Legal · reviewed 4 August 2026

Privacy, in operational terms.

Who is responsible

Pixelheads B.V., established in the Netherlands and trading as Guardy, operates Guardy and acts as an independent controller for the personal data it processes to provide, secure, bill for, and improve the service. A Discord server administrator separately decides why and how their community uses Guardy's guild settings.

Guardy operator identity and contact details
Registered namePixelheads B.V.
Trade nameGuardy
Physical addressDe Nieuwe Erven 3, 5431 NV Cuijk, Netherlands
KVK69959447
VAT IDNL858081301B01
Privacy contactsupport@guardybot.com

Current Phase 1 processing

Depending on configuration and use, Guardy processes:

  • Discord user, server, channel, role, and application identifiers;
  • usernames and avatars where needed for dashboard accounts, rank cards, or leaderboards;
  • XP, levels, message-award counts, eligible voice time, activity windows, rewards, and rank-card preferences;
  • import job metadata and staged user ID, XP, and source-level rows until an import is applied;
  • guild settings, bot lifecycle, command, security, rate-limit, and privacy-operation records;
  • Discord OAuth account data and encrypted access or refresh tokens for dashboard access; and
  • subscription, entitlement, invoice, and payment references. Guardy does not store payment-card details.

Phase 1 leveling observes eligible message events and voice states but does not request the Message Content privileged intent, store message text, or record voice audio.

Planned moderation and AI processing

Planned, not active in Phase 1.Phases 2–3 may process message content for configurable moderation, case records, join-gate checks, AI-assisted review, moderator decisions, and appeals. A model may suggest a concern; a human moderator remains responsible for the decision. Punishment notices and the review surface will disclose AI involvement and explain how to appeal. Guardy will not market or activate this processing before the engineering and launch privacy gates are complete.

Why data is processed

Processing supports the requested service, imports, leveling and rewards, privacy controls, subscriptions, security, abuse prevention, support, and legal duties. Depending on the activity, the legal basis may be contract performance, legitimate interests in operating and securing Guardy, legal obligation, or consent where applicable.

Data received during an import

A member normally does not provide imported leaderboard data directly to Guardy. A server administrator either asks Guardy to read that server's public MEE6 leaderboard or uploads an authorized export from MEE6, Lurkr, Polaris, AmariBot, or a CSV source. The imported categories are Discord user identifiers and XP; a supported source may also supply a source level or reward-role definitions for the administrator's separate review.

Guardy processes those records to perform the administrator-requested migration and preserve community progress. The intended basis is the controller's legitimate interest in providing a portable leveling service, balanced by source authorization, a preview before apply, member privacy controls, and objection and erasure routes. After a successful apply, Guardy posts one server notice naming the source and linking members to this policy, public-leaderboard opt-out, and deletion controls. This section supplies the controller, categories, source, purpose, basis, retention, rights, and contact information required when the data was obtained indirectly.

Retention schedule

Guardy data retention schedule
RecordFreePremiumNotes
Case and audit metadata30 daysUnlimited while the guild remains activeLegal, dispute, and abuse evidence may follow a separate lawful hold.
Message-content logs30 days90 daysPlanned for Phase 2; each guild can configure a shorter period.
Appeals180 days after resolutionPlanned for Phase 3.
join_gate_checks90 daysPlanned for Phase 2.
ai_verdictsContent redacted after review plus 90 daysNon-content metadata may remain for false-positive analytics.
Staged import rows awaiting reviewUp to 30 daysA staged job expires after the administrator's review window. Active reads transition to staged or failed first.
Failed import rowsUp to 7 daysShort recovery window for a failed read or apply.
Successfully applied import rowsDeleted immediatelyThe completed job keeps aggregate counts, not staged member rows.
Departed guild service dataAuto-purged 30 days after the bot leavesApplies to ordinary XP, configuration, role-state, and import data. Narrow billing, security/audit, deletion, lifecycle, or legal evidence follows its own disclosed lifecycle and is minimized or pseudonymized where possible.

Short-lived XP flush deduplication records are normally removed after 24 hours. Raw import files are discarded after parsing, and staged import rows are deleted once an apply succeeds. Billing or legally required records may follow statutory retention. Backups and in-flight queues may need a limited period to converge after deletion.

Service providers and transfers

Guardy uses the following provider set:

  • Discord for identity, commands, events, and community interactions;
  • Supabase for managed PostgreSQL services;
  • Railway for the bot service and Redis;
  • Laravel Forge on DigitalOcean (Amsterdam) for dashboard hosting;
  • Cloudflare for DNS, edge security, and caching;
  • Sentry for redacted error monitoring when enabled;
  • Stripe and/or Discord for paid-plan processing; and
  • OpenRouter and Anthropic, plus OpenAI if used, only for the planned AI processing described above.

Primary production data region: European Union (eu-west-1, Amsterdam). International-transfer safeguards: EU-only processing; no transfers outside the EEA. Guardy does not sell personal data or use it for third-party advertising.

Member rights and controls

Subject to applicable law, members may request access, correction, portability, restriction, objection, or erasure and may complain to a competent data-protection authority.

  • /privacy leaderboard off removes the member's name and avatar from public web leaderboards while preserving in-server rank.
  • /data-export provides the supported machine-readable export.
  • /data-delete current-server or /data-delete all-servers starts an erasure workflow.
  • Email support@guardybot.com for requests that self-service commands do not cover.

Security, children, and changes

Guardy uses encrypted transport, encrypted OAuth tokens, least-privilege access controls, rate limiting, default-deny database protections, secret redaction, and monitoring. Guardy is not intended for anyone below Discord's minimum age or the applicable digital age. Material policy changes will update the effective date and be communicated through an appropriate Guardy surface.