Privacy Policy
This policy explains what information Gachord collects when you use the bot or its web interface, how we use it, and the choices you have.
01 Overview
This Privacy Policy applies to the Gachord Discord bot and its companion website. It describes the information we collect when you interact with Gachord and how we handle it. By using Gachord you agree to the practices described here.
02 Information we collect
- Discord identifiers. We store Discord IDs (user, server, channel, message, and role IDs) as text. Usernames and avatars are not stored: they are fetched from Discord when a page or message is rendered and held in memory for at most five minutes.
- Gameplay data. Cards you own, shard balances, pulls, pity counters, wishlists, trades, set completions, and Triple Triad match history.
- Server configuration. Settings, drop-rate and pity configuration, card definitions, and any images and text uploaded by server administrators.
- Authentication data. If you sign in to the web interface with Discord, we use OAuth2 with the
identifyandguildsscopes to confirm who you are and which servers you can administer. A signed, expiring session cookie stores your Discord user ID and a snapshot of your administrable servers. We never receive your Discord password. - Usage and security logs. We record limited activity such as command and feature usage, logins, and administrative actions, with timestamps, to operate the service, prevent abuse, and produce aggregate statistics.
- Payment data. If a server subscribes to Premium, Stripe processes the payment. We store a Stripe customer and subscription identifier and the subscriber's Discord ID. We never receive or store your full card number — that is handled by Stripe.
- Voting data. If you vote for Gachord on top.gg, we receive a notification of your vote so we can credit the in-game reward.
03 How we use your information
We use the information above to operate and maintain the bot and website; to run game features such as packs, trading, battles, and leaderboards; to provide and bill Premium subscriptions; to prevent fraud, abuse, and rule violations; to produce aggregate, non-identifying statistics; and to respond to support requests.
05 Third-party services
07 Data retention and deletion
We keep gameplay data for as long as Gachord is installed in your server — your collection, shard balance and pity counters are the game itself. Retention is bounded and enforced automatically:
- Server removal. When Gachord is removed from a server, that server's gameplay and configuration data — cards, uploaded artwork, settings, every record keyed on the server — is deleted 30 days later. The grace period exists so that an accidental removal does not destroy a community's collection; re-adding Gachord within those 30 days cancels the deletion.
- Operational logs. Records of which command or admin action was used, by which user ID and when, are purged after 365 days. Card-drop and mini-game records are purged 90 days after the drop closes. Expired trade offers are deleted when they expire, and top.gg vote records after 365 days.
- Backups. Backups are encrypted and rotate on a ten-day cycle, so a deletion is also complete in backups within about ten days.
- On request. You can delete your own data at any time — see section 10. Deletion takes effect immediately.
Records we must keep for legal, billing or anti-abuse reasons may be retained for as long as required.
08 Data security
We take reasonable technical and organizational measures to protect your information. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
09 Children's privacy
Gachord is not directed to children under 13, or under the minimum age required to use Discord in your country. We do not knowingly collect data from anyone below that age. If you believe a child has provided us with information, contact us and we will remove it.
10 Your rights
Depending on where you live, you may have rights to access, correct, or delete your personal data, or to object to or restrict certain processing. There are two ways to delete your data:
- Self-serve. Sign in on any server's web collection page and use Delete my data at the bottom of the page. This removes your cards, shards, wishlists, decks, pending trade offers, votes and support tickets on every server, immediately and permanently. Your past trades and battles remain in other players' history without your identifier.
- By email. Contact us using the details below. We may need to verify your identity before acting on a request.
11 International transfers
Gachord may be operated from, and your data processed in, countries other than your own. Where we transfer data across borders, we take steps to protect it consistent with this Policy.
12 Changes to this Policy
We may update this Policy from time to time. The "Last updated" date above reflects the latest version, and material changes take effect when posted. Your continued use of Gachord after a change constitutes acceptance of the revised Policy.
13 Contact
For privacy questions or requests, contact us at 0xc0c0@proton.me.