Privacy Policy
Last updated: August 11, 2026
This Privacy Policy explains what information RowBot ("we", "us", "our", operated by softsrv) collects when you use the Service, how we use it, and the choices you have. It should be read alongside our Terms of Service.
1. Information We Collect
From Discord (when you sign in)
When you log in with Discord, Discord shares your Discord user ID, username, and email address with us. If you're a server manager, we also read the list of servers you manage so we can show you which ones RowBot is available to install on.
From Concept2 (when you connect your Logbook)
When you link your Concept2 Logbook account, we store an encrypted access token (and refresh token, if provided) so we can fetch your workout results on your behalf. We do not receive or store your Concept2 password.
Workout results
We do not store your workout history. When Concept2 notifies us that you've logged an activity, we fetch the details for that single result directly from Concept2's API, render it into an image, post it to your configured Discord channel, and discard it — we keep no historical record of your workouts in our database.
Discord server registrations
If you register to receive results in a Discord server (via the site or the
/setchannel flow), we store
your Discord user ID, Discord username, and the server (guild) ID and name.
Session & security data
To keep you signed in, we store a hashed (not plaintext) refresh token, plus the device type, IP address, and browser/user-agent string associated with each login session, so you can view and revoke your active sessions from your profile page.
2. How We Use Information
- To authenticate you and keep you signed in
- To fetch your workout results from Concept2 and post them to the Discord channel you've configured
- To show you which Discord servers you can install or register RowBot to
- To let you manage your active sessions and revoke access from devices you no longer use
- To maintain the security and reliability of the Service (e.g. rate limiting, abuse prevention)
We do not use your data for advertising, and we do not sell your data to anyone.
3. How We Share Information
We share information only as necessary for RowBot to function:
- Discord — we post your generated result card to the Discord channel your server has configured, visible to that server's members.
- Concept2 — we send your access token to Concept2's API to fetch your workout data.
We do not share your data with any other third party, and we do not use third-party advertising or analytics trackers on this site.
4. Data Retention
| Data | Retention |
|---|---|
| Workout results | Not stored — fetched, posted, and discarded |
| Refresh tokens (sessions) | Purged 90 days after expiry or revocation |
| Account data (email, Discord/Concept2 links) | Kept until you delete your account |
A background job runs daily to purge expired or stale session and verification records per the schedule above.
5. Data Security
- Concept2 and Discord access/refresh tokens are encrypted at rest
- Session tokens are hashed (SHA-256) before storage — the raw token exists only in your browser's cookie
- Session cookies are
HttpOnly, sent over HTTPS, and never readable by JavaScript - We do not store passwords — RowBot has no password-based login at all
6. Your Rights & Account Deletion
You can permanently delete your RowBot account and all associated data (linked connections, sessions, and registrations tied to your account) at any time from your profile page. This action is immediate and cannot be undone.
7. Children's Privacy
RowBot is not directed at children under 13, matching Discord's own minimum age requirement. We do not knowingly collect information from anyone under 13. If you believe a child has provided us data, contact us and we'll remove it.
8. Cookies
We use two cookies, both strictly necessary for the Service to function: an access token and a refresh token, both used solely to keep you signed in. We do not use tracking, advertising, or analytics cookies.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we'll update the "Last updated" date above.
10. Contact
Questions about this Privacy Policy, or requests regarding your data? Reach out at softsrv.inc@gmail.com.