Privacy Policy
Last updated: September 11, 2026
- Who we are
- Google user data we access
- Microsoft mail
- Data we store
- How we use the data
- Sharing
- Retention & deletion
- Security
- Children
- Changes
- Contact
Who we are
AccountBot (“the app”) is a Discord bot that helps authorized operators retrieve Steam Guard one-time codes from linked email accounts.
Google user data we access
If you sign in with Google, the app requests the
gmail.readonly scope. With that permission we:
- Read your Gmail address (account identity)
-
List and read message content only for mail from
[email protected] - Parse those messages for Steam Guard / verification codes so they can be shown to authorized Discord users
We do not use Gmail data for advertising, analytics products, or sale to third parties. We do not transfer Google user data to other apps except as required to operate the bot for the account owner who linked it.
Microsoft mail
If you sign in with Microsoft, the app requests read access to mail via Microsoft Graph and applies the same Steam sender filter and purpose.
Data we store
- A label you choose for the mailbox
- Your email address
- OAuth refresh tokens (so the bot can keep reading Steam mail)
- Discord user IDs allowed to use the bot (configured by the operator)
Tokens and account metadata are stored on the operator’s server (for
example in a local accounts.json file). Codes are fetched
on demand and shown in Discord; they are not kept as a long-term archive.
How we use the data
Sole purpose: authenticate to your mailbox and retrieve Steam Guard codes for people the bot operator has authorized in Discord.
Sharing
We do not sell or rent your data. Codes and mailbox identity are only visible to Discord users on the operator’s allowlist. Hosting providers may process traffic as part of running the server.
Retention & deletion
Linked accounts remain until removed with the bot’s remove command or until the operator deletes stored credentials. You can also revoke access anytime in your Google Account permissions or Microsoft account security settings. After revoke or removal, the app can no longer read your mail.
Security
Access to the Discord bot is limited to configured user IDs. OAuth tokens should be treated as secrets on the host. Use HTTPS for the public OAuth callback domain.
Children
The app is not directed at children under 13.
Changes
We may update this policy. The “Last updated” date at the top will change when we do.
Contact
Questions about this policy or your data: contact the AccountBot operator who asked you to link your mailbox (the Discord server / bot owner).