Accountability Bot · Privacy
Security & Privacy Overview
The app’s protections, and their limits.
Updated 12 September 2026 · About the main app
Built around controlled access
The app requires sign-in for account and task pages and checks user and owner permissions. Passwords are stored as hashes rather than readable passwords. Repeated failed sign-ins trigger a temporary account lockout, and selected administrative actions require the owner’s password again.
Your owner is part of the accountability relationship
Your assigned owner can review and manage your accountability information. Server administrators may also access the database, files, logs, and backups. App permissions are not a guarantee that data is hidden from the people operating the installation.
Connected services have their own boundaries
Discord proof checking uses configured channels and threads, checks the submitting Discord identity and proof code, and records matched responses and message references. It may inspect other messages in those channels while looking for proof. Channel permissions determine who else can see posts.
Notification settings control enabled delivery routes. Notifications can reveal task information on Discord or a device’s lock screen. Remote diagnostics also send installation, owner identity, and operational information. The Privacy Policy explains these data flows.
Hosting and backups matter
App records are held on the installation’s hosting machine, with backups where configured. The operator is responsible for secure hosting, HTTPS, strong secrets, updates, and access to backup storage. Local logs can contain sensitive proof excerpts. These records need the same care as the main database.
What we can and cannot promise
We can describe the access checks and safeguards implemented in the app. We cannot promise absolute security, anonymity, or that another person will never copy information shared with them.
We do not claim encryption at rest, zero-knowledge operation, end-to-end encryption of app data, SOC 2 compliance, or an independent security audit. This overview is not an audit or a public source-code release. Its description reflects the reviewed September 2026 app version; hosting settings and other versions can differ.
Ask before sharing something especially sensitive
Use the Request information form for privacy questions or to report a security concern. A short description and a contact method are enough to start; ask for a suitable way to share any sensitive technical details.