Archived version
Discord Tickets privacy notice
Written for the person who opened a ticket: what is kept afterwards, that it is encrypted, and that nothing deletes itself.
This is the current version. It is kept here under a fixed address so it can be cited and compared. The live document is the same text.
If you opened a ticket on somebody's server
Short version, because this is the part that concerns you.
Your ticket conversation is probably kept after it closes. Archiving is on by default: the messages, the names of everyone in the ticket, and a readable transcript of the whole thing are stored when the ticket closes. The server's staff can read it afterwards.
It is encrypted where it is stored. Message content, usernames and display names are encrypted before they are written to the database, so somebody with the database alone does not have your conversation.
Nothing deletes itself. There is no retention period. A transcript stays until somebody removes it.
The server's operators decide all of this, not us. They can switch archiving off, and they can delete transcripts. Ask them.
Who is responsible
The people who run the Discord server. They are the controller.
Where we host the bot for them, we are their processor and act on their instructions; for our own infrastructure the controller is Gelhaus Solutions, Eichenwald 3, 49624 Löningen, Germany, egelhaus@ennogelhaus.de.
What is stored
About a ticket: who opened it, when, its number and topic, the category, who claimed it, who closed it and the reason, timestamps for the first response and last message, the message count, priority, and any tags applied.
Your answers to the questions the server asks when a ticket is opened. Encrypted.
The conversation, where archiving is on: every message's content, its author, whether it was edited or deleted. Content is encrypted.
The people in it: user id, username, display name, avatar reference and hoisted role at the time. Username and display name are encrypted; the Discord user id and the avatar reference are not, because they are Discord's own identifiers rather than text somebody wrote.
A rendered HTML transcript of the whole ticket.
Feedback, where the server asks for it: a rating, a comment, and the answers to any feedback form. Encrypted.
Server configuration, including a blocklist of users and roles that may not open tickets.
Encryption, precisely
Encryption is on unless somebody deliberately turned it off, and turning it off in production requires setting a second environment variable specifically named to make that an uncomfortable thing to do, plus the process prints a warning banner every time it starts. On instances we host, it is on.
It protects the stored data. It does not hide anything from the server's own staff, who read tickets through the bot in the ordinary way — and it is not meant to.
Why
Running the support service is the server operator's legitimate interest under Art. 6(1)(f), and where you opened the ticket to get help from them it is also Art. 6(1)(b): you asked them to act.
How long
Indefinitely, unless somebody deletes it. There is no automatic expiry. This is the honest answer and it is worth knowing before typing something into a ticket.
A server can switch archiving off entirely, in which case the conversation is not stored at all. It can also delete transcripts and export its data.
Who else touches it
Where we host it: IONOS SE (Germany), Contabo GmbH (Germany, being wound down), and our own hardware in Germany. All in the EU, no transfer to a third country. No error reporting service, no analytics, no AI.
Discord itself is where the conversation happens and is subject to Discord's own terms with you, which are not ours.
Your rights
Access, rectification, erasure, restriction, portability and objection — directed to the people who run the server, because they are the controller. Where we host it for them, they can act and we assist them.
You may complain to a supervisory authority. Ours is Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover; if the server is run by somebody else, theirs is the competent one.
Version identifier
discord-tickets-revamped-privacy-2026-09-06
Content hash, SHA-256
afc87a89eb378631c34359cf3ba4bb4f331bd3ebca37dfbf3ac2c61be611879f