Privacy Policy
Effective: 7 June 2026
Data controller
The controller responsible for processing personal data in connection with this website, the dashboard, and the Discord bot is:
Lukas Telbam
Fester Str. 24
42289 Wuppertal
Germany
Email: [email protected]
As there is currently no legal obligation to appoint a data protection officer, no data protection officer has been designated. Transparency requirements for controller details and, where applicable, DPO contact details arise from Art. 13 and 14 GDPR.
Scope and subject matter of this notice
This privacy policy applies to our website, the associated dashboard, sign-in via Discord and, where applicable, Roblox, and to the use of our Discord bot and related functions, in particular configuration and administration features, appeals, applications, forms, tickets, voice support, logging, security modules, team features, message and template features, and comparable server-related workflows. The actually enabled feature set is decisive in each case.
Important note on Discord and other platforms
Our service uses interfaces from Discord and – where enabled – Roblox and other third-party platforms. When you interact with the bot on Discord or sign in via Discord or Roblox, Discord and/or Roblox also process personal data for their own purposes. Their respective privacy information applies to those independent processing activities. The same applies to other platforms when you actively use or link their services. Our privacy policy covers only processing for which we are ourselves responsible under data protection law.
What data we process
Depending on use, we process in particular the following categories of data:
- Access and technical log data such as IP address or truncated IP address, date and time of access, pages and endpoints accessed, referrer, browser and device information, status codes, error and security events;
- Account and login data such as Discord ID, username, display name, avatar, and where applicable guild/server list; with optional Roblox connection additionally Roblox identification and profile data;
- Session and security data such as session identifiers, CSRF/OAuth status data, rate-limit, replay-protection and abuse-prevention information;
- Bot and server data such as guild ID, channel ID, role IDs, interaction IDs, commands, button/modal/select interactions, timestamps, and configuration data;
- Content data where a specific function requires it, e.g. form responses, appeal texts, ticket or support content, moderation reasons, templates, reminders, message references, or other content you enter into a function;
- Communication data when you contact us, e.g. by email or via a support system.
Where the data comes from
Data comes either directly from you, from your use of the dashboard or bot, from technical communication with your browser, or – with platform integrations – from the respective integrated services, in particular Discord and optionally Roblox. With bot functions, data may also come from the respective server context, from input by other participants, or from processes initiated by server administrators.
Purposes and legal bases of processing
We process personal data to provide and securely operate our service, in particular for account and login management, dashboard provision, execution of requested bot functions, handling of appeals, forms, tickets and support cases, management of server settings and templates, detection and prevention of abuse, spam, raids and other security risks, error analysis, data backup, and assertion and enforcement of our own rights. Depending on the situation, processing is based on Art. 6(1)(b) GDPR where required to provide requested functions or perform the user relationship, and otherwise regularly on Art. 6(1)(f) GDPR where required for security, stability, further development, abuse prevention, or server-related documentation. Legally required processing is based on Art. 6(1)(c) GDPR. Where consent is exceptionally required, we rely on Art. 6(1)(a) GDPR.
Legitimate interests
Where we process personal data on the basis of Art. 6(1)(f) GDPR, our legitimate interests lie in particular in secure and stable operation of the service, prevention of abuse and attack attempts, administration and documentation of server-related processes, troubleshooting, traceability of moderation and administration decisions, and assertion, exercise or defence of legal claims.
Hosting and IT infrastructure
Where legally required, we have concluded data processing agreements under Art. 28 GDPR with the service providers named below.
Hosting (Hetzner)
This website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Data is stored exclusively on servers within the European Union. Legal basis: Art. 6(1)(f) GDPR.
Security and performance (Cloudflare)
We also use services from Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA. Cloudflare acts as a reverse proxy to protect against attacks (e.g. DDoS) and optimise load times; technical data (e.g. IP addresses) is processed in the process. Legal basis: Art. 6(1)(f) GDPR. Cloudflare is certified under the EU-US Data Privacy Framework (Art. 45 GDPR).
Sign-in via Discord and optional third-party platforms
When you sign in via Discord or Roblox, we receive the data required for login and account assignment from the OAuth permissions you grant. Legal basis: Art. 6(1)(b) GDPR.
Discord: Scopes identify (user ID, username, avatar) and guilds (server list). An email address is not retrieved.
Roblox: Scopes openid and profile (user ID, username, profile picture).
Session management: Absolute lifetime 30 days, inactivity limit 14 days. Session tokens are rotated every 24 hours. OAuth tokens are stored encrypted (AES-256) in Redis and automatically removed after expiry.
Discord bot functions and content
When using the bot, we process platform and interaction data required for the respective function. This may include user, server, channel, role and interaction identifiers, timestamps, selected options, form fields, ticket and appeal content, moderation reasons, and message references. Official Discord documentation lists for message objects inter alia channel_id, content, and timestamp; user objects contain inter alia id, username, global_name, and avatar data. We do not process such data wholesale “in reserve”, but only where required for the enabled function or a documented security or support purpose.
Server administrators and visibility within a server
Where the bot is deployed on a Discord server, authorised server administrators or team members they authorise may view certain server-related data where required for the respective function, e.g. ticket histories, appeal or form content, moderation data, or configurations. Discord and the respective server operators may also bear their own data protection responsibility. Where we use processors, this is done only in accordance with Art. 28 GDPR.
Further bot functions and transient processing
Anti-raid protection (transient storage)
To detect spam and raid attacks, the bot temporarily processes Discord user IDs, usernames, avatar hashes, join timestamps, and message content hashes in working memory (no persistent database). Legal basis: Art. 6(1)(f) GDPR. Security-relevant bot actions (e.g. timeout, kick, ban) are persisted in a security action log (max. 100 entries/server, circular; Discord user ID encrypted, AES-256). Access: server administrators via the dashboard.
Active Roblox API queries
At the request of server administrators, Leveo queries the Roblox API (user search, avatar retrieval). Usernames and Roblox IDs are cached for a maximum of 5 minutes. Legal basis: Art. 6(1)(f) GDPR.
Team list function
Discord display names and role memberships are retrieved via the Discord API and cached in working memory for up to 5 minutes, without persistent storage in the Leveo database. Legal basis: Art. 6(1)(f) GDPR.
Support, ticket and form functions
Where enabled, we process Discord user identifiers, status/timestamp data, form responses, and channel/message references to carry out the requested process. Legal basis: Art. 6(1)(b) and (f) GDPR.
Server backups and restoration
When the backup function is used, configurations of enabled modules including identifiers and creator/restoration data are processed. Legal basis: Art. 6(1)(f) GDPR.
Technical logs, protection and abuse measures
To secure the service, we process technical log and security data (audit logs), e.g. to detect impermissible requests, CSRF attacks, OAuth abuse, replay attacks, spam, raid behaviour, or other security incidents. Legal basis: Art. 6(1)(f) GDPR.
IP anonymisation: IP addresses are generally stored in anonymised form (last octet removed for IPv4 or /64 for IPv6).
User agent: Stored not in plain text but only as an HMAC-SHA256 hash.
Audit log retention: maximum 30 days, then automatic deletion unless longer retention is required for evidence purposes.
Support and communication
When you contact us, we process the data you provide, in particular contact details, the content of your message, and the handling history, to process your request, answer follow-up questions, and document cases. The legal basis is Art. 6(1)(b) GDPR where the request relates to our service, and otherwise Art. 6(1)(f) GDPR.
Cookies, local storage and similar technologies
We use only technically necessary cookies and similar storage technologies (Section 25(2) TDDDG, formerly TTDSG), e.g. for session management, CSRF protection, login/OAuth status, and language settings. For non-essential tracking or marketing technologies, we obtain separate consent in advance; we do not currently use such tools.
Note: Over HTTPS, security cookies may be set with the __Host- prefix.
| Name | Purpose | Duration |
|---|---|---|
sid / sv | Session management and integrity check (HMAC) | 30 days |
csrf | CSRF protection | 30 days |
oauth-state-discord | Discord OAuth security check | 10 min. |
oauth-state-roblox | Roblox OAuth security check | 10 min. |
ehrp_login_loop | Protection against redirect loops during login | 30 sec. |
ehrp_cookie_notice_dismissed | Cookie notice dismissed | 180 days |
cf_clearance | Cloudflare security check (suspicious traffic) | 30 min. |
lang | Website language | 365 days |
Purely technical UI states in browser localStorage contain no personal data. Further information: cookie policy.
Recipients of data
Recipients of personal data may include in particular:
- Hetzner Online GmbH — hosting (EU)
- Cloudflare Inc. — security and performance (USA, DPF)
- Discord Inc. — OAuth login and bot platform (USA, DPF)
- Roblox Corporation — optional OAuth login (USA, SCC)
- authorised server administrators within the affected Discord server
- other technical service providers (e.g. database/cache services) where required
Disclosure occurs only to the extent required. Where service providers process data on our behalf, we conclude contracts under Art. 28 GDPR where required.
Transfers to third countries
OAuth logins and IT infrastructure may involve transfers to the USA, each only under Art. 44 et seq. GDPR:
- Discord Inc.: EU-US Data Privacy Framework (Art. 45 GDPR)
- Cloudflare Inc.: EU-US Data Privacy Framework (Art. 45 GDPR); technical data only
- Roblox Corporation: standard contractual clauses (Art. 46 GDPR)
Retention period
We store personal data only as long as required for the respective purposes. Specific periods (unless longer retention is required by law):
- Account data (Discord/Roblox profile): until account deletion
- Sessions: 30 days absolute / 14 days inactivity
- Audit logs: 30 days
- Staff activity: 90 days
- Applications and appeals: 90 days after decision; pending until server deletion
- Team leave records: 180 days (display name anonymised after 7 days)
- Team warnings/degradations: 365 days
- Shift data: 180 days after shift end
- GDPR requests: 3 years (evidence obligation)
- Server error logs: 90 days
- In-game server data: 90 days after last activity
- Anti-raid data: transient in memory only; security action log max. 100 entries/server (circular)
- Roblox API cache: max. 5 minutes
- Application progress (bot): 6 hours
Server-related content (tickets, forms, configurations) is deleted when the function ends, the server is removed, or no retention grounds remain. See the data overview below for details.
Obligation to provide data
Where we need data for login, account management, session management, secure operation, or performance of a function you explicitly request, providing that data is required. Without this data, we cannot provide or cannot fully provide the user account, the respective bot function, or the requested communication. Otherwise, providing personal data is voluntary.
Your rights
Subject to statutory requirements, you have the right to access personal data we process, to rectification of inaccurate data, to erasure, to restriction of processing, to data portability, and to object to processing based on Art. 6(1)(e) or (f) GDPR. Where processing is based on your consent, you may withdraw it at any time with future effect. You also have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work, or place of the alleged infringement. We generally process requests without undue delay and at the latest within one month of receipt; this period may be extended in cases permitted by law.
Contact for data subject requests: [email protected]. Self-service: account settings (access, export, deletion), restriction, objection.
Competent supervisory authority (NRW): State Commissioner for Data Protection and Freedom of Information, [email protected], www.ldi.nrw.de.
No solely automated decision-making under Art. 22 GDPR
We do not carry out solely automated decision-making with legal effect or similarly significant impact within the meaning of Art. 22 GDPR. This does not affect automated technical and moderation-related rules that may detect security-relevant events, classify content, or trigger server-side workflows where required to protect the service and affected Discord servers.
Overview of processed data
| Data category | Fields | Purpose | Retention |
|---|---|---|---|
| Discord profile | User ID, username, avatar URL | Account management, login | Until account deletion |
| Roblox profile | User ID, username, profile picture URL | Account management, login | Until account deletion |
| Sessions | Session ID, device fingerprint (encrypted), IP prefix (anonymised) | Security, session management | 30 days absolute / 14 days inactivity |
| Audit logs | Event type, timestamp, account ID, IP prefix (/24 or /64), UA hash (HMAC-SHA256) | Security monitoring | 30 days |
| Staff activity | Moderator ID, Roblox user ID/name (encrypted, AES-256), sanction type, reason | Moderation accountability | 90 days |
| Trusted devices | Device fingerprint (encrypted), last seen | Security, device management | Until account deletion or 90 days inactivity |
| Applications | Discord ID (encrypted), username, form responses, status, reviewer note | Application process | 90 days after decision; pending until server deletion |
| Appeals | Roblox user ID/name (encrypted), form responses, status | Appeal handling | 90 days after decision; pending until server deletion |
| Team leave records | Discord ID (encrypted), display name (anonymised after 7 days), reason, period, roles | Team management | 180 days; display name anonymised after 7 days |
| Team warnings/degradations | Discord ID (encrypted), type, reason, roles | Inactivity management | 365 days |
| Shift data | Discord user ID (encrypted), shift type, times, breaks | Time tracking | 180 days after shift end |
| Consent records | Account ID, consent type, version, IP prefix, UA hash | Proof (Art. 7 GDPR) | Until account deletion |
| GDPR requests | Account ID, request type, status, deadline | Data subject rights | 3 years |
| Blocked IP prefixes / devices | IP prefix or device fingerprint, reason, expiry | Abuse prevention | Until expiry or revocation |
| Server settings | Server ID, configurations (JSONB) | Server administration | Until server removal |
| Security action logs | Source system, action type, module ID, Discord user ID (encrypted), detail text | Bot security log | Max. 100 entries/server (circular) |
| In-game moderation history | Roblox IDs/names target/moderator (encrypted), reason, action ID | Moderation history | Max. 1,000/server, 75/target user (LRU); 180 days |
| Trigger cooldowns | Discord user ID (encrypted), trigger ID, expiry | Prevent repeated triggers | Until cooldown expiry |
| Application progress | HMAC of Discord ID, step, interim answers | Multi-step applications | 6 hours |
| Server error logs | Error category, message, context (guild/channel/user ID) | Error diagnosis | 90 days |
| In-game server data | Server name, description, owner, player count (public API) | Dashboard display | 90 days after last activity |
| Message template revisions | Account ID, template snapshot | Version history | Max. 50 entries/server (LRU) |
| Support tickets | Creator ID (encrypted), form responses, status, channel/message references | Support handling | Until ticket deletion or server removal |
| Voice support cases | Discord user ID, voice channel, status, comments | Voice support | Until completion; thereafter until server removal |
| Form submissions | Discord user ID, username, responses, thread/message references | Form/report processes | Until deletion by server administrators |
| Server backups | Backup contents, creator/restoration data | Backup and restoration | Per server retention rules |
Changes to this privacy policy
We update this privacy policy when the legal position, feature set, service providers used, or processing activities change materially. The version published on this page applies.