Legal
Privacy policy
Last updated: September 28, 2026
1. Who is responsible
The controller within the meaning of the GDPR is Donnie Graf, Pitzerstraße 4, 67753 Aschbach, Germany. E-mail: [email protected]. See also the legal notice.
2. Message content
Octo reads message content in memory to run the features administrators turn on — auto moderation, the honeypot and message-based automations — and does not store the text of ordinary messages. Three features are the exception:
- Logging module — if enabled, edited and deleted messages are posted, with their text and attachment file names, into the server's own log channel chosen by its administrators. A bulk deletion (e.g. a moderator using
/purge) posts a.txtfile with the deleted messages instead. This only ever goes to the server's own channels — never to us. - Auto Moderation and Honeypot logs — when a message triggers a rule, the log entry posted to the server's log channel includes an excerpt of that message so moderators can see what was caught.
- Ticket transcripts — saved to our database when a ticket is closed, posted to the ticket log channel, and optionally DMed to the person who opened it (if that setting is on). Kept for 12 months.
Outside of these, message content only exists briefly in the Discord library's own in-memory cache (up to about an hour) so recently seen messages can be shown if they're later edited or deleted — it is never written to our database.
3. Data the bot processes on Discord servers
When Octo is added to a server, it receives data from Discord that is needed for the features the server's administrators turn on:
- Server data — server ID, name, icon, owner ID and member count, and the settings the administrators choose in the dashboard.
- Moderation cases — user ID and name of the affected member, the moderator, the action, the reason and the time. Kept for 24 months.
- Member event logging — if the Logging module is on, joins, leaves, nickname/username/avatar changes, role changes and voice activity are posted into the server's own log channels.
- Levels — Discord ID, tag, avatar, XP, level and message count per member, used for the ranking system and the optional public leaderboard. Kept for 12 months after the member's last activity.
- Invite tracker — member and inviter Discord IDs and tags, the invite code used, join and leave times, and a flag for suspected fake accounts. Kept for 12 months.
- Giveaways — who entered which giveaway. Entries are deleted 90 days after the giveaway ends.
- Custom embeds — messages server staff compose and send through the dashboard's Embed Sender are kept until deleted from the dashboard, or until the server leaves.
- Temporary voice channels — channel ID and the ID of the member who owns it, until the channel is deleted.
- Direct messages — Octo DMs members for things administrators configure: punishment notices, welcome messages, level-up announcements, giveaway win notices, ticket transcripts and automation replies. These are sent, not stored, beyond the transcript case above.
- Statistics — only counts per day (joins, leaves, messages, voice minutes, messages per channel). No personal data. Kept for 400 days.
- Global blocklist — if a Discord account or server is blocked from using Octo (e.g. for abuse), we keep its Discord ID, the reason and an optional expiry, based on our legitimate interest in preventing abuse of the service (Art. 6 (1) (f) GDPR).
Legal basis is our legitimate interest in providing the features the server administrators requested (Art. 6 (1) (f) GDPR). The administrators of each server decide which modules are active and are responsible for informing their members.
4. Automated decisions
Some features can take action automatically: the join gate can kick or time out an account below a minimum age or without an avatar, anti-raid and anti-nuke can lock down the server or reverse a burst of harmful actions, and auto moderation or the honeypot can delete a message or punish the member who sent it. These are automated in the sense of Art. 22 GDPR, but every rule is configured — and can be turned off or reversed — by that server's own administrators, not by us. If you believe such an action affected you unfairly, contact that server's staff first; you can also reach us using the details above.
5. Public leaderboard
The Levels module can show a public leaderboard at getocto.gg/leaderboard/[server]. It is off by default and only visible to anyone with the link once a server's administrators explicitly turn it on; the page is never indexed by search engines.
6. Dashboard and login
You sign in with Discord (OAuth2). We receive your Discord user ID, username, display name and avatar, and the list of your servers including your permissions there, so we can show the servers you may manage. Your Discord access token is stored encrypted and used only for this purpose.
- Sessions end when you log out and are deleted after 30 days at the latest.
- Your profile data is deleted after 12 months without a login.
- Changes you make to a server's settings are recorded in that server's audit log (who, what, when) and kept for 12 months.
Legal basis is the performance of the service you request (Art. 6 (1) (b) GDPR).
7. Cookies
We only use one strictly necessary cookie that keeps you signed in, plus a short-lived cookie that protects the login against forgery. No tracking, no analytics, no advertising cookies — which is why there is no cookie banner.
8. Status page
status.getocto.gg shows whether Octo is online. It is served through Cloudflare like the rest of our web traffic (see below) and processes only connection data needed to serve the page — no visitor tracking, and no fonts loaded from Google.
9. When Octo leaves a server
If Octo is removed from a server, all data of that server (settings, cases, tickets, statistics) is deleted after 30 days. The grace period lets administrators re-invite Octo without losing their setup.
10. Hosting and recipients
- Our own servers in Germany run the bot, the dashboard and the database.
- Cloudflare, Inc. (USA) acts as our processor for all web traffic to the site and dashboard, including TLS termination, and protects it against attacks. Cloudflare processes connection data such as IP addresses. Transfers to the USA are based on the EU-US Data Privacy Framework and standard contractual clauses.
- Discord Inc. (USA) operates the platform the bot runs on. Discord's own privacy policy applies to your use of Discord.
- Payments for paid plans will be processed by Discord. We only learn which server has which plan, not your payment details.
We do not sell data and do not share it with anyone else unless we are legally required to.
11. Server logs and backups
Our own servers keep technical logs (request IDs, guild names and error details) for our intended maximum of 14 days, used only to diagnose problems. We take encrypted, off-site backups of the database; when data is deleted per this policy, it will still be included in existing backups until they are rotated out, for up to 30 days.
12. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interest (Art. 15–21 GDPR) — including the automated decisions described in section 4. Write to [email protected] — please include your Discord user ID. You may also lodge a complaint with a data protection supervisory authority, such as the Landesbeauftragter für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz.
13. Minimum age
Octo is used through Discord, so you must meet Discord's own minimum age requirement to use it.
14. Changes
We update this policy when Octo changes. The date at the top shows the latest version.