XBGuide Privacy Policy
Last updated: August 2, 2026
XBGuide is a Discord bot and website that shows Xbox Live information: profiles, achievements, gamer cards, Game Pass and store listings, and independent Xbox service status. This policy explains exactly what is stored, why, and how to remove it.
Data the Discord bot stores
XBGuide stores the minimum needed to work:
- Account link (only if you run
/link set): your Discord user ID, your Xbox gamertag, and your Xbox user ID (XUID). During verification a short code and its expiry are stored temporarily, then cleared. - Preferences: your saved card theme and custom accent color.
- Feedback: messages you voluntarily submit with
/feedback, along with your Discord user ID and the server ID, so we can follow up. - Usage counts: anonymous per-command totals. A number per command, with no user information attached.
- Votes: if you vote for XBGuide on top.gg, your Discord user ID and the time of the vote. This is used only to give you reduced command cooldowns for 12 hours, and to count votes in total.
API keys
If you are issued a key for the public API, we store a one-way hash of it, the first few characters so it can be identified, the label it was issued under, how many calls it has made, and when it was last used. The key itself is never stored, so it cannot be recovered or leaked from our database - if you lose it, it has to be replaced.
Data servers store
If a server manager uses /settings, XBGuide stores that server's ID and the channel IDs chosen to receive Xbox outage alerts, Game Pass updates, or deal alerts, plus the deal threshold. No message content is stored. /settings alerts-off, /settings gamepass-off and /settings deals-off remove these.
Data the website stores
- Nothing about you is written to disk. The site keeps no accounts and no analytics.
- IP addresses are held briefly in memory to enforce rate limits and are never saved to disk or shared.
- One cookie, only in the developer area. If you enter the access code at
/dev, a single cookie is set so you stay signed in for 30 days. It contains an expiry timestamp and a signature, nothing else - no identifier, no personal data, and no way to track you. It is scoped to/dev, so it is not sent when you browse the rest of the site. Ordinary visitors never receive a cookie. - Looked-up profiles are cached for about 10 minutes to reduce load on the Xbox API. This is public Xbox Live data, the same information visible on a public Xbox profile.
- Player pages and the public API (
/player/...,/badge/...,/api/player/...) serve only public Xbox Live data for the gamertag requested.
Data XBGuide does NOT store
- Discord message content or server content
- Xbox or Microsoft credentials of any kind
- Xbox profile data at rest. Profile, achievement, presence and store information is fetched live and held only in short-lived in-memory caches.
Service monitoring
XBGuide records the results of its own checks against public Xbox service endpoints: whether a hostname resolved, whether a connection succeeded, response time, and the resolved IP address of the Microsoft service. This is infrastructure data about Microsoft's servers and contains no user information.
Resolved addresses are kept only so that a service moving can be detected. They are never published: the Xbox 360 archive reports that a service changed address and when, not what the address was.
Where data lives and how long it is kept
Stored data lives in a private database on the bot's hosting provider. Automatic backups are taken daily, stay on that same private storage, and the most recent 7 are kept before older ones are deleted. Backups are never copied anywhere else.
How long things are kept:
- Account links and preferences: until you remove them with
/link remove. - Feedback messages: 180 days, then deleted automatically.
- Vote records: 90 days, then deleted automatically.
- Service monitoring history: 90 days.
- Server settings: until the server removes them or the bot leaves.
Data is never sold or shared, and is used only to operate XBGuide.
Third-party services
- OpenXBL (xbl.io): fetches public Xbox Live data. Gamertags you look up are sent to this API.
- Discord: the bot operates on Discord's platform under Discord's own privacy policy.
- Microsoft: the public product catalog is queried for game titles and US pricing. No user information is sent.
- Railway: hosts the bot and website.
- Cloudflare: sits in front of xbguide.com and processes requests to it, including IP addresses, under its own privacy policy.
- top.gg: if you choose to vote for XBGuide there, top.gg tells us your Discord user ID.
Removing your data
/link removeimmediately deletes your account link and your saved card preferences./settings ...-offremoves a server's alert channel settings.- To request deletion of feedback messages, vote records, or anything else, use
/feedback, or the support server linked in/about.
Removing a player page
xbguide.com can build a page for any gamertag someone looks up, including one belonging to a person who has never used XBGuide. If you would like your gamertag removed, ask through /feedback or the support server linked in /about.
Once removed, the player page, gamer card, signature badge, API lookup and the gamertag/XUID converter all stop returning anything for that gamertag, and any cached copy is cleared immediately. Player pages are also served with a noindex instruction to search engines, so they are kept out of search results.
Children
XBGuide does not knowingly collect data from children under 13. Discord requires users to be at least 13.
Changes
If this policy changes materially, the updated version will be posted here with a new "last updated" date.
XBGuide is a fan-made project and is not affiliated with, endorsed by, or sponsored by Microsoft Corporation or Xbox.