Privacy
What the bot stores, why, and how to get rid of it.
Who runs this
Justin Minkmar, reachable at kontakt@minkmar.me. See the imprint for the full details.
What is stored
- Trades — Discord user id of the poster and of whoever claims, the server id, channel and message id, item name, quantity, price, category, status and timestamps.
- Vouches — the rating, the optional comment, who gave it, who it is for, and which trade it belongs to.
- Per-server settings — log channel, announcement channel, cooldown, categories, jobs and reaction-role panel locations and mappings, each tied to a server id and, where applicable, a channel, message or role id.
- News posts — the operator's title, summary, body, author id and publication dates, plus which servers have already received an announcement.
- Aggregate music statistics — song title, artist, first and last playback time, and total play count. No user id or server id is stored with a play.
- Post cooldowns — a server id, a user id and the time of the last post.
- Dashboard sessions — if you sign in on this site: your Discord user id, username, avatar hash and an access token, until you sign out or the session expires after seven days.
No message content, no member lists, no email addresses. The bot requests no privileged intents, so it cannot read your conversations.
Why
To provide the feature you used: an offer has to be stored to be listed and claimed, a rating has to be stored to be shown. Signing into the dashboard requires a session so you stay signed in between pages. The legal basis is the performance of the service you requested, Art. 6(1)(b) GDPR.
Who else sees it
Nobody. The data lives on Privately hosted on a self-managed Proxmox server and is not sold, shared or handed to an analytics provider. Signing in talks to Discord, which is subject to Discord's own privacy policy.
How long
Trades and vouches stay as long as the bot is in the server, since they are what the history and reputation are built from. Sessions expire after seven days. Cooldown entries are overwritten on each post. Removing the bot from a server does not delete anything automatically — a removal is often temporary — so ask if you want it gone. News posts and their announcement records stay until the operator deletes them. Aggregate song counters remain without any member or server link.
Your rights
You can ask for a copy of what is stored about you, have it corrected, or have it deleted — write to kontakt@minkmar.me. You may also complain to a data protection authority. Deleting a vouch you received is not something the person rated can demand on its own; the rating belongs to the trade it came from.
Cookies
One, and only after you sign in: a session identifier so the dashboard knows who
you are. It is HttpOnly, expires after seven days, and there is no
tracking or advertising cookie of any kind.