Privacy Policy

How Archivian handles account, Discord community, service, and billing data.


Updated at: 25 September 2026

1. Controller and contact details

For processing where Archivian decides why and how personal data is used, the controller is Martin Haslien, acting as Archivian.

For much of the Discord community data described below, the operator of the relevant Discord server may instead be the controller and Archivian may act as its processor. Contact that server's operator for questions about why its moderation or logging configuration processes your data.

2. Scope

This Policy applies to the following Archivian surfaces (the "Service"): the marketing website at archivian.net, achv.in, and archivian.bot; the dashboard at app.archivian.net; the API at api.archivian.net; the documentation at docs.archivian.net; Archivian's Discord bot and app integrations; support; operational telemetry; and future paid subscriptions. It applies to Customers, dashboard users, support contacts, and Community Members whose data is processed through a Discord server.

3. Categories of personal data

Depending on the features a server enables and how a person uses Archivian, the Service processes:

Messages and moderation records can contain sensitive or special-category information because users may place such information in free text or files. Customers should take care to remove content that contains unnecessary sensitive data.

4. Sources of personal data

5. Message Tracking

Archivian automatically tracks and stores all messages sent by users in Discord servers where Archivian is installed.

What We Track

Why We Track Messages

The ability to track messages is needed for most of Archivian's features to function. This is not an exhaustive list, but here are some examples of features that will not work without it:

Messages Before Archivian Was Added

Archivian will not start fetching messages sent before it was added to the community unprompted.

Old messages may reach us and be stored if something causes Discord to dispatch the data to us, or if there are other legitimate reasons for us to start looking up old messages on behalf of the customer or its members. Examples include using message purging triggered by the customer, or if a message gets reported by one of the community members.

How Long We Keep Messages

An exception for this is when a server chooses to terminate their use of Archivian. After the termination period ends, data is automatically purged. Note that how fast the purging process is depend on system load, but will not exceed 30 days after completed termination.

Discord's Framework

Discord's Terms of Service explicitly warn users that third-party bots may access user content. By participating in a Discord server that uses Archivian, you acknowledge that Discord may provide certain information to Archivian to operate its features.

Your Rights

You can request information about or deletion of your messages by contacting the server owner, or contact us. Refer to section 14 for more information.

6. Purposes and legal bases

PurposeTypical roleProbable legal basis
Operating, moderating, and administering Customer Discord servers on the Customer's instructions, including safety, security, and community-management functionsUsually processorDetermined by the Customer; governed by the DPA where applicable
Secure the Service, prevent abuse, investigate incidents, and maintain audit recordsController or processor, depending on contextGDPR Art. 6(1)(f); Art. 6(1)(c) where a legal duty applies
Provide accounts, authentication, requested features, and supportControllerGDPR Art. 6(1)(b); Art. 6(1)(f) where the user is not the contracting party
Product analytics and service improvementControllerGDPR Art. 6(1)(f) for necessary server-side measurements; consent where required for non-essential client storage or tracking
Send requested or operational communicationsControllerGDPR Art. 6(1)(b), Art. 6(1)(f), or consent under Art. 6(1)(a), depending on the message
Operate paid subscriptions, invoicing, tax, and accountingController; a merchant of record may be a separate controllerGDPR Art. 6(1)(b) and Art. 6(1)(c)

Where we rely on legitimate interests, those interests are operating a reliable service, protecting users and systems, understanding feature use, and defending legal claims. We assess necessity and balance those interests against affected individuals' rights. Consent may be withdrawn at any time without affecting earlier lawful processing.

8. Archivian as controller and processor

Archivian as controller

Archivian generally acts as controller for its own account administration, authentication, support, billing, fraud and service-abuse prevention, security monitoring, product improvement, legal obligations, and product analytics.

Archivian as processor

Archivian generally acts on the Customer's instructions for server configuration, message-related processing, moderation records, reports, appeals, staff-managed logs, and comparable community data. The boundary is context-dependent: Archivian may independently process limited copies or metadata for security, abuse prevention, legal compliance, or establishing and defending legal claims.

The exact scope of what Archivian observes in a server depends on the Discord permissions granted to the bot and the Customer's configuration. A server administrator decides which features are enabled, who has staff access, which automation runs, and in some areas how long data remains.

Customers that need Article 28 terms should review our Data Processing Agreement.

9. Analytics, error monitoring, and browser storage

PostHog

Archivian uses PostHog's EU endpoint for server-side product and operational events. Those events can contain stable pseudonymous Discord user or server IDs, event names, and feature properties. Dashboard browser analytics are opt-in; persistence, autocapture, and session recording are disabled in that default state, so no PostHog cookie, identifier, or browser-storage entry is written and no analytics events are sent from your browser.

Sentry

Archivian uses Sentry for errors and sampled performance traces in the dashboard and server services. Payloads may include stack traces, release and environment information, request metadata, URLs, IPs, server or user identifiers deliberately attached to an error, and data present in an exception. Dashboard Session Replay may be opted into, and will only be submitted when errors occur to help identify and reproduce the original problem. An an unexpected error can include personal data from the failing operation, but where possible we try to censor these before they even get sent.

Cookies and local browser storage

Archivian sets no advertising, profiling, or cross-site tracking cookies, and loads no third-party fonts, tag managers, CDNs, or advertising resources on any of its sites. Each site serve their own fonts, so simply opening a page sends your IP address to no one but us. Every item listed below is either strictly necessary to deliver a function you asked for, or a preference you set yourself. Under § 25 Abs. 2 Nr. 2 TDDDG that means none of it requires your prior consent, which is why Archivian shows no cookie banner. If we ever enable something that does need consent, we will ask for it first, with an equally easy way to decline, and this section will list it before it is switched on.

Cookies

All cookies are first-party. They are set by api.archivian.net on the .archivian.net domain; it is shared across sub-domains so that your session can be used for personalization across our sites. They are all are marked Secure and SameSite=Lax. Secrets are stored using httpOnly.

NamePurposeStored forConsent
session Signed authentication token proving you are signed in. Not readable by JavaScript (HttpOnly). 7 days, or until you sign out or clear it. After that you need to sign in again. Not required; strictly necessary
csrfToken Cross-site request forgery token. Readable by JavaScript by design, because the page must copy it into a request header for the server to compare. The dashboard also checks for it to tell whether you are signed in before opening a live connection. Contains no identifier. 7 days, the same as session, and replaced each time you sign in. Not required; strictly necessary
loginState One-time value tying your Discord sign-in redirect to the browser that started it, so a third party cannot complete a login on your behalf. Restricted to the sign-in callback path and not readable by JavaScript. 2 minutes. Not required; strictly necessary

Storage inside your browser

These are not cookies and are never sent to our servers with each request; they stay in your browser and are readable only by the site that wrote them. Clearing site data removes them. sessionStorage is discarded automatically when you close the tab.

KeyWherePurposeConsent
accountData app: sessionStorage Caches your user ID and the servers you are staff in, so each page does not have to re-fetch them. Not required — strictly necessary
anonUUID app: sessionStorage A random identifier generated per browser session, used to correlate the dashboard's own requests while you are using it. It is not a cross-site or advertising identifier and it is discarded when the tab closes. Not required — strictly necessary
chunk-reload-attempted app: sessionStorage A one-shot marker that stops the page reloading in a loop when a stale asset fails to load after a deployment. Not required — strictly necessary
uiData app: localStorage Your dashboard interface preferences, so it looks the same next time. Not required — a preference you set
currentDraft app: localStorage An unsent draft you were writing, kept so it is not lost if you navigate away or reload. Not required — a preference you set
setsCompleted app: localStorage Which introductory or setup steps you have already finished, so they are not shown again. Not required — a preference you set
archivian:admin:* app: localStorage Working state for internal administration tools. Only written for Archivian staff accounts. Not required — strictly necessary
archivian database app: IndexedDB Cached application data — server configuration, moderation records, and similar content you already have access to — so the dashboard stays responsive and does not re-download everything on each navigation. Not required — strictly necessary
starlight-theme docs: localStorage Whether you chose light or dark mode for the documentation. Not required — a preference you set
pagefind-ui* docs: localStorage State for the documentation search box. Search runs entirely in your browser; queries are not sent to us. Not required — strictly necessary

The marketing site itself stores nothing.

You can delete all of the above at any time through your browser's site-data controls, and block cookies for our domain entirely — though doing so will sign you out and prevent the dashboard from working, since the items above are the mechanism by which it works. Signing out clears the login cookies.

10. Billing and payment data

Archivian uses Paddle for paid checkout and subscription billing. Depending on the checkout shown to the purchaser, Paddle may act as Archivian's payment processor or a Paddle merchant-of-record product may be the seller and separate controller for the transaction. The checkout identifies the seller. Payment providers process payment credentials, fraud signals, billing address, tax location, transaction history, and related support data under their own notices. Archivian receives the subscription and transaction information needed to grant and manage plan access.

11. Recipients and service providers

Personal data may be disclosed to:

See the maintained Subprocessor List for the current provider inventory and unresolved provider details.

12. International transfers

Some providers or their support operations may process data outside Germany or the European Economic Area. Where GDPR transfer restrictions apply, Archivian will use an adequacy decision, the European Commission's Standard Contractual Clauses with supplementary measures where necessary, or another lawful transfer mechanism. See Subprocessor List for more details about region transfers with our providers.

13. Retention

Most types of Customer controlled records are not subject to a fixed automated retention period. These records are retained indefinitely unless and until the relevant Discord server operator, acting as controller, chooses to delete them. Server operators may at any time delete cases and other moderation records from their server. Such deletions are performed independently by the Customer and do not require Archivian's approval or involvement.

Here's a non-exhaustive summary:

Billing and tax records will be kept for statutory periods once paid plans launch.

Backups and disaster recovery

Infrastructure and database backups for disaster recovery purposes are retained for up to one year. These backups are stored securely and are only restored when necessary to recover from data loss or system failure. Backups are not used for routine data access.

14. Access and erasure requests

To exercise your rights to access, correction, restriction, or erasure, email us at [email protected].

What to include

Tell us your Discord username and, if you know it, your Discord user ID. If your request concerns a particular Discord server, describe that server by name or include an invitation link or its server ID, so we can identify the operator. You do not need to know a server's ID to make a request; a name or invite link is enough, and we will help identify the server if the description is ambiguous.

Verification

Because an email is not automatically tied to your Discord account, we may ask reasonable follow-up questions to confirm that you control the account the request is about. This protects your data as well as other people's. Requests are free of charge.

Data Archivian Controls

Where Archivian is the controller, for example its own account data, support records, security data, and future billing records, we review and answer your request ourselves, without undue delay and in any event within one month of receiving it. If a request is complex or numerous, we may extend that period by up to two further months, and we will tell you about the extension and its reasons within the first month.

Data a Discord server operator controls

Much of the community data described in this Policy, messages, moderation records, reports, and similar, is controlled by the operator of the relevant Discord server, with Archivian acting as its processor. For those parts of your request, we forward your request to the server operator, who reviews it and decides what to do. We assist the operator in locating the relevant records and in carrying out approved deletions or disclosures, and we relay the operator's response back to you. The server operator, as controller, decides which records to delete, partially erase, or retain; Archivian does not decide that outcome on the operator's behalf. You may also contact the server operator directly, for example through the server's own staff.

Erasure requests

An erasure request never triggers an automatic global deletion. Data may remain where continued processing is permitted or required, including to protect another person's rights, for security, for legal obligations, or for establishing or defending legal claims. Where records are retained, you will receive a category-level explanation of the reason, without disclosing protected information or other people's data.

What an Archivian-controller erasure includes

For data Archivian controls, an approved erasure includes Archivian's cached copy of your Discord profile. Archivian may retrieve the profile from Discord again if a feature later needs to display it; permanently deleting the profile at its source requires deleting your Discord account with Discord.

Active sessions

A small number of records describe a live session, such as your current voice-state in a server. Those cannot be erased while the session is ongoing because they are needed to operate and moderate it, and they become eligible for deletion once the session ends.

15. Security

Archivian uses role- and permission-based access controls, authenticated sessions and CSRF protection, TLS for public service endpoints, restricted backend delivery of private files, environment/Kubernetes secret handling, service separation, dependency and deployment controls, credentials and IP allow-listing for databases, and operational logging. No internet service is risk-free. See the Technical and Organizational Measures for a factual overview and known gaps.

16. Your rights

Subject to the GDPR's conditions and exceptions, you may have rights to:

Submit access request, corrections, and erasure requests to us via email. See section 14 for more information.

17. Complaints

You may complain to a data-protection supervisory authority, in particular in the EEA country of your habitual residence, place of work, or the alleged infringement. The authority responsible for Archivian's future German establishment must be confirmed after the service address is finalized.

18. Children and minors

Archivian is not directed at children for independent purchase. Discord server users may include minors, so Customers should configure moderation and retention proportionately and comply with applicable rules. A purchaser must have legal capacity or valid authority to contract. Contact us if you believe a child's data is being processed unlawfully.

19. Changes and contact

We may update this Policy when the Service, providers, or law changes. Material changes will be highlighted where appropriate, and the effective date above will be updated. Questions and rights requests can be sent to [email protected].