Observer

Retention and erasure

Retention windows

Per server, under Overview: keep chat logs for 60 days, 6 months, 1 year, or 2 years — or forever, by leaving the window unset. An hourly sweep deletes messages past the window and records what it did in your audit trail.

What outlives the window

Messages under an active flag, cited by an open investigation finding, or covered by a legal hold survive any sweep — deleting evidence mid-case defeats the point of a moderation tool. They become deletable when the flag resolves, the case closes, or the hold releases.

Disconnected servers: the 60-day rule

If the Observer bot is removed from a Discord server and not re-invited, that server's chat logs are deleted 60 days after removal. Admins are warned at removal time — a dashboard banner and an email. Re-inviting the bot at any point stops the clock; your settings, ban lists, and audit trail are kept regardless.

Erasure requests

Community members have a right to be forgotten, and Observer gives you the machinery under Settings → Privacy:

  • The public form — every org has an unguessable privacy-request URL to share with your community (server rules, a pinned message). Submissions arrive as requests in your dashboard.
  • Filed by your team — moderators and admins can file a request directly.

Requests are processed in two admin steps — verify the requester is who they claim (Observer won't delete a person's history, or reveal what exists, on a stranger's say-so), then process. Processing erases the person's messages from your logs and permanently severs their records in Observer's research corpus from their identity. The outcome is recorded as a compliance log. Requests can also be rejected, with a reason.

Legal holds

When you're required to preserve data — a law-enforcement request, a dispute — place a hold scoped to a person, an event, or the whole org. Held data survives retention sweeps and erasure processing until an admin releases the hold; every hold records who placed and released it, and why.