This notice explains how Bureaucramancer processes personal information when the bot, website, archive, moderation, backup, recovery and account features are used.
Bureaucramancer operates Bureaucramancer. For information a Discord server chooses to collect and process through Bureaucramancer, the server operator normally acts as the controller and Bureaucramancer acts as its processor. The server operator decides which modules are enabled, which channels are covered, who may use administrative tools and the retention settings used for that guild, subject to Bureaucramancer's product-wide retention ceilings.
Bureaucramancer acts as controller for information needed to operate and secure the service itself, including website authentication, account/session records, abuse prevention, service-security logs, support, privacy request administration and billing/entitlement records.
Depending on the modules and features a server uses, information can include:
Guild-controlled information is processed on the server operator's instructions for purposes such as:
For Bureaucramancer's own controller processing, the applicable basis depends on the activity and can include performing a contract, legitimate interests in operating and securing the service, and compliance with legal obligations. Consent is used only where a feature specifically asks for it and consent is the appropriate basis.
Bureaucramancer does not sell archived member content, use private server content to build advertising profiles, or use customer archives to train advertising systems.
A message being visible to other Discord members does not remove data-protection obligations. Searchable archives, deleted-message preservation, identity linking, protected attachments and restricted channels can create a greater privacy impact than ordinary reading of a Discord post. Bureaucramancer therefore applies guild-scoped access, retention controls, auditing and privacy-request workflows to these features.
Ordinary Discord message content is never kept in Bureaucramancer's live searchable archive for more than 30 days. This ceiling also applies to ordinary message-derived Tupper/proxy audit content, edits, deletion records and protected attachment references. A guild or plan can use a shorter Archive window, but cannot extend ordinary message retention beyond 30 days.
Historical content imported by Backfill can be older than 30 days because staff deliberately requested it for an investigation. Newly imported old content receives only a short, non-refreshable processing/export hold and is then removed by the same retention system unless authorised staff deliberately preserve relevant material as Case evidence. Case evidence is stored separately from the rolling Archive and follows the Case retention policy.
Other operational records have separate purposes and retention periods. Server History can be retained between 30 and 365 days, structural server backups between 7 and 365 days depending on plan/settings, closed Cases between 30 and 730 days, and web-action records between 7 and 90 days. Structural backups contain server configuration such as channels, roles and permissions; they are not a hidden long-term copy of ordinary message content.
When Bureaucramancer is removed from a server, guild-controlled data enters the configured uninstall grace period of 0 to 30 days (30-day default) before deletion, unless immediate deletion is requested or limited retention is required for a legal, security, accounting or dispute-resolution reason. Infrastructure recovery copies can persist until their normal rotation expires and are not restored into the live service except for recovery purposes.
Dashboard data is isolated by Discord guild. Website access uses Discord OAuth and only exposes installed servers the signed-in account is authorised to manage. Sensitive operations use additional permission checks, CSRF protection, rate limits and audit records. Restore and privacy-erasure workflows use extra confirmation and authorisation checks.
Information is also processed by infrastructure and platform providers needed to deliver the service, including Discord and the hosting/database/private-storage providers used by Bureaucramancer. Processors are limited to the service they provide and are subject to their applicable contractual and security obligations.
Discord and infrastructure providers can process information in countries outside the UK. Where UK data-protection law requires safeguards for an international transfer, Bureaucramancer relies on the applicable adequacy decision, approved contractual safeguards or another lawful transfer mechanism provided by the relevant service arrangement.
Bureaucramancer uses essential authentication and security cookies for Discord OAuth state, safe return paths, CSRF protection and the Bureaucramancer web session. These cookies are not used for behavioural advertising. Session identifiers are random, server-side, HttpOnly, Secure and time-limited; the current dashboard session lifetime is up to 30 days and can be revoked sooner.
Depending on the circumstances and legal basis, UK data-protection rights can include access, rectification, erasure, restriction, objection and data portability. Rights are not absolute and exemptions can apply.
Requests about a Discord server's archived content are normally handled by that server operator as controller, with Bureaucramancer providing the controller tools needed to locate, export, restrict or erase eligible records. Bureaucramancer's verified request portal ties a request to the requester's Discord user ID rather than a changeable display name.
Right to object: where processing relies on legitimate interests, you can object to that processing. The controller considers the reasons and any overriding lawful grounds before deciding the request.
File or review a privacy requestBureaucramancer is an administration service for Discord server operators, not a service directed at children. A server operator that permits younger members remains responsible for ensuring its use of archive, moderation and safety features is lawful, proportionate and appropriately explained to those members. Bureaucramancer processes that guild data only within the configured service and controller instructions, subject to its own legal obligations.
Bureaucramancer uses HTTPS/HSTS, environment-managed secrets, server-side sessions, guild-scoped authorisation, private attachment storage, CSRF tokens, guarded destructive workflows, database-backed rate limits, sensitive-read auditing, automated dependency/secret scanning and hosting/database recovery controls. Security controls are reviewed as the service and threat model change.
Privacy requests can be submitted through the verified privacy portal. The verified portal is the service's privacy contact channel.
If you are in the UK, you can also complain to the Information Commissioner if you believe your data-protection rights have been infringed. We ask that you contact the relevant server operator or Bureaucramancer first where practical so the issue can be investigated promptly.