Privacy Policy

1. Scope

This policy applies to data processed by the Service operators. It does not cover Discord, Jagex, WiseOldMan, or other third parties you interact with directly—their policies apply to those services.

2. Information we collect

2.1 Discord account (web login)

When you sign in with Discord OAuth2, we receive and store:

  • Discord user ID (primary identifier)
  • Username and display name as exposed by Discord’s API
  • Avatar URL (if provided by Discord)
  • OAuth tokens only for the duration needed to complete login (not stored long-term as session secrets)

We create a session cookie (session) containing a random token mapped to your Discord user ID in our database, typically for up to seven days. Short-lived cookies may be used during login (oauth_state, oauth_redirect_uri, oauth_next).

2.2 Clan and membership data

If you create or join a clan, we store data you or your clan staff submit, including:

  • Clan name, owner Discord ID, creation time, optional WiseOldMan group ID
  • Member roster: Discord IDs, OSRS character names, roles (owner, staff, member), rank assignments
  • Linked Discord server (guild) IDs for your clan
  • Clan events, leaderboards, rank ladders, and plugin feature settings per server

2.3 OSRS and statistics data

When you link OSRS usernames or refresh stats, we store usernames and may fetch or cache gameplay statistics from our stats service and/or WiseOldMan (XP, boss kills, hiscore checks, and related metadata). This data is used for dashboards, events, and rank progression.

2.4 Applications

Clan application forms store questions, Discord channel IDs for apply/review messages, embed configuration, and applicant answers (including Discord user ID and submitted text). Published forms interact with Discord channels you select.

2.5 Party finder (OSRS plugin)

Server administrators may configure party types, roles, ping settings, and optional gallery images. Signup data includes Discord user IDs and choices made through Discord interactions.

2.6 Player reports

Reports may include:

  • Reporter and reported Discord user IDs (when provided)
  • Reported OSRS username (when provided)
  • Category, description, status (pending, accepted, denied, deleted)
  • Uploaded evidence files (images), stored on our servers
  • Reviewer notes and timestamps for moderation

2.7 Discord server and member data (operational)

When the bot is in a Discord server, we process data necessary to provide features, such as guild and channel IDs, channel names, role lists, member lists (for clan staff adding members from a server), message IDs for application embeds, and message content when authorized administrators use admin messaging tools or when the bot posts or reads messages in configured channels. We may cache member display names and presence status for roster display.

2.8 Enforcement and administration

Bot administrators may record suspensions (bans) for Discord users or entire servers, including reason, who applied the ban, and optional expiry. Admin tools may send direct messages to users affected by enforcement actions. System metrics (disk usage, database size, process stats) may be collected for operations.

2.9 Technical logs

Server logs may include IP addresses, request paths, timestamps, error messages, and host headers for security and debugging. We do not use third-party advertising trackers on the dashboard.

3. How we use information

We use collected information to:

  • Authenticate you and enforce role-based access on the web dashboard
  • Operate clan features, events, ranks, applications, and Discord commands
  • Display stats, leaderboards, and rank progress
  • Moderate player reports and communicate outcomes where applicable
  • Prevent abuse, enforce bans, and protect the Service
  • Maintain, secure, and improve the Service
  • Comply with legal obligations where required

We do not sell your personal information. We do not use your data for third-party advertising.

4. Legal bases (EEA/UK users)

Where GDPR or similar laws apply, we rely on:

  • Contract — processing needed to provide features you request
  • Legitimate interests — security, abuse prevention, and improving the Service
  • Consent — where you choose to sign in, submit reports, or apply to clans
  • Legal obligation — when we must retain or disclose data under law

5. How we share information

  • Discord — we send and receive data through Discord’s API when you use bot or dashboard features tied to Discord.
  • WiseOldMan / stats API — OSRS usernames are queried to fetch or sync group and player statistics.
  • Clan staff and members — roster, events, and application data are visible to users with permission in your clan.
  • Authorized bot admins — may access reports, metrics, messaging tools, clan overviews, and enforcement data.
  • Service providers — hosting, infrastructure, or CDN providers that process data on our behalf under confidentiality obligations.
  • Legal requirements — if required by law, court order, or to protect rights and safety.

6. Retention

We retain data while your clan, account, or reports remain active and as needed to operate the Service. Web sessions expire and are periodically purged. Evidence files for reports may be deleted when reports are purged by administrators. Clan deletion removes associated clan data from our database (subject to backups for a limited time). We may retain minimal logs longer for security and audit purposes.

7. Security

We use reasonable technical measures (HTTPS where configured, hashed session tokens, access controls, and server-side permission checks). No system is perfectly secure; you use the Service at your own risk.

8. Your choices and rights

Depending on where you live, you may have the right to:

  • Access, correct, or delete personal data we hold about you
  • Object to or restrict certain processing
  • Withdraw consent where processing is consent-based
  • Request a portable copy of your data
  • Lodge a complaint with a supervisory authority

To exercise rights, contact us via the Support Discord. We may need to verify your Discord identity. Clan owners can remove members or delete clans through the dashboard where those features exist.

You can end web sessions by logging out. Removing the bot from a Discord server stops new Discord-side processing for that server but may not delete historical database records until removed through admin or clan tools.

9. Children

The Service is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have, contact us and we will take steps to delete it.

10. International transfers

Data may be processed on servers located in countries other than your own. By using the Service, you understand that data may be transferred to jurisdictions with different data protection laws.

11. Changes to this policy

We may update this Privacy Policy. We will revise the “Last updated” date and post the new version on this page. Continued use after changes take effect indicates acceptance of the updated policy.

12. Contact

Privacy questions or requests: Support Discord. For report-related issues you may also use the report page.