Docs / The Discord bot
What the bot can & can’t do
A short, least-privilege permission list, why it can never read your messages, and where your data actually lives.
Adding a bot to your server is worth being cautious about. Here's the whole, honest picture.
The only permissions it asks for
When someone invites the bot, Discord shows a consent screen listing exactly this, and nothing more. Never Administrator.
| Permission | Why it's asked for |
|---|---|
| View Channels | See the channel list so it knows where to post. |
| Send Messages | Post event announcements and reminders. |
| Embed Links | Show events as rich embeds instead of plain text. |
| Manage Roles | Keep members' Discord roles in sync with their rank on the site. |
| Manage Nicknames | Keep members' server nicknames in sync with their display name. |
| Manage Events | Create and update Discord's built-in scheduled events. |
What it never does
✕ Read what you write
The bot never requests the Message Content permission, so the words in your messages are invisible to it — full stop. The one optional exception is the activity-heatmap feature (off by default): it can note that a member posted, for participation charts, but never what they wrote.
✕ Get Administrator
No admin, no "Manage Server," no "Manage Channels." Only the six permissions above.
✕ Kick or ban anyone
It has no moderation power in Discord at all. Removing someone is always a human decision, made in Discord.
✕ Send your data anywhere
Everything lives in the server owner's own Cloudflare account. There's no mustr company server collecting it.
Why that's provable, not just a promise
- Runs request-and-response, by default. The bot is a Cloudflare Worker that wakes up to answer a button press or a scheduled post — no live connection to your chat exists unless you deliberately turn on the optional activity gateway.
- Every request is cryptographically verified. The bot only acts on messages Discord has signed; a forged request is rejected.
- It's self-hosted. Each community runs its own copy, with its own bot, on its own account. Your members' data never touches another org's install.
- The permission list mirrors the source code — the same least-privilege set the invite link is built from.
Discord's verified badge is for bots living in 75+ servers. mustr's bot is deliberately the opposite: one small bot per community, invited into a single server. It will never qualify for the badge — not because it's untrustworthy, but because it isn't a large shared bot pulling data from thousands of servers. The permission list above is the real thing to check.