file 02 / 04 · legal register
Privacy Policy.
doc/privacylast updated 2026-10-03lang en
1. Information We Collect
Through Discord OAuth we only receive:
- Discord user ID
- Username + global name
- Avatar URL
- Email (for sign-in)
OAuth does not grant access to servers or messages. Separate intelligence-collection processes may process memberships, roles and public-channel activity visible to the collector account inside monitored communities. Private messages and DM contents are not processed.
2. How We Use Data
- Account authentication, sessions and membership management
- Query quotas, payments and abuse prevention
- Aggregate site-usage and page-performance analytics where consent is granted
- Providing server operators with security and anti-cheat intelligence
- Reviewing ban appeals, data-subject requests and legal claims
- Audit logs (who queried what — for security)
3. Data Retention
Retention depends on the data category and purpose:
- Account and authentication data — while the account remains open; after a verified closure request, data without an ongoing legal basis is removed.
- Query and security audit logs — normally no longer than 90 days.
- Membership, role, name and avatar history — while necessary for cross-community security and record accuracy; reassessed record by record following a verified objection.
- Ban records and connection identifiers — while they retain intelligence value, considering source reliability, age, independent corroboration and appeal outcomes.
- Request, erasure and suppression records — only to the minimum extent and duration needed to demonstrate compliance and prevent deleted data from being re-indexed.
Isolated backups expire through the normal rotation schedule. If a backup is restored, recorded erasure and suppression decisions are reapplied before restored data is used in production.
4. Third-Party Sharing
Personal data is not sold or shared for advertising.
As part of the service, authorised Argos users and server operators may see the portion of query results made available to them. Infrastructure providers (Cloudflare, Hostinger and the application server provider), Discord authentication, Google Analytics for consented usage measurement, co-operating servers that contribute records, and legally authorised authorities may receive data only within their respective role and the necessary scope.
5. Your Rights
- Request access to your data (via Discord contact)
- Correction / deletion of your data
- Restriction of processing
- Object to processing
- Data portability where applicable (JSON export)
- Information about data sources and recipient categories
A request sent from the relevant Discord account is used to establish the account link. Only necessary and proportionate additional information is requested where reasonable doubt remains. Requests are assessed by data category, and disputed processing is restricted during an objection review where the conditions for restriction are met.
Where the GDPR applies, requests are answered without undue delay and normally within one month. That period may be extended by up to two further months where the complexity or number of requests requires it; the extension and reasons are given within the first month. Where a request is manifestly unfounded or excessive, particularly because it is repetitive, a reasonable fee may be charged or the request may be refused to the extent permitted by law. A refusal states the reasons and the available complaint and judicial remedies.
6. Security
All traffic is TLS 1.3+. Sessions are httpOnly + secure cookie. CSRF, helmet, rate-limit active. We don't store passwords (OAuth-only). VDS hardened with fail2ban + UFW + daily updates.
7. Records Held About You Even If You Are Not a User
The sections above describe account holders. Argos also holds records about accounts that are publicly visible in monitored communities — those people do not need an Argos account. What is held:
- Discord ID, username and name history, avatar history
- Memberships in monitored servers and the roles carried there
- Ban records shared by co-operating servers
- Ticket metadata (who, when, which category — not the contents)
- Signals extracted from public messages in monitored servers (invite links, keywords)
- FiveM connection identifiers (Steam, license, Xbox Live and similar)
IP addresses and hardware identifiers that may arrive with ban records are treated as restricted data; they are not used for display in standard user queries and access is limited by role. We have no access to your private messages, your DMs, or servers we do not monitor, and nothing is scanned on your computer.
The principal basis for this processing is legitimate interest: letting server owners recognise people linked to security incidents in other communities. Each objection is assessed by data category. Data for which no continuing processing condition exists is erased or anonymised. Limited records needed for a legal obligation, the rights of others, or the establishment, exercise or defence of legal claims may be retained in restricted form with the reason documented. You can contest an inaccurate ban record at /ban-appeal.
8. International Transfers
The infrastructure is hosted abroad: content delivery and attack filtering on Cloudflare, web hosting on Hostinger, and the application server on a virtual server abroad. Authentication runs through Discord. Where analytics consent is granted, aggregate usage measurements are processed through Google Analytics. Transfers are limited under applicable data protection rules, contractual safeguards and data-minimisation principles. If you live in Turkey, our KVKK notice also applies.
9. Age Requirement
You sign in to Argos with a Discord account, so you must meet Discord’s own minimum age (13 in most countries, higher in some). We do not knowingly offer Argos to anyone below that age. If we learn an account belongs to someone under it, we delete the record.
10. Changes to This Policy
This policy may be updated as the service or applicable law changes. Meaningful changes are announced on the site or in the announcements channel of our Discord community server. Changes apply prospectively from their stated effective date; they do not retroactively narrow a data-subject request already received or remove rights granted by law.
end of recorddoc/privacy