Privacy Policy
Last updated: 9 October 2026
This policy explains what information TicketAssist AI (the Discord bot and the website at ticketassistai.io, together the "Service") collects, why, who it's shared with and the choices you have. It applies to server owners and admins who use the Service, members of Discord servers where the bot is added, and visitors to our website.
1. Who we are
TicketAssist AI is operated by ClassTech Development ("we", "us", "our"), based in the United Kingdom. You can contact us through our contact page.
2. Our role
- Server content. When a Discord server adds TicketAssist AI, that server's owner decides how the bot is used there: which channels it works in, what its knowledgebase says and which features are on. For the messages and member information the bot handles in that server, the server owner is the controller and we process the information on their behalf to provide the Service.
- Our own records. We are the controller for dashboard accounts, billing, rewards, the AI blacklist, security and operational logs, and messages you send to our own support server.
If you're a member of a server that uses TicketAssist AI and have a question about how that server uses it, please contact the server's owner first. You can also contact us.
3. What the bot can see
Like other Discord bots, TicketAssist AI receives messages from Discord in the channels its role is allowed to view, and receives basic member information (such as usernames and roles) for servers it's in. This depends on the permissions the server gives it.
- The bot only reads and acts on message content in support tickets (channels in the server's ticket category, or opened from a TicketAssist AI ticket panel) and in channels a server has set up as an open AI support channel.
- For every message Discord delivers, the bot records a short operational log line (time, server name, channel name and the sender's Discord username, without the message content). We use these logs to run, debug and secure the Service.
Server owners control what the bot can see through its role and channel permissions.
4. Information we collect
From Discord servers using the bot
- Identifiers: server, channel, role, message and user IDs; usernames and display names.
- Ticket content: messages in tickets (text, and images such as screenshots on plans with screenshot reading), answers to ticket question forms, who opened, claimed and closed each ticket, and when.
- AI support channel content: messages sent to the AI in a channel or forum a server has set up for AI answers, and recent messages from the same person in that channel for context.
- Imported content: web pages and files a server imports into its knowledgebase. Uploaded files are deleted once the import finishes.
- Transcripts: copies of ticket conversations created when a ticket is deleted or a transcript is requested.
- Feature data: AI ticket summaries, feedback ratings, questions the AI couldn't answer (knowledge gaps), priority and incident flags, and drafts created with Ticket to Knowledgebase.
- Server configuration: settings, knowledgebase articles, ticket panels, topics and branding.
- Usage: counts of AI messages and tickets, used for plan limits and analytics.
- Ratings: the 1-5 star rating a member gives when a ticket closes (sent by Discord DM), linked to the ticket and the staff member who handled it, used for the server's team stats.
- Notification settings: a webhook URL and email address a server chooses for ticket notifications, and the notifications sent to them (ticket number, member's username, topic and reason).
- Safety data: AI misuse warnings and blacklist records (Discord user ID, the server, a short reason and dates).
- Security scanning: on plans with secret detection, messages are scanned for passwords, tokens and keys. When one is found, the original message is deleted and only a redacted version is stored.
From the website and dashboard
- Discord sign-in: when you log in with Discord we receive your Discord ID, username, avatar, email address and the list of servers you're in (to show the servers you can manage).
- Billing: payments are handled by Stripe. We receive and store your Stripe customer and subscription IDs, plan, billing status and dates. We never receive or store your full card details.
- Referrals: your referral code, who you referred (or who referred you), and referral rewards earned and used.
- Top-ups: one-off AI message purchases (amount, server and Stripe session reference).
- Rewards: Daily Reward spins, Advent Calendar doors and results, votes received from listing sites (Top.gg, DiscordForge) with your Discord ID, and bonus spins. For cash prizes, the details needed to verify and pay you.
- Activity logs: changes made from the dashboard (who, what, when).
- Technical data: IP address, browser type and request logs kept by our web host, and a session cookie (see Cookies).
When you contact us
Messages and tickets you send us through our contact page or support server.
5. How we use it, and our legal bases
- To provide the Service: generating AI replies, running tickets, transcripts, summaries, analytics, reminders and the features a server turns on (performance of a contract with the server owner, and our legitimate interest in providing the Service to their members).
- To manage accounts, plans and payments (contract; legal obligation for tax and accounting records).
- To keep the Service safe: preventing abuse, enforcing the AI blacklist and our Terms, detecting fraud in rewards, and securing systems (legitimate interests).
- To improve the Service: fixing bugs and understanding which features are used, using aggregated or operational data (legitimate interests).
- To run rewards such as the Daily Reward, vote rewards and the Advent Calendar (contract / the rewards terms).
- To communicate with you: service messages, ticket transcripts and reward notifications by Discord DM, and replies to support requests (contract; legitimate interests).
- To meet legal obligations and respond to lawful requests.
We don't sell personal information, and we don't use it for advertising.
6. AI processing
AI replies are generated by Anthropic (Claude) through its API. To produce a reply we send Anthropic the relevant conversation, any screenshots (on plans with screenshot reading), the server's matching knowledgebase articles and its AI settings. When a server imports articles, we fetch the web pages it links to (public pages only) or read the file it uploads, and send that content to Anthropic to turn into articles. When staff use "Write with AI", the related ticket conversation is sent to draft the article. Anthropic processes this data to return a response. Under its commercial terms it does not train its models on data sent through its API by default. Passwords, tokens and keys caught by secret detection are not sent.
AI replies may be inaccurate. Please don't share sensitive personal information (such as health, financial or government ID details) in tickets unless the server you're in has asked you to and you're comfortable doing so.
7. Who we share it with
- Discord: the platform the bot runs on.
- Anthropic: AI replies, summaries and related features.
- Stripe: payments and billing.
- Our hosting and infrastructure providers: to store data and run the Service.
- Vote listing sites (Top.gg, DiscordForge): they tell us when a Discord account votes.
- Destinations a server chooses for notifications: when a server turns on notifications, ticket details are sent to the webhook URL or email address it set, which may be run by another company.
- The server you're in: server owners and their staff can see tickets, transcripts, logs, summaries, feedback and analytics for their own server, in Discord and on the dashboard.
- Our support team: may access a server's data to provide support, investigate abuse or fix problems. Access to ticket content and customer details requires a recorded reason, is time-limited and is logged.
- Authorities or others where required by law, or to protect the rights, safety and security of users, the public or us.
- A buyer or successor if the Service is sold or restructured, under this policy.
8. International transfers
Some providers (including Discord, Anthropic and Stripe) process data outside the UK, mainly in the United States. Where this happens we rely on UK adequacy regulations (such as the UK-US data bridge) or approved safeguards such as the UK International Data Transfer Addendum and standard contractual clauses.
9. How long we keep it
- Ticket messages and transcripts: for the period the server owner chooses on the dashboard's Data & privacy page (30 days to 2 years; 12 months if they don't choose), then deleted automatically. Server owners can delete them sooner at any time.
- Other feature data (articles, settings, unanswered questions): while the server uses TicketAssist AI and the data is needed for the features it has turned on, or until the server owner deletes it.
- Servers that remove the bot: the server owner can delete all of their server's data on the Data & privacy page, or ask us to. We may also delete data for servers that have been inactive for an extended period.
- Ratings: for the same period as ticket messages, or until the server owner deletes them.
- Notification emails: deleted from our queue 30 days after they're sent.
- Operational logs: kept for a short period (normally up to 30 days) unless needed to investigate a security or abuse issue.
- AI blacklist records: while the block is active, then deleted automatically 12 months after it ends (or 12 months after the last warning), to apply repeat-misuse rules.
- Accounts and dashboard logs: while your account is active, and deleted on request.
- Billing records: as long as tax and accounting law requires (usually 6 years in the UK).
- Rewards records: as long as needed to run the rewards and prevent abuse, and longer for cash prizes where accounting rules require.
10. Security
We use access controls, encrypted connections, limited staff access with audit logs, and automatic secret detection on supported plans to protect information. No system is perfectly secure, so we can't guarantee absolute security. If a breach affects your personal information, we'll notify you and the regulator where the law requires.
11. Your rights
Under UK data protection law you can ask to access, correct or delete your personal information, to restrict or object to how we use it, and for a copy in a portable format. Where we rely on consent, you can withdraw it at any time. To make a request, contact us through our contact page. We may need to verify your identity, and we'll reply within one month. If your request is about a server where we act for the server owner, we may pass it to them.
You can also complain to the UK Information Commissioner's Office (ico.org.uk). We'd appreciate the chance to help first.
Server owners can choose how long ticket conversations are kept, and delete their ticket history or all of their server's data, on the dashboard's Data & privacy page. Billing records are kept because the law requires it.
12. Children
The Service is for people who meet Discord's minimum age (13 in the UK, or older where local law requires). We don't knowingly collect information from anyone younger. If you think a child has given us information, contact us and we'll delete it.
13. Cookies
The website uses one strictly necessary session cookie to keep you signed in and protect forms. We don't use advertising or tracking cookies. Stripe may set its own cookies on its checkout pages.
14. Direct messages
The bot may DM you ticket transcripts (if the server has this on), reward notifications and service messages. You can stop DMs by changing your Discord privacy settings for the server.
15. Changes
We may update this policy. We'll change the date at the top and, for significant changes, give notice on the website or in our support server.
16. Contact
For any privacy question or request, contact ClassTech Development through our contact page.
TicketAssist