Privacy Policy

Last updated 2026-07-21

This policy explains what personal data Ruination Bots processes, why, on what legal basis and for how long, and what rights you have. It is written to meet Articles 12 to 14 of the General Data Protection Regulation (GDPR) together with the German Federal Data Protection Act (BDSG) and the Telecommunications Digital Services Data Protection Act (TDDDG).

1.Who is responsible

The controller for the processing described in this policy, within the meaning of Art. 4(7) GDPR, is:

Controller
TODO: Your full legal name or company name incl. legal form
Address
TODO: Street and house number, TODO: Postal code TODO: City, Germany
Email
TODO: privacy@yourdomain.tld
Data protection officer
We are not required to appoint one under Art. 37 GDPR / § 38 BDSG and have not done so. Please direct all privacy enquiries to the address above; they are handled by the operator personally.

2.Two different roles, and which one applies to you

This matters more here than on a typical website, because the same platform handles two very different kinds of data.

  • If you have an account with us — you signed in with Discord to run bots — we are the controller for your account data. Sections 3 to 6 describe that processing, and your rights under section 11 are exercised against us.
  • If you are a member of a Discord server that runs one of our customers' bots, we are only a processor. The operator of that bot decides what is collected and why; we merely store and process it on their instructions. Section 8 describes what that involves, and requests about that data must go to the bot operator, not to us. We will forward any that reach us, and assist the operator in answering them.

If you are a bot operator

You are the controller for your server members' data and you need a data processing agreement with us under Art. 28 GDPR. It is already written and forms part of your contract — see the Data Processing Agreement.

3.Account, sign-in and profile

There is no password and no registration form. You sign in with Discord (OAuth 2.0). We receive from Discord only what that authorisation grants: your Discord user ID, your username and display name, your avatar and your email address. We never receive your Discord password.

DataPurposeLegal basisKept
Discord user ID, username, display nameIdentifying your account, showing who you are in the dashboard, letting bot owners find you when granting moderator access.Art. 6(1)(b) GDPR — performance of the contract.Until the account is deleted.
Email addressAccount-related notices, security messages, and the emails you have opted into.Art. 6(1)(b) GDPR; for product and promotional email Art. 6(1)(a) — your consent.Until the account is deleted.
Avatar imageDisplaying your profile. On first sign-in your Discord avatar is copied to our storage and resized; you can replace or remove it at any time.Art. 6(1)(b) GDPR.Until replaced, removed, or the account is deleted.
Session cookiesKeeping you signed in between page loads.Art. 6(1)(b) GDPR; strictly necessary under § 25(2) no. 2 TDDDG.See section 7.

4.Preferences and consent records

When you choose a dashboard language or decide which emails you want, we store that choice against your account so it follows you between devices. Alongside the choices themselves we store the time at which you last made them.

That timestamp is not incidental: Art. 7(1) GDPR requires us to be able to demonstrate that consent was given, and a stored boolean on its own proves nothing. It is kept for as long as we rely on the consent and, after withdrawal, for as long as we may need to defend against a claim that we sent something without permission.

Data
Interface language, email opt-in flags, time of the last change, whether onboarding was completed.
Legal basis
Art. 6(1)(b) GDPR for the interface language; Art. 6(1)(a) and Art. 7(1) GDPR for the email consent record; Art. 6(1)(f) GDPR for retaining evidence of consent after withdrawal.
Kept
Until the account is deleted; consent evidence for up to three years after withdrawal, matching the standard limitation period under § 195 BGB.

5.Bots and their configuration

To run a bot for you we store the bot's Discord application ID, its name and avatar, the servers it is connected to and their names and icons, its status and error history, and everything you configure: modules, commands, automatic replies, panels, giveaways, scheduled messages, alerts and so on. Where you name or address a Discord user in that configuration, that identifier is stored with it.

Your bot token is stored encrypted and is never displayed back to you, never logged and never sent to your browser. We keep a one-way hash of it separately so that the same token cannot be registered twice.

Legal basis
Art. 6(1)(b) GDPR — we cannot run the bot you asked us to run without it.
Kept
Until you delete the bot or your account. Deleting a bot removes its configuration and its token.

6.Audit log and technical logs

Every change made through the dashboard is recorded so that a bot owner can see who changed what, and when. An entry contains the acting account, the action, the affected bot and object, the outcome, the browser user agent and a hash of the IP address rather than the address itself. Refused actions are recorded too — an audit log that only shows successes hides exactly the events worth looking for.

Audit entries are deleted automatically after 90 days. Our hosting providers additionally keep short-lived server logs containing IP addresses and request metadata for the operation and security of the service, for TODO: e.g. 14 days.

Legal basis
Art. 6(1)(f) GDPR. Our legitimate interest is the security and traceability of a service where several people can hold administrative access to the same bot. We weighed this against your interests and reduced it accordingly: IP addresses are hashed rather than stored, request bodies are never logged, and everything expires automatically.
Kept
90 days for audit entries; TODO: e.g. 14 days for server logs.

7.Statistics inside the dashboard

The dashboard shows member counts, message volumes, joins and leaves per bot per day. These are aggregate counters, not records of individuals: no message content and no individual identifiers are stored in them.

We use no third-party web analytics, no advertising networks, no tracking pixels and no profiling on this website.

Legal basis
Art. 6(1)(b) GDPR — the statistics are part of the product you signed up for.
Kept
For as long as the bot exists.

8.Cookies and local storage

We store information on your device only where it is strictly necessary to provide the service you requested. Under § 25(2) no. 2 TDDDG that requires no consent, which is why you are not shown a cookie banner. We would rather not have one than have one that asks for nothing.

NameTypePurposeDuration
Supabase authentication cookiesCookieKeeping you signed in and refreshing your session.Session and refresh lifetime; removed on sign-out.
rb-localeLocal storageRemembering your interface language so the first paint is in the right one.Until you clear it.

9.Data your bots process about Discord members

When a bot operator switches on a feature, the bot may store data about the members of their server. We do this on the operator's instructions, as their processor. Depending on which features are enabled, that can include:

  • Discord user IDs and usernames of members who interact with a bot.
  • Moderation records: bans, kicks, timeouts, warnings, the reason given and the moderator who acted.
  • Levelling data: experience, level and message counts per member.
  • Invite tracking: which member joined through which invite, and invite counters.
  • Ticket, suggestion and giveaway participation, including the content members write into those flows.
  • Temporary roles, verification records, reaction-role assignments and voice channel ownership.

We do not read or store general message content. Only the content a member deliberately submits to a bot feature — a ticket message, a suggestion, a command argument — is stored, and only for the server it was submitted in.

If you are a server member

The controller for this data is the person or organisation that runs the bot on your server, not us. Please direct requests for access or erasure to them. If you cannot identify them, contact us at TODO: privacy@yourdomain.tld and we will pass the request on.

Legal basis
For us: Art. 6(1)(b) and Art. 28 GDPR — processing on documented instructions. The bot operator is responsible for having their own legal basis.
Kept
Until the operator deletes it, deletes the bot, or the account is deleted, whichever comes first.

10.Email we send you

Service email. Messages about your account and your bots — an outage, a security event, a change to these terms — are sent on the basis of Art. 6(1)(b) GDPR because they are part of the service. They cannot be switched off entirely while you hold an account, though you control which operational alerts you receive.

Product and promotional email. News about new features, offers and surveys is sent only if you have actively switched it on. The legal basis is your consent under Art. 6(1)(a) GDPR and § 7(2) no. 2 UWG. Nothing is pre-ticked and nothing is sent by default.

You can withdraw that consent at any time with no reason and no disadvantage, either by switching the relevant option off in your account settings or by using the unsubscribe link in any such email. Withdrawal does not affect the lawfulness of processing carried out before it.

We do not use tracking pixels to record whether you opened an email. Our email provider processes your address and the message content on our behalf under a data processing agreement; see section 10.

11.Who else sees your data

We do not sell personal data and we do not share it for anyone else's marketing. Data is disclosed only to the providers we need in order to run the service, each bound by a data processing agreement under Art. 28 GDPR and permitted to act only on our instructions:

ProviderPurposeLocation
Supabase
Supabase, Inc., 970 Toa Payoh North, Singapore (US/EU operations)
Database, authentication and file storage for account data, bot configuration and avatars.TODO: the region your Supabase project runs in, e.g. eu-central-1 (Frankfurt)
Railway
Railway Corp., 2261 Market Street, San Francisco, CA 94114, USA
Application hosting for the dashboard, API and bot workers, including the job queue.TODO: the region your Railway services run in
TODO: your email provider
TODO: legal entity and address, e.g. Resend, Inc., …
Delivery of service and, where consented, product emails.TODO: processing region

The current list is maintained at Sub-processors.

The following services are not processors: they decide for themselves how they handle data and act as independent controllers. Your relationship with them is governed by their own privacy policies.

ServiceWhy it is involvedTheir policy
Discord
Discord Netherlands B.V. (EEA users) / Discord, Inc., 444 De Haro Street, San Francisco, CA 94107, USA
Sign-in via Discord OAuth, and every action your bots perform on Discord. Discord decides how it processes data on its own platform.Privacy policy
Twitch
Twitch Interactive, Inc., 350 Bush Street, 2nd Floor, San Francisco, CA 94104, USA
Live-stream alerts, where a user configures them. Only public channel data is retrieved.Privacy policy
YouTube / Google
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Video upload alerts, where a user configures them. Only public channel data is retrieved.Privacy policy

We may also disclose data where we are legally obliged to, for example to law enforcement on a valid order, or where necessary to establish, exercise or defend legal claims (Art. 6(1)(c) and (f) GDPR).

12.Transfers outside the EU/EEA

Some of the providers above are established in the United States or operate infrastructure there. Where personal data leaves the EU or EEA, the transfer is covered by one of the safeguards in Chapter V GDPR — as a rule the European Commission's Standard Contractual Clauses under Art. 46(2)(c), supplemented by technical measures such as encryption in transit and at rest, and where applicable the adequacy decision for the EU–U.S. Data Privacy Framework under Art. 45.

You can request a copy of the safeguards in place at TODO: privacy@yourdomain.tld. We would also point out honestly that United States authorities may have access rights that have no equivalent under EU law, and that enforceable data subject rights against such access may be limited.

13.Your rights

You have the following rights in respect of your personal data:

  • Access (Art. 15 GDPR) — confirmation of whether we process your data, a copy of it, and the details of that processing.
  • Rectification (Art. 16 GDPR) — correction of inaccurate data and completion of incomplete data.
  • Erasure (Art. 17 GDPR) — deletion where one of the listed grounds applies. You can also delete your entire account yourself, at any time, from your account settings.
  • Restriction (Art. 18 GDPR) — of processing in the cases set out there.
  • Data portability (Art. 20 GDPR) — the data you provided, in a structured, commonly used, machine-readable format.
  • Objection (Art. 21 GDPR) — to processing based on legitimate interests, on grounds relating to your particular situation. Where data is processed for direct marketing you may object at any time, without giving reasons, and we will stop.
  • Withdrawal of consent (Art. 7(3) GDPR) — at any time, with effect for the future.
  • Complaint (Art. 77 GDPR) — to a supervisory authority, in particular in the member state of your residence, place of work or the alleged infringement.

To exercise any of these, write to TODO: privacy@yourdomain.tld. We answer within one month and will tell you if we need longer, as Art. 12(3) GDPR permits in complex cases. There is no charge unless a request is manifestly unfounded or excessive.

Competent supervisory authority

TODO: Your state data protection authority incl. address

14.What deleting your account actually does

Deleting your account from the settings page shuts down every bot you own, deletes those bots together with their configuration and stored tokens, removes you as a moderator from anyone else's bots, deletes your profile and avatar files, and erases your account row. It happens immediately, with backups overwritten within 30 days and cannot be undone.

Two exceptions, both narrow. Data that we are legally required to keep — invoices and accounting records under §§ 147 AO and 257 HGB, retained for six to ten years — is kept and processed for that purpose only. And data your bots stored on behalf of servers you do not own remains with the bot that owns it, because it was never yours to delete.

15.Whether you have to provide data

Providing your data is neither required by law nor by contract, but the data described in sections 3 and 5 is necessary to create an account and to run a bot. Without it we cannot provide the service. There is no obligation to give consent to product email, and refusing has no consequence for your use of the service.

16.Automated decision-making

We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you, within the meaning of Art. 22 GDPR. Automated technical measures such as rate limiting and abuse detection may temporarily restrict access to the API; these are protective measures, they are reviewable by a human on request, and they do not evaluate personal aspects.

17.Security

We apply technical and organisational measures appropriate to the risk under Art. 32 GDPR, in particular:

  • TLS encryption for all traffic between your browser, our API and our providers.
  • Bot tokens encrypted at rest with a separate key, never returned to the browser, never written to logs.
  • Row-level security in the database, so an account can only read its own rows even if application code is at fault.
  • Least-privilege access: administrative database credentials exist only on the server side and are never exposed to the client.
  • Request bodies excluded from all application logging, because they can carry credentials.
  • Automatic expiry of audit data and hashing of IP addresses rather than storing them.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours under Art. 33 GDPR and inform you directly where Art. 34 requires it.

18.Children and young people

Using the service requires a Discord account, and Discord's own terms set a minimum age. In addition, where we rely on your consent — which for us means product and promotional email only — German law sets the age for valid consent to information society services at 16 (Art. 8(1) GDPR in conjunction with the German derogation). If you are under 16, do not switch those emails on without the consent of the holder of parental responsibility.

Everything else we do rests on the performance of the contract rather than consent. If you believe a person under 16 has given us consent without authorisation, contact us and we will delete the consent record and stop the mailings.

19.Changes to this policy

We update this policy when the service changes or the law does. The date at the top always shows the current version. Where a change materially affects how we process your data we will tell you by email or in the dashboard before it takes effect, and where a change requires your consent we will ask for it rather than assume it.