What we ask Discord for
Three permissions, and none of them grants access to messages. The bot reads and writes only in the channels the guild invited it to announce raids in.
Your Discord name and avatar. It is how the site knows who you are without a new password.
Which servers you are in — so it can show your guilds, and not everybody else's.
Which roles you hold on those servers. It is what makes the site honour the same permissions the bot does.
What we keep about you
What the addon publishes
This is character data from a game, sent by an officer of the guild those characters belong to. It is the same thing anyone sees by inspecting you in the game — the difference is that here it is added up and dated.
about each character
- name, class, race, level and guild rank
- item level and gear slot by slot
- which slots are missing an enchant or a gem
- spec and talent points
- professions and the level of each
- attunements for each raid
about each night
- who was there and in how many five-minute snapshots they appeared
- when they arrived and when they left
- whether the connection dropped
- whether they had food and a flask
- which bosses died, in how many attempts
about the loot
- which item
- who got it
- when and on which raid
- the method the guild used
The guild's two switches
Two decisions belong to the guild, not to us. And the default on each one is the most conservative answer available.
no guild starts with this on. whoever turns it on knows they turned it on.
for whoever wants the tool without the shopfront. the internal roster never depends on this switch.
Who sees what
Three layers, and each one sees everything the previous one sees plus its own slice. The gate into the second is sharing a Discord server with the guild: a guild key in a URL answers 404 to anyone who does not pass it.
+ everything layer 1 sees
+ everything layer 2 sees
GuildOS staff come in only to investigate a problem, with a striped banner on the screen saying so, and in read-only mode.
Where the data goes
No analytics, no trackers, no pixel, no ads. Nothing is sold.
the only cookie is your session. it can be checked: the code is open and there is no third-party call beyond the three above.code on GitHubSecurity, unadorned
How to delete
Deleting the account and the rest is on request, through the ? or on Discord. There is no button today.
we would rather say that than fake a button. when it exists, this line changes.Where this runs, and who we are
We are a small project, hosted on a single machine, in Brazil. If you are in Europe, your data crosses the Atlantic — we say so rather than hide it. We have no legal team and no data protection officer; we have one person who answers on the ? and on Discord.
if this policy changes, the date at the top changes and the notice goes out on your guild's Discord. a change that widens what we read needs notice beforehand, not afterwards.