discord bot
Last revised:
The same operator runs the website and bot. You do not need a Gamorium account to ask a privacy question or exercise your rights. Full statutory details are in the imprint.
| Situation | What happens | Legal basis |
|---|---|---|
| You have not opted in | We receive your Discord ID and presence in memory, check a one-way code, then discard the packet without storing anything about you. | Art. 6(1)(f) GDPR - operating the opt-in feature with the least possible processing. |
| You use a command | We process the command and your Discord ID to reply, rate-limit abuse and keep minimal diagnostics for 30 days. | Art. 6(1)(f) GDPR - operation, security and cost protection. |
| You opt into play recording | We store game activity and session times against a one-way account code until you withdraw and erase it. | Art. 6(1)(a) GDPR - your consent. |
| You send feedback | We store what you enter and limited operational context for 12 or 24 months. | Art. 6(1)(f) GDPR - handling reports and improving the bot. |
| An admin installs the bot | We keep pseudonymous install state and lifecycle history for 24 months. | Art. 6(1)(f) GDPR - reliable operation and aggregate install, retention and churn measurement. |
Discord sends the bot the presence of members in every server where it is installed. It does not offer a way to request presence only for people who opted into Gamorium.
For each packet, we derive a one-way code from your Discord ID and check whether it belongs to someone who opted in. If it does not, the packet is dropped in memory before its activity is inspected, stored or logged. We do not retain your ID or the derived code. Three anonymous in-memory totals count received, discarded and opted-in packets so we can detect a broken connection; they contain nothing about a person.
You can prevent receipt entirely by disabling activity sharing globally or for that server in Discord. Removing the bot from the server also stops it.
Because we keep no identifier and no contact details for anyone who has not opted in, we cannot notify you individually that this happened, and building the ability to do so would mean retaining exactly the data we discard. This notice, published and reachable without an account, is the measure we take instead - which is what Art. 14(5)(b) GDPR contemplates where individual notice is impossible or disproportionate.
When you use a slash command, button, select menu or modal, Discord sends the interaction and your user ID so we can respond. We use a one-way caller code for rate limiting and, for personal commands, to find a Discord account you previously linked. The raw ID is not written to our database.
We retain a diagnostic event for 30 days containing the command or control name, outcome, duration, locale and one-way caller and server codes. It excludes command options, game titles, modal text, messages and raw Discord IDs. A rate-limit counter row holds a keyed one-way digest of the caller rather than a raw identifier, and is deleted once it is 26 hours old, whatever its window length.
If /scout or /fit names an uncatalogued game, we send the game title alone to Anthropic's Claude API (Anthropic Ireland, Limited). Claude may search the web for an unfamiliar title, and we may retain the public source URLs with the catalog score. No Discord ID, portrait or server information is included. See the website notice's AI section for the recipient and transfer details.
/feedback and Report problem modals store the report type, description you enter, allowlisted surface, app version and time. We do not attach commands, game titles, presence, messages, tokens or server member lists. Anonymous tickets are deleted after 12 months. If you request follow-up, we also retain a one-way caller code and delete the ticket after 24 months. The ticket ID lets you request earlier deletion.
To triage reports we also post each ticket as a private thread in our own Discord support server, containing the ticket ID, report type, surface, app version and the description you entered. It never contains your Discord account, name or the one-way caller code, so the thread cannot be traced back to you. Deleting a ticket by its ID removes the thread too.
Recording starts only after /consent shows the disclosure and you complete two deliberate steps: choose enable, then confirm the separate modal. Joining a server, using another command or linking Discord does not enable recording.
After consent, we store the game name, optional activity details and state, Discord application ID, and session start and end times. They are attached to a one-way account code rather than your Discord ID. You can correct or exclude sessions and create future ignore rules on your private account page. See the website notice's play-activity section for the corresponding account processing.
Pausing stops new recording but retains history. Withdraw and erase stops recording and permanently deletes every observed session, total, correction and future rule. Both controls are available through /consent; withdrawal does not require a site visit.
The bot is intended for people aged 18 or older, matching the site. We do not verify age and we do not knowingly record activity for anyone younger; if you are under 18, do not opt in, and contact us if you already have.
The bot does not request message content and cannot read messages. It does not access channels, friends, voice activity, roles, other servers or email. Personal command replies are ephemeral, so other members and admins cannot see them.
| Recipient | Purpose |
|---|---|
| Discord | Independent controller delivering interactions, presence and private replies. Also hosts the private channels that receive our error alerts and the identity-free feedback triage threads. |
| DigitalOcean | EU hosting processor in Frankfurt. |
| Neon / Databricks | EU database processor in Frankfurt. |
| Anthropic Ireland, Limited | AI processor receiving only a game title on the catalog-scoring path. |
| IGDB / Twitch / Amazon | Source of public game metadata; the bot sends only a game title and renders no images, so nothing about you reaches IGDB through it. The website is different - see its section 3. |
Hosting and database processing take place in the EU. Our contracting party is Anthropic Ireland, Limited (Dublin, Ireland), so that processing is EU-to-EU. Where Anthropic passes data on to its US parent, its Data Processing Addendum incorporates the EU Standard Contractual Clauses by reference; the website notice's recipients section links the published addenda for every processor. Discord applies its own transfer safeguards as an independent controller. We do not sell bot or play-activity data and server admins cannot access a member's stored activity.
| Data | Retention |
|---|---|
| Non-opted-in presence | Discarded immediately in memory; no personal record retained. |
| Command rate limits | Deleted once the counter row is 26 hours old, whatever its window length. |
| Interaction diagnostics | 30 days. |
| Feedback | 12 months, or 24 months when follow-up was requested. |
| Recorded play activity | Until you withdraw and erase it. |
| Server-install state | While installed; inactive state is deleted after 24 months. |
| Pseudonymous install lifecycle and attribution | 24 months. |
/consent to pause or to withdraw and erase, or use the controls on your account page.You may request access, rectification, erasure, restriction, portability where applicable, and object to processing based on legitimate interests under Arts. 15-21 GDPR. You may withdraw consent at any time and complain to a competent EU supervisory authority. Email hello@gamorium.com. If you never opted in, we deliberately have no reversible identifier with which to locate you.
Installing the bot does not opt members in or let you see what they play. It does cause Discord to deliver member presence for the filtering described above. Tell members the bot is installed and link them to this notice.
To make that reachable rather than optional, the bot posts one message when it is added, in the server's system channel or the first channel it is permitted to post in. The message says what the bot does, states that nothing is recorded about anyone who has not opted in, and links here. It mentions nobody, is never repeated, and is not sent again when the bot reconnects. If it has permission to post nowhere, it stays silent and the duty in the paragraph above remains yours. Choosing where to post means reading the server's channel list at that moment; we do not store it.
We keep a one-way server code, coarse member-count range, install context, lifecycle event and timestamps to recognize installations, reconcile gateway state after downtime, and measure aggregate installs, removals and reinstalls. Active state remains while installed; lifecycle history and inactive state are deleted after 24 months. We do not store the raw server ID, owner, channels, member list or exact member count.
On connection, a rotating operational log may contain the server name, or raw ID if Discord supplied no name, and the presence count in the initial snapshot. It is not joined to members. The presence container keeps at most three log files of 10 MB each; older content is overwritten as that size-limited log rotates.
First-party install links retain a one-way server code, coarse source and install surface. A completed guild installation is counted only after Discord's OAuth callback. Its access token and raw server ID are discarded immediately. Attribution records are deleted after 24 months.
We publish the revision date at the top. A material change to optional recording or its purpose creates a new consent version; an earlier opt-in does not silently authorize it.