1
Data We Collect
The Bot collects only the minimum data necessary to provide its features. We may collect and store the following categories:
- Discord User IDs โ A numeric identifier assigned by Discord. Used to track balances, roles, and activity within the Bot.
- Discord Server (Guild) IDs and Names โ Used to store per-server configuration and identify which guilds use the Bot.
- Usernames and Discriminators โ May be stored temporarily for display purposes (e.g. leaderboards, logs).
- Command Interaction Data โ Including command names, timestamps, and any parameters you provide when using Bot commands.
- Economy & Game Data โ Virtual currency balances, transaction history, gambling results, and game statistics.
- Verification Data โ Temporary tokens generated during the verification flow, including the associated user ID, guild ID, and CAPTCHA result. Tokens expire and are deleted after use or timeout.
- Server Configuration โ Settings saved by server administrators such as logging channel IDs, welcome channel IDs, role IDs, and enabled/disabled features.
- Access Logs โ Server-side request logs including IP addresses, timestamps, and HTTP routes accessed via the web dashboard. These are used for security monitoring and debugging.
We do not collect real names, email addresses, passwords, payment information, private messages, or any other sensitive personal data.
2
How We Use Your Data
All data collected is used solely to operate and improve the Bot and its associated services. Specifically, data is used to:
- Provide core Bot functionality, including economy systems, games, moderation tools, and server utilities.
- Store user progress and server configuration across Bot restarts and updates.
- Authenticate users via Discord OAuth2 when they access the web dashboard.
- Process CAPTCHA verifications and assign roles upon successful completion.
- Detect and prevent abuse, cheating, or unauthorized use of Bot features.
- Generate anonymized analytics to understand feature usage and improve reliability.
- Maintain access logs for security auditing and debugging purposes.
We do not use your data for advertising, profiling, or any commercial purpose unrelated to operating xCloudd.
3
Data Storage & Security
All data is stored on servers under our direct control. We apply the following security measures:
- Data is stored in local SQLite databases on a secured VPS hosted with Contabo (Frankfurt, Germany).
- All web traffic is encrypted in transit using TLS/HTTPS via Let's Encrypt certificates.
- Access to the server and database is restricted to authorized personnel only.
- Session tokens and verification tokens are cryptographically random and time-limited.
- Sensitive configuration values (tokens, keys) are stored in environment variables, not in source code.
While we take reasonable precautions, no system is 100% secure. By using the Bot, you acknowledge and accept this inherent risk.
4
Data Sharing & Third Parties
We do not sell, rent, or trade your personal data. Limited data interactions with third parties occur only as follows:
- Discord โ The Bot operates on Discord's platform and communicates via the Discord API. Your use of Discord is governed by Discord's own Privacy Policy.
- Google reCAPTCHA โ Used during the verification flow. Google may collect browser and behavioural data as described in Google's Privacy Policy.
- Legal Obligations โ We may disclose data if required by law, court order, or governmental authority.
- Server Administrators โ Server admins may view limited data (such as user IDs and role assignments) through the Bot's admin commands. They do not have access to raw database contents.
5
Data Retention
- Data is retained for as long as it is necessary to provide Bot functionality or as long as the Bot remains in your server.
- Verification tokens are automatically deleted after use or after expiring (typically within 10 minutes).
- Access logs are retained for up to 90 days for security purposes, then purged.
- If the Bot is removed from a server, server-specific configuration data may be retained for up to 30 days before deletion, in case the Bot is re-added.
- You may request full deletion of your data at any time by contacting us (see Section 9).
6
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right of Access โ You may request a summary of the data we hold about you.
- Right to Rectification โ You may request that inaccurate data be corrected.
- Right to Erasure โ You may request deletion of your data ("right to be forgotten").
- Right to Restriction โ You may request that we limit how your data is used in certain circumstances.
- Right to Portability โ You may request a machine-readable copy of your data where technically feasible.
- Right to Object โ You may object to processing of your data at any time.
To exercise any of these rights, contact us via the details in Section 9. We will respond within a reasonable timeframe (typically within 14 days).
You may also stop data collection at any time by removing the Bot from your server or ceasing to use its features.
7
Children's Privacy
xCloudd is not directed at children under the age of 13 (or under 16 in the EU/EEA). We do not knowingly collect personal data from children. Discord itself requires users to be at least 13 years old. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
8
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we do, we will update the "Last updated" date at the top of this page. Significant changes may also be announced in our Discord support server.
Your continued use of the Bot after any changes constitutes your acceptance of the revised policy. We encourage you to review this page periodically.
9
Contact
If you have any questions, concerns, or data requests regarding this Privacy Policy, please contact the developer directly: