Privacy Policy
This English version is a convenience translation. Only the German version is legally binding.
1. Controller
This Privacy Policy provides information about the processing of personal data when using the website and the web dashboard at usecloudy.xyz as well as the Discord bot “Cloudy” (together the “Service”).
Controller within the meaning of Art. 4(7) GDPR:
D.I-Solutions
David Ipekoglu
c/o Block Services
Stuttgarter Str. 106
70736 Fellbach
Germany
E-mail: info@usecloudy.xyz
2. Hosting and server log files
The Service is operated on servers of OVH GmbH, St. Johanner Straße 41–43, 66111 Saarbrücken, Germany, in data centres within the European Union. A data processing agreement pursuant to Art. 28 GDPR is in place with OVH.
When you access the website, our web server automatically processes technical access data: IP address, date and time of access, page/resource requested, HTTP status code, referrer URL and browser identification (user agent). This data is technically necessary in order to deliver the website and additionally serves the security and stability of operations (e.g. defence against attacks and misuse). Server log files are deleted regularly, at the latest after 14 days, unless a security-relevant incident requires longer retention.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and stable provision of the Service).
3. Cookies, local storage and analytics
The technically necessary, first-party cookies listed below are set without consent; they are strictly necessary to operate the Service (Section 25(2) no. 2 TDDDG — German Telecommunications Digital Services Data Protection Act). We do not use advertising cookies or cross-site tracking. In addition we carry out analytics — this only takes place after your explicit consent and is described separately below.
- __Secure-cloudy.session_token — login session (session cookie). HttpOnly, Secure, SameSite=Lax. Duration: 7 days.
- __Secure-cloudy.session_data — short-term cache of the session data to speed up the dashboard. HttpOnly, Secure, SameSite=Lax. Duration: 5 minutes.
- cloudy-locale — stores the selected language (German/English). Duration: 1 year.
- During the login process, our authentication system additionally sets short-lived cookies to secure the OAuth process (e.g. state/CSRF protection); these are no longer used once the login has been completed.
- cloudy-theme — stores the appearance setting (light/dark) in your browser's localStorage; no transmission to us takes place.
- cloudy-cookie-consent — stores your decision about analytics (consent or refusal) together with its timestamp in your browser's localStorage. Storing it does not itself require consent, since otherwise we would have to ask you again on every page view.
Legal basis: Art. 6(1)(b) GDPR (provision of the dashboard when logged in) and Art. 6(1)(f) GDPR (user-friendly design of the Service).
Analytics with PostHog (only with your consent)
To understand how our website is used and which features people find, we use the analytics software PostHog (PostHog, Inc.). The data is stored on servers in the European Union (Frankfurt am Main). A data processing agreement pursuant to Art. 28 GDPR is in place with the provider.
None of this happens without your consent. As long as you have not agreed in the cookie banner, the analytics software is not even loaded — no cookies are set and no data is transmitted. If you do agree, we process:
- a randomly generated, pseudonymous identifier (ph_*) — as a cookie with a 30-day lifetime and as an entry in your browser's localStorage; both are deleted immediately on withdrawal,
- pages viewed, time spent, referring page and the events you trigger (e.g. clicking “Add to your server”),
- technical details about browser, operating system, device type and screen size,
- page loading performance metrics (Core Web Vitals), in order to improve performance,
- your IP address — used to derive an approximate country and not stored permanently by PostHog,
- if you are signed in to the dashboard: your Discord user ID and display name, so that usage can be linked across sessions.
Deliberately not used: session recordings, automatic capture of clicks and form contents (“autocapture”), cross-site tracking and any form of advertising. All analytics requests also travel via our own domain (usecloudy.xyz/ingest) rather than directly to the provider.
Legal basis: your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
Withdrawal: you can withdraw your consent at any time with effect for the future — via the Cookie settings link in the footer of every page. On withdrawal, the cookies and localStorage entries set by PostHog are deleted and no further data is collected. The lawfulness of processing carried out up to the withdrawal remains unaffected.
Retention: analytics data is deleted automatically after 30 days. The pseudonymous identifier in the cookie expires after the same period.
4. Registration and login via Discord (dashboard)
You can only sign in to the dashboard using your Discord account (OAuth2). In doing so, we request the permissions identify (profile information), email (e-mail address), guilds (list of your servers) and guilds.join (see below) from Discord. We receive and store:
- Discord user ID, display name and avatar URL,
- the e-mail address stored with Discord,
- OAuth access and refresh tokens — encrypted in our database in accordance with the state of the art (authenticated 256-bit encryption),
- session data including IP address and browser identification (for session management, security and prevention of misuse),
- your Discord server list — only for a short time in a server-side cache (approx. 2–3 minutes) in order to display the dashboard; it is not stored permanently.
To prevent misuse, we also use short-lived request counters (rate limiting) which are assigned to your Discord ID and expire automatically after 60 seconds at the latest.
On your first sign-in, your Discord account is automatically added to our community/support server via the guilds.join permission (legal basis: Art. 6(1)(f) GDPR — connection to support and product information). You can leave the server again at any time.
Retention period: The login session ends after 7 days without use of the dashboard; if you use it actively, it is extended accordingly. We store account and session data for as long as you use the dashboard; on request we delete your account in full (see section 12).
Providing your Discord account data is neither required by law nor by contract, but it is necessary in order to use the dashboard — without it, a login is technically not possible. The bot itself can also be used on a server without a dashboard login.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for security and anti-misuse measures Art. 6(1)(f) GDPR.
5. Data processing by the Discord bot
If the bot is added to a Discord server by a server administrator, we process data transmitted to us via the Discord API. We do not receive the data of server members directly from the data subjects, but via Discord (Art. 14 GDPR).
5.1 Server and configuration data
Server ID, channel and role IDs as well as the settings made by the server administrator (e.g. welcome messages, log channels, plugin configurations).
Custom Bot (Premium): If a server administrator provides their own bot token, we store it encrypted (AES-256-GCM) together with the application ID, name and avatar of the bot application and the associated presence settings in order to operate the bot under this identity. This data is deleted when the configuration is removed or the bot is removed from the server.
5.2 Functional data of individual users
Only if the respective feature is enabled on a server or is used by you do we store — in each case linked to your Discord user ID and the server ID:
- Birthdays: month and day, optionally the year of birth — only if you provide these voluntarily via the
/set-birthdaycommand (legal basis: Art. 6(1)(a) GDPR — consent; may be withdrawn at any time without any particular form, see section 12), - Level system: experience points (XP) and level,
- Economy system: virtual balance and activity timestamps,
- Virtual pets: the name you assign, type and game progress,
- Polls: polls created by you (title, description, answer options, creator ID) as well as the vote you cast,
- Giveaways: creation (creator ID), participation and winning,
- Reminders: the reminder text you enter, the time and the target channel,
- Custom commands: the ID of the user creating them,
- Custom games: game statistics (wins/losses/points) as well as, where applicable, queue bans including the reason and the ID of the moderator issuing them,
- Warnings (AutoMod/moderation): in the event of violations of AutoMod rules configured by the server administrator, we store a warning (rule, reason, time, where applicable the ID of the acting moderator); server administrators can view these in the dashboard,
- Feedback system: feedback requests and ratings given (including the record of which user rated which user),
- Temporary voice channels: ownership of the channel (only while the channel exists).
5.3 Message content
As a rule, the bot processes message content only transiently (e.g. to award XP or to detect custom commands) and does not store it in its database. There are two exceptions, which are controlled by server administrators:
- Message logging: If enabled by the server administrator, the bot posts the content of edited or deleted messages (including the author) as a log message in a Discord channel designated by the administrator.
- Ticket transcripts: When a ticket is closed, the entire history of the ticket channel can be exported as an HTML file to a Discord log channel designated by the administrator.
In addition, server administrators can enable further log categories (e.g. server joins and leaves, voice channel activity), in which member information such as Discord ID, avatar and account creation date is posted as a log message in a Discord channel.
These log messages and transcripts are stored at Discord (in channels of the respective server), not on our systems. The administrators of the respective server are responsible, together with Discord, for the storage and deletion there; we recommend that administrators inform their members about this (see also our Terms and Conditions).
5.4 Retention period and erasure
- If the bot is removed from a server, the data stored for that server (configurations and all functional data of the members) is automatically deleted from our database; this does not apply to licence and billing data, for which the retention periods set out in section 7 apply.
- You can delete reminders and virtual pets yourself at any time.
- Expired queue bans are removed automatically.
- Any further erasure (e.g. of individual functional data or your birthday) is carried out by us on request (see section 12).
Legal bases: Art. 6(1)(b) GDPR (provision of the features requested by the server or user), Art. 6(1)(f) GDPR (security, prevention of misuse) as well as Art. 6(1)(a) GDPR (voluntary information such as birthdays).
6. Discord as a platform
The Service requires the use of Discord. For the processing of data by Discord itself, Discord Netherlands B.V., Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands, is the controller for users in the European Economic Area. Insofar as data is transferred to Discord Inc. in the USA, Discord Inc. is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR). Details: https://discord.com/privacy.
In the dashboard, profile pictures, server icons and banners are loaded directly from Discord's content delivery network (cdn.discordapp.com) in your browser. In doing so, your IP address is transmitted to Discord (legal basis: Art. 6(1)(f) GDPR — display of the Discord content necessary for the functionality).
7. Payment processing via Stripe (Premium)
Paid premium features are processed via the payment service provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (“Stripe”). The payment process takes place on pages hosted by Stripe (Stripe Checkout, Stripe customer portal).
- Transmitted to Stripe are: your name and your e-mail address (from your dashboard account) as well as your Discord user ID and, where applicable, the server ID as an order reference. You enter payment data (e.g. card details) directly with Stripe; it never reaches our systems at any time.
- We store: Stripe reference numbers (customer, subscription or payment IDs), the licence or subscription status, the associated Discord user ID and, where applicable, server ID, as well as the declarations concerning the right of withdrawal you made during the ordering process (content and time).
Stripe processes payment data in part under its own responsibility (e.g. for fraud prevention and to comply with its own legal obligations). Stripe, Inc. (USA) is certified under the EU-U.S. Data Privacy Framework. Details: https://stripe.com/de/privacy.
Retention period: We retain purchase and billing data for as long as this is necessary for the performance of the contract, and beyond that within the scope of statutory commercial and tax retention periods (up to 10 years).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (statutory retention obligations).
8. Optional features with third-party APIs
- Valorant statistics: If you use the
/valo-statscommand, the Riot ID you enter (name and tag) is transmitted to the third-party API “HenrikDev” (api.henrikdev.xyz) in order to retrieve game statistics. The results are only displayed, not stored. The transfer takes place solely upon your active request (legal basis: Art. 6(1)(b) GDPR; for any transfer to a third country without an adequacy decision: Art. 49(1)(b) GDPR — the transfer is necessary for the performance of the feature requested by you). - Streaming notifications: For live notifications, the bot queries the APIs of Twitch (Twitch Interactive, Inc., USA), Kick (Kick Streaming Pty Ltd, Australia) and YouTube (Google Ireland Ltd., Ireland). In doing so, only the channel or streamer names stored by the server administrator are transmitted — no data of server members.
9. Disclosure of data; recipients
Personal data is only disclosed:
- to the processors and service providers named in this policy (OVH, Stripe, Discord, PostHog — the latter only where consent has been given, see section 3 —, in individual cases HenrikDev/Twitch/Kick/YouTube as described in section 8),
- within the Service: server administrators with management rights can see in the dashboard who purchased the premium licence for their server (display name, avatar, Discord ID of the purchaser),
- where we are legally obliged to do so (Art. 6(1)(c) GDPR) or where you have given your consent (Art. 6(1)(a) GDPR).
10. Transfers to third countries
Our systems are operated in the EU. Transfers to the USA only take place to recipients which are certified under the EU-U.S. Data Privacy Framework (Discord Inc., Stripe Inc.) — an adequacy decision of the EU Commission (Art. 45 GDPR) therefore exists. For analytics (section 3) we deliberately use PostHog's EU deployment: the analytics data is stored in Frankfurt am Main and does not leave the EU in normal operation. Insofar as the provider, as a US company, may nevertheless obtain access in the course of support or maintenance, this is safeguarded by the EU Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). When using optional third-party features (section 8), a transfer to further third countries may take place, which is triggered solely by your active use of the feature; the legal basis for this is Art. 49(1)(b) GDPR.
11. Contact
If you contact us by e-mail or via the Discord support server, we process the information you provide in order to handle the enquiry (Art. 6(1)(b) GDPR; for other enquiries Art. 6(1)(f) GDPR). The correspondence is deleted as soon as it is no longer required and no statutory retention obligations exist.
12. Your rights
You have the following rights with regard to the personal data concerning you:
- access (Art. 15 GDPR),
- rectification (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- withdrawal of consent given, with effect for the future (Art. 7(3) GDPR).
Right to object (Art. 21 GDPR): Insofar as we process data on the basis of Art. 6(1)(f) GDPR (legitimate interest), you have the right to object at any time, on grounds relating to your particular situation, to the processing.
Erasure of your data: Please send erasure requests and other data subject requests without any particular form by e-mail to info@usecloudy.xyz (stating your Discord user ID). We will then erase your data without undue delay, unless statutory retention obligations preclude this. Deleted data may still be contained in daily backups for up to 14 further days before it is finally removed.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), e.g. with the supervisory authority responsible for us, the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach.
Last updated: 20 August 2026