Privacy Policy
1. Controller
Benedict Schlegel, email: privacy@zonebuddy.de. The address can be found in the Imprint.
2. Hosting and server logs
The website, dashboard, API (api.zonebuddy.de) and bot run on servers of Hetzner Online GmbH in Germany. When you access them, the web server stores technically necessary information in access logs: IP address, time, requested address, status code and browser identifier.
The purpose is secure operation, in particular detecting and defending against attacks (among others with the software CrowdSec). The legal basis is Art. 6(1)(f) GDPR. The logs are deleted after about seven days.
Operational logs: the bot, dashboard and API write technical events (e.g. errors, sign-in attempts, executed commands, request duration) with time, Discord ID and server ID to an internal log on a separate server at Hetzner in Germany. IP addresses are shortened (last block removed); passwords, tokens and message contents are not logged. The purpose is to find bugs and detect abuse (Art. 6(1)(f) GDPR). Only the ZoneBuddy team has access; entries are deleted after 14 days.
3. This website
zonebuddy.de itself does not set cookies and does not use analytics services. Our own ad spaces (labelled “Ad”) are served from our own server – without tracking and without cookies; only a click takes you to the advertiser’s site. In addition, ads from Google AdSense may appear (see below). Fonts are loaded from our own server, not from third parties. The status indicator in the footer queries the bot status from our own API.
4. Donations
The donation buttons (Ko-fi, GoFundMe) are simple links. Only when you click them do you leave zonebuddy.de; the privacy policy of the respective provider applies there. When you donate, we learn what the provider sends us (usually name, email address, amount and possibly your message). We use this only to attribute the donation and to thank you if applicable, and do not link it to your Discord account. It is kept as long as tax law requires.
Advertising (Google AdSense): zonebuddy.de displays ads from Google AdSense (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). When you visit the site, your browser loads a script from Google; Google receives technical data such as IP address, browser and device information and the page visited. Before Google uses cookies or similar technologies for personalised advertising and measurement, Google’s consent dialog (“Privacy & messaging”, certified under the IAB Transparency & Consent Framework) asks for your consent. If you decline, Google shows at most non-personalised or limited ads, for which Google may use cookies only for fraud prevention and frequency capping. The legal basis for personalised advertising is your consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR), otherwise our legitimate interest in financing the free service (Art. 6(1)(f) GDPR). Google stores your decision in a cookie; you can change or withdraw it at any time via “Privacy settings” in the footer. Data may be transferred to Google LLC in the USA; Google is certified under the EU-US Data Privacy Framework (Art. 45 GDPR). You can also turn off personalised advertising at adssettings.google.com. Details: How Google uses cookies in advertising and Google’s Privacy Policy.
5. Signing in to the dashboard
Signing in at app.zonebuddy.de is done via Discord (OAuth2) with the scopes “identify” and “guilds”. We receive your Discord ID, username, avatar and the list of your servers with your permissions there — to check which servers you may manage.
After signing in, your browser stores a sign-in token (in local storage, not a cookie) that expires after seven days or is deleted when you sign out. Changes you make in the dashboard are logged with your Discord ID and name in the activity log of the respective server. Activity log entries are automatically deleted after 12 months, moderation cases after 24 months. The legal basis is Art. 6(1)(b) GDPR (provision of the dashboard).
The sign-in itself is subject to the privacy policy of Discord Inc. (USA).
6. The bot on Discord servers
On servers ZoneBuddy has been invited to, the bot processes the following about members:
- Discord ID, username, date of joining and, if applicable, leaving the server – for all members as soon as the bot sees them (not only after their first message), so that leaderboards, profiles and statistics are complete
- Activity counters: number of messages, minutes in voice chat, XP, level, daily streak — no message contents. For server statistics and the weekly report, additionally daily values (messages per hour, channel and member, voice minutes per member); these are automatically deleted after 400 days. With leaderboard seasons enabled, XP per season.
- Economy and games: balance, transactions, game statistics, purchases, loans, crypto holdings
- Moderation: warnings with reason, moderation cases, temporary bans
- Birthdays — only if you enter yours yourself; the year of birth is optional
- Scam image block (only if the server has enabled it): a fingerprint (perceptual hash, 64 bits) is calculated from image attachments and compared with a block list; the image itself is not stored for this. Only fingerprints of images the team has marked as scams or that appeared in a wave of new accounts are added to the block list. For wave detection, the bot remembers in memory for up to two hours who posted which fingerprint.
- Images a server’s team uploads in the dashboard for messages: they are stored and – like images in Discord – publicly accessible via their random link until the team deletes them
- Tickets (only if the server has enabled them): who opened, claimed and closed a ticket and when, the answers to the questions before opening and, if applicable, the reason for closing. A transcript (history of the ticket channel, at most 1,000 messages) is only stored if the team creates one or has enabled automatic transcripts for the server; it is accessible via a random, unguessable link until the team deletes it.
- Applications and forms (only if the server has enabled them): your answers, time, the team’s decision with reason as well as follow-up questions and your answers to them. For multi-page forms, progress is stored for at most one hour.
- Voice support (only if the server has enabled it): when you entered the waiting room, which team member claimed and closed the case, and the team’s notes on the case
- Team management (only for team members of a server that uses it): team warnings with reason and absences with period, reason and decision
- Suggestions (only if the server has enabled them): title, description and category of your suggestion, who voted for or against it, and the team’s decision with reason – even for “anonymous” suggestions, the server’s team can see who submitted them
- Invites (only if the server has enabled them): whose invite or which invite code you joined through, when you joined and possibly left, and whether your account was younger than the server’s requirement; plus a bonus assigned by the team. To detect this, the bot reads the usage counters of the server’s invites.
- Auto roles with “restore roles” (only if the server has enabled it): when you leave the server, the list of your roles so you get them back when you return; deleted when you rejoin or after 180 days at the latest
- Verification (only if the server has enabled it): status (pending/verified/removed), time, failed attempts and, if applicable, the note that your Discord account is younger than the server’s requirement; the captcha code is only stored encrypted (hashed). Deleted after 7 days.
Messages are only checked in memory — for XP and, if a server has enabled AutoMod, against its rules (e.g. spam or links). The content is neither stored nor logged.
The legal basis is Art. 6(1)(f) GDPR: server owners have a legitimate interest in moderation and community features. For birthdays, the legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by deleting the entry (/birthday remove).
The data remains stored until it is deleted — at your request or that of the server owner. Some data deletes itself: activity log entries after 12 months, moderation cases (e.g. kick, ban, timeout) after 24 months, daily challenges after 30 days, AI chat counters after 14 days, expired boosts after one hour. Warnings remain stored (including lifted ones) until you request deletion.
7. AI chat and AI images
AI chat and AI images are off by default. If a server enables them, they only apply in the channels selected for them. When you write in the AI chat, we send the text of your message together with your display name to OpenAI (OpenAI, L.L.C., USA) to generate a reply. So that the AI can follow the conversation, up to eight previous messages from that channel (at most 30 minutes old, with display names) are also sent, as well as – if you reply to a message – its text and its author’s display name. In the normal AI chat, the AI also knows the server name, the bot’s commands and the server knowledge stored by the server. If a server has enabled AI welcome characters, only your display name (and the server name) is sent to OpenAI when you join, so the character can greet you. ZoneBuddy itself does not store the contents, only a counter for the daily limits.
In the AI image channel, we send the text of your message to OpenAI, first for automatic screening for prohibited content, then for image generation. If you edit an image via “Edit”, your change and the image are sent to OpenAI — either the image from the channel or one you upload yourself in the form. The bot posts the result in the channel with your display name; ZoneBuddy stores neither the request nor the image, but only logs who generated or edited an image and when. For the daily points balance when editing, we store how many points you used on which day; these entries are deleted after 14 days. Images are labelled as AI-generated.
AI moderation: if a server enables AI moderation in AutoMod, we send the text of new messages (four letters or more, not from moderators or exempt roles/channels) to OpenAI’s moderation API. Only an assessment of whether the message is, for example, insulting or threatening is returned; the bot then deletes the message, warns or reports it to the server’s team – depending on the settings. We do not store any message content, only the rule, category and action in the server’s log. The legal basis is the server’s legitimate interest in a safe community (Art. 6(1)(f) GDPR).
AI welcome characters: if a server has enabled them, we send your display name and the server name to OpenAI when you join, so the character can greet you personally. Nothing is stored.
OpenAI processes the data under its own terms; according to OpenAI, data submitted via the API is not used for training and is retained for at most 30 days for abuse detection. Data is transferred to the USA in the process. If you do not want this, do not write in AI chat channels.
8. Roast channel and roast files
If a server sets up a roast channel, each member chooses on their first message how personal the bot may get: FULL, LITE or Don’t use. We store the choice with your Discord ID; you can change it at any time with /roastfile mode.
Roast file: the server’s moderators can store short details about members (e.g. game name, role, running gags); with FULL you can submit details yourself, which moderators review before saving. The file is only used if you have chosen FULL.
Learning (FULL only): the bot remembers your messages as well as messages from others that mention you, name you or reply to you – except in channels the server excludes and except from members who chose “Don’t use”. Once a day, these messages are sent to OpenAI (USA) and condensed into at most 12 bullet points; addresses, health, origin, religion and sexuality are excluded. The messages themselves are deleted after evaluation, after three days at the latest; only the bullet points remain stored. Roast memory (FULL and LITE): so that the bot does not repeat itself, we store its last six roast lines about you (considered for at most 14 days) and include them in the next roast sent to OpenAI. If you choose “Don’t use”, we delete them immediately. If you switch to LITE or “Don’t use”, we immediately delete what was learned and cached; moderators delete the file on request.
The legal basis is your consent by choosing FULL (Art. 6(1)(a) GDPR), which you can withdraw at any time by switching to LITE; for messages from others about you, it is the members’ legitimate interest in the roast feature you chose with FULL (Art. 6(1)(f) GDPR).
9. Bug reports and feature requests
If you report a bug or request via /bugreport or with “bug:” or “feature:” in the chat, we store the text, Discord ID, username and server on our server. To process it, we also create an entry (issue) in a non-public project on GitHub (GitHub, Inc., USA). We only transmit the text of your report, the type (bug/request), the time and an internal number – not your name, Discord ID or server. Therefore, please do not include personal details in the report. The transfer to the USA is based on the EU-US Data Privacy Framework, under which GitHub is certified. The purpose is to improve ZoneBuddy (Art. 6(1)(f) GDPR); we delete the entries when they are resolved, after two years at the latest.
10. Premium and payment
Server owners can buy ZoneBuddy Premium (subscription or one-time payment). Payment is processed by Stripe (Stripe Payments Europe, Ltd., Ireland). On Stripe’s checkout page you enter your name, email address, billing address if applicable and your payment method; only Stripe receives card details, not us. Stripe also processes the data for fraud prevention and may transfer it to Stripe, Inc. (USA) (EU Standard Contractual Clauses, EU-US Data Privacy Framework). Stripe’s privacy policy also applies.
For the purchase we store: server ID, Discord ID of the buyer, Stripe customer number, selected plan, term, status and expiry date. We also receive invoice data from Stripe (name, email, amount). The legal basis is performance of the contract (Art. 6(1)(b) GDPR) and, for invoices, the statutory retention obligation (Art. 6(1)(c) GDPR, § 147 AO, § 257 HGB: up to 10 years). You manage cancellation, invoices and payment methods in Stripe’s customer portal, accessible via “Manage subscription” in the dashboard.
Cancellation via “Cancel contracts here”: we store the details from the form (name, email, server and contract if applicable, type, reason, date) with the time of receipt in order to process the cancellation and be able to prove it (Art. 6(1)(b) and (c) GDPR). It is deleted after three years.
11. Twitch, YouTube and Reddit notifications
For stream, video and post notifications, the bot queries public information about the registered channels from Twitch (Twitch Interactive, Inc., USA), YouTube (Google Ireland Ltd.) and Reddit (Reddit, Inc., USA). No data of server members is transmitted.
12. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interests. You can withdraw consent at any time with effect for the future (Art. 7(3) GDPR). To do so, write to privacy@zonebuddy.de — please state your Discord ID and the server concerned.
You can also lodge a complaint with a data protection supervisory authority.