not send your Discord account, servers or chat content to it. You can withdraw consent at any time on the Cookie settings page, which also deletes its cookies.

20. Advertising

If UBITS uses advertising or tracking technologies, these will be disclosed through the cookie-management mechanism.

Where consent is legally required, advertising cookies will not be activated until valid consent has been obtained.

22. Third-party technologies

Third-party services may set cookies or access information where permitted.

The cookie settings page lists every cookie and similar technology Modu uses, including the third-party verification check on the report form.

23. Managing cookies

Users can manage cookies through:

modu.ubits.tech/cookies

Browser controls may also be available.

Disabling essential cookies may affect functionality.

24. Changes

We may update this Privacy Notice and Cookie Policy when:

  • our Services change;
  • our processing changes;
  • legal requirements change; or
  • regulatory guidance changes.

The latest version will be published on the website.

25. Contact

UBITS LIMITED
Company number: 16156587
Privacy: [email protected]
Data protection complaints: [email protected]

Part C: Modu

26. How Modu uses your information

This part describes the processing specific to Modu, the UBITS service that manages Discord servers. Parts A and B apply to it as well.

Your account

  • You sign in with Discord. We receive your Discord user ID, username, avatar, email address and the list of servers you belong to (the identify, email and guilds permissions). With the guilds.join permission, which Discord shows as "Join servers for you", our bot adds you to the UBITS community server when you sign in; it is used for nothing else, and you can leave that server at any time. We do not receive or store your Discord password.
  • Discord access tokens are encrypted at rest (AES-256-GCM). Session tokens are stored only as one-way hashes.
  • Sign-in sessions expire after 7 days without use and after 30 days at most.

Servers you connect

  • For each server you connect, we store a snapshot of its structure (channels, categories, roles and permissions) so the agent can plan changes. Snapshots are refreshed and removed when you disconnect the server.
  • When a task needs it, the agent reads message content in the channels it operates on. That content is used only for the task.
  • We keep a history of the operations the agent performs, so changes can be reviewed and reversible ones undone.
  • On servers that use them, moderation features process messages as they are sent (for automod and commands), and the snipe command keeps recently deleted or edited messages in memory for up to 2 hours so members can see them. Snipe data is never written to our database, and server admins can turn it off.

Members of servers that use the bot

  • In servers that turn them on, the bot records activity to run its features: how many messages each member sends per channel and per day, time spent in voice, which member they reply to (counted, not the message), XP and levels, activity streaks, and which invite each member joined through. These power stats, leaderboards, rank and Wrapped cards, streak and stat roles, and invite tracking. Message content is not stored for these.
  • Any member can stop being counted in a server with .statsprivacy (or /privacy); this also deletes what was counted about them there, including replies other members sent them.
  • Features members use themselves store what they need: reminders (text and time, deleted once sent), AFK status and the nickname to restore, birthdays, suggestions and votes, and ban appeals (the answers given and the staff decision). Moderation keeps a case history (action, moderator, reason) and, where temporary roles are used, when a role is due to be taken back.
  • When the bot bans someone it may send them a direct message with the reason and, if the server takes appeals, a link to appeal.

AI processing

  • Your instructions, and the server information a task needs, are sent to the AI model provider we use to plan and carry out the task. That is one of Google (Gemini), OpenAI, Anthropic or Groq, depending on configuration. These providers may process data outside the UK and EEA; section 10 applies.
  • We do not sell your data, and we do not use your server content to train AI models.
  • We record usage (such as the number of actions and model tokens used) to apply plan limits.

Payments

  • Subscriptions are processed by Stripe. We store your plan, subscription status and billing period. Card details are held by Stripe, never by us.

Reports

  • When you use the report form, we store the report, any name and email you choose to give, and a one-way hash of your IP address to detect abuse. The verification check on that form is provided by Cloudflare Turnstile.

Deleting your data

  • You can disconnect a server at any time. To delete your account and associated data, email [email protected]. We will remove it, except for records we must keep for legal, accounting or safety reasons.