YAGPDB privacy notice
Written for members of a server that uses our YAGPDB instance: what the bot records, who decides, and when it is deleted.
This applies alongside the general terms of service and privacy policy. Where they differ on a point about YAGPDB specifically, this page wins.
If you are on a server that uses this bot
The server's moderators decide what the bot records, not us. Ask them first: they control its settings and can delete most of what it holds.
Message logs are deleted after 30 days. Everything else a server holds in the bot stays while the server uses it and is deleted 30 days after the bot leaves the server.
Who is responsible
The people who run the Discord server. They are the controller, and we are their processor.
For our own infrastructure, the dashboard at bot.ennogelhaus.de and the username history (which belongs to no single server), the controller is Gelhaus Solutions, Eichenwald 3, 49624 Löningen, Germany, contact@gplatform.org.
What it records
What a server switches on decides which of these exist:
- Message logs: when a moderator saves a log, with the logs command or with a moderation action, the recent messages of that channel with their authors' Discord ids and names.
- Moderation records: warnings, mutes and their reasons, automod rule hits, and the commands members ran with their text.
- Nickname history on the server, and username history across the servers the bot is on.
- Reputation points and their log, verification sessions and verified members, role menus, reminders, event sign-ups and tickets opened through the bot.
- Data a server's custom commands store, which can name members.
- Server statistics in aggregate: member and message counts over time.
- The server's configuration, and a log of who changed it in the dashboard.
Signing in to the dashboard
The dashboard signs you in with Discord. It receives your Discord id, name and avatar and the servers you share with the bot, and keeps a session until you sign out or it expires. Avatars and server icons load from Discord's servers; everything else the dashboard needs, fonts and scripts included, comes from our own server. Our web server logs each request with your IP address and browser and deletes the log after 14 days.
Why
Moderating and running the server is the server operator's legitimate interest under Art. 6(1)(f) GDPR. The username history serves the same moderation purpose and rests on ours and the servers' legitimate interest. The dashboard sign-in and the web server log are needed to provide the dashboard you asked for, Art. 6(1)(b) and (f).
How long
- Message logs: 30 days after they were saved.
- Everything a server holds in the bot: while the server uses it, and deleted 30 days after the bot leaves.
- Username history: each entry 24 months after it was recorded.
- Web server log: 14 days. Copies in backups expire within 90 days.
Who else receives it
Discord, Inc. (United States) is where all of this happens and delivers everything the bot sees, under Discord's own terms with you. The bot runs on a server we rent from IONOS SE in Germany.
Google, only on a server that uses member verification: the verification page uses Google reCAPTCHA, which receives your IP address and browser data. Google LLC is certified under the EU-US Data Privacy Framework.
The bot checks links against Google Safe Browsing using lists it downloads; no message and nothing about you is sent. Feeds from Reddit and Twitch fetch public posts and send nothing about members. No analytics, no error reporting service, no AI.
Your rights
Access, rectification, erasure, restriction, portability and objection: ask the server's moderators, because they are the controller. You can also write to us, and we pass it on or act on the server operator's instruction. For the username history and the dashboard, write to us directly.
You may complain to a supervisory authority. Ours is Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover.
Versions of this document
- 2026-10-03 in force since 3 October 2026