Privacy Policy
Last updated 24 July 2026
1. Who is responsible for your data
Ilvyx is an independent project operated from Italy.
For anything to do with this policy, or to exercise any right described here, write to support@ilvyx.com and it reaches the operator directly.
There are two roles to keep apart.
For people who sign in to the dashboard, we are the data controller.
For the data the bot handles inside a Discord server, the server owner is the controller and we act as their processor, following their configuration and this policy.
2. What we collect
Only what a feature cannot work without, and nothing else.
Your Discord user ID, username and avatar, which Discord gives us and which identify who a balance, a level or a ticket belongs to.
The server ID, name and icon, plus the configuration your staff set in the dashboard.
The feature data tied to your ID in that server: XP and level, virtual currency balances, inventory, game statistics, quests, achievements, birthdays and reminders you save yourself, moderation records, and tickets you open.
A session cookie when you sign in to the dashboard, and short lived server logs holding IP address, user agent and requested URL.
Ticket transcripts, only when your server staff switch that feature on, captured at the moment a ticket is closed.
If a server buys a paid plan, we store the subscription's status, plan, renewal date and the Discord ID of the buyer, so we know which server has premium and until when.
3. What we do not collect
We do not receive your email address, because the dashboard sign in asks Discord for the identify and guilds permissions only.
We never see or store your card details, billing address or invoices: payments are handled entirely by Polar as Merchant of Record, and they hold that data under their own privacy policy.
We do not read or store regular chat messages, with the single ticket transcript exception above.
We do not track you across other websites, we do not profile you for advertising, and we run no analytics of any kind on this site.
We do not use your data to train machine learning models.
We do not sell your data to anyone, and we never will.
We do not knowingly collect special category data such as health, political opinions or biometric data, and you should not put such data into bot configuration fields.
4. Why we process it, and on what legal basis
Every item in the list above exists to make a feature work: balances make the economy work, XP makes leveling work, ticket records make support work.
For dashboard accounts, the legal basis is our legitimate interest in providing the service you asked for under Article 6(1)(f) of the GDPR.
Where the bot processes member data inside a server, we do so on the documented instructions of the server owner, who relies on their own legal basis, usually legitimate interest in running their community.
For security logging and abuse handling, the basis is our legitimate interest in keeping the service safe.
We do not rely on consent for anything essential, so there is nothing you need to accept for the bot to work.
5. Cookies
The dashboard sets one strictly necessary cookie, which keeps you signed in after you authenticate with Discord.
It is not used for tracking or advertising and it cannot be switched off without breaking sign in, so no consent banner is required for it.
There are no analytics, advertising or social media cookies on this site.
If that ever changes, we will ask for your consent first and update this page.
6. Who we share it with
Only the providers needed to run the service, each bound by a contract limiting what they may do with it.
Discord Inc., which operates the platform the bot runs on and through whose API all bot data necessarily passes.
Hetzner Online GmbH, which hosts our servers and database inside the European Union.
Cloudflare Inc., which provides DNS and protects the site from attacks.
Polar Software, Inc., which as Merchant of Record sells the paid plans, processes payments and issues invoices, and tells us only which server bought a plan and its subscription status.
That is the entire list, and there is no advertising network, data broker or analytics provider on it.
We may also disclose data where the law compels us to, or where it is necessary to establish or defend a legal claim, and we will tell you when we are allowed to.
7. Where your data is stored, and transfers outside the EU
Our database and application servers are located in the European Union.
Discord, Cloudflare and Polar are established in the United States, so limited data reaches them there.
Those transfers rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies.
You can ask at support@ilvyx.com for details of the safeguards in place for any specific transfer.
8. How long we keep it
Server configuration and member feature data are kept while the bot is in the server, and are deleted after the bot has been removed for thirty days.
That grace period exists so an accidental kick does not destroy a community's setup.
Ticket transcripts are kept until the ticket record or the server is deleted, and copies your staff sent to a log channel or by direct message live in Discord and are outside our control.
Dashboard sessions expire automatically after thirty days of inactivity.
Security logs are kept for up to thirty days, then deleted.
Backups are kept for thirty days on a rolling basis, so deleted data may persist in a backup for that long before it is overwritten.
Nothing here is kept indefinitely, and there is no category we are legally obliged to retain against your wishes.
9. How we protect it
All traffic to the dashboard and the API is encrypted in transit with TLS.
Sensitive secrets, in particular the bot tokens submitted for the Bot Personalizer feature, are encrypted at rest and are never displayed again after they are saved.
Access to production systems is limited to the operator, protected by key based authentication.
Databases are not exposed to the public internet, and backups are stored encrypted.
No system is perfectly secure, so we cannot promise absolute safety, but we do commit to the measures above.
10. If something goes wrong
If a personal data breach happens and it is likely to result in a risk to your rights, we will notify the competent supervisory authority within seventy two hours of becoming aware of it.
Where the risk to you is high, we will also inform affected users and server owners directly and without undue delay.
We will tell you what happened, what data was involved, and what you can do about it.
11. Your rights
You can ask what data we hold about your Discord ID, and receive a copy of it.
You do not have to ask at all: sign in to the dashboard and open My data from the account menu, where the same copy downloads straight away and the same deletion happens on the spot.
You can ask us to correct it if it is wrong.
You can ask us to delete it, and because we hold nothing the law forces us to keep, the answer is yes.
You can ask us to restrict processing, or object to processing that relies on our legitimate interest.
You can ask for your data in a portable, machine readable format.
Server owners can additionally request deletion of their entire server's data at any time.
Write to support@ilvyx.com and we will respond within thirty days, free of charge.
We may need to verify that the request really comes from the owner of the Discord account in question, which normally means asking you to send it from the account itself.
Where we act as processor for a server, we will forward your request to the server owner, who is the controller for that data.
12. Complaints
If you think we have handled your data badly, please tell us first, because most problems are a misunderstanding we can fix quickly.
You also have the right to lodge a complaint with the data protection authority of the country where you live or work.
You do not need to contact us first before approaching it.
13. Children
The service is not directed at children below Discord's minimum age, which is thirteen in most countries and higher in some.
We do not knowingly collect data from anyone below that age.
If we learn that we hold data belonging to such a user, we delete it promptly.
If you are a parent or guardian and believe this has happened, write to support@ilvyx.com and we will act.
14. Automated decisions
Some features act automatically, such as automod deleting a message or a raid filter kicking an account.
These follow rules the server staff configured themselves, not profiling by us, and they never produce legal effects on you outside that Discord server.
A human on the server's staff can always review and reverse them.
15. Changes to this policy
We may update this policy as the service evolves.
The date at the top of this page reflects the latest revision.
Material changes will be announced through the dashboard and the support server before they take effect.
