This policy explains what the Albion Mass Discord bot and the dashboard at albionmass.com store about you, why, and what you can do about it. It is written to describe the system as it actually behaves.
1. Who is responsible
The Service is operated by the individual reachable at ivan@expgaming.org, who is the data controller for the purposes of the UK/EU GDPR.
2. What is stored
From Discord, automatically. When the bot is in a server you belong to, it stores for each member:
- Discord user ID, username/tag, and server display name (nickname);
- avatar image URL;
- the IDs of the Discord roles you hold in that server;
- which servers you are a member of, and when you joined or left.
That you provide.
- Your Albion Online character name, and the public character ID it resolves to, if you choose to run the
/linkcommand. This is optional. - Which builds you can play, are learning, or want to play, if you fill those in on the My Roles page.
- Free text you type: objective names and zones, event titles and descriptions, composition names. Do not put personal information in these.
Generated by using the Service. Event signups and attendance records; your dashboard roles (Member, Caller, Admin, Super Admin) per server; and a record of which Discord user created an objective, granted a role, or recorded attendance.
Cookies. Two, both strictly necessary and neither used for advertising or analytics: a signed session cookie that keeps you logged in, and a cookie remembering which server you last selected. There is no third-party tracking, no analytics, and no advertising on this site.
Not stored. The dashboard signs you in with Discord using only the identify scope. It never receives or stores your Discord password, email address, direct messages, or the contents of any channel.
3. Why, and on what legal basis
- To run the Service — showing a roster, gating access, recording attendance, posting timers. Legal basis: legitimate interests, in operating a tool that a server’s administrators chose to install for their members.
- Linking an Albion character and stating which builds you play is optional and done by you. Legal basis: consent, which you may withdraw by clearing those fields.
- Keeping the Service secure — checking your Discord roles on each request so access is withdrawn correctly. Legal basis: legitimate interests.
There is no automated decision-making with legal effects, and no profiling for advertising.
4. Who it is shared with
Your data is not sold, and not shared for marketing. It is handled by:
- Discord — the Service reads from and writes to Discord’s API. Anything the bot posts in a channel is visible to whoever can see that channel.
- Albion Online’s public API (Sandbox Interactive) — queried only to verify a character name you chose to link. Only that name is sent.
- Amazon Web Services — hosting and the database, in the Frankfurt region (eu-central-1), within the EU.
Other members of your Discord server can see your display name, linked Albion character, attendance, and which builds you say you can play. That visibility is the point of the tool.
5. How long it is kept
- Leaving a Discord server marks your record inactive and ends your dashboard access, but does not delete it. History is kept so that attendance records stay meaningful and so rejoining restores your roles.
- Removing the bot from a server deactivates that server and everyone in it. Data is retained unless deletion is requested.
- Objective timers are deleted automatically 15 minutes after they elapse.
- On request, your data is deleted — see below.
6. Your rights
Under the GDPR you may request access to your data, correction, erasure, restriction of processing, objection to processing, and a copy in a portable format. To exercise any of these, email ivan@expgaming.org from an address you can be identified by, or contact the operator on Discord. Requests are answered within 30 days.
Some of this you can do yourself: clear your linked character with /link, untick your build selections on My Roles, or leave the Discord server to end access.
If you think your data is being handled improperly, you may complain to your local data protection authority.
7. Security
Traffic is encrypted with HTTPS. The database is not reachable from the internet and accepts connections only from the application. Session cookies are signed, HTTP-only, and expire after 7 days of inactivity. No system is perfectly secure, and the Service is run by one person as a hobby project — please do not store anything sensitive in it.
8. Children
The Service is not directed at children below the minimum age required by Discord in their country. If you believe a child’s data has been stored, contact us and it will be deleted.
9. Changes
This policy may change as the Service changes. The date at the top shows when it was last updated. Material changes will be announced in the Discord servers where the bot is installed.