Xenon
Entrar
Adicionar o Xenon

Privacy Policy

Last updated

This Privacy Policy describes what personal data We collect when You use the Service, why, who receives it, how long We keep it, and the rights You have over it.

Definitions

Words with a capitalized initial letter have the meanings below, in the singular and the plural alike.

  • Company (also “We”, “Us” or “Our”) refers to Merlin Fuchs, Alte Str. 5, 04229 Leipzig, Germany, the controller of the processing described here.
  • Discord Data means content and metadata from Discord servers that You choose to process with the Service, such as server settings, channels, roles, messages and attachments contained in backups, chatlogs, templates and synchronizations.
  • Gallery means the public catalog of Discord server templates that the Website serves, and the listings published in it.
  • Personal Data is any information that relates to an identified or identifiable individual.
  • Service refers to the Website and the Discord bots operated by the Company, including the earlier version of Xenon that is being retired.
  • Website refers to Xenon, accessible from https://xenon.bot and https://app.xenon.bot, together with the other subdomains of xenon.bot on which the Company serves it.
  • You means the individual accessing or using the Service, or the company or other legal entity on behalf of which such individual is accessing or using the Service.

What We Collect

Your account

You sign in with Discord. On login We receive from Discord Your user ID, username, display name, avatar and the email address of Your Discord account. When You add a server, We also receive the list of servers You are a member of, in order to check Your permissions on the one You chose.

Usage data

Our servers record the IP address, browser identification, requested page and time of each request, in application logs. The analytics described below record which pages are viewed.

Discord Data

The Service exists to back up, copy, restore and synchronize Discord servers. When You create a backup, chatlog, template or synchronization, We store the Discord Data that feature requires, including server settings, channels, roles, permissions and, where the feature provides it, messages, message authors and attachments.

For Discord Data You are the controller and We are Your processor. The terms of that processing, including the security measures, the sub-processors and what happens on deletion, are in the Data Processing Addendum, which forms part of the Terms of Service. Discord Data is not sold, not used for advertising and not used to train machine learning models.

Publishing a template to the Gallery is the one thing You can do with Discord Data that works the other way around.

For the Gallery We are the controller. You decide to submit a listing; from there We decide whether it appears, how it is checked, where it ranks and how long it stands, so the Data Processing Addendum does not govern it and this Privacy Policy does.

A listing publishes Your Discord username and avatar, the name and description Discord holds for the template, and the structure of the server it was taken from: its channels, categories, roles, and their names and settings. That structure contains no members and no messages. A listing is served to anyone who asks for it, is indexed by search engines, and appears on a page listing everything You have published.

Before a listing enters the Gallery, its text (the template’s name and description and the names of its channels, categories and roles) is sent to Mistral AI for classification, and a listing classified as unsuitable is rejected. That decision is made without a human involved, and the reason is shown to You on Your templates page. It decides whether a template appears in a public catalog and nothing else, so it produces no legal or similarly significant effect within the meaning of Art. 22 GDPR. If You think it got Yours wrong, write to abuse@xenon.bot.

Upvoting a listing records that You upvoted it, so that a second vote from You does not count twice.

We also use what is published in the Gallery to develop and improve the automated features of the Service, including features that generate or suggest templates. That uses the listing itself, a structure of channels, categories and roles, and never anybody’s messages or member list. Nothing in a backup, a chatlog or an unpublished template is used this way.

The Gallery also holds listings published in the earlier version of Xenon, where they were already public. They keep the identity of the person who published them, and because a listing needs an owner, an account and a workspace may already exist here for You even if You have never signed in. Signing in for the first time adopts that account. If a listing is Yours and You would rather it were not there, write to privacy@xenon.bot.

Cookies and local storage

We use one strictly necessary cookie. It is set when You log in, holds Your session identifier, and is marked HttpOnly so scripts cannot read it. It expires seven days after You last used it and no later than 90 days after You signed in. Logging out ends it at once, and You can end every session You have from any device.

We do not use advertising, analytics or tracking cookies, and We do not embed third-party tracking pixels. The Website stores interface preferences such as Your color theme in Your browser’s local storage, and a marker in session storage so the analytics below do not repeat themselves within a visit. Neither is sent to Us.

Analytics

We measure how the Website and the dashboard are used. The analytics run on Our own infrastructure; no analytics provider receives Your data.

A visit is counted against an identifier derived by hashing request data together with a secret We hold, not against anything stored on Your device. If You are signed in, Your Discord user ID and display name, and the workspace You are viewing, are recorded alongside the events of that visit. Those events are Personal Data, and an erasure request covers them.

Why We Process It

We process Personal Data on the following legal bases under Art. 6(1) GDPR:

  • Performance of a contract (Art. 6(1)(b)): creating and operating Your account, providing the features You use, and delivering and billing a Subscription.
  • Legitimate interests (Art. 6(1)(f)): keeping the Service secure and available, preventing abuse and fraud, debugging errors, understanding how the Service is used in order to improve it, running the Gallery as a public catalog and improving the Service with what is published in it, and defending legal claims. You may object to processing on this ground as described under Your rights below.
  • Legal obligation (Art. 6(1)(c)): retaining transaction and tax records and responding to lawful requests from public authorities.

We contact You only with the notices running the Service requires, such as a change to these documents or a security notice, in the Service and on this website. Emails about a purchase, a renewal or a receipt are sent by Paddle.

Who Receives It

We rely on the following processors, each bound by a data processing agreement and permitted to use Your data only on Our instructions:

  • netcup GmbH, Germany: the servers the Service runs on, and the databases holding Your account, Your workspace and Your Discord Data.
  • Hetzner Online GmbH, Falkenstein (Germany) and Helsinki (Finland): object storage holding backups, chatlogs, attachments and the copies of them We keep.
  • Better Stack: application logs, metrics, uptime monitoring and Our status page. Logs identify the operation being logged, so they routinely carry Discord user IDs and server IDs. Our data is stored in their European region, but Better Stack is a United States company and engages sub-processors of its own outside the European Economic Area, so some of its processing happens there under the European Commission’s Standard Contractual Clauses.
  • Mistral AI, France: classification of listings submitted to the Gallery, as described above. It receives the text of the listing and nothing else, and does not use it to train its models.

We also exchange Personal Data with the following companies, each of which is a controller in its own right:

  • Discord: the platform the Service operates on, the source and destination of all Discord Data, and Our identity provider for login. Your relationship with Discord is governed by Discord’s privacy policy.
  • Paddle: Our payment provider and Merchant of Record. Paddle collects and processes the billing and tax data required to complete Your order. It receives no Discord Data.
  • Patreon: where a Patreon membership of Yours unlocks paid features, We read Your membership status and the Discord account You connected to it.

Other members of Your workspace can see Your Discord username and avatar and the actions You take in it, for example in the audit log. What You publish to the Gallery is public.

We may disclose Personal Data where the law requires it, in response to a valid request by a public authority, or where necessary to establish, exercise or defend legal claims. If the Company is involved in a merger, acquisition or sale of assets, Personal Data may be transferred as part of it.

Except as said above, every processor named here stores and processes Your data inside the European Economic Area. Where Personal Data leaves it, We rely on an adequacy decision of the European Commission or on its Standard Contractual Clauses. A copy of the safeguards is available on request.

How Long We Keep It

WhatHow long We keep it
Account dataUntil You ask Us to close the account
Discord Data (backups, chatlogs, templates, synchronizations)Until You delete the artifact, until the retention limit of Your plan supersedes it, or until Your workspace is closed
The audit log of Your workspaceUntil the workspace is deleted
Discord audit log entries We mirror for a synchronization90 days
Gallery listings, and the moderation decision on themUntil the listing is deleted
Gallery upvotesUntil the listing they were cast on is deleted
Exports You generate24 hours
Session cookie7 days from Your last use of it, and at most 90 days from signing in
Application logs90 days
Metrics30 days
Analytics eventsUntil they stop being useful for understanding how the Service is used; events naming a signed-in user are deleted when that user asks Us to erase them
Our own infrastructure backupsUp to 35 days, encrypted throughout, then overwritten on the rotation cycle
Transaction recordsAs long as German commercial and tax law requires, generally up to ten years

We keep data beyond these periods where a legal obligation requires it or a legal claim depends on it.

Your Rights

Under the GDPR You have the right to access Your Personal Data and obtain a copy of it (Art. 15), to have it rectified (Art. 16) or erased (Art. 17), to have its processing restricted (Art. 18), to receive the data You provided in a machine-readable format (Art. 20), and to object at any time to processing based on Our legitimate interests (Art. 21).

To exercise any of these rights, write to privacy@xenon.bot. We respond within one month, and may extend that by two further months for complex requests, in which case We tell You why.

You can delete backups, chatlogs, templates and Gallery listings from within the Service. To close Your account and have the Personal Data associated with it erased, write to Us; there is no button for it yet. An erasure We carry out covers the analytics events that name You, Your Gallery listings and creator page, and the data held by the earlier version of Xenon.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of Your residence, Your place of work, or the place where You think something went wrong.

The Earlier Version of Xenon

Part of the Service still runs on the version of Xenon that this one replaces, and will until it is retired. Where that version serves You:

  • Its website asks You to accept cookies through a banner, and sets more than the single strictly necessary cookie described above.
  • Its analytics are Ours and run on Our own infrastructure, but record a signed-in user’s email address alongside their Discord user ID and display name.
  • It records events in Your Discord servers in order to synchronize them, including the Discord user ID and the reason written by the moderator who took the action, and keeps those records until that version is retired.
  • It has no self-service account deletion. To have data held by it erased, write to privacy@xenon.bot.
  • The Data Processing Addendum does not apply to it.

This section goes when that version does.

Security

The technical and organizational measures We apply to Discord Data are described in the Data Processing Addendum, and the same infrastructure holds the rest of Your Personal Data.

Children

The Service requires a Discord account and is not directed at anyone below the minimum age Discord requires in Your country. Purchases may only be made by users who are 18 or older, or by a parent or guardian on a minor’s behalf. If You are a parent or guardian and believe Your child has provided Us with Personal Data, write to privacy@xenon.bot and We will remove it.

Changes to this Privacy Policy

We may update this Privacy Policy. Changes are published on this page, with the date at the top updated.

Contact Us

Write to the address that fits what You need, or to contact@xenon.bot if none of them does: