Last updated: October 7, 2026
Discortics handles personal data to provide and secure its Discord bot, dashboard and related services. This page explains how to exercise applicable GDPR rights. It is not a certification of compliance. Read our Privacy Policy for data categories, purposes, recipients and retention.
Your rights
Where applicable, you may request access to your personal data, correction of inaccurate data, erasure, restriction of processing, portability of eligible data, or object to processing based on legitimate interests. You can withdraw consent for processing that relies on consent without affecting earlier lawful processing. You may complain to your local supervisory authority; see the EDPB authority directory.
Submit a request
For account data removal, use /privacy, ;privacy, or sign in with Discord and open Dashboard → Privacy. The confirmation applies to your own account and does not need server-management permission. For other data protection rights, an unavailable deletion flow or a blocked request, email [email protected].
- Leave all servers using Discortics first; membership and new activity can create data again.
- Delete personal data from active Discortics databases and caches, including levels, stored messages, counters, feature records and Advanced verification data.
- Remove verified access across servers and prevent verification for three calendar months from confirmation.
- Remove Lifetime Premium and its custom bot access; transfer them first if you want to keep them.
- Cancel or transfer active subscriptions and other owned custom bots before confirmation can queue deletion.
- Preserve other users' data and server-owned content. Historical Discord-hosted messages, legally retained payment-provider records and rotating backups are outside this automated deletion.
The flow stores your Discord ID, request reference, timestamps and progress. Confirmation tokens are hashed and expire after five minutes. The dashboard reports queued, processing, blocked or completed; accepting the request does not claim deletion has finished. We may need proportionate additional information for other rights requests if identity or authority is uncertain.
Timing and outcome
For applicable GDPR requests, we respond without undue delay and within one month of receipt. Where permitted because of complexity or volume, we may extend by up to two further months and explain that extension within the first month. Requests are normally free. Any lawful refusal or fee will be explained, including available complaint or remedy options.
Confirmed account deletion runs through a durable cleanup job. Completion is recorded only after the required cleanup succeeds, including personal feature data, verification records and caches. Relevant server staff are notified of removed verification access. A blocked job remains incomplete and can require support. Contact us about data we control outside the automated scope, legally retained records or copies controlled independently by server administrators. We notify processors or recipients of required erasure where applicable; limited legal exceptions must be explained rather than treating all security records as exempt.
A minimal completion receipt and session-revocation record expire seven days after completion. A separate record containing your Discord ID and restriction expiry prevents verification for three months from confirmation. Backup copies remain subject to ordinary rotation; completed erasure decisions must be reapplied after a restore. New activity can create fresh records.
Advanced verification and human review
Advanced verification uses network information and browser/device fingerprinting to create protected matching records linked to your Discord ID across participating servers. These are pseudonymous personal data. Proofs are retained while you belong to at least one server with Advanced verification enabled, then for one year after the last participating membership ends. Membership events and periodic checks maintain the clock; returning to a participating server stops it. Before deletion, cleanup confirms there is no participating membership. Failed checks postpone deletion. Historical records without a confirmed departure start their inactivity period at the first conclusive absence check. An approved erasure request can require earlier deletion. Active retention and the one-year safety period still require documented necessity and proportionality; stating a duration does not establish compliance.
Internal verification decision summaries support troubleshooting and human review. They record outcome and reason categories, the source of the report, relevant account and server IDs, timestamps and attempt counts, and may identify a linked account and categories of checks involved. Access is restricted to authorized Discortics operators. These summaries expire 90 days after the latest occurrence of that reason for the account and server and are then removed by database TTL cleanup. Browser-reported failures are diagnostic reports, not evidence of wrongdoing. You can ask Discortics to review inaccurate records or exercise applicable data rights.
Network or browser/device matches may link accounts. Clearing cookies or using a private window may not prevent matching because device characteristics can still be observed; no identifier is guaranteed to persist or to be unique. Another linked account being present, banned or within a departure cooldown in the target server can block automatic verification. Network screening can also block verification. Shared networks, similar devices and browser changes can cause incorrect results. A match does not prove identity or wrongdoing; missing or unavailable checks leave verification incomplete. You may decline the check and remain unverified. Ask server staff for human review and a server-only whitelist, or contact Discortics about your data. Erasing a global proof removes that stored verification status and its matching observations; verification after the three-month restriction may create a new proof. A server-only whitelist does not create a global proof.
Fingerprinting is subject to applicable terminal-access/privacy rules as well as GDPR. The purpose, lawful basis, necessity, consent or exemption, global matching and alternatives require assessment; clicking Continue is not a general waiver. Cloudflare processes connection and challenge data separately from the application's hashed records.
Contact and accountability
Contact [email protected] for privacy matters. Discortics is responsible for its service and global verification processing; server administrators determine their own enabled features and admission policies. Controller/processor roles, processing records, legitimate-interest assessments, DPIA screening, provider agreements and international-transfer safeguards must reflect the actual deployment and processing. This page does not establish that those operational obligations have been completed.