Working draft. This document has not yet been reviewed by a lawyer. Bracketed placeholders are unfilled. Do not rely on it until this banner is removed.
Privacy Policy
Version 2026-08-26.
1. Two hats
[OPERATOR_NAME — the person or future entity operating the Service] operates this Service. We handle personal data in two roles. For account data — the Discord identity you sign in with, your billing records — we decide how and why it is processed (we are the controller). For Community data — your Members' player identifiers, chat and event logs, moderation records — your Community decides; we process it only on the Community's behalf (we are the processor, under the DPA). If you are a player in a community that uses this Service, your community is responsible for that data — contact them first; we support them in honouring your rights.
2. What we hold
- Sign-in: your Discord user id and display name, held in a signed session cookie and used to decide which communities you may administer. We do not store your Discord password and cannot post as you.
- Community configuration: game-server addresses and RCON passwords, your Discord application's bot token, payment-provider secrets — all encrypted at rest, used only to operate the Service for your Community, never shown back once entered.
- Community operations data (as processor): player names and platform identifiers, IP addresses observed by game tooling, chat and game event logs, moderation records (bans, kicks, notes), Discord ids your Community links to players, and — where your Community sells supporter benefits — supporter names/emails/identifiers your payment provider sends in webhooks.
- Billing: invoices for your Community (line items, amounts, status). Card details go directly to Stripe on Stripe's own pages; we never receive or store card numbers.
- Logs: operational logs (request ids, errors) kept briefly to run the Service.
3. Why, and on what basis
To provide the Service you asked for (performance of a contract); to bill and collect (contract and legitimate interest); to secure the Service and its tenants against abuse (legitimate interest); and to comply with law. We do not sell personal data, and we do not use Community data for advertising.
4. Retention and deletion
Event history is aged out automatically at your Community's configured retention window. Deleting a Community removes its data — including stored credentials — from the live system; residual copies may persist in backups for a limited period before cycling out. Retention and deletion as service features carry no guaranteed level (see the Terms, Section 4); where the law gives a person deletion rights, we honour the law.
5. Who else touches the data (subprocessors)
- Cloudflare — network routing and TLS in front of the Service.
- Stripe — platform billing (checkout and payment state).
- Discord — sign-in and the Community's own bot integrations.
- The Community's chosen payment providers (Stripe, PayPal, Patreon, Ko-fi, Buy Me a Coffee) — only for communities that connect them, under the community's own accounts.
6. Security
Tenant isolation at the database layer, credentials encrypted at rest (AES-256-GCM), signed sessions, per-community webhook verification, and audit trails on administrative actions. No system is perfectly secure and we do not warrant security outcomes; see the Terms.
7. Your rights
Depending on where you live you may have rights to access, correct, export, or erase personal data, and to complain to a supervisory authority. For account data, contact us. For Community data, contact your Community (the controller); we assist them under the DPA. Contact: [CONTACT_EMAIL].
8. Children
The Service is not directed to children under 13 and may not be used by them.
9. Changes
Material changes will be announced the same way as Terms changes, with a new version stamp.