Files
tg-archive/static/privacy-policy.md
T
Elias Wendland 126b9e9e9f
CI and release / Detect release commit (push) Successful in 27s
CI and release / Run tests (push) Successful in 4m14s
CI and release / Build and publish container (push) Successful in 9m2s
CI and release / Create release (push) Skipped
Large 0.3 changes
- Split the gigantic mess that web.rs was into seperate files
- Split the app into two clear functions: web and bot
- Add privacy policy
- Add privacy
- Make the site respect GDPR and Discord ToS
- Add basic API
- Add timezone detection and automatic time changes
2026-08-31 17:10:02 +02:00

168 lines
9.4 KiB
Markdown

# Privacy Policy
Last updated: 31 August 2026
This Privacy Policy explains how TG Archive ("the Archive") collects, uses, stores, and protects information obtained through Discord and through the Archive's web interface.
The Archive exists to maintain a historical archive of the Discord server in which the Archive bot operates and to make that archive available to authorized members of that server.
## 1. Data Controller
The Archive is operated by Elias Wendland.
For privacy-related questions or requests, contact:
tg-archive-privacy@mail.ewenlau.net
## 2. Information We Collect
The Archive may collect and store information made available through the Discord API, including:
- Discord user IDs, usernames, display names, avatars, and other relevant user information;
- message content;
- message IDs and timestamps;
- message edits, replies, attachments, embeds, reactions, and other message-related information where applicable;
- server, channel, thread, role, and permission information necessary to organize the archive and control access to it; and
- other Discord API data necessary for the operation, security, and maintenance of the Archive.
When you use the Archive's web interface, the Archive may also process information necessary to authenticate you through Discord OAuth2, maintain your session, enforce access controls, and protect the service from abuse.
The Archive is not intended to collect information unrelated to its archival, authentication, access-control, security, or maintenance functions.
## 3. Why We Process This Data
Discord data is processed for the purpose of maintaining a historical archive of the server and making archived material available to authorized server members.
Additional processing may be performed where necessary to:
- authenticate users;
- determine which archived channels a user is currently permitted to access;
- operate and secure the service;
- investigate technical problems or abuse; and
- comply with applicable legal obligations and Discord's requirements.
## 4. Legal Basis
Where the General Data Protection Regulation ("GDPR") applies, the Archive primarily processes personal data on the basis of legitimate interests under Article 6(1)(f) GDPR.
The legitimate interest pursued is the preservation and provision of a historical archive of the server's discussions and activities. The Archive limits access to archived material according to users' current Discord permissions and implements measures intended to reduce unnecessary impacts on users' privacy.
Where processing is necessary to comply with a legal obligation, Article 6(1)(c) GDPR may also apply.
## 5. Access to Archived Data
The Archive is not intended to make private Discord content publicly accessible.
Access to the web interface requires authentication through Discord OAuth2. Before providing access to archived channel content, the Archive checks whether the authenticated Discord user is currently authorized to access the corresponding channel.
Losing access to a channel on Discord therefore also results in losing access to that channel through the Archive, although personal content is always accessible to the user who created it.
Archive administrators may access stored data where reasonably necessary to operate, secure, maintain, or troubleshoot the service or to respond to privacy and legal requests.
## 6. Data Retention
Because the purpose of the service is historical archival, archived messages and associated metadata may be retained for an extended period while the Archive continues to operate and the information remains necessary for its archival purpose.
Information that is no longer necessary for the operation or stated purposes of the Archive will be deleted or anonymized where appropriate.
Data may also be deleted when required by applicable law, Discord's requirements, or a valid data-subject request.
If operation of the Archive is permanently discontinued, stored Discord API data will be handled in accordance with Discord's applicable requirements and applicable law.
## 7. Anonymization
Authenticated users are provided with a self-service mechanism to de-identify previously archived data associated with their Discord account.
When this function is used, identifying account information and the association between the user's Discord account and previously archived messages are removed. Message content and non-identifying message metadata, such as timestamps, may remain in the Archive.
Because message content itself may contain information capable of identifying its author, use of this feature should not necessarily be understood as complete anonymization for every purpose under applicable data protection law.
Anonymization affects only information already stored at the time the action is performed. If the user subsequently participates in the Discord server, newly generated information may be archived and associated with their Discord account.
This feature is separate from the right to request deletion of personal data.
## 8. Your Data Protection Rights
Depending on applicable law and the circumstances of the processing, you may have rights including the right to:
- request access to personal data concerning you;
- request correction of inaccurate personal data;
- request erasure of personal data;
- request restriction of processing;
- object to processing based on legitimate interests; and
- receive certain personal data in a portable format where the legal requirements for data portability apply.
To exercise these rights, contact:
tg-archive-privacy@mail.ewenlau.net
The Archive may request information reasonably necessary to verify that you control the Discord account concerned before fulfilling a request.
Requests made under the GDPR will generally be answered within one month of receipt. This period may be extended where permitted by law, in which case you will be informed as required by the GDPR.
You also have the right to lodge a complaint with a competent data protection supervisory authority.
## 9. Deletion Requests
You may request deletion of personal data associated with your Discord account by contacting tg-archive-privacy@mail.ewenlau.net.
Deletion requests will be handled in accordance with applicable law and Discord's requirements. Where data must be deleted, it will be removed from the Archive rather than merely hidden from your account.
Some minimal non-personal structural information may be retained where doing so does not identify or remain associated with you and is necessary to preserve the structure of the Archive.
## 10. Data Security
Reasonable technical and organizational measures are used to protect stored information against unauthorized access, disclosure, alteration, or destruction.
Discord API data stored by the Archive is encrypted at rest. Connections to the Archive's web interface are protected using HTTPS/TLS.
Access to stored data and administrative systems is restricted to persons and systems requiring access for operation of the Archive.
No method of electronic storage or transmission can provide an absolute guarantee of security.
## 11. Service Providers and Data Sharing
Personal data is not sold.
Data may be processed by infrastructure or service providers where necessary to host, secure, or operate the Archive. These providers process information only as necessary to provide their respective services.
Current relevant service providers include:
- Discord, as the platform from which archived data originates and as an authentication provider;
- Cloudflare, which may process certain network traffic for content delivery, security, and DDoS protection where its services are used;
- Proton, which provides email services and may therefore process personal data contained in emails sent to or from the Archive, including privacy requests.
Data may also be disclosed where required by law or where reasonably necessary to protect the security and integrity of the service.
## 12. International Data Transfers
The Archive's primary application, database, backups, and logging infrastructure are self-hosted and operated directly by the Archive operator in France.
Some third-party services used by the Archive may process personal data outside the EEA. These include Discord and, where applicable, Cloudflare. Proton provides email services for the Archive.
Where personal data is transferred outside the EEA, such transfers are handled in accordance with applicable data protection law and the transfer mechanisms implemented by the relevant service providers.
## 13. Automated Decision-Making and Profiling
The Archive does not use archived Discord messages to make decisions producing legal or similarly significant effects concerning users.
The Archive does not use archived message content to create behavioral profiles of Discord users.
## 14. Changes to This Policy
This Privacy Policy may be updated when the Archive's functionality, data-processing practices, legal obligations, or Discord's requirements change.
Material changes will be communicated where required by applicable law.
The date at the top of this policy indicates when it was last updated.
## 15. Contact
For questions about this Privacy Policy or requests concerning your personal data, contact:
tg-archive-privacy@mail.ewenlau.net
---
This privacy policy was drafted with assistance from ChatGPT and subsequently reviewed and adopted by the operator. The operator remains responsible for the accuracy of this policy and for the Archive's data-processing practices.