DAnalytics privacy notice
Written for the members of a server that uses it as much as for the people who run one: what is recorded, what decides it, and what you can do on your own.
This applies alongside the general terms of service and privacy policy. Where they differ on a point about DAnalytics specifically, this page wins.
If you are a member of a server that uses this
You probably did not choose DAnalytics and have never heard of us. Here is the short version.
The people who run your server decide what is recorded. They are the controller. If you want something changed or deleted, they are who can do it, and the section below tells you how to reach them and what you can do without them.
By default, your messages are not stored. The profile every server starts on records that a message happened — when, in which channel, how long it was, how many people it mentioned — and drops the text. A server administrator can change that. The rest of this notice tells you how to find out what yours has done.
You can act on your own. Type /privacy in the server. It shows what is stored about you and lets you opt out, either for that server or everywhere.
Who is responsible
For a server somebody else runs, they are, and we process nothing.
Where we host DAnalytics for a customer, that customer is still the controller of their server's data and we are their processor under the data processing agreement and its annex.
Gelhaus Solutions, Eichenwald 3, 49624 Löningen, Germany, egelhaus@ennogelhaus.de.
What can be recorded, and what decides it
Every field that could identify somebody has three possible fates: kept as it is, hashed, or dropped. Which one applies is set per server by a profile, and the profile a server starts on is standard.
On standard — the default:
- Message events: time, server, channel, thread, author, a hashed message id, length, word count, who was mentioned, attachment count and kinds, emoji used, whether it was a reply. Not the text. Not attachment filenames.
- Voice: joins, leaves, moves, and the channel. Not audio, and no speaker timeline.
- Members: joins and leaves, account age, roles added and removed, whether a nickname or avatar changed. Not the nickname itself.
- Moderation: the action, the actor, the target, and a hashed reason.
- Reactions, polls answered, interactions and commands used, tickets, boosts, invites, threads, stage and scheduled events.
- Not typing events, not presence activity names, not poll questions, not stage topics.
On minimal, everyone's identity is hashed and nearly everything above is dropped.
On full, message content, attachment filenames, nicknames, presence activity names, poll questions, stage topics and typing events are all recorded in the clear.
Three things bound whatever a server chooses:
- The effective setting is the strictest of the server's profile, its per-field overrides, and a global cap set by whoever operates the instance. A cap above cannot be loosened from below.
- Hashes are HMACs computed with a salt belonging to that server alone. A hash of you in one server cannot be matched against a hash of you in another.
- Changing a profile only affects what happens next. It does not retroactively recover what was dropped.
Where it comes from
Live events from Discord, and — where a server administrator asks for it — history reconstructed from the server's audit log, from a log channel another bot wrote, or from message history. Backfilled events follow the profile in force when the backfill runs.
Accounts on the web interface
Where you sign in to look at dashboards: your Discord id, name, global name, email address, avatar, locale, and the sessions and API tokens you create. API keys are stored as hashes. Dashboards can be shared by link, and a shared link can carry a password — stored as a hash — an expiry, and can be revoked.
What you can do
In Discord, without asking anybody: /privacy shows what is stored about you and lets you opt out for that server or globally. An opt-out is enforced by the software.
Erasure: ask, and the request is tracked through to completion. Where we host the instance, ask the server's operators; they can act, and we assist them.
Everything else — access, rectification, restriction, portability, objection — is directed to whoever runs the server, because they are the controller. If they run it themselves, we cannot reach their database and could not act even if we wanted to.
How long
365 days by default. Retention is enforced by the service rather than by the database, deliberately, so that a server can set its own — which means a server can also extend it, or switch deletion off entirely and keep events indefinitely. Ask yours which it has done; /privacy is the fastest route.
Who else touches it
Where we host it: servers rented from IONOS SE (Germany) and Contabo GmbH (Germany, being wound down), and our own hardware in Germany. All in the EU, no transfer to a third country.
Discord itself is where the data originates and is subject to Discord's own terms, which are not ours.
Where a server administrator connects another bot's API, the credentials for it are stored encrypted, and what that integration does is between them and that bot.
Complaints
You may complain to a supervisory authority. Ours is Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover. If the server is run by somebody else, the competent authority is theirs rather than ours.