Roody Roody / Legal

Privacy Policy

How we collect, use, store and protect your information when you use Roody and our services.

Last updated: 2 August 2026

1. Data controller

Under article 13 of the GDPR, the controller of your personal data is:

Contact email[email protected]
Websitedashboard.roody.es

You can use that address for anything to do with your data. See also the legal notice.

No Data Protection Officer has been appointed, as none of the cases in article 37 of the GDPR applies. For any privacy matter you can write to the address above.

2. Introduction

At Roody we respect your privacy and are committed to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, store and protect your information when you use our Discord bot and related services.

Quick summary

  • We only collect the data needed for the bot to work.
  • We do not sell your personal information to third parties.
  • You can request the deletion of your data at any time.
  • We apply technical and organisational measures to protect it.

3. Information we collect

3.1 Information provided automatically by Discord

When you invite Roody to your server, we automatically collect:

  • Discord user ID: a unique numeric identifier.
  • Username and discriminator: your visible name on Discord.
  • Avatar: your profile picture (if public).
  • Server ID: the identifier of the server where the bot is used.
  • Roles and permissions: information about your role in the server.

3.2 Bot usage information

We record data about how you interact with the bot:

  • Commands used: which commands you run and when.
  • Server settings: your server's specific configuration.
  • Economy and level data: currency, XP and progress.
  • Moderation logs: moderation actions and penalties.
  • Ticket content: messages exchanged in support tickets.
  • Messages analysed by automatic moderation: if the administrator enables AI moderation, the text of the server's messages is analysed to detect prohibited content. See section 6.

3.3 Information provided voluntarily

  • Contact forms: data you send us by email or through the website.
  • Custom settings: preferences you define in the dashboard.
  • Feedback and suggestions: comments you share with us.

4. How we use your information

4.1 Bot functionality

  • Processing commands and responding appropriately.
  • Maintaining your server's configuration.
  • Providing moderation features.
  • Managing economy, levels and tickets.

4.2 Service improvement

  • Analysing usage patterns to improve features.
  • Identifying and fixing errors.
  • Developing new features.
  • Providing technical support.

What we do NOT do

  • We do not sell your personal information to third parties.
  • We do not send spam or unsolicited advertising.
  • We do not share one server's data with another Discord server.
  • We do not read your direct messages with other people: Roody only sees what is written in the channels of the servers it is in, and only for the features the administrator has enabled.

5. Legal basis for processing

The GDPR requires every processing activity to rest on a legal basis. These are ours:

ProcessingLegal basis
Running the bot and the dashboard: handling commands, storing server configuration, levels, economy and tickets.Performance of a contract (art. 6(1)(b) GDPR): this is the service you asked for when you invited the bot or signed in to the dashboard.
Managing subscriptions, payments and invoicing.Performance of a contract (art. 6(1)(b)) and legal obligation (art. 6(1)(c)) for keeping tax records.
Automatic moderation, anti-raid and security logs.Legitimate interest (art. 6(1)(f)): keeping the service safe and usable. Each server's administrator decides whether to enable it.
Aggregated usage metrics to find bugs and improve features.Legitimate interest (art. 6(1)(f)).
Answering enquiries sent through the form or by email.Consent (art. 6(1)(a)), which you give by writing to us.
Referral attribution cookie.Consent (art. 6(1)(a) GDPR and art. 22(2) of the Spanish LSSI).

Where the basis is legitimate interest, you can object at any time as explained in section 8.

6. Who we share your data with

We neither sell nor trade your data. We do work with providers that process it on our behalf («processors»), under a processing agreement compliant with article 28 of the GDPR:

ProviderWhat forWhere they process it
DiscordThe platform the bot runs on and that you sign in with.USA — policy
MongoDB AtlasThe service database.European Union
StripeTaking subscription payments. Roody never sees your card details.USA — policy
Google (Drive)Storage for the encrypted backups.USA
Artificial intelligence providerAnalysing message text when the administrator enables AI moderation. The message text is sent without your name or your identifier, and is not used to train models.USA

6.1 International transfers

Some of these providers are in the United States, outside the European Economic Area. Those transfers rely on the Standard Contractual Clauses approved by the European Commission and, where the provider is certified, on the EU–US Data Privacy Framework.

You can ask us for a copy of the safeguards in place by writing to [email protected].

6.2 Other disclosures

We may also disclose data to courts, law enforcement and public authorities where there is a legal obligation to do so.

7. Data storage and retention

7.1 Where we store your data

  • Main database: MongoDB Atlas, encrypted at rest, in a European Union region.
  • Backups: encrypted and stored on Google Drive. Google acts as a processor and may handle them outside the EEA; see section 6.
  • Bot and dashboard hosting: a provider with servers in the European Union.

7.2 How long we keep your data

Data typeRetentionReason
Server settingsWhile the bot is in the serverBot functionality
Economy and level data2 years of inactivityPreserving user progress
Moderation logs1 yearAuditing and dispute resolution
Support tickets2 yearsTechnical support and improvements
Error logs6 monthsDebugging and improvements

8. Your rights

Under the GDPR and other data protection laws, you have the following rights:

  • Access: to know what data we hold about you and how we use it.
  • Rectification: to correct inaccurate or incomplete information.
  • Erasure: to request the deletion of your personal data.
  • Portability: to receive your data in a structured format.
  • Objection and restriction: to object to or restrict processing.
  • Withdraw consent: where processing is based on it, without affecting the lawfulness of processing carried out beforehand.
  • Complain to a supervisory authority: if you think we have not handled your rights properly, you can complain to the Spanish Data Protection Agency (C/ Jorge Juan 6, 28001 Madrid) or to the authority in your country.

Exercising these rights is free of charge. We will reply within one month, extendable by two further months for complex requests, telling you why.

How to exercise your rights

9. Data security

We implement several measures to protect your information:

  • Encryption in transit and at rest with TLS and AES-256.
  • Limited access: only authorised staff can access user data.
  • Monitored infrastructure: firewalls and 24/7 monitoring.
  • Reinforced authentication for the administration panel.

10. Cookies and similar technologies

The web dashboard uses cookies to:

  • Essential cookies: keep your session logged in.
  • Functional cookies: remember your preferences.

We do not use third-party analytics or advertising cookies. You can manage cookies from your browser settings. Disabling some may affect functionality. See the cookie policy for details.

11. Children

Roody is not aimed at children under 14. In Spain, article 7 of the LOPDGDD sets that as the minimum age to consent to the processing of one's own data; below it, consent from a parent or guardian is required.

Using Discord requires being at least 13, or the minimum age required by the law of your country of residence. In Spain and the rest of the European Union, you must be 14 or over to use Roody.

If we find that we have processed the data of a child below that age without the necessary authorisation, we will delete it. If you believe this has happened, write to [email protected] and we will sort it out without delay.

12. Changes to this policy

We may update this policy from time to time. When we do:

  • We will publish the new version on this same page.
  • We will update the "last updated" date.
  • We will notify significant changes from the dashboard.
  • For major changes we will ask for your explicit consent.

13. Contact

If you have questions about this policy or about how we handle your data, get in touch:

Response times: we answer general enquiries as soon as we can. For data protection rights, the legal deadline is one month from receiving the request, extendable by two further months if it is complex (art. 12(3) GDPR).

Other legal documents