Privacy policy
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Boostify Digital
Sole proprietorship, owner: Timon Wodtke
Kücknitzer Hauptstraße 46
23569 Lübeck
Germany
Phone: 01520 9522330
Email: kontakt@boostify-digital.de
Requests about the service and data protection: contact@bitguard.app
2. Overview
BitGuard consists of three parts: this website (bitguard.app), the Discord bot and the dashboard (dash.bitguard.app). Which data we process depends on which part you use and which modules a server has enabled. We do not sell data, do not use it for advertising and do not use any tracking or analytics services.
3. Website
Hosting and server log files
This website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (Hetzner privacy policy). We have concluded a data processing agreement with Hetzner in accordance with Art. 28 GDPR.
When you visit the site, the web server stores in log files:
- IP address (anonymized after 7 days)
- Date and time, requested address, HTTP status code, amount of data transferred
- Browser, operating system and referrer
The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in secure operation and error analysis. The log files are deleted after 30 days at the latest.
Fonts
All fonts are hosted on our own server. Loading the page does not create a connection to Google or any other font provider.
Cookies
The website itself does not set any cookies. The language is part of the address (e.g. /de/...), not stored in a cookie.
Public ranking
The ranking at /ranking only shows servers whose admins have explicitly agreed to take part in the dashboard: server name, server icon, member count and aggregated activity figures. Individual members are not named. Your browser loads the server icons directly from Discord (cdn.discordapp.com). Discord receives your IP address in the process, also on servers in the USA (see section 6). The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in displaying the servers in a recognizable way.
4. Discord bot
The bot only processes data on servers it has been invited to, and only for the modules enabled there. It reads messages to run filters (AutoMod), level XP, custom commands and automations. We only store message content in two cases: as a ticket transcript and as the text of a reminder that you create yourself.
What we store and for how long
| Data | Purpose | Retention |
|---|---|---|
| Server settings (channel and role IDs, texts written by admins) | Configuration of the modules | until deleted by the server, at the latest 30 days after the bot is removed |
| Ticket transcripts: message content, display name, user ID, time, links to attachments | Traceability of support requests for the server team | 30 days |
| Message counters per user ID, channel and day (without content) | Server statistics in the dashboard, ranking | 60 days |
| Joins and leaves (user ID, time) | Server statistics | 30 days |
| Moderation actions and warnings (user ID, moderator ID, reason, time) | Moderation, warning escalation | 180 days |
| Level and XP per user ID | Leveling | as long as the server uses the module |
| Economy: balance, inventory, cooldowns, game statistics per user ID | Economy module | as long as the server uses the module |
| Birthday (day and month, no year) | Congratulations, only if you enter it yourself | until you remove it (/birthday) |
| Reminders (text, channel, time) | /remind | until delivered |
| Giveaways (participant and winner IDs) | Draw | 14 days after the end |
| Ticket ratings (user ID, stars) | Rating of the support | the latest 500 per server |
| Backups of the server structure: roles, channels and their permissions (possibly including user IDs with special permissions), no messages | Recovery after an attack (anti-nuke) | the 7 most recent per server |
| Error log (server, channel and user ID, command) | Error analysis | 14 days |
| Block list (user or server ID, reason) | Protection against abuse of the bot | until lifted |
Servers can shorten these periods in the dashboard. The bot deletes expired data automatically. If BitGuard is removed from a server, we delete all data of that server 30 days later. If the bot is invited again before then, the data is kept.
Log channels
If a server enables logging, the bot sends deleted and edited messages, joins, leaves and moderation actions to a channel of that server. These messages are then stored by Discord on that server and are visible to its team. BitGuard itself does not store them.
Legal basis
For server admins who invite BitGuard and set it up in the dashboard, the legal basis is Art. 6 (1) (b) GDPR (provision of the service). For members of a server who do not have a contract with us themselves, the legal basis is Art. 6 (1) (f) GDPR. The legitimate interest lies in providing the features the server has chosen for its community, such as moderation, protection against spam and raids, tickets and leveling.
5. Dashboard and Discord login
Logging in to the dashboard works via Discord OAuth2 with the scopes identify and
guilds. In the process we receive:
- Discord user ID, username, display name, avatar and language setting
- the list of your servers with your permissions there
We do not request your email address. We do not store Discord's access token.
Of the server list, we only keep the servers you are allowed to manage and on which BitGuard is present.
This data is kept in your session on our server. The session cookie
(bitguard_sid) is technically necessary, lasts at most 7 days and ends when you log out.
No consent is required under § 25 (2) TDDDG. The legal basis is Art. 6 (1) (b) GDPR.
If you choose a language in the dashboard yourself, we remember that choice in the cookie
bitguard_lang. It only contains the language code (e.g. en), lasts one year
and is only set when you actively switch the language. It stores a setting you asked for and is
therefore allowed without consent under § 25 (2) no. 2 TDDDG.
We log changes made in the dashboard with your user ID, the time and a short summary, so that server teams can see who changed what. This log is deleted after 30 days.
6. Recipients and transfers to third countries
Discord: The bot and the dashboard only work through the interfaces of Discord Inc., 444 De Haro Street, Suite 200, San Francisco, CA 94107, USA. All messages, roles and server data are primarily stored by Discord and are also processed by Discord in the USA. The transfer is based on the EU-US Data Privacy Framework, insofar as Discord is certified under it, and otherwise on the European Commission's Standard Contractual Clauses. The Discord privacy policy also applies.
Social alerts: For notifications, the bot queries public interfaces of Twitch, YouTube, Kick, Reddit, Bluesky, GitHub, Steam and GamerPower as well as the RSS feeds a server enters. We do not transmit any member data in the process, only the channel or feed being queried.
Hosting: The bot, dashboard and database run on servers of Hetzner Online GmbH in Germany. Beyond that, we do not share any data unless we are legally obliged to.
7. Your rights
Under the GDPR, you have the right to:
- Access to your stored data (Art. 15)
- Rectification (Art. 16) and erasure (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Object to processing based on legitimate interests (Art. 21)
As a member of a server, write to us at contact@bitguard.app
and include your Discord user ID. You can remove your birthday yourself at any time with
/birthday.
As a server admin, you can export all data of your server as a file in the dashboard
under Settings. The server owner can delete all data there immediately.
We answer requests within one month.
8. Right to lodge a complaint
You can lodge a complaint with a data protection supervisory authority, for example at your place of residence. The authority responsible for us is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Kiel, Germany, www.datenschutzzentrum.de.
9. Data security
Connections to the website and dashboard are encrypted via HTTPS. The dashboard and bot only communicate via signed requests, and on every change the bot checks again whether you have the "Manage Server" permission on the server. When invited, the bot only requests the Discord permissions it needs for its modules and does not hand out roles with dangerous permissions. Only the operator and a few named support staff, who are bound to confidentiality, have access to the data of all servers. Support can only read, and only as far as necessary for troubleshooting.
10. Changes
We update this policy when BitGuard or the legal situation changes. The version published here applies.
As of September 2026