Legal policies, feature reference, command list, and everything you need to know about using Antonio in your server.
Antonio collects the minimum data needed to function. We never sell your data. You can request deletion at any time.
When you use Antonio, we collect and process only what is strictly required to deliver the requested feature:
| Data Type | What We Store | Why |
|---|---|---|
| User IDs | Discord snowflake (numeric ID) | Identify users for moderation records, reminders, AFK, and personalisation |
| Guild IDs | Discord server snowflake | Per-server configuration: welcome, tickets, automod, roles |
| Moderation Records | Warn reason, moderator ID, timestamp, case type | Persistent mod history for server admins and appeals |
| Giveaway Data | Message ID, channel ID, participant user IDs, prize, end time | Running and resolving giveaways fairly |
| Ticket Data | Channel ID, opener user ID, open/close timestamps | Managing and tracking support tickets |
| Application Responses | Answers submitted through application portals | Delivering application to server staff for review |
| Reminder Data | Reminder text, channel ID, scheduled timestamp | Delivering scheduled reminders on time |
| AFK Status | AFK reason, timestamp set, ping count | Informing other members when you are away |
| QOTD Config | Channel ID, interval, last post time, template | Scheduling automatic question posting |
| Automod Config | Rule settings, exempt roles/channels, action type | Enforcing server-defined moderation rules automatically |
| Welcome/Booster Config | Channel IDs, message templates, role IDs | Automating welcome and boost announcement messages |
| Dashboard Accounts | Username (hashed), bcrypt password hash, linked Discord ID | Dashboard login and server management access |
| Verification Tokens | Token string, user ID, guild ID, creation time | Linking a Turnstile/OAuth verification to a Discord user |
| Sniped Messages | Last 10 deleted messages per channel (content, author, timestamp) | The a.snipe command — cleared on bot restart |
We do not collect, store, or process:
Your data is used solely to operate and improve Antonio:
For users in the European Economic Area, our legal bases are:
We never sell, rent, or trade personal data. Limited sharing occurs only where technically necessary:
Depending on your jurisdiction, you may have rights including: Access · Rectification · Erasure ("right to be forgotten") · Portability · Objection · Restriction of processing. To exercise any right, contact us via the Contact section. We respond within 30 days.
We implement technical and organisational measures including encrypted storage (AES-256), TLS 1.2+ in transit, environment-variable secret management, restricted access controls, and regular dependency audits. No system is 100% secure; we cannot guarantee absolute security.
Antonio is not directed at children under 13 (or 16 in the EEA). We do not knowingly collect data from children. If you believe a child has submitted data, contact us immediately and we will delete it.
Material changes will be announced in our support server. Continued use after any change constitutes acceptance of the updated policy.
By inviting Antonio to your server or using any of our services, you agree to these Terms in full. If you do not agree, do not use Antonio.
These Terms of Service ("Terms") constitute a legally binding agreement between you and the Antonio development team ("we", "us", "our"). By accessing or using Antonio ("the Service"), you confirm that you are at least 13 years of age, have read and understood these Terms, and agree to be bound by them in their entirety.
Antonio is a multi-purpose Discord bot providing the following capabilities (among others): real-time moderation, automated rule enforcement (automod), music playback in voice channels, AI-powered conversation and image analysis, giveaway management with quantum-random winner selection, member verification via Cloudflare Turnstile and Discord OAuth, ticket-based community support systems, staff application portals, Question of the Day automation, welcome and booster event messages, anti-raid and anti-nuke server protection, role management, sniping, AFK tracking, reminders, tags, notes, and a web-based management dashboard. The Service is provided free of charge. We reserve the right to modify, suspend, or discontinue any feature at any time without notice.
Antonio may be used for:
You agree not to use Antonio to:
If you are a server administrator who has invited Antonio:
Antonio includes AI-powered conversation features. You agree that when using AI features:
Antonio's music playback streams audio from publicly available sources. You agree that:
All code, design, branding, and content comprising Antonio are the exclusive property of the Antonio development team. You receive a limited, non-exclusive, non-transferable, revocable licence to use the Service solely for its intended purpose. You may not copy, modify, distribute, sublicense, sell, or create derivative works without explicit written permission.
The Service is provided "as is" and "as available" without warranties of any kind, express or implied. We do not warrant that the Service will be uninterrupted, error-free, secure, or meet your specific requirements.
To the maximum extent permitted by applicable law, the Antonio team shall not be liable for any indirect, incidental, special, consequential, or punitive damages — including loss of data, revenue, goodwill, or profits — arising from your use of or inability to use the Service. Our total aggregate liability shall not exceed USD $0, as the Service is provided free of charge.
We reserve the right to terminate or restrict access to Antonio at any time, with or without notice, for any violation of these Terms or conduct we deem harmful. You may terminate your use at any time by removing Antonio from your server. Upon termination, your data will be retained per our Data Retention Policy and then deleted.
You agree to indemnify and hold harmless the Antonio development team, its contributors, and affiliates from any claims, damages, losses, liabilities, and expenses (including legal fees) arising from your use of the Service, your violation of these Terms, or your violation of any third-party rights.
Any disputes shall first be attempted to be resolved through informal negotiation. Contact us via the Support Server or email. If unresolved within 30 days, disputes may proceed to binding arbitration under applicable arbitration rules. Class action claims are waived to the fullest extent permitted by law.
These Terms shall be governed and construed in accordance with applicable law. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
We may revise these Terms at any time. Continued use after any change constitutes acceptance of the updated Terms. Significant changes will be announced in our official support server with reasonable advance notice where possible.
These Terms, together with the Privacy Policy and Acceptable Use Policy, constitute the entire agreement between you and the Antonio team regarding the Service and supersede all prior agreements and understandings.
We take security seriously. If you discover a vulnerability, please disclose it privately before any public disclosure.
Follow responsible disclosure:
Include in your report: clear description · steps to reproduce · potential impact and severity · proof-of-concept code or screenshots (if safe to share).
| Step | Timeframe | Action |
|---|---|---|
| Acknowledgement | Within 48 hours | Confirm receipt and assign severity |
| Assessment | Within 7 days | Evaluate scope and impact |
| Fix — Critical | < 24 hours | Emergency patch deployed |
| Fix — High | < 7 days | Priority fix |
| Fix — Medium/Low | < 30 days | Scheduled patch |
| Disclosure | Agreed with reporter | Public acknowledgement (if applicable) |
Antonio includes built-in protective modules that monitor for: mass channel/role deletion · mass bans executed in rapid succession · unusual permission changes · webhook creation spikes · join rate anomalies. When triggered, the system removes elevated permissions from the offending account, logs the incident, and alerts the owner. These protections are best-effort and do not guarantee complete prevention of all attacks.
In the event of a confirmed security incident affecting user data: contain within 24 hours · notify affected users and server admins promptly · publish post-mortem in support server · notify applicable regulatory authorities if required by law (e.g. GDPR Art. 33).
| Data Type | Retention Period | Notes |
|---|---|---|
| Server configuration | Until bot is removed | All config deleted when Antonio leaves a server |
| Moderation cases & warns | Indefinite (admin-controlled) | Server admins can clear records at any time via commands |
| Giveaway data | 30 days after conclusion | Winner data retained for dispute resolution only |
| Ticket data | 90 days after closure | Auto-deleted unless an admin explicitly archives |
| Application responses | 60 days after decision | Admins can delete at any time |
| Reminders | Deleted on delivery | Immediately removed from storage after sending |
| AFK status | Deleted when cleared | No persistence after the member returns from AFK |
| Sniped messages | Until bot restart | In-memory only; max 10 per channel, cleared on restart |
| Verification tokens | 10 minutes | Expired tokens are purged automatically |
| Application tokens | 30 minutes | Expire after single use or time limit |
| Dashboard sessions | 24 hours | Invalidated on logout or automatic expiry |
| QOTD last_posted | Indefinite (config) | Part of server config, deleted with server data |
| Status incidents | 30 days | Status page history auto-trimmed |
a.clearcase or a.clearwarns.Some data may be retained longer where required by law or for legitimate purposes such as fraud prevention and legal compliance.
data.json on the bot's host server| Category | Examples | Severity |
|---|---|---|
| CSAM / Illegal Content | Any content involving minors sexually; content facilitating illegal acts | Zero Tolerance |
| Abuse & Harassment | Using mod commands to target users for protected characteristics; coordinated harassment campaigns | Critical |
| Bug Exploitation | Exploiting race conditions, bypassing permission checks, accessing restricted commands | Critical |
| Spam / Flooding | Mass command invocations; flooding channels via bot interactions; self-bots | High |
| Impersonation | Faking Antonio responses; pretending to be our staff in a server | High |
| API Abuse | Scripted automated requests to HTTP endpoints; scraping dashboard data | High |
| Ban Evasion | Creating alt accounts to re-enter servers after a global bot ban | High |
| Reverse Engineering | Decompiling, disassembling, or extracting proprietary bot components | Medium |
| Misinformation | Deliberately using AI features to generate and spread misleading content | Medium |
Actions are at our sole discretion. Appeals may be submitted via our support server.
The following are reserved exclusively for verified bot owners and are inaccessible to any server administrator or user: global user ban/unban · bot-wide enable/disable toggle · shard management · infrastructure commands. Attempting to access these commands without authorisation is a critical violation.
This policy explains how Antonio's web-facing services (Dashboard, Verification Portal, Application Portal) use sessions and storage.
| Name / Type | Purpose | Duration | Storage |
|---|---|---|---|
| Dashboard session token | Authenticates dashboard login; stores in localStorage | 24 hours or logout | Browser localStorage |
| Verification token | Links a pending verification to a Discord user; passed via URL parameter | 10 minutes | URL only (not stored) |
| Application token | Identifies an active application session; passed via URL | 30 minutes | URL only (not stored) |
| OAuth state | CSRF protection during Discord OAuth login flow | Single use | Temporary URL parameter |
Cloudflare __cf_bm | Bot detection by Cloudflare infrastructure | 30 minutes | Cookie (set by Cloudflare) |
We do not use Google Analytics, Facebook Pixel, advertising cookies, or any third-party tracking technology. We do not build profiles of individual users based on browsing behaviour.
Antonio's name, logo, source code, and all associated creative content are copyright © 2024–2026 the Antonio development team. All rights reserved.
Antonio's music features stream audio from publicly available sources. We do not store, cache, or redistribute copyrighted audio files. Music playback is intended for personal, non-commercial use within Discord voice channels. We are not responsible for content users choose to play. If you are a rights holder and believe Antonio's music features infringe your copyright beyond applicable fair use or safe harbours, contact us below.
A valid DMCA notice must include:
If content was wrongfully removed, you may file a counter-notice. Knowingly filing a false counter-notice may expose you to legal liability.
Antonio is a full-suite Discord bot. Below is a complete overview of every major feature module.
30m, 2h, 1d). Delivered to the channel where the reminder was set.a.snipe. Stores last 10 deleted messages per channel in memory. Cleared on bot restart for privacy.dash.html. Discord OAuth or username/password login. Configure every feature without Discord commands.Prefix commands use a. · Slash commands use /. Arguments in <angle brackets> are required; [square brackets] are optional.
All = any member · Mod = Kick/Ban Members or Manage Messages · Admin = Administrator or Manage Server · Owner = Bot owner only
1d, 12h).10s – 28d.a.tag <name>.30s, 10m, 2h, 1d.The Antonio dashboard (dash.html) lets you configure every feature visually without Discord commands. Access it via your bot's HTTP server URL.
Two login methods are available:
Dashboard session tokens are stored in your browser's localStorage and expire after 24 hours. Always log out on shared devices.
After login, you are shown a grid of servers where you have Manage Server permission AND Antonio is present. Click a server card to open its configuration.
| Panel | What You Can Configure |
|---|---|
| Welcome | Welcome/goodbye channel, message template with {user}/{server}/{count} variables, enable/disable toggle |
| Booster | Booster announcement channel, custom message, booster role assignment |
| Server | Custom server name display, server banner image URL, bot bio for this guild |
| Tickets | Panel channel, support role to ping, panel button label and message |
| Applications | Application review channel, approved role, question builder (up to 10 questions, short/long/choice types), panel setup |
| Trade Applications | Separate application flow for trade helper roles with dedicated panel and role assignment |
| Verification | Verification channel, unverified role, verified role, verification method (button/Turnstile/OAuth) |
| Autoroles | Roles automatically assigned on member join, with optional delay |
| Mod Log | Channel where all moderation actions are logged |
| QOTD | Enable/disable, channel, interval (1–168 hours), custom template, "Post Now" button |
| Automod | Enable/disable, log channel, action (delete/warn/timeout/kick), timeout duration, exempt roles/channels, per-rule toggles and thresholds |
| Anti-Nuke | Enable/disable, action thresholds, whitelisted admin IDs |
| Anti-Raid | Enable/disable, join rate threshold, lockdown action, auto-ban/kick toggle |
| Giveaways | View active giveaways, create from template, end/reroll from dashboard |
| Bot Profile | Custom bot nickname for this server, custom bio/about text |
| Random Roles | Configure a reaction/button panel that randomly assigns a role from a configured list |
All dashboard configuration is backed by an HTTP API running on the bot's server. Key endpoints:
| Endpoint | Method | Purpose |
|---|---|---|
/dashboard/login | POST | Authenticate with username/password |
/dashboard/signup | POST | Create a new dashboard account |
/dashboard/guilds | GET | List guilds available for management |
/dashboard/guild/{id}/automod | GET · POST | Read or write automod configuration |
/dashboard/guild/{id}/qotd | GET · POST | Read or write QOTD configuration |
/dashboard/guild/{id}/qotd/post | POST | Immediately post a question to the QOTD channel |
/dashboard/guild/{id}/welcome | GET · POST | Read or write welcome configuration |
/dashboard/guild/{id}/giveaways | GET · POST | List giveaways or create from template |
/stats | GET | Public live bot stats (no auth required) |
All non-public endpoints require a valid session token in the Authorization: Bearer <token> header. Scripted or automated access beyond normal dashboard use violates our Acceptable Use Policy.
Questions about these policies, a security issue, or need help? Reach us through any channel below.
| Channel | Expected Response | Best For |
|---|---|---|
| Discord Support Server | Usually within a few hours | General help, configuration questions, bug reports |
| Security Reports (DM) | Within 48 hours | Vulnerability reports — private disclosure |
| Within 3–5 business days | DMCA notices, formal data requests, legal enquiries | |
| DMCA Notices (email) | Within 14 days | Copyright takedown requests |
To exercise access, deletion, or portability rights, contact us via the Support Server or email with subject line "Data Request — [Your Discord Username]". We process all requests within 30 days.