Privacy Policy
This Privacy Policy explains how personal data is processed when you visit aethor.eu, use the Aethor Discord application, interact with Aethor commands, use the web dashboard, contact us, or participate in a Discord server in which Aethor has been installed.
1. Controller
The controller responsible for the processing of personal data in connection with Aethor and aethor.eu is:
Yoshua Bieren
Aethor
c/o Impressumservice Dein-Impressum
Stettiner Straße 41
35410 Hungen
Germany
Email: bierenyoshua@gmail.com
“Aethor” is the name of the software project and Discord application operated by Yoshua Bieren and does not constitute a separate legal entity.
2. Scope of this Privacy Policy
This Privacy Policy applies to the processing of personal data through:
- the website aethor.eu;
- the Aethor Discord bot/application;
- the Aethor web dashboard;
- Discord OAuth2 authentication used in connection with Aethor;
- moderation, logging, AutoMod, anti-abuse and security features;
- ticket, ModMail and support functionality;
- communications sent directly to us.
Discord itself is a separate service provided by Discord and processes personal data in accordance with its own terms and privacy information.
3. Categories of Personal Data
Depending on the features used and the permissions granted to Aethor within a Discord server, the following categories of personal data may be processed.
Discord account and profile data
- Discord user ID;
- username;
- display name and server nickname;
- avatar and other publicly available profile information;
- roles and relevant server permissions;
- server membership information;
- account creation date or account age where required for security features;
- language or locale information where provided by Discord.
Discord server data
- server ID and server name;
- channel and category IDs;
- role IDs and permission information;
- server configuration;
- configured moderation and logging settings;
- configured AutoMod rules and exemptions.
Messages and interaction data
Where necessary for a feature enabled by a Discord server administrator, Aethor may process:
- message IDs;
- message content;
- message timestamps;
- channel information;
- mentions;
- links;
- attachments and attachment metadata;
- reactions;
- commands and command parameters;
- button, modal and other Discord interaction data.
Message content is accessed only where required for functionality such as moderation, AutoMod, logging, ModMail, tickets, support or other features explicitly enabled by authorised server administrators.
Moderation data
- warnings;
- timeouts;
- kicks and bans;
- moderation case IDs;
- moderation reasons;
- responsible moderator information;
- timestamps;
- relevant message or channel references;
- evidence required to document a moderation action;
- AutoMod violations and triggered moderation rules.
Security and anti-abuse data
- message frequency;
- mention frequency;
- join timestamps;
- account age;
- link and domain information;
- spam indicators;
- repeated-message indicators;
- raid and mass-join indicators;
- other technical indicators required to prevent abuse.
Such information is used to identify technical patterns and rule violations. Aethor does not use Discord API data to create advertising profiles or commercially trade user profiles.
4. Tickets, ModMail and Support
If you open a ticket, use ModMail, contact server staff through Aethor or otherwise use support functionality, Aethor may process the information you submit as part of that communication.
This may include:
- your Discord user ID and username;
- the content of your request;
- attachments submitted by you;
- messages exchanged with moderators or support staff;
- timestamps;
- ticket status and internal assignment information;
- transcripts where the relevant server has enabled transcript functionality.
Users should not submit special categories of personal data, financial information, passwords, authentication tokens or other highly sensitive information through Aethor unless absolutely necessary and explicitly requested through an appropriate secure process.
5. Logging Features
Discord server administrators may configure Aethor to log certain events occurring within their server.
Depending on the configuration, logs may include member joins and leaves, moderation actions, role changes, channel changes, voice-state metadata, deleted or edited messages and other server events.
Aethor does not record or store the actual audio content of Discord voice conversations through ordinary voice logging functionality. Voice logging refers to technical metadata such as joining, leaving or switching voice channels.
Server administrators are responsible for configuring logging features in a lawful and proportionate manner and for informing their server members where required.
6. AutoMod and Automated Moderation
Aethor may automatically analyse Discord messages and server events where an authorised server administrator has enabled moderation or security features.
Depending on configuration, the system may identify spam, excessive mentions, repeated messages, prohibited words, links, invitations, suspicious URLs, excessive characters, raid patterns or other rule violations.
Aethor may automatically perform configured technical moderation actions, including deleting messages, recording an infraction, issuing a warning or applying a temporary moderation restriction.
Server administrators remain responsible for the rules they configure and may review, modify or reverse moderation actions where permitted by Discord and the respective server's policies.
Aethor is not intended to make decisions that produce legal effects concerning users or similarly significantly affect them within the meaning of Article 22 GDPR.
7. Web Dashboard and Discord OAuth2
Where the Aethor dashboard uses Discord OAuth2, users are redirected to Discord in order to authenticate.
After successful authentication, Aethor may receive information authorised through the selected OAuth2 scopes. This may include your Discord user ID, username, avatar and information regarding Discord servers for which you have relevant permissions.
Authentication information is used to identify the logged-in user, determine which servers the user is authorised to configure and protect the dashboard against unauthorised access.
Authentication tokens must only be retained for as long as required for the authentication session or functionality for which they were issued and must be protected against unauthorised access.
8. Website Access and Server Log Files
When aethor.eu is accessed, technical information may automatically be transmitted by the user's browser to the server hosting the website.
This information may include:
- IP address;
- date and time of access;
- requested page or resource;
- HTTP status code;
- browser type and version;
- operating system;
- referrer information where transmitted;
- technical security and error information.
These data are processed in order to deliver the website, maintain technical security, identify attacks, diagnose faults and ensure the reliable operation of the service.
9. Purposes and Legal Bases of Processing
| Purpose | Typical Data | Legal Basis |
|---|---|---|
| Providing Aethor and requested functionality | Discord IDs, commands, settings, interactions | Article 6(1)(b) GDPR where processing is necessary to provide a requested service |
| Operating Discord server features | Member, server, message and configuration data | Article 6(1)(f) GDPR, legitimate interest in providing functional server-management tools |
| Moderation and abuse prevention | Messages, infractions, moderation cases, security indicators | Article 6(1)(f) GDPR, legitimate interest in maintaining safe and secure communities |
| Website operation and security | IP address, access logs, technical information | Article 6(1)(f) GDPR, legitimate interest in secure and reliable operation |
| Responding to enquiries | Email address, Discord account data, communication content | Article 6(1)(b) GDPR where contract-related; otherwise Article 6(1)(f) GDPR |
| Compliance with legal obligations | Information required by applicable law | Article 6(1)(c) GDPR |
| Optional processing based on explicit consent | Data associated with the relevant optional feature | Article 6(1)(a) GDPR |
Where processing is based on Article 6(1)(f) GDPR, the legitimate interests include providing the requested Discord functionality, protecting Aethor and participating communities against abuse, maintaining system stability, preventing fraud and enforcing technical and community rules.
10. Discord Server Administrators
Many Aethor features are configured independently by the administrators of individual Discord servers.
Server administrators may determine which logging, moderation, ticket or security features are enabled and how those features are used within their community.
Depending on the specific processing activity, a Discord server operator may therefore have separate responsibilities under applicable data protection law.
Where Aethor processes personal data solely on documented instructions of another controller, the respective roles and any legally required data-processing arrangements must be determined separately.
11. Recipients and Service Providers
Personal data may be disclosed to service providers only where this is necessary to operate Aethor, provide requested functionality, protect the service or comply with legal obligations.
Potential recipients may include:
- Discord and its affiliated service providers;
- hosting and infrastructure providers;
- database and storage providers;
- email and communication providers;
- technical security and backup providers;
- authorised moderators or server administrators where required for the requested feature;
- public authorities where disclosure is required by law.
Service providers are selected with regard to data protection and security requirements and are given access only to data required for their respective task.
Aethor does not sell Discord API data or disclose it to advertising networks or data brokers.
12. International Data Transfers
Some service providers involved in operating Aethor or Discord may process personal data outside the European Union or European Economic Area, including in the United States.
Where personal data is transferred to a country outside the EEA, such transfers are made only where an appropriate legal transfer mechanism is available. Depending on the provider and circumstances, this may include an adequacy decision, participation in an applicable data privacy framework or European Commission Standard Contractual Clauses.
Discord states that it uses legally recognised mechanisms for international transfers, including applicable adequacy mechanisms and Standard Contractual Clauses.
13. Storage and Retention
Personal data is retained only for as long as necessary for the respective processing purpose, unless longer retention is required by law or necessary for the establishment, exercise or defence of legal claims.
| Data Category | Retention |
|---|---|
| Website security and access logs | Up to 14 days unless required longer to investigate a security incident |
| Discord authentication sessions | Until logout, expiry or revocation of the relevant session |
| Server configuration | For as long as Aethor is installed, plus up to 30 days after removal for recovery and deletion processing |
| Ordinary event and message logs stored by Aethor | Up to 90 days unless deleted earlier or a shorter period is configured |
| Moderation cases and infractions | Up to 24 months, unless earlier deletion is appropriate or longer retention is legally necessary |
| Closed ticket and ModMail data | Up to 180 days after closure unless the relevant server deletes it earlier |
| Anti-abuse and security event data | Up to 90 days, or longer where necessary to investigate an active security incident |
| Support correspondence | Normally up to 24 months after the matter is resolved |
| Backups | Deleted data may remain in protected rolling backups for up to 30 additional days |
Data may be deleted sooner where it is no longer required. Individual server administrators may also be provided with functionality to remove stored server data.
14. Cookies, Local Storage and Similar Technologies
Aethor may use technically necessary cookies, local storage or similar technologies where required to provide login sessions, maintain security, remember essential preferences or operate requested dashboard functionality.
Access to or storage of information on a user's device that is strictly necessary to provide a digital service expressly requested by the user may take place without consent where permitted by Section 25(2) TDDDG.
Technologies that are not strictly necessary, including optional analytics, advertising or tracking technologies, may only be activated where a valid legal basis and, where required, prior user consent exist.
Aethor does not use personal data obtained through Discord for behavioural advertising.
15. Data Security
Appropriate technical and organisational measures are used to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Depending on the relevant system, such measures may include encrypted network connections, restricted administrative access, role-based permissions, secure authentication, database access controls, logging of administrative activity, software updates, backups and other security measures appropriate to the risk.
No internet-based service can guarantee absolute security. Security measures are therefore continuously reviewed and adjusted where reasonably necessary.
16. Data Obtained From Discord
A significant portion of the personal data processed by Aethor is obtained through the official Discord API rather than directly from the data subject.
The exact information available to Aethor depends on the Discord permissions, intents, OAuth scopes and functionality enabled for the application and the relevant server.
Additional information may be provided by Discord server administrators, moderators or other users, for example when a moderation reason, ticket message or report is submitted.
17. Your Rights
Subject to the requirements and limitations of applicable law, data subjects may have the following rights under the GDPR:
- the right to obtain information about whether personal data is being processed;
- the right of access to personal data;
- the right to rectification of inaccurate personal data;
- the right to erasure of personal data;
- the right to restriction of processing;
- the right to data portability where the statutory requirements are met;
- the right to object to certain processing;
- the right to withdraw consent at any time where processing is based on consent;
- the right to lodge a complaint with a competent data protection supervisory authority.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
18. Right to Object
Where personal data is processed on the basis of Article 6(1)(f) GDPR, you have the right to object to the processing on grounds relating to your particular situation.
We will cease processing the relevant personal data unless compelling legitimate grounds for the processing can be demonstrated which override your interests, rights and freedoms, or the processing is required for the establishment, exercise or defence of legal claims.
19. Requests for Access or Deletion
Privacy-related requests may be submitted using the contact details provided in this Privacy Policy.
In order to locate Discord-related data, we may ask you to provide your Discord user ID or other information reasonably necessary to identify the relevant records.
Additional verification may be required where reasonably necessary to ensure that personal data is not disclosed or deleted at the request of an unauthorised person.
Requests will be handled in accordance with applicable data protection law.
20. Removal of Aethor From a Discord Server
Removing Aethor from a Discord server stops future processing associated with ordinary server operation, subject to technical completion of pending operations.
Stored server configuration and other data that is no longer required will be deleted or anonymised in accordance with the retention periods described above.
Certain moderation, security or legal records may be retained for a limited additional period where there is a legitimate or legal reason to do so.
21. Children and Minimum Age
Aethor is intended to be used only in accordance with Discord's applicable minimum-age requirements.
We do not knowingly request personal data from persons who are not permitted to use Discord under Discord's rules or applicable law.
If we become aware that personal data has been processed contrary to applicable minimum-age requirements, appropriate steps will be taken to remove the data where required.
22. No Sale of Personal Data
Aethor does not sell personal data obtained through Discord or aethor.eu.
Discord API data is not provided to data brokers, advertising networks or other organisations for behavioural advertising purposes.
Message content obtained through Discord is not used to train general-purpose machine learning or artificial-intelligence models unless a separate lawful arrangement and any permissions required by Discord and applicable law exist.
23. Legal Requirements and Protection of Rights
Personal data may be processed or disclosed where reasonably necessary to comply with a binding legal obligation, court order or lawful request from a competent authority.
Data may also be retained or processed where necessary for the establishment, exercise or defence of legal claims, protection against fraud, prevention of abuse or protection of the rights and security of Aethor, its operator or other persons.
24. Changes to this Privacy Policy
This Privacy Policy may be updated where Aethor's functionality, technical infrastructure, service providers or legal requirements change.
The current version will be made available on aethor.eu. Where changes materially affect the way personal data is processed, reasonable measures will be taken to inform users where required.
25. Contact Regarding Data Protection
If you have questions about this Privacy Policy, the processing of your personal data or wish to exercise a data protection right, please contact:
Yoshua Bieren
Aethor
Email:
bierenyoshua@gmail.com