Legal
Privacy Policy
Last updated: August 12, 2026
1. Who We Are
Keystone Management ("we", "us") operates the Keystone Management web dashboard at keystonemgmt.io, the Keystone Management Discord bot, Keystone CAD at cad.keystonemgmt.io, and the Keystone desktop companion application (together, the "Service"). This policy covers all of them. Keystone Atlas is separate open-source software released under the MIT Licence. It runs entirely in your browser, has no account system, and sends us no data; this policy does not apply to it. We are not affiliated with Roblox Corporation, Discord Inc., Police Roleplay Community, Stripe, Inc., or Google LLC.
2. What Data We Collect
- Discord user ID — Collected when you sign in with Discord OAuth or when a member verifies in your server.
- Roblox username & user ID — Collected during the Roblox verification flow to link your Discord account to your Roblox identity.
- Server join timestamps — When you join a Discord server that uses this Service, the bot records the date and time of your join. This is used solely to enforce the minimum-tenure requirements that server administrators configure on application forms.
- Application submissions — If you submit an application form through the Service, we collect your answers (which may include text, numbers, URLs, and images you choose to upload), your Roblox username, and your Discord user ID. The resulting submission record also stores the review status and any reviewer notes added by server staff.
- Uploaded images — Images submitted through application forms are compressed and stored in Supabase Storage. Server administrators may also upload banner images for their forms, which are stored in the same storage bucket.
- Moderation records — When a moderation action (warning, mute, or kick) is issued against a member, we store the action type, reason, target Roblox username and Discord user ID, the issuing moderator's Discord user ID, and a timestamp.
- Warning records — Individual warnings issued to members, including the reason and the Discord user ID of the person warned, are stored per guild.
- ERLC server key — Provided by you when configuring Voice Routing or Mod Tools. Stored encrypted at rest with AES-256-GCM; the raw key is never returned by the API.
- Zone & channel configuration — Coordinate bounds and Discord voice channel IDs you create in the Zone Editor.
- Guild metadata — Discord server ID, server name, server icon hash, and the IDs of roles and channels you configure in the dashboard.
- Staff, training & HR records — Staff profiles, training records, and related data that server administrators enter or generate through the HR features.
- Shift & patrol data — Shift clock-in/out timestamps and patrol log entries tied to Discord user IDs.
- Ticket data — Thread IDs, the Discord user ID of the ticket opener, category name, status, close reason, and timestamps.
- Keystone CAD records — The in-character profile you create (name, date of birth, and similar roleplay details), together with dispatch calls, incident reports, citations, BOLOs, licences, vehicles, property and wallet records created in the CAD. This is fictional roleplay content, but it is tied to your Discord user ID and we treat it as your data.
- Billing information — If your server subscribes to a paid plan, we store a Stripe customer ID, the subscription tier, billing period, and status. Card numbers and payment details are handled entirely by Stripe and never reach our servers.
- AI feature content — Messages you send to Keystone Kal and the prompts and images you submit to the AI Livery Generator, along with what those features return. See section 6.
- Usage analytics — Pages visited, a small number of named actions (such as starting a subscription checkout), and — where you have not declined cookies — session replays of your use of the dashboard and CAD. Text you type into form fields is masked before a replay leaves your browser. See section 5.
- Error diagnostics — When something goes wrong, we receive an automatic error report containing the error and stack trace, the page or command involved, and basic browser or application information. These reports can include your Discord user ID so we can correlate a fault with the account that hit it.
3. How We Use Your Data
We use collected data to provide and operate the Service: verifying members, routing players to voice channels, processing support tickets, enabling moderation and HR features, evaluating application submissions, running the CAD, taking payment for paid plans, diagnosing faults, understanding which parts of the product are used, and displaying your server configuration in the dashboard. We do not sell or rent your data. We do not share it with third parties for their own marketing. Where data-protection law such as the UK or EU GDPR applies to you, our legal bases are: performance of a contract (operating the Service and the features your server has configured); our legitimate interests (keeping the Service secure and working, diagnosing faults, understanding product usage in the aggregate); your consent (advertising and analytics cookies, which you can decline and later change); and compliance with legal obligations.
4. Where Your Data Is Stored
Data is stored in a Supabase PostgreSQL database and Supabase Storage. The Discord bot runs on Railway, and the dashboard and CAD are hosted on Netlify. ERLC server keys are encrypted with AES-256-GCM before storage. Access is restricted by row-level security policies keyed to your Discord user ID. Uploaded images are stored in a non-public-by-default bucket with scoped access. We are based in the United States and our infrastructure and service providers are located primarily in the United States. If you access the Service from outside the United States, your data will be transferred to and processed there, where data-protection law may differ from that of your own country. We take reasonable precautions but cannot guarantee absolute security.
5. Analytics
We do not show advertisements anywhere on the Service, and we do not share your data with advertisers. We use PostHog for product analytics to understand how the dashboard is used and where it needs improving. PostHog records page visits, a small number of named actions (such as starting a subscription checkout), and — once you sign in — associates them with your Discord user ID and username. It also records anonymised session replays of dashboard usage; all text you type into form fields is masked before the recording leaves your browser. We do not use this data for advertising and we do not share it with advertisers. If you decline cookies, analytics data is held in memory for the current tab only, no analytics cookies or local storage are written, and no session replay is recorded.
6. AI Features
Two features send content to third-party AI providers so they can process it on our behalf. Keystone Kal builds automations from your instructions. To do that, your chat messages and the relevant parts of your server's configuration — such as the names of channels and roles the automation needs to reference — are sent to OpenRouter, which routes the request to a model provider. The AI Livery Generator sends the prompt and any source image you provide to Replicate, which runs the image model. We do not send these providers your Discord credentials or your ERLC server key. We do not use your content to train our own models, and we have no control over the retention or training practices of the underlying model providers beyond what their own terms state. If you would rather not have content processed this way, do not use these features — the rest of the Service works without them.
7. Third-Party Services
- Discord — OAuth login and bot functionality. Subject to Discord's Privacy Policy.
- Roblox — OAuth for account linking. Subject to Roblox's Privacy Policy.
- ERLC API — Live player position data queried with your server key. Subject to ERLC's terms.
- Stripe — Payment processing for paid plans. Card details are handled by Stripe and never reach us. Subject to Stripe's Privacy Policy.
- PostHog — Product analytics and session replay for the dashboard and CAD. Subject to PostHog's Privacy Policy.
- Sentry — Automatic error reporting across the dashboard, bot, CAD and desktop app. Reports can include your Discord user ID. Subject to Sentry's Privacy Policy.
- OpenRouter — Routes Keystone Kal's requests to an AI model provider. See section 6. Subject to OpenRouter's Privacy Policy.
- Replicate — Runs the image model behind the AI Livery Generator. See section 6. Subject to Replicate's Privacy Policy.
- Supabase — Database and file storage hosting. Subject to Supabase's Privacy Policy.
- Netlify — Web hosting and serverless functions. Subject to Netlify's Privacy Policy.
- Railway — Hosting for the Discord bot. Subject to Railway's Privacy Policy.
8. Cookies
We use cookies and similar browser storage for two purposes beyond what is strictly needed to sign you in: advertising on the verification page, and product analytics. A consent banner is shown on your first visit. If you decline, no advertising or analytics cookies are set, analytics is held in memory for the current browser tab only, and no session replay is recorded. Clearing your browser storage for the site will make the banner appear again so you can change your answer. Storage that is strictly necessary — such as the token that keeps you signed in — is not covered by that choice, because the Service cannot function without it.
9. Data Retention
We retain your data for as long as your server uses the Service. Verified member records, zones, application submissions, uploaded images, CAD records, and configuration are deleted upon request. Server keys are deleted when you remove the ERLC configuration in the dashboard. Server join timestamps are retained only while the guild is active in the Service. Analytics and error-diagnostic data are kept on a rolling basis by our providers under their standard retention periods and are not retained indefinitely by us. Billing records may be retained for as long as we are required to keep them for tax and accounting purposes. We do not retain data for longer than necessary.
10. Your Rights
You have the following rights over your personal data: • Access & Export — You may download a copy of all data we hold about you at any time from your dashboard under Account → Export My Data. The export is provided as a JSON file and is generated immediately. • Correction — You may request correction of inaccurate data. • Deletion — You may request deletion of all your personal data at any time. We will action deletion requests within 30 days. • Withdraw consent — You may change your cookie choice at any time, as described in section 8. Depending on where you live, you may also have the right to object to or restrict certain processing, to receive your data in a portable format, and to complain to your local data-protection authority. To exercise any right not covered by the self-service export, contact us using the details in section 13. We do not charge for this, and we will not treat you differently for asking.
11. Children
The Service is not directed at children under 13, and you must be at least 13 to use it. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The revision date at the top of this page will reflect the latest changes. Where changes are material, we will ask you to accept the updated version the next time you use the Service; otherwise, continued use after changes are posted constitutes acceptance of the updated policy.
13. Contact
For privacy-related questions, data access requests, or deletion requests, email privacy@keystonemgmt.io. You can also reach us via our Discord support server; links are available on the main site.
