file 02 / 04 · legal register
Privacy Policy.
doc/privacylast updated 2026-05-25lang en
1. Information We Collect
Through Discord OAuth we only receive:
- Discord user ID
- Username + global name
- Avatar URL
- Email (for sign-in)
We never access your Discord servers, messages, or DMs.
2. How We Use Data
- Account authentication and session management
- Tier tracking (free/premium)
- Query quota (5/day for free)
- Audit log (who queried what — for security)
3. Data Retention
Data is kept while your account is active. Upon deletion request, all data is removed within 30 days. Audit logs are auto-purged after 90 days (GDPR compliance).
4. Third-Party Sharing
Your data is never shared with third parties except under legal obligation — and you will be notified in such cases.
5. Your Rights
- Request access to your data (via Discord contact)
- Correction / deletion of your data
- Object to processing
- Data portability (JSON export)
6. Security
All traffic is TLS 1.3+. Sessions are httpOnly + secure cookie. CSRF, helmet, rate-limit active. We don't store passwords (OAuth-only). VDS hardened with fail2ban + UFW + daily updates.
end of recorddoc/privacy