1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
lio.gg - Sven Rolnik
c/o Online-Impressum #3362
Europaring 90
53757 St Augustin
Deutschland
Email: support@lio.gg
A Data Protection Officer has not been appointed at this time, unless required by law.
2. Overview
Lio.gg is a hosted Discord bot with a modular web dashboard. Server administrators ("Users") configure the bot per Discord server. End users on Discord servers ("Server Members") may be affected by activated bot modules without logging into the dashboard.
We process personal data only to the extent necessary for operation, authentication, contract fulfillment, security, and (where activated) the bot functions configured by the server operator.
3. Discord Bot "Lio"
The bot "Lio" is an application for the Discord platform (Discord Inc.). It is hosted centrally by us and connects to servers on which it has been invited via the Discord API.
Data the bot may process (depending on activated modules and permissions):
- Discord IDs, display names, nicknames, avatars, and roles of server members
- Message content, edit and delete events (e.g. logging, leveling, moderation)
- Voice channel status (join/leave/move), where logging is enabled
- Configuration data of the server operator (channel IDs, thread IDs, role IDs, module settings)
- Content created by the server operator in the dashboard (embeds, rules, panel texts)
- Depending on modules, e.g.: birthdays; invite stats; moderation cases; tickets/helpdesk (including notes, ratings, transcript references); applications/absences/time clock; suggestions and bug reports; economy/Lioconomy balances and transactions; sticky roles, AFK, giveaways; vanity-link click counts (aggregated); optional platform surveys (answers, username, avatar)
The server operator is responsible for the lawfulness of bot use on their server (e.g. information obligations toward server members, consents where required). We provide the technical platform.
The bot is not affiliated with or endorsed by Discord Inc. Discord is a trademark of Discord Inc.
4. Dashboard & Login
We use Discord OAuth2 for the dashboard. We currently request the "identify" and "guilds" scopes (no Discord email). Upon login, we typically receive from Discord:
- Discord user ID, username, discriminator/global name
- Avatar URL
- List of Discord servers on which you have Manage Server permission
We store a session token (JWT) in your browser (local storage) to keep you logged in. We also store Discord access and refresh tokens server-side in our database so the dashboard can refresh your server list without requiring you to log in again. Tokens are removed or invalidated on logout or account deletion. Legal basis: Art. 6 para. 1 lit. b GDPR (contract/pre-contractual measures) and Art. 6 para. 1 lit. f GDPR (IT security, session continuity).
5. Internal Staff Panel: Discord Invite Links
To ensure platform operation, handle support and abuse cases, and pursue legitimate business outreach (in particular partnerships), the Provider operates an internal, access-restricted staff panel. Access is limited to authorized personnel of the Provider.
The staff panel does not grant the Provider independent administrative access to Discord servers or any insight into server content (e.g. messages, voice, member lists) beyond what the bot processes in the course of modules activated by the server operator and permissions granted to the bot.
In the staff panel, authorized personnel may, solely for Discord servers on which the bot "Lio" has been invited, cause the bot—via the Discord API—to retrieve an existing invite link or, where technically possible and covered by the bot's permission scope, to create a new invite link. The request is executed programmatically on behalf of the bot; the Provider does not act as a covert server administrator.
Any server join by employees of the Provider—if it occurs at all—does not take place through the staff panel, but exclusively through their personal Discord account and subject to the Discord rules applicable to every member as well as the rules of the respective server. Creating or providing an invite link does not establish permanent presence on the server for the Provider or access to server content beyond the invite process.
Data processed in connection with this function includes in particular:
- Guild ID and server metadata already present in platform operation
- Channel ID and/or channel name of the target channel for the invite
- Invite code, invite URL, and validity/usage parameters set by Discord
- Timestamp and technical context of the API request (log data in the staff panel and/or server logs)
The legal basis is Art. 6 para. 1 lit. f GDPR (legitimate interests): secure and efficient platform operation, communication with server operators, abuse prevention, and proportionality in relation to the interests of data subjects. This function requires that the bot has been invited to the server and holds the necessary permissions.
Invite links are not permanently stored in a separate database for contact purposes; they are displayed temporarily in the staff panel and may be contained in technical logs for a limited period (see section 12). Invites remaining on the Discord server are subject to Discord's storage and visibility rules.
6. Purposes and Legal Bases
| Purpose | Legal basis |
|---|---|
| Provision of bot and dashboard | Art. 6 para. 1 lit. b GDPR |
| Module functions (configured by server operator) | Art. 6 para. 1 lit. b/f GDPR; consent of server operator/member where applicable |
| Creation/retrieval of Discord invite links via the staff panel (platform operation, support, partnership communication) | Art. 6 para. 1 lit. f GDPR |
| Billing for Plus/Premium plans (via Stripe) | Art. 6 para. 1 lit. b GDPR |
| Abuse prevention, rate limits, technical logs (including request IP address) | Art. 6 para. 1 lit. f GDPR |
| Support requests by email | Art. 6 para. 1 lit. b/f GDPR |
7. Data Categories in Detail
Account data (dashboard users): Discord ID, profile data, plan status (Free/Plus/Premium), Stripe customer/subscription IDs where present, Discord OAuth tokens (access/refresh), warnings/blocks by our team, registration timestamps.
Server configuration: guild ID, module status, JSON configurations (channels, roles, embeds, logging targets, etc.), stored in our database (MongoDB, self-hosted).
Bot operational data: temporary cache entries, API calls to Discord and configured integrations, error logs without unnecessary personal references where possible; for API/dashboard access, IP addresses for rate limits and abuse prevention.
Staff panel (invite links): guild ID, channel name/ID where applicable, invite code and URL, timestamp of the Discord API request, and triggering log data in the staff panel. Invite links are not permanently stored for contact purposes; invites existing on the Discord server may remain subject to Discord's rules.
Server member data: processed by the bot only where modules are active and Discord events occur; scope depends on configuration by the server operator (see section 3).
First-party metrics: e.g. vanity URL click counts (aggregated by day, without storing visitor IPs in the analytics database) and optional platform surveys if you participate. We do not set third-party marketing/tracking cookies.
8. Discord as Third Party
Discord Inc., 444 De Haro Street, Suite 200, San Francisco, CA 94107, USA, provides the platform through which the bot communicates. Data transfers to the USA may occur. Discord provides its own privacy information and, where applicable, standard contractual clauses.
Further information: discord.com/privacy
Avatars, icons, and media may be loaded by the browser or bot via Discord's CDN (cdn.discordapp.com); your or our server IP may be transmitted to Discord. We have no influence over data processing by Discord outside of our bot and dashboard integration.
9. Further Integrations and Fetches
Tebex: If the server operator enables the Tebex module and stores shop secrets, we retrieve transaction and shop data via the Tebex API on the server operator's instructions (including purchases, player names, and buyer emails where Tebex provides them). Shop secrets are stored AES-encrypted and are not shown again in clear text in the dashboard. The server operator is responsible for the lawfulness of these fetches toward members/buyers; we provide the technical connection. Tebex Ltd. is an independent provider (own privacy notices).
Streamer and social feeds: On the server operator's configuration, we fetch public status or feed data from services such as Twitch, YouTube, Kick, TikTok, Instagram, or X to update notifications or panels. Our server IP may reach the respective provider.
Game server status: Modules may query FiveM (including Cfx.re) or Minecraft server status where the server operator configures endpoints. Technical status data is retrieved; the server IP may reach the target system.
10. Hosting and Processors
The bot, backend API, and dashboard are hosted by the following processor:
Processor: Hetzner Online GmbH
Industriestr. 25, 91710 Gunzenhausen, Deutschland
Location of data processing: Serverstandort: Rechenzentren in Deutschland (u. a. Nürnberg und Falkenstein)
Provider privacy information: https://www.hetzner.com/de/legal/privacy-policy
Payments are processed by Stripe, Inc. (510 Townsend Street, San Francisco, CA 94103, USA). Stripe processes card data; we store only Stripe customer and subscription IDs. Transfers to the USA may occur; Stripe relies on Standard Contractual Clauses and/or the EU-US Data Privacy Framework where applicable.
Provider privacy information: stripe.com/privacy
On the same Hetzner servers we run MongoDB (self-hosted) and a reverse proxy (Caddy) with TLS certificates from Let’s Encrypt (the server IP may be sent to Let’s Encrypt). Server backups/snapshots are stored locally by default; optional S3-compatible storage may be configured. We enter into Art. 28 GDPR agreements where required. Questions: support@lio.gg.
11. Website: Fonts and Local Storage
Fonts and icons on https://lio.gg are served by us (including Next.js font optimization and locally bundled icon fonts). Page loads do not fetch Google Fonts or other font CDNs; your IP address is not sent to Google solely to load fonts.
Strictly necessary browser storage is described in our Cookie Policy. We currently do not set analytics or marketing cookies.
12. Retention Period
We store account data for as long as your dashboard account exists and thereafter only to the extent required by statutory retention obligations. Discord OAuth tokens are removed on logout or account deletion.
Server configurations remain stored until the server operator removes the bot, deactivates modules, or requests deletion.
Log data and technical records—including records of Discord API requests in the staff panel (invite links)—are generally deleted on a rolling basis (typically a few days to weeks), unless longer retention is required for error analysis or abuse prevention.
Messages posted by the bot in Discord channels are subject to Discord's retention and the server operator's settings.
13. Your Rights
Under the GDPR, you have in particular the following rights:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Withdrawal of consent given (Art. 7 para. 3 GDPR)
Server members should primarily contact the administrator of the respective Discord server for bot-related requests. You may also contact support@lio.gg.
Right to lodge a complaint with a supervisory authority, e.g. for Deutschland the competent state data protection authority of your place of residence.
14. Obligation to Provide Data
Providing Discord profile data is required for dashboard use. Without OAuth login, the dashboard cannot be used. Bot functions on Discord require the bot permissions set by the server operator.
15. Changes to this Policy
We update this Privacy Policy when the legal situation, services, or data processing change. The current version is available at https://lio.gg/privacy. We inform registered users of material changes where appropriate.
These texts are carefully drafted for the operation of Lio.gg and the Discord bot “Lio”, but do not replace individual legal advice. For questions contact support@lio.gg.