Privacy Policy

This English version is a convenience translation. Only the German version is legally binding.

1. Controller

This Privacy Policy provides information about the processing of personal data when using the website and the web dashboard at usecloudy.xyz as well as the Discord bot “Cloudy” (together the “Service”).

Controller within the meaning of Art. 4(7) GDPR:
David Ipekoglu
c/o COCENTER, Koppoldstr. 1, 86551 Aichach, Germany
E-mail: info@usecloudy.xyz

2. Hosting and server log files

The Service is operated on servers of OVH GmbH, St. Johanner Straße 41–43, 66111 Saarbrücken, Germany, in data centres within the European Union. A data processing agreement pursuant to Art. 28 GDPR is in place with OVH.

When you access the website, our web server automatically processes technical access data: IP address, date and time of access, page/resource requested, HTTP status code, referrer URL and browser identification (user agent). This data is technically necessary in order to deliver the website and additionally serves the security and stability of operations (e.g. defence against attacks and misuse). Server log files are deleted regularly, at the latest after 14 days, unless a security-relevant incident requires longer retention.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and stable provision of the Service).

3. Cookies and local storage

We use exclusively technically necessary, first-party cookies. No tracking, analytics or advertising cookies and no third-party cookies are used. Consent is therefore not required (Section 25(2) no. 2 TDDDG — German Telecommunications Digital Services Data Protection Act); for this reason we also do not display a cookie banner.

  • __Secure-cloudy.session_token — login session (session cookie). HttpOnly, Secure, SameSite=Lax. Duration: 7 days.
  • __Secure-cloudy.session_data — short-term cache of the session data to speed up the dashboard. HttpOnly, Secure, SameSite=Lax. Duration: 5 minutes.
  • cloudy-locale — stores the selected language (German/English). Duration: 1 year.
  • During the login process, our authentication system additionally sets short-lived cookies to secure the OAuth process (e.g. state/CSRF protection); these are no longer used once the login has been completed.
  • cloudy-theme — stores the appearance setting (light/dark) in your browser's localStorage; no transmission to us takes place.

Legal basis: Art. 6(1)(b) GDPR (provision of the dashboard when logged in) and Art. 6(1)(f) GDPR (user-friendly design of the Service).

4. Registration and login via Discord (dashboard)

You can only sign in to the dashboard using your Discord account (OAuth2). In doing so, we request the permissions identify (profile information), email (e-mail address), guilds (list of your servers) and guilds.join (see below) from Discord. We receive and store:

  • Discord user ID, display name and avatar URL,
  • the e-mail address stored with Discord,
  • OAuth access and refresh tokens — encrypted in our database in accordance with the state of the art (authenticated 256-bit encryption),
  • session data including IP address and browser identification (for session management, security and prevention of misuse),
  • your Discord server list — only for a short time in a server-side cache (approx. 2–3 minutes) in order to display the dashboard; it is not stored permanently.

To prevent misuse, we also use short-lived request counters (rate limiting) which are assigned to your Discord ID and expire automatically after 60 seconds at the latest.

On your first sign-in, your Discord account is automatically added to our community/support server via the guilds.join permission (legal basis: Art. 6(1)(f) GDPR — connection to support and product information). You can leave the server again at any time.

Retention period: The login session ends after 7 days without use of the dashboard; if you use it actively, it is extended accordingly. We store account and session data for as long as you use the dashboard; on request we delete your account in full (see section 12).

Providing your Discord account data is neither required by law nor by contract, but it is necessary in order to use the dashboard — without it, a login is technically not possible. The bot itself can also be used on a server without a dashboard login.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for security and anti-misuse measures Art. 6(1)(f) GDPR.

5. Data processing by the Discord bot

If the bot is added to a Discord server by a server administrator, we process data transmitted to us via the Discord API. We do not receive the data of server members directly from the data subjects, but via Discord (Art. 14 GDPR).

5.1 Server and configuration data

Server ID, channel and role IDs as well as the settings made by the server administrator (e.g. welcome messages, log channels, plugin configurations).

Custom Bot (Premium): If a server administrator provides their own bot token, we store it encrypted (AES-256-GCM) together with the application ID, name and avatar of the bot application and the associated presence settings in order to operate the bot under this identity. This data is deleted when the configuration is removed or the bot is removed from the server.

5.2 Functional data of individual users

Only if the respective feature is enabled on a server or is used by you do we store — in each case linked to your Discord user ID and the server ID:

  • Birthdays: month and day, optionally the year of birth — only if you provide these voluntarily via the /set-birthday command (legal basis: Art. 6(1)(a) GDPR — consent; may be withdrawn at any time without any particular form, see section 12),
  • Level system: experience points (XP) and level,
  • Economy system: virtual balance and activity timestamps,
  • Virtual pets: the name you assign, type and game progress,
  • Polls: polls created by you (title, description, answer options, creator ID) as well as the vote you cast,
  • Giveaways: creation (creator ID), participation and winning,
  • Reminders: the reminder text you enter, the time and the target channel,
  • Custom commands: the ID of the user creating them,
  • Custom games: game statistics (wins/losses/points) as well as, where applicable, queue bans including the reason and the ID of the moderator issuing them,
  • Warnings (AutoMod/moderation): in the event of violations of AutoMod rules configured by the server administrator, we store a warning (rule, reason, time, where applicable the ID of the acting moderator); server administrators can view these in the dashboard,
  • Feedback system: feedback requests and ratings given (including the record of which user rated which user),
  • Temporary voice channels: ownership of the channel (only while the channel exists).

5.3 Message content

As a rule, the bot processes message content only transiently (e.g. to award XP or to detect custom commands) and does not store it in its database. There are two exceptions, which are controlled by server administrators:

  • Message logging: If enabled by the server administrator, the bot posts the content of edited or deleted messages (including the author) as a log message in a Discord channel designated by the administrator.
  • Ticket transcripts: When a ticket is closed, the entire history of the ticket channel can be exported as an HTML file to a Discord log channel designated by the administrator.

In addition, server administrators can enable further log categories (e.g. server joins and leaves, voice channel activity), in which member information such as Discord ID, avatar and account creation date is posted as a log message in a Discord channel.

These log messages and transcripts are stored at Discord (in channels of the respective server), not on our systems. The administrators of the respective server are responsible, together with Discord, for the storage and deletion there; we recommend that administrators inform their members about this (see also our Terms and Conditions).

5.4 Retention period and erasure

  • If the bot is removed from a server, the data stored for that server (configurations and all functional data of the members) is automatically deleted from our database; this does not apply to licence and billing data, for which the retention periods set out in section 7 apply.
  • You can delete reminders and virtual pets yourself at any time.
  • Expired queue bans are removed automatically.
  • Any further erasure (e.g. of individual functional data or your birthday) is carried out by us on request (see section 12).

Legal bases: Art. 6(1)(b) GDPR (provision of the features requested by the server or user), Art. 6(1)(f) GDPR (security, prevention of misuse) as well as Art. 6(1)(a) GDPR (voluntary information such as birthdays).

6. Discord as a platform

The Service requires the use of Discord. For the processing of data by Discord itself, Discord Netherlands B.V., Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands, is the controller for users in the European Economic Area. Insofar as data is transferred to Discord Inc. in the USA, Discord Inc. is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR). Details: https://discord.com/privacy.

In the dashboard, profile pictures, server icons and banners are loaded directly from Discord's content delivery network (cdn.discordapp.com) in your browser. In doing so, your IP address is transmitted to Discord (legal basis: Art. 6(1)(f) GDPR — display of the Discord content necessary for the functionality).

7. Payment processing via Stripe (Premium)

Paid premium features are processed via the payment service provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (“Stripe”). The payment process takes place on pages hosted by Stripe (Stripe Checkout, Stripe customer portal).

  • Transmitted to Stripe are: your name and your e-mail address (from your dashboard account) as well as your Discord user ID and, where applicable, the server ID as an order reference. You enter payment data (e.g. card details) directly with Stripe; it never reaches our systems at any time.
  • We store: Stripe reference numbers (customer, subscription or payment IDs), the licence or subscription status, the associated Discord user ID and, where applicable, server ID, as well as the declarations concerning the right of withdrawal you made during the ordering process (content and time).

Stripe processes payment data in part under its own responsibility (e.g. for fraud prevention and to comply with its own legal obligations). Stripe, Inc. (USA) is certified under the EU-U.S. Data Privacy Framework. Details: https://stripe.com/de/privacy.

Retention period: We retain purchase and billing data for as long as this is necessary for the performance of the contract, and beyond that within the scope of statutory commercial and tax retention periods (up to 10 years).

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (statutory retention obligations).

8. Optional features with third-party APIs

  • Valorant statistics: If you use the /valo-stats command, the Riot ID you enter (name and tag) is transmitted to the third-party API “HenrikDev” (api.henrikdev.xyz) in order to retrieve game statistics. The results are only displayed, not stored. The transfer takes place solely upon your active request (legal basis: Art. 6(1)(b) GDPR; for any transfer to a third country without an adequacy decision: Art. 49(1)(b) GDPR — the transfer is necessary for the performance of the feature requested by you).
  • Streaming notifications: For live notifications, the bot queries the APIs of Twitch (Twitch Interactive, Inc., USA), Kick (Kick Streaming Pty Ltd, Australia) and YouTube (Google Ireland Ltd., Ireland). In doing so, only the channel or streamer names stored by the server administrator are transmitted — no data of server members.

9. Disclosure of data; recipients

Personal data is only disclosed:

  • to the processors and service providers named in this policy (OVH, Stripe, Discord, in individual cases HenrikDev/Twitch/Kick/YouTube as described in section 8),
  • within the Service: server administrators with management rights can see in the dashboard who purchased the premium licence for their server (display name, avatar, Discord ID of the purchaser),
  • where we are legally obliged to do so (Art. 6(1)(c) GDPR) or where you have given your consent (Art. 6(1)(a) GDPR).

10. Transfers to third countries

Our systems are operated in the EU. Transfers to the USA only take place to recipients which are certified under the EU-U.S. Data Privacy Framework (Discord Inc., Stripe Inc.) — an adequacy decision of the EU Commission (Art. 45 GDPR) therefore exists. When using optional third-party features (section 8), a transfer to further third countries may take place, which is triggered solely by your active use of the feature; the legal basis for this is Art. 49(1)(b) GDPR.

11. Contact

If you contact us by e-mail or via the Discord support server, we process the information you provide in order to handle the enquiry (Art. 6(1)(b) GDPR; for other enquiries Art. 6(1)(f) GDPR). The correspondence is deleted as soon as it is no longer required and no statutory retention obligations exist.

12. Your rights

You have the following rights with regard to the personal data concerning you:

  • access (Art. 15 GDPR),
  • rectification (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • withdrawal of consent given, with effect for the future (Art. 7(3) GDPR).

Right to object (Art. 21 GDPR): Insofar as we process data on the basis of Art. 6(1)(f) GDPR (legitimate interest), you have the right to object at any time, on grounds relating to your particular situation, to the processing.

Erasure of your data: Please send erasure requests and other data subject requests without any particular form by e-mail to info@usecloudy.xyz (stating your Discord user ID). We will then erase your data without undue delay, unless statutory retention obligations preclude this. Deleted data may still be contained in daily backups for up to 14 further days before it is finally removed.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), e.g. with the supervisory authority responsible for us, the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach.

Last updated: 17 July 2026