Legal · reviewed 4 August 2026
Privacy, in operational terms.
Privacy policy effective .
Who is responsible
Pixelheads B.V., established in the Netherlands and trading as Guardy, operates Guardy and acts as an independent controller for the personal data it processes to provide, secure, bill for, and improve the service. A Discord server administrator separately decides why and how their community uses Guardy's guild settings.
| Registered name | Pixelheads B.V. |
|---|---|
| Trade name | Guardy |
| Physical address | De Nieuwe Erven 3, 5431 NV Cuijk, Netherlands |
| KVK | 69959447 |
| VAT ID | NL858081301B01 |
| Privacy contact | support@guardybot.com |
Current Phase 1 processing
Depending on configuration and use, Guardy processes:
- Discord user, server, channel, role, and application identifiers;
- usernames and avatars where needed for dashboard accounts, rank cards, or leaderboards;
- XP, levels, message-award counts, eligible voice time, activity windows, rewards, and rank-card preferences;
- import job metadata and staged user ID, XP, and source-level rows until an import is applied;
- guild settings, bot lifecycle, command, security, rate-limit, and privacy-operation records;
- Discord OAuth account data and encrypted access or refresh tokens for dashboard access; and
- subscription, entitlement, invoice, and payment references. Guardy does not store payment-card details.
Phase 1 leveling observes eligible message events and voice states but does not request the Message Content privileged intent, store message text, or record voice audio.
Planned moderation and AI processing
Why data is processed
Processing supports the requested service, imports, leveling and rewards, privacy controls, subscriptions, security, abuse prevention, support, and legal duties. Depending on the activity, the legal basis may be contract performance, legitimate interests in operating and securing Guardy, legal obligation, or consent where applicable.
Data received during an import
A member normally does not provide imported leaderboard data directly to Guardy. A server administrator either asks Guardy to read that server's public MEE6 leaderboard or uploads an authorized export from MEE6, Lurkr, Polaris, AmariBot, or a CSV source. The imported categories are Discord user identifiers and XP; a supported source may also supply a source level or reward-role definitions for the administrator's separate review.
Guardy processes those records to perform the administrator-requested migration and preserve community progress. The intended basis is the controller's legitimate interest in providing a portable leveling service, balanced by source authorization, a preview before apply, member privacy controls, and objection and erasure routes. After a successful apply, Guardy posts one server notice naming the source and linking members to this policy, public-leaderboard opt-out, and deletion controls. This section supplies the controller, categories, source, purpose, basis, retention, rights, and contact information required when the data was obtained indirectly.
Retention schedule
| Record | Free | Premium | Notes |
|---|---|---|---|
| Case and audit metadata | 30 days | Unlimited while the guild remains active | Legal, dispute, and abuse evidence may follow a separate lawful hold. |
| Message-content logs | 30 days | 90 days | Planned for Phase 2; each guild can configure a shorter period. |
| Appeals | 180 days after resolution | Planned for Phase 3. | |
join_gate_checks | 90 days | Planned for Phase 2. | |
ai_verdicts | Content redacted after review plus 90 days | Non-content metadata may remain for false-positive analytics. | |
| Staged import rows awaiting review | Up to 30 days | A staged job expires after the administrator's review window. Active reads transition to staged or failed first. | |
| Failed import rows | Up to 7 days | Short recovery window for a failed read or apply. | |
| Successfully applied import rows | Deleted immediately | The completed job keeps aggregate counts, not staged member rows. | |
| Departed guild service data | Auto-purged 30 days after the bot leaves | Applies to ordinary XP, configuration, role-state, and import data. Narrow billing, security/audit, deletion, lifecycle, or legal evidence follows its own disclosed lifecycle and is minimized or pseudonymized where possible. | |
Short-lived XP flush deduplication records are normally removed after 24 hours. Raw import files are discarded after parsing, and staged import rows are deleted once an apply succeeds. Billing or legally required records may follow statutory retention. Backups and in-flight queues may need a limited period to converge after deletion.
Service providers and transfers
Guardy uses the following provider set:
- Discord for identity, commands, events, and community interactions;
- Supabase for managed PostgreSQL services;
- Railway for the bot service and Redis;
- Laravel Forge on DigitalOcean (Amsterdam) for dashboard hosting;
- Cloudflare for DNS, edge security, and caching;
- Sentry for redacted error monitoring when enabled;
- Stripe and/or Discord for paid-plan processing; and
- OpenRouter and Anthropic, plus OpenAI if used, only for the planned AI processing described above.
Primary production data region: European Union (eu-west-1, Amsterdam). International-transfer safeguards: EU-only processing; no transfers outside the EEA. Guardy does not sell personal data or use it for third-party advertising.
Member rights and controls
Subject to applicable law, members may request access, correction, portability, restriction, objection, or erasure and may complain to a competent data-protection authority.
/privacy leaderboard offremoves the member's name and avatar from public web leaderboards while preserving in-server rank./data-exportprovides the supported machine-readable export./data-delete current-serveror/data-delete all-serversstarts an erasure workflow.- Email support@guardybot.com for requests that self-service commands do not cover.
Security, children, and changes
Guardy uses encrypted transport, encrypted OAuth tokens, least-privilege access controls, rate limiting, default-deny database protections, secret redaction, and monitoring. Guardy is not intended for anyone below Discord's minimum age or the applicable digital age. Material policy changes will update the effective date and be communicated through an appropriate Guardy surface.