Privacy Policy
Rankit, by BuiltByTerra
Last updated: July 25, 2026
1. Introduction
This Privacy Policy describes how BuiltByTerra collects, uses, and stores information when you use Rankit. We are committed to handling your data responsibly and transparently.
2. Data We Collect
We collect only the data necessary to operate Rankit:
- Guild (Server) ID, to store per-server configuration such as the level-up announcement settings.
- Per-member XP records, your user ID together with your total XP and current level, one record per server you share with Rankit. Nothing else about your activity is recorded.
- Configuration IDs, reward role IDs and the levels that unlock them, and the level-up announcement channel ID.
- Timestamps, when a member's XP record was last updated and when settings were changed.
- Error diagnostics, if something fails, a short technical record of the error, which may include the server and user id involved, is written to an internal log and automatically deleted after 30 days.
- Operational analytics, the id and name of each server Rankit is in, that server's member count, and the dates Rankit was added to or removed from it, plus hourly totals of how many times each command was used. Command totals are counts only: they record that a command ran forty times in an hour, never who ran it, what they typed, or which server they ran it in.
- Product announcements, when we post an update about Rankit in your server we record which server received it, when, and the id of the message itself, so that the same update is never posted twice and can be moved if you later choose a different channel for it. Replying to one is entirely optional and only possible for someone with the Manage Server permission; if they do, we store what they wrote along with their Discord user id and handle, and the channel it was written from so that we can answer there. Any answer we send is posted publicly in that channel, never what they wrote to us. Choosing which channel updates should go to records that channel id and who chose it; turning announcements off records the server id and who turned them off, and nothing else. Both are reversible from the same buttons at any time.
Rankit never reads messages, it does not request Discord's Message Content intent at all, so message text is technically inaccessible to it. XP is awarded from the fact that a message event occurred, nothing more. The Server Members intent is used to keep voice channel member lists populated so voice XP can be awarded to members actually present.
3. How We Use Data
Collected data is used solely to:
- Award XP and compute levels: message events and voice presence are counted, message content is never read or stored.
- Render rank cards and leaderboards: XP totals are sorted and displayed on request.
- Assign level rewards: reward role IDs are compared against a member's level to grant exactly those roles.
- Announce level-ups: the configured announcement settings decide where (and whether) level-ups are posted.
- Diagnose faults: error records are used only to find and fix bugs, and are never used to build a profile of anyone.
- Tell the servers that installed Rankit about changes to it, and read what they choose to write back.
We do not sell, share, or disclose your data to third parties for marketing or advertising purposes.
4. Data Storage and Security
Data is stored in a PostgreSQL database with encrypted connections (SSL/TLS). We take reasonable technical measures to protect stored data from unauthorized access. However, no system is completely secure, and we cannot guarantee absolute security.
Operational analytics are kept in a database separate from Rankit's feature data. The analytics themselves carry no user identifiers of any kind, no user ids, no message content, and no per-member activity. That same separate database also holds the delivery record for product announcements, anything a server admin chooses to write back to us, and the records of our ambassador program. Those three do include the Discord user id and handle of the person who wrote in, because a message someone sends us has to come from someone; none of them is ever populated without a deliberate action by that person. It is readable only by the developer, through a private dashboard that requires both a randomly generated access token and a time-based one-time code from an authenticator app. That dashboard is excluded from search engines and returns an ordinary "page not found" to anyone who is not signed in. Its database credential can read the analytics and write only the announcement and ambassador records; it cannot reach Rankit's feature data at all. None of this is ever sold, shared, or used for advertising.
5. Data Retention
Your leveling data, server settings, XP records, exclusion lists, and reward configuration, is retained while Rankit remains in your server. If Rankit is removed, all of that server's data is automatically and permanently deleted 7 days after removal. Re-adding Rankit within those 7 days cancels the scheduled deletion and restores your data. You may also request immediate deletion at any time (see Section 8).
This applies to operational analytics with no exception. When Rankitis removed from a server, that server's analytics record, its id, name, member count, and install and removal dates, is permanently deleted on the same 7-day schedule as everything else, from the analytics database as well as the application's own. Announcement records go with it: which updates that server received, whether it turned announcements off, and anything it wrote back to us. Re-adding Rankit within those 7 days cancels the deletion. Nothing about a server that removed Rankit is retained beyond that window.
6. Third-Party Services
Rankit operates within the Discord platform and is subject to Discord's Privacy Policy. We do not integrate with other third-party data processors beyond the database provider used to store operational data.
7. Children's Privacy
Rankit is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided data, please contact us so we can remove it.
8. Your Rights and Data Requests
You may request access to, correction of, or deletion of your data at any time. For server administrators, this includes all data associated with your guild ID.
To submit a data request, join our Discord community and open a support ticket with your Discord server ID or user ID.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of Rankit after changes constitutes your acceptance of the revised policy.
10. Contact
For questions, concerns, or data requests, join our Discord community.