Discord Application
Last updated: 26 August 2026
This policy covers the Gamers' Strife Discord bot (the “bot”, “the application”) — the Discord application that runs slash commands, tracks community activity, and posts match and tournament updates in Discord servers where it has been installed.
The Gamers' Strife website is covered by a separate website Privacy Policy. The two systems share one database, so where the bot sends data to the website, the website policy governs what happens to it from that point on. Where the two documents overlap, both are accurate; this one describes the Discord side in detail.
Gamers' Strife (“we”, “us”, “our”) operates the bot and is the data controller for the personal data described here. For any privacy question, request, or complaint about the bot, email privacy@gamersstrife.com.
Discord sends the bot events over a gateway connection. The scope of those events is set by the intents the application requests. We request the minimum the bot can function on: one privileged intent and one sensitive one. Two further privileged intents are deliberately not requested.
Needed to resolve a Discord user ID to a member of the server, to read the roles they hold, and to know whether they are boosting the server. Roles and boost status determine XP eligibility and XP bonuses; excluded roles receive no XP at all. Member data is used at the moment of the event and is not warehoused.
The application does not request the Message Content intent. Discord therefore does not send us the text of your messages at all, and it is not technically possible for the bot to read, log, store, or transmit them.
The bot is still told that a message was sent, which is how activity XP is awarded. That event carries who sent it, in which channel and server, and the message's numeric identifier — the body arrives empty. Every command the bot offers is a slash command; it defines no text-prefix commands, so no code path examines message text.
Needed to award XP for time spent in voice channels. The bot records when you join and leave a voice channel and which channel you are in, so it can calculate minutes present. The bot does not connect to voice channels, and never receives, records, or processes audio. It cannot hear anything.
The application does not request the Presence intent. It cannot see your online/idle/DND status, the game you are playing, your Spotify activity, or any other Rich Presence data, and no part of the bot reads or stores presence information.
The following is kept in the bot process's working memory to make it function, is never written to disk or database, and is lost whenever the bot restarts or redeploys:
When you earn XP, the bot sends a signed webhook to the website containing: your Discord user ID, the amount of XP, whether it came from a message or from voice, and metadata consisting of the channel ID, the server ID, the message ID (for messages) or the number of minutes (for voice), and which XP bonus was applied. This is stored against your account as your XP total, level, message count, voice minutes, and a history row.
Competitive commands — challenging a team, reporting a result, registering for a tournament, inviting or removing a roster member — are performed by the bot on your behalf against the website's API, carrying your Discord user ID so the website can identify you and apply exactly your own permissions. The records these create (challenges, matches, results, registrations, roster changes) are website data governed by the website Privacy Policy, and are identical to the records created when you do the same thing on the site.
If you attach a screenshot to a match report through the bot, the image is downloaded from Discord and uploaded to our storage, where it becomes part of the match record and is visible to match reviewers. Only JPEG, PNG, WebP, and GIF images within the size limit are accepted. Do not attach screenshots containing personal information you do not want reviewers to see.
So that a restart does not orphan a live tournament, the bot records the identifiers of the Discord objects it creates: server ID, category and channel IDs, participant role ID, message IDs, and match thread IDs. These identify channels and messages, not people, and contain no personal data.
The bot writes runtime logs for diagnostics, which may include Discord user IDs and usernames, server IDs and names, which command was run, and error details. These logs stay on the bot host, are used only to keep the service working, and roll over as the host rotates them.
The bot does send direct messages — for example, a card notifying a team leader of an incoming challenge. Sending a DM does not let it read your DMs, and you can close DMs from server members at any time without losing access to any feature; the same information also appears on the website.
We do not sell data, and we do not share it for advertising. Data is processed by the following providers solely to run the service:
| Processor | Purpose | Data involved |
|---|---|---|
| Discord | The platform the bot runs on | Gateway events; messages the bot posts |
| Fly.io | Hosting for the bot process | Data in transit and runtime logs |
| Supabase | Database and file storage | Stored activity, competitive records, proof screenshots |
We may also disclose data where we are legally required to, or where it is necessary to investigate abuse of the platform.
Under the GDPR and equivalent legislation, you have the rights of access, rectification, erasure, restriction, portability, and objection. In practice:
The bot holds no database credentials — everything it writes goes through the website's authenticated API, so a compromise of the bot host cannot reach the database directly. Activity webhooks are signed with HMAC-SHA256 and carry a timestamp that expires within five minutes, which prevents forged or replayed XP. Requests made on your behalf carry your permissions and no more: the bot's own token grants it no authority to act as a team leader, referee, or admin. Data at rest lives in a Supabase-hosted PostgreSQL database with access restricted to the service role, and all traffic is encrypted in transit.
The bot is not directed at children. In line with Discord's own Terms of Service, you must be at least 13 years old — or the minimum digital age of consent in your country, where that is higher — to use Discord and therefore this bot. We do not knowingly collect data from anyone below that age. If you believe we have, contact us and we will delete it promptly.
Our infrastructure is hosted in the United States. If you use the bot from outside the United States, your data is transferred there and processed by the providers listed in section 8 under their respective data protection commitments.
Discord is a separate controller for the data it holds about you. What Discord does with your account, messages, and servers is governed by Discord's Privacy Policy, not this one. Gamers' Strife is not affiliated with or endorsed by Discord Inc.
We may update this policy as the bot changes. The “Last updated” date at the top reflects the most recent revision, and material changes will be announced in the community. Continued use of the bot after a change constitutes acceptance of the revised policy.
Privacy questions or requests concerning the bot: privacy@gamersstrife.com. General or legal enquiries: legal@gamersstrife.com.