Updated at: 25 September 2026
1. Controller and contact details
For processing where Archivian decides why and how personal data is used, the controller is Martin Haslien, acting as Archivian.
For much of the Discord community data described below, the operator of the relevant Discord server may instead be the controller and Archivian may act as its processor. Contact that server's operator for questions about why its moderation or logging configuration processes your data.
2. Scope
This Policy applies to the following Archivian surfaces (the "Service"): the marketing website at archivian.net, achv.in, and archivian.bot; the dashboard at app.archivian.net; the API at api.archivian.net; the documentation at docs.archivian.net; Archivian's Discord bot and app integrations; support; operational telemetry; and future paid subscriptions. It applies to Customers, dashboard users, support contacts, and Community Members whose data is processed through a Discord server.
3. Categories of personal data
Depending on the features a server enables and how a person uses Archivian, the Service processes:
- Server data. Things like the server's public-facing details, its configurations, channels, roles, expressions, audit logs, invitation records, and other data made available to the bot.
- Server events such as audit logs, Discord AutoMod violations, changes to resources in the server or changes to members, changes to member states and their profile data.
- Server-produced data produced in and for your community's moderation, safety, and management. Examples include cases, reports, Archivian-generated audit records, staff titles, configuration of Archivian for your community, message collections, blocked files.
- Discord profile. Things like your Discord ID, metadata like account flags, and visible data like your username and profile picture.
- Messages and their content, including files. Those contain things like author information, metadata, references, IDs, timestamps, interaction information, and more.
- Account and communications data like user preferences with Archivian, direct-message channels, support correspondence, an email address when you (or authorized server staff on your behalf) set up case or incident notifications, and your feed feedback provided to us.
- Authentication and technical data when visiting Archivian's own websites. We collect data like login attempts, IP addresses, user-agents, request and response metadata, error logs, performance traces.
- Billing data that's necessary for Archivian to determine your payment plan and its status. Refer to the billing section for more information.
Messages and moderation records can contain sensitive or special-category information because users may place such information in free text or files. Customers should take care to remove content that contains unnecessary sensitive data.
4. Sources of personal data
- you, when you use Archivian or interact with any of its services
- Discord, through OAuth, APIs, gateway events, interactions, and the permissions granted to Archivian on behalf of the customer;
- the Customer and its staff, through configuration, moderation decisions, uploads, and instructions;
- other Community Members, for example through messages, reports, or content involving you;
- Archivian systems, through security, audit, telemetry, and automated-moderation events; and
- payment providers.
5. Message Tracking
Archivian automatically tracks and stores all messages sent by users in Discord servers where Archivian is installed.
What We Track
- Full messages and all their types of content
- Edit history
- Deletion information
Why We Track Messages
The ability to track messages is needed for most of Archivian's features to function. This is not an exhaustive list, but here are some examples of features that will not work without it:
- Message change alerts
- Auto-moderation
- Mass-deletion filtering
- Message reporting
- Message strikes
- Message vote-deletion
- Support ticket transcripts
- Dashboard message history (in various contexts)
- Evidence preservation
- Control center
Messages Before Archivian Was Added
Archivian will not start fetching messages sent before it was added to the community unprompted.
Old messages may reach us and be stored if something causes Discord to dispatch the data to us, or if there are other legitimate reasons for us to start looking up old messages on behalf of the customer or its members. Examples include using message purging triggered by the customer, or if a message gets reported by one of the community members.
How Long We Keep Messages
- Standard retention: 14-30 days (configured by customer). Paying customers may choose a higher retention at their discretion.
- Extended retention: Indefinite for messages involved in something or specifically targeted by some process. For example reports, bulk purges, flagging by auto-mod, or investigations. These may be triggered manually or be completely automatic.
An exception for this is when a server chooses to terminate their use of Archivian. After the termination period ends, data is automatically purged. Note that how fast the purging process is depend on system load, but will not exceed 30 days after completed termination.
Discord's Framework
Discord's Terms of Service explicitly warn users that third-party bots may access user content. By participating in a Discord server that uses Archivian, you acknowledge that Discord may provide certain information to Archivian to operate its features.
Your Rights
You can request information about or deletion of your messages by contacting the server owner, or contact us. Refer to section 14 for more information.
6. Purposes and legal bases
| Purpose | Typical role | Probable legal basis |
|---|---|---|
| Operating, moderating, and administering Customer Discord servers on the Customer's instructions, including safety, security, and community-management functions | Usually processor | Determined by the Customer; governed by the DPA where applicable |
| Secure the Service, prevent abuse, investigate incidents, and maintain audit records | Controller or processor, depending on context | GDPR Art. 6(1)(f); Art. 6(1)(c) where a legal duty applies |
| Provide accounts, authentication, requested features, and support | Controller | GDPR Art. 6(1)(b); Art. 6(1)(f) where the user is not the contracting party |
| Product analytics and service improvement | Controller | GDPR Art. 6(1)(f) for necessary server-side measurements; consent where required for non-essential client storage or tracking |
| Send requested or operational communications | Controller | GDPR Art. 6(1)(b), Art. 6(1)(f), or consent under Art. 6(1)(a), depending on the message |
| Operate paid subscriptions, invoicing, tax, and accounting | Controller; a merchant of record may be a separate controller | GDPR Art. 6(1)(b) and Art. 6(1)(c) |
Where we rely on legitimate interests, those interests are operating a reliable service, protecting users and systems, understanding feature use, and defending legal claims. We assess necessity and balance those interests against affected individuals' rights. Consent may be withdrawn at any time without affecting earlier lawful processing.
8. Archivian as controller and processor
Archivian as controller
Archivian generally acts as controller for its own account administration, authentication, support, billing, fraud and service-abuse prevention, security monitoring, product improvement, legal obligations, and product analytics.
Archivian as processor
Archivian generally acts on the Customer's instructions for server configuration, message-related processing, moderation records, reports, appeals, staff-managed logs, and comparable community data. The boundary is context-dependent: Archivian may independently process limited copies or metadata for security, abuse prevention, legal compliance, or establishing and defending legal claims.
The exact scope of what Archivian observes in a server depends on the Discord permissions granted to the bot and the Customer's configuration. A server administrator decides which features are enabled, who has staff access, which automation runs, and in some areas how long data remains.
Customers that need Article 28 terms should review our Data Processing Agreement.
9. Analytics, error monitoring, and browser storage
PostHog
Archivian uses PostHog's EU endpoint for server-side product and operational events. Those events can contain stable pseudonymous Discord user or server IDs, event names, and feature properties. Dashboard browser analytics are opt-in; persistence, autocapture, and session recording are disabled in that default state, so no PostHog cookie, identifier, or browser-storage entry is written and no analytics events are sent from your browser.
Sentry
Archivian uses Sentry for errors and sampled performance traces in the dashboard and server services. Payloads may include stack traces, release and environment information, request metadata, URLs, IPs, server or user identifiers deliberately attached to an error, and data present in an exception. Dashboard Session Replay may be opted into, and will only be submitted when errors occur to help identify and reproduce the original problem. An an unexpected error can include personal data from the failing operation, but where possible we try to censor these before they even get sent.
Cookies and local browser storage
Archivian sets no advertising, profiling, or cross-site tracking cookies, and loads no third-party fonts, tag managers, CDNs, or advertising resources on any of its sites. Each site serve their own fonts, so simply opening a page sends your IP address to no one but us. Every item listed below is either strictly necessary to deliver a function you asked for, or a preference you set yourself. Under § 25 Abs. 2 Nr. 2 TDDDG that means none of it requires your prior consent, which is why Archivian shows no cookie banner. If we ever enable something that does need consent, we will ask for it first, with an equally easy way to decline, and this section will list it before it is switched on.
Cookies
All cookies are first-party. They are set by api.archivian.net on the
.archivian.net domain; it is shared across sub-domains so that your session can be used for personalization across our sites.
They are all are marked Secure and
SameSite=Lax. Secrets are stored using httpOnly.
| Name | Purpose | Stored for | Consent |
|---|---|---|---|
session |
Signed authentication token proving you are signed in. Not readable by JavaScript
(HttpOnly).
| 7 days, or until you sign out or clear it. After that you need to sign in again. | Not required; strictly necessary |
csrfToken | Cross-site request forgery token. Readable by JavaScript by design, because the page must copy it into a request header for the server to compare. The dashboard also checks for it to tell whether you are signed in before opening a live connection. Contains no identifier. | 7 days, the same as session, and replaced each time you sign in. | Not required; strictly necessary |
loginState | One-time value tying your Discord sign-in redirect to the browser that started it, so a third party cannot complete a login on your behalf. Restricted to the sign-in callback path and not readable by JavaScript. | 2 minutes. | Not required; strictly necessary |
Storage inside your browser
These are not cookies and are never sent to our servers with each request; they stay in your
browser and are readable only by the site that wrote them. Clearing site data removes them.
sessionStorage is discarded automatically when you close the tab.
| Key | Where | Purpose | Consent |
|---|---|---|---|
accountData | app: sessionStorage | Caches your user ID and the servers you are staff in, so each page does not have to re-fetch them. | Not required — strictly necessary |
anonUUID | app: sessionStorage | A random identifier generated per browser session, used to correlate the dashboard's own requests while you are using it. It is not a cross-site or advertising identifier and it is discarded when the tab closes. | Not required — strictly necessary |
chunk-reload-attempted | app: sessionStorage | A one-shot marker that stops the page reloading in a loop when a stale asset fails to load after a deployment. | Not required — strictly necessary |
uiData | app: localStorage | Your dashboard interface preferences, so it looks the same next time. | Not required — a preference you set |
currentDraft | app: localStorage | An unsent draft you were writing, kept so it is not lost if you navigate away or reload. | Not required — a preference you set |
setsCompleted | app: localStorage | Which introductory or setup steps you have already finished, so they are not shown again. | Not required — a preference you set |
archivian:admin:* | app: localStorage | Working state for internal administration tools. Only written for Archivian staff accounts. | Not required — strictly necessary |
archivian database | app: IndexedDB | Cached application data — server configuration, moderation records, and similar content you already have access to — so the dashboard stays responsive and does not re-download everything on each navigation. | Not required — strictly necessary |
starlight-theme | docs: localStorage | Whether you chose light or dark mode for the documentation. | Not required — a preference you set |
pagefind-ui* | docs: localStorage | State for the documentation search box. Search runs entirely in your browser; queries are not sent to us. | Not required — strictly necessary |
The marketing site itself stores nothing.
You can delete all of the above at any time through your browser's site-data controls, and block cookies for our domain entirely — though doing so will sign you out and prevent the dashboard from working, since the items above are the mechanism by which it works. Signing out clears the login cookies.
10. Billing and payment data
Archivian uses Paddle for paid checkout and subscription billing. Depending on the checkout shown to the purchaser, Paddle may act as Archivian's payment processor or a Paddle merchant-of-record product may be the seller and separate controller for the transaction. The checkout identifies the seller. Payment providers process payment credentials, fraud signals, billing address, tax location, transaction history, and related support data under their own notices. Archivian receives the subscription and transaction information needed to grant and manage plan access.
11. Recipients and service providers
Personal data may be disclosed to:
- the relevant Customer, authorized server staff, and Community Members where a feature intentionally displays the information;
- infrastructure, object-storage, database, email, analytics, error-monitoring, security, and payment providers;
- Discord where needed to perform configured Discord actions;
- professional advisers, authorities, or courts where legally required or necessary to protect rights; and
- a successor in a genuine business transfer, subject to applicable safeguards.
See the maintained Subprocessor List for the current provider inventory and unresolved provider details.
12. International transfers
Some providers or their support operations may process data outside Germany or the European Economic Area. Where GDPR transfer restrictions apply, Archivian will use an adequacy decision, the European Commission's Standard Contractual Clauses with supplementary measures where necessary, or another lawful transfer mechanism. See Subprocessor List for more details about region transfers with our providers.
13. Retention
Most types of Customer controlled records are not subject to a fixed automated retention period. These records are retained indefinitely unless and until the relevant Discord server operator, acting as controller, chooses to delete them. Server operators may at any time delete cases and other moderation records from their server. Such deletions are performed independently by the Customer and do not require Archivian's approval or involvement.
Here's a non-exhaustive summary:
- messages and their history use retention deadlines, but manual and automatic systems may place temporary or indefinite preservation locks on them;
- message attachments receive a configured deletion deadline, from two weeks up to thirty days, controlled by the Customer;
- server-specific data is deleted when Archivian has been absent from that server for seven consecutive days, unless the server re-adds Archivian or asks us to pause deletion;
- server backups normally expire after seven days and can be extended to fourteen days while in use;
- verification sessions expire thirty days after their challenge deadline;
- unpromoted anti-raid invocation evidence expires after three days, while evidence promoted to an incident is retained with that incident
Billing and tax records will be kept for statutory periods once paid plans launch.
Backups and disaster recovery
Infrastructure and database backups for disaster recovery purposes are retained for up to one year. These backups are stored securely and are only restored when necessary to recover from data loss or system failure. Backups are not used for routine data access.
14. Access and erasure requests
To exercise your rights to access, correction, restriction, or erasure, email us at [email protected].
What to include
Tell us your Discord username and, if you know it, your Discord user ID. If your request concerns a particular Discord server, describe that server by name or include an invitation link or its server ID, so we can identify the operator. You do not need to know a server's ID to make a request; a name or invite link is enough, and we will help identify the server if the description is ambiguous.
Verification
Because an email is not automatically tied to your Discord account, we may ask reasonable follow-up questions to confirm that you control the account the request is about. This protects your data as well as other people's. Requests are free of charge.
Data Archivian Controls
Where Archivian is the controller, for example its own account data, support records, security data, and future billing records, we review and answer your request ourselves, without undue delay and in any event within one month of receiving it. If a request is complex or numerous, we may extend that period by up to two further months, and we will tell you about the extension and its reasons within the first month.
Data a Discord server operator controls
Much of the community data described in this Policy, messages, moderation records, reports, and similar, is controlled by the operator of the relevant Discord server, with Archivian acting as its processor. For those parts of your request, we forward your request to the server operator, who reviews it and decides what to do. We assist the operator in locating the relevant records and in carrying out approved deletions or disclosures, and we relay the operator's response back to you. The server operator, as controller, decides which records to delete, partially erase, or retain; Archivian does not decide that outcome on the operator's behalf. You may also contact the server operator directly, for example through the server's own staff.
Erasure requests
An erasure request never triggers an automatic global deletion. Data may remain where continued processing is permitted or required, including to protect another person's rights, for security, for legal obligations, or for establishing or defending legal claims. Where records are retained, you will receive a category-level explanation of the reason, without disclosing protected information or other people's data.
What an Archivian-controller erasure includes
For data Archivian controls, an approved erasure includes Archivian's cached copy of your Discord profile. Archivian may retrieve the profile from Discord again if a feature later needs to display it; permanently deleting the profile at its source requires deleting your Discord account with Discord.
Active sessions
A small number of records describe a live session, such as your current voice-state in a server. Those cannot be erased while the session is ongoing because they are needed to operate and moderate it, and they become eligible for deletion once the session ends.
15. Security
Archivian uses role- and permission-based access controls, authenticated sessions and CSRF protection, TLS for public service endpoints, restricted backend delivery of private files, environment/Kubernetes secret handling, service separation, dependency and deployment controls, credentials and IP allow-listing for databases, and operational logging. No internet service is risk-free. See the Technical and Organizational Measures for a factual overview and known gaps.
16. Your rights
Subject to the GDPR's conditions and exceptions, you may have rights to:
- access and receive a copy of your data;
- correct inaccurate data;
- erase data or restrict processing;
- object to processing based on legitimate interests;
- receive portable data where applicable;
- withdraw consent; and
- not be subject to a solely automated decision with legal or similarly significant effects where Article 22 applies.
Submit access request, corrections, and erasure requests to us via email. See section 14 for more information.
17. Complaints
You may complain to a data-protection supervisory authority, in particular in the EEA country of your habitual residence, place of work, or the alleged infringement. The authority responsible for Archivian's future German establishment must be confirmed after the service address is finalized.
18. Children and minors
Archivian is not directed at children for independent purchase. Discord server users may include minors, so Customers should configure moderation and retention proportionately and comply with applicable rules. A purchaser must have legal capacity or valid authority to contract. Contact us if you believe a child's data is being processed unlawfully.
19. Changes and contact
We may update this Policy when the Service, providers, or law changes. Material changes will be highlighted where appropriate, and the effective date above will be updated. Questions and rights requests can be sent to [email protected].