Privacy Policy
Last Updated: July 15, 2026 • Version 1.7 • GDPR Compliant
/privacy slash command in Discord or the Privacy Dashboard.
1. Data Controller
The data controller for Levlix is:
- Operator: Atraxo - Levlix
- Country: Switzerland
- Email: support [at] levlix [dot] io
- Service: Levlix Discord Bot
2. Data We Collect
2.1 Data Collected Automatically
When you interact with Levlix, we automatically collect:
| Data Type | Purpose | Retention |
|---|---|---|
| Discord User ID | Identify users across sessions | Until deletion request |
| Discord Username | Display in leaderboards | Updated on each interaction |
| Server (Guild) ID | Associate data with servers | Until bot removal |
| Activity Metrics | Message counts, voice channel durations, reactions, and invite tracking for points and leaderboards | Numerical counts only (no message or audio content). Identifier removed and rows anonymised after 2 years of inactivity; aggregated counts kept for server statistics with no link to your identity. |
| Action Histories | Logs of shop purchases, mini-game wagers, and RPG character progression for support and moderation | Until deletion request |
| Last Active Timestamp | Track user activity for server administration | Updated on each interaction |
| Points Balance | Core bot functionality | Until deletion request |
| Presence Minutes (opt-in) | Online/Idle/DND/Offline minutes per hour, stored in user_presence_logs, used to render your personal screentime statistics |
Disabled by default. When enabled, retained until disabled or deletion request. |
| Message Audit Snapshots (toggleable) | When a message you sent is deleted or edited, the affected content (up to 1024 characters) is posted to the server's moderation log channel so server moderators retain an audit trail. This snapshot lives in the Discord log channel, not in our database. | Governed by the server's Discord channel; collection stops when you disable the Message Audit toggle via /privacy. |
| Moderation Case Evidence (not toggleable) | When the automated moderation system (see § 2.8) or a moderator opens a case about a message, up to 500 characters of that message are stored in mod_cases.message_content as case evidence. |
Retained with the moderation case for server-safety accountability; exempt from self-service deletion (Art. 17(3), see § 5.3). Included in your data export where the case concerns you. |
2.2 Data We Do NOT Collect
- Message content for general features (only numerical counts are stored). Exceptions: deleted/edited message snapshots posted to the server's audit log channel (§ 2.5), moderation case evidence when a message triggers a moderation case (§ 2.8), and messages you deliberately send to the AI assistant (§ 2.9)
- Direct messages (DMs)
- Voice conversations (audio)
- IP addresses (via the Discord Bot)
- Payment or financial information
2.3 Web Dashboard Data & Analytics
When using our web dashboard, we additionally process:
- OAuth2 tokens (for Discord authentication, stored securely)
- Session cookies (for login persistence)
- Browser user agent (for security/analytics)
- IP Addresses & Security Logs: We temporarily process and log your IP address to protect our infrastructure from automated attacks (using Rate Limiters and Fail2Ban). These logs are automatically purged.
2.4 Web Beacons, Cookies & Web Analytics
Our website uses "Cookies" — small text files stored on your device. We separate these into two categories:
- Essential Cookies: Used to keep you logged in to the dashboard securely. These cannot be disabled.
- Analytics Cookies (Google Analytics 4): Used to measure website traffic and improve our services. These are disabled by default.
Google Analytics 4 (GA4): If you provide your explicit consent via our Cookie Banner, we use GA4 (provided by Google Ireland Limited). We have activated the anonymize_ip feature, which means your IP address is truncated and anonymized before being stored by Google.
Revoking Consent: You can revoke your consent at any time by clicking the "Cookie Settings" link in the footer of our website, or by clearing your browser cookies.
Cloudflare Web Analytics: Our CDN provider (Cloudflare, Inc.) injects a lightweight, cookieless analytics beacon (beacon.min.js) into our web pages. It collects aggregated performance and visit metrics (page URL, referrer, browser type, country-level location) without cookies, fingerprinting, or cross-site tracking, and stores no persistent identifiers on your device. Because no user profile is created and nothing is stored on your device, this processing is based on our legitimate interest in monitoring site performance and availability (Art. 6(1)(f) GDPR) and does not require cookie consent.
2.5 Granular Privacy Controls (Self-Service)
You can manage how Levlix processes your data at any time using the /privacy slash command (an ephemeral Components V2 panel only you can see) or the Privacy Dashboard. Both interfaces expose the same three toggles:
| Toggle | What it controls | Default | Legal basis |
|---|---|---|---|
| Presence Tracking | Hourly Online/Idle/DND/Offline minutes in user_presence_logs, used for your personal screentime statistic. |
Opt-in (FALSE) | Art. 6(1)(a) consent |
| Activity Tracking | XP, voice time and message activity counters that drive levels, leaderboards and rewards (core bot functionality). | Enabled (TRUE) | Art. 6(1)(b) contract |
| Message Audit Storage | When a message you sent is deleted or edited, post up to 1024 characters of its content to the server's moderation log channel. Note: this toggle does not affect moderation case evidence stored by the moderation system (§ 2.8), which is retained on overriding server-safety grounds. | Enabled (TRUE) | Art. 6(1)(f) server owner legitimate interest |
Disabling a toggle takes effect immediately and stops further collection of that data category. Existing rows are kept until the next scheduled purge or until you request deletion (see § 5.3 and § 6).
2.6 Data Export & Self-Service Deletion
- JSON Data Export: The
/privacycommand and the Privacy Dashboard let you download a machine-readable JSON archive of the data we hold about you (GDPR Art. 15 access + Art. 20 portability), including moderation cases that concern you, your AI assistant conversations, support tickets and reports you filed. Excluded for security reasons: stored security credentials (e.g. two-factor secrets) and internal staff audit logs; identifiers of other users are always omitted. Rate-limited to one export per 24 hours per user to prevent abuse. - Immediate Account Deletion: The same interfaces expose a destructive
gdpr_delete_user_now()action that purges your user-level data across all participating tables on the spot, in addition to the automated 2-year inactivity purge described in § 5.3. A small set of records is exempt from this deletion — see the retention exceptions in § 5.3.
2.7 Privacy Audit Log
To prove to supervisory authorities that self-service privacy actions were initiated by the account holder, we keep a minimal audit log of these events (toggle changes, data exports, account deletions, opt-ins). Each entry contains the Discord User ID, the action, the interface used (bot, dashboard or API), a timestamp, a coarse user-agent category and a salted SHA-256 hash of the requesting IP address. The salt is rotated daily and discarded after at most 36 hours, after which the hash can no longer be linked back to a specific IP. Privacy audit log entries are retained for 3 years (Art. 5(2) accountability and Art. 17(3)(e) defence of legal claims) and then deleted automatically by gdpr_purge_privacy_audit_log.
2.8 Automated Moderation (AI-assisted)
Servers can enable a moderation system that automatically evaluates messages in real time, including an AI-assisted filter that scores message content on locally hosted models. When a message triggers it, a moderation case is created that stores up to 500 characters of the message and the assigned scores (mod_cases), and a moderation action configured by the server (such as a timeout, kick or ban on that server) may be applied automatically. Legal basis: Art. 6(1)(f) (the server community's overriding interest in a safe environment). You have the right to contest any automated moderation action and obtain human review: the server's moderators can review and revoke every case, and you can additionally contact our support (§ 6). Moderation case evidence is retained for server-safety accountability and is exempt from self-service deletion (Art. 17(3)); cases that concern you are included in your data export.
2.9 AI Assistant
If you use the optional AI assistant, the messages you send to it and the assistant's replies are stored as your conversation history (local_ai_context), together with session titles. The AI model runs on our own servers (locally hosted via Ollama); your conversations are not sent to any third-party AI provider. Conversation history is used solely to provide context within your sessions, is included in your data export, and is deleted with your account. Legal basis: Art. 6(1)(b) (you actively request the feature).
2.10 Support Tickets & User Reports
Support tickets: when you open a ticket we store its subject, status and timestamps, and any feedback rating, feedback comment and close reason. Tickets you opened are included in your data export and deleted with your account. User reports: when you report a message, we store your report (reason and a snapshot of the reported message) for moderation review. Reports you filed are exported and deleted with your account; note that if someone reports one of your messages, the snapshot in their report is processed as moderation evidence under § 2.8.
2.11 Service Telemetry & Deletion Tombstone
Command statistics: we record which command was used by which account and when, to operate the service, detect abuse and plan capacity. These records are anonymised (your ID is removed) when you delete your account. Deletion tombstone: when you delete your account or opt out, your bare Discord User ID is permanently kept in an opt-out list (gdpr_opt_outs) — this is technically required so that we keep honouring your deletion and do not start collecting data about you again (Art. 6(1)(c) in conjunction with Art. 17).
3. Legal Basis for Processing (GDPR Art. 6 / nDSG Art. 6)
We process your data based on the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nDSG):
- Contract Performance (Art. 6(1)(b)): Processing necessary to provide the Bot's services you requested
- Legitimate Interest (Art. 6(1)(f)): Security, fraud prevention, and service improvement
- Consent (Art. 6(1)(a)): For optional features and analytics
4. How We Use Your Data
Your data is used exclusively to:
- Provide core Bot functionality (points, leaderboards, games)
- Track activity for rewards and milestones
- Prevent abuse and ensure fair gameplay
- Provide server administrators and owners with aggregated member activity overviews (e.g. levels, points, last active status) via the web dashboard, limited to their own server's data
5. Data Storage & Security
5.1 Storage Location
Your data is stored on servers located in:
- Primary Database: European Union (Germany, Hetzner)
- CDN & Security: Global Edge Network (Cloudflare)
5.2 Security Measures
- Encrypted database connections (TLS/SSL)
- Parameterized queries (SQL injection prevention)
- Rate limiting and DDoS protection
- Automated backups with encryption
5.3 Data Retention
- User data: Retained until deletion request or account inactivity (2 years, enforced by
gdpr_purge_inactive_users). After that, the user profile and PII-heavy records are deleted; aggregated activity counts are anonymised and kept for long-term server statistics with no link to your identity. - Self-service immediate deletion: Available at any time via the
/privacycommand or the Privacy Dashboard (gdpr_delete_user_now()). Takes effect on the spot, independent of the 2-year inactivity purge. - Self-service data export: Available at any time via the
/privacycommand or the Privacy Dashboard, rate-limited to one export per 24 hours. - Server data: Deleted 30 days after bot removal (
gdpr_purge_inactive_guilds). - Security logs (dashboard role changes, internal team actions, admin-initiated data exports): The personal identifiers in these logs (IP address and browser user-agent) are removed after 30 days; the anonymised action records (who did what, when) may be retained longer where required for our legitimate security interests. Admin-initiated data-export records are deleted in full after 30 days. Enforced automatically by
gdpr_purge_old_security_logs. - Privacy audit log (self-service toggle changes, exports, deletions): Retained for 3 years with a daily-rotating salted IP hash (unlinkable after at most 36 hours), then deleted automatically (
gdpr_purge_privacy_audit_log). See § 2.7. - Operational logs (error traces, crash reports, performance metrics): Deleted after 30 days by a daily automated task. These files can contain your Discord user ID and the ID of the server an error occurred on; access tokens, passwords, database credentials and e-mail addresses are masked automatically before anything is written. They hold no message content.
- Retention exceptions on account deletion (Art. 17(3)): the following survive a deletion request — moderation case evidence (
mod_cases, § 2.8) and user reports about your messages (server-safety accountability), the privacy audit log entry proving your deletion request (§ 2.7), reputation endorsements written by other users (their data), fully anonymised aggregate statistics with no link to your identity, and your bare Discord ID in the deletion opt-out list (§ 2.11).
6. Your Rights (GDPR)
Under GDPR, you have the following rights:
Right to Access (Art. 15)
Download a JSON copy of all data we hold about you via the /privacy command or the Privacy Dashboard (rate-limited to one export per 24 hours).
Right to Erasure (Art. 17)
Delete your account immediately and irrevocably via /privacy or the Privacy Dashboard (gdpr_delete_user_now()). No support ticket required. A small set of records is exempt under Art. 17(3) — see the retention exceptions in § 5.3.
Right to Rectification (Art. 16)
Most identity data is mirrored directly from Discord. For anything else, contact support.
Right to Portability (Art. 20)
The same self-service JSON export delivers a machine-readable archive you can move to another service.
Right to Object (Art. 21)
Object to legitimate-interest processing by turning off the Activity or Message Audit toggles in /privacy or the Privacy Dashboard (Presence is consent-based and can be withdrawn the same way). Moderation case evidence (§ 2.8) is retained on overriding server-safety grounds and is not affected by the toggles.
Right to Restriction (Art. 18)
Pause specific processing categories at any time using the granular toggles in /privacy or the Privacy Dashboard.
How to Exercise Your Rights
- Self-service (recommended): Run the
/privacyslash command in any server where Levlix is active, or open the Privacy Dashboard. Export, toggle changes and account deletion are available 24/7 without staff intervention. - Send an email to support [at] levlix [dot] io with your Discord User ID.
- Or contact us via our official Discord server and open a support ticket.
Self-service actions complete in real time. Email and ticket requests are answered within 30 days as required by GDPR. The exercise of your rights is free of charge.
7. Data Processors & Sharing
We share data only in these limited circumstances with our trusted providers (Sub-processors). All non-EU/EEA transfers are protected by Standard Contractual Clauses (SCCs) per § 9.
| Sub-processor | Purpose & Data | Location | Legal basis |
|---|---|---|---|
| Discord (Discord Inc.) | Required for bot operation. Governed by Discord's Privacy Policy. | USA (SCCs) | Art. 6(1)(b) |
| Hetzner Online GmbH | Bot & database hosting (primary infrastructure). | Germany (EU) | Art. 6(1)(b) |
| Cloudflare, Inc. | DDoS protection, edge cache and TLS termination for the web frontend. Also provides cookieless Web Analytics (aggregated performance and visit metrics via beacon.min.js; no cookies, no cross-site tracking — see Section 2.4). |
Global edge (SCCs) | Art. 6(1)(f) |
| top.gg | Public bot-listing service. Levlix posts aggregate guild_count and shard_count. When a user votes for Levlix on top.gg, their discord_id and the vote timestamp are stored in our topgg_votes table to grant in-bot rewards. |
USA (SCCs) | Art. 6(1)(f) |
| Ko-fi (Ko-fi Labs Ltd.) | Voluntary donations page. Payment is handled entirely by Ko-fi and its processors (PayPal, Stripe). When a donation completes, Ko-fi notifies Levlix; we store the Ko-fi transaction id, amount, currency, timestamp and, only if the supporter linked their Discord account on Ko-fi, their discord_id in our kofi_donations table to grant the cosmetic Donator role. Supporter email, name and message are not stored. |
UK (adequacy decision) | Art. 6(1)(f) |
| Google Analytics 4 (Google Ireland Ltd.) | Property G-6G5G4X7N5P. Loaded only after explicit cookie consent. anonymize_ip: true is enforced; no user-level tracking occurs without consent. |
USA (SCCs) | Art. 6(1)(a) |
| Legal Requirements | Disclosure if compelled by binding law or valid legal process. | Switzerland / EU | Art. 6(1)(c) |
8. Contact & Complaints
For privacy-related questions or concerns:
- Email: support [at] levlix [dot] io
- Discord: Join our support server and open a ticket
Supervisory Authority
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. For Switzerland, the competent authority is:
- FDPIC (EDÖB)
- Federal Data Protection and Information Commissioner
- Feldeggweg 1, 3003 Bern, Switzerland
- www.edoeb.admin.ch
For EU residents, you may also contact your local data protection authority.
9. International Data Transfers
Your data is primarily stored in the European Union (Germany). However, some of our service providers (e.g., Cloudflare) may process data outside the EU/EEA. In such cases, data transfers are protected by:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable (Switzerland is recognized as providing adequate protection)
- Provider-specific DPAs (Data Processing Agreements) with all sub-processors
10. Children's Privacy (GDPR Art. 8)
Within the EU/EEA, GDPR Art. 8(1) sets the default age for independent consent to information-society services at 16, unless national law lowers that threshold. Member states have made use of this option, so the effective age limit varies (for example 14 in Austria and Italy, 16 in Germany and applied by analogy in Switzerland under the nDSG). Users below the locally applicable threshold require verifiable parental consent.
Levlix currently relies on Discord's Terms of Service compliance, which require users to be at least 13 years old, and does not implement automated age gating of its own. Server owners are responsible for ensuring that their audience meets the consent age that applies in their jurisdiction. If you believe a child below the applicable threshold has provided us with personal data without the required parental consent, please contact us at support [at] levlix [dot] io and we will promptly delete it.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you via:
- The Bot's announcement system
- Our official Discord server
- This webpage (with an updated "Last Updated" date)
Continued use of the Bot after changes constitutes acceptance of the updated Privacy Policy.
12. Automated Decision-Making
All game mechanics, point calculations and leaderboard rankings are transparent, rule-based systems with no AI-driven profiling. One exception exists: servers can enable the automated moderation system described in § 2.8, which can automatically apply server-level moderation actions (such as a timeout, kick or ban on that server) when a message triggers it, including an AI-assisted content filter running on locally hosted models. You always have the right to contest such an action and obtain human review — the server's moderators can review and revoke every automated case, and you can contact our support (§ 6). We do not use automated decision-making for any other purpose, and never for profiling across servers.