Privacy Policy
Last updated: 28 September 2026
1. Who we are
Ravenkeep (the Discord bot and this website, ravenkeep.gw2.com.ua) is operated by PE Pushnoi Roman Olexiyovych, a sole proprietor (фізична особа-підприємець, FOP) registered in Ukraine (“we”, “us”). For anything about your data, contact us at [email protected].
Discord IDs (numbers that identify users, servers, channels, roles and messages) are personal data when they identify a user. We store as little as the service needs, listed completely below.
2. Two roles
- Server content. A server's admins decide whether Ravenkeep logs their server and runs tickets there. For that content (log messages, ticket transcripts, form answers) we act on their behalf; the server's admins are responsible for having a reason to log and for telling their members. Log messages and transcripts are posted into the server's own Discord channels — they are stored by Discord and controlled by the server, not by us.
- Our own users and customers. For dashboard logins, Premium purchases and our technical records, we decide how data is used and are responsible for it.
3. What we store in our database
About servers
| Table | What it contains | Why | How long |
|---|---|---|---|
Guild (servers) | Server ID; when Ravenkeep was first added; when it was removed (if it was). | To know which servers use Ravenkeep and to schedule deletion after removal. | While Ravenkeep is in the server; deleted 30 days after Ravenkeep is removed from the server (kept as an empty ID only if the server has billing records). |
GuildEvent (join/leave history) | Server ID, “added” or “removed”, time. | Service statistics (how many servers join and leave). | Deleted 30 days after Ravenkeep is removed from the server. |
TicketConfig (ticket settings) | Server ID; IDs of the staff roles, ticket category and transcript channel; the last ticket number; timestamps. | To run the ticket system as the server's admins configured it. | While Ravenkeep is in the server. Deleted with /data delete, or 30 days after Ravenkeep is removed from the server. |
Panel (ticket panels) | Server, channel and message IDs; the title, description and colour written by the admins; the user ID of the admin who created it; whether the server had Premium when the message was last posted; timestamps. | To show the panel, and to update its message when Premium starts or ends. | While Ravenkeep is in the server. Deleted with /data delete, or 30 days after Ravenkeep is removed from the server. |
TicketType (ticket types on a panel) | Button text, emoji, button colour and form questions written by the admins; the ticket channel name prefix; the IDs of its category and extra staff roles; its order on the panel; timestamps. | To show each type's button or dropdown option and form, and to create its tickets in the right place for the right staff. | While Ravenkeep is in the server. Deleted with /data delete, or 30 days after Ravenkeep is removed from the server. |
RoleConfig (auto-roles) | Server ID; the IDs of the roles new members get; whether bots get them too; timestamps. | To give new members the roles the admins chose. | While Ravenkeep is in the server. Deleted with /data delete, or 30 days after Ravenkeep is removed from the server. |
RolePanel (role panels) | Server, channel and message IDs (for a reaction panel on an existing message: that message's IDs); whether it uses buttons or reactions; the title, description and colour written by the admins; how it works (toggle, only one, verify); the ID of the role needed to use it; the user ID of the admin who created it; whether the server had Premium when the message was last posted; timestamps. | To show the panel, and to update its message (or Ravenkeep's reactions) when Premium starts or ends. | While Ravenkeep is in the server. Deleted with /data delete, or 30 days after Ravenkeep is removed from the server. |
RolePanelOption (roles on a role panel) | The role ID; the button text, emoji, colour and dropdown description written by the admins; its order on the panel; timestamps. | To show each role's button, dropdown option or reaction and give members the role they pick. | While Ravenkeep is in the server. Deleted with /data delete, or 30 days after Ravenkeep is removed from the server. |
RoleReaction (who reacted on reaction role panels) | Server ID; which role of which reaction panel; the user ID of the member whose reaction Ravenkeep handled; when. | So Ravenkeep notices what changed while it was offline (e.g. during an update): a reaction removed in the meantime takes the role back, and a role a moderator removed isn't given back. Button panels store nothing about who clicked. | Until the member removes the reaction, leaves the server, the role's emoji or the panel changes, or the panel is deleted; also with /data delete, 30 days after Ravenkeep is removed from the server, or at a user's request. |
Greeting (welcome and leave messages) | Server ID; for the welcome message, welcome DM and leave message: whether it's on, its channel ID, and the text and embed written by the admins; the welcome card's design (background, its two lines of text, colours) and which uploaded picture is its own background; timestamps. | To greet new members and say goodbye as the admins set up. Nothing about the members who join or leave is stored — their name and avatar are used to draw their welcome card, which is sent to Discord and not kept. | While Ravenkeep is in the server. Deleted with /data delete, or 30 days after Ravenkeep is removed from the server. |
Ticket | Server ID; ticket number; the ticket type (ID and name); ticket channel ID; user IDs of the member who opened it, the staff member who claimed it and who closed it; status; open/close times; the close reason typed by staff; the member's answers to the panel's form questions (text). | To run tickets (who may see and close them, numbering, one open ticket per member) and to show the answers to staff. | Open tickets: while Ravenkeep is in the server. Closed tickets: deleted 12 months after they were closed (the transcript posted in the server stays in Discord). Also deleted with /data delete, or 30 days after Ravenkeep is removed from the server. |
LogConfig (log settings) | Server ID; log channel IDs; which event types are switched off; IDs of ignored channels and roles; why logging stopped (if it did); timestamps. | To post the server logs the admins chose. | While Ravenkeep is in the server. Deleted with /data delete, or 30 days after Ravenkeep is removed from the server. |
LogWebhook | Log channel ID; ID and secret token of the webhook Ravenkeep created in that channel. | To post log messages into the log channel. | While Ravenkeep is in the server. Deleted with /data delete, or 30 days after Ravenkeep is removed from the server. |
LoggedMessage (recent messages, for logs) | In servers with logging on, for each member message in a logged channel: server, channel, message and author IDs; the send and edit times; and, encrypted, the text, the author's name and avatar link, and attachment file names (not the files). | So edit and deletion logs can show what a message said and who wrote it, also after the bot restarts. Messages from bots and in ticket categories, ignored channels or log channels (and, with Premium, from ignored roles) are not stored. | 24 hours after the message was sent (30 days for servers with Premium), then deleted automatically; deleted straight away when the message is deleted; also with /data delete, 30 days after Ravenkeep is removed from the server, or at a user's request. Not included in backups. |
Message (saved messages) | Server ID; the name, text, embed (title, description, colour, author line, footer, picture links) and link buttons written by the admins; where it's posted (channel and message ID); which uploaded pictures are attached; whether to publish it to followers; the user ID of the admin who created it; timestamps. | To post the message and update it in place when the admins edit it. | While Ravenkeep is in the server. Deleted with /data delete, or 30 days after Ravenkeep is removed from the server. Also deleted when the admins delete the message (the copy already posted in Discord is removed too). |
MessageImage (uploaded pictures) | Server ID; the message it belongs to (or that it's the welcome card's own background); file type, size and dimensions; the user ID of the admin who uploaded it; upload time. The picture itself is a file on our server (not in the database), stored without hidden data such as camera details or GPS location (card backgrounds are also cropped to the card's size), and shown only to people who manage that server. | To attach the picture when the bot posts or updates the message, or to draw the server's welcome cards. | While Ravenkeep is in the server. Deleted with /data delete, or 30 days after Ravenkeep is removed from the server. Also deleted with its message, when it's replaced or removed, or 24 hours after upload if it was never saved in a message or as a card background. The copy Discord stores with a posted message is Discord's. |
About dashboard users and customers
| Table | What it contains | Why | How long |
|---|---|---|---|
WebSession (dashboard logins) | A SHA-256 hash of your login cookie (not the cookie itself); your Discord user ID, display name and avatar ID (updated when you change them on Discord); your Discord access token, encrypted (AES-256-GCM); when the login expires. | To keep you logged in and to ask Discord which servers you can manage. | Until you log out or the login expires (Discord logins last about 7 days); expired logins are deleted automatically. |
Subscription (Premium) | Server ID; Paddle subscription and customer IDs; status; monthly or yearly plan; price ID; end of the paid period; whether it's canceled; the Discord user ID of the buyer; timestamps. | To turn Premium on for the right server and to let only the buyer manage it. | As long as required by accounting and tax law (billing records are not removed by /data delete). |
PremiumInterest (“Notify me when Premium opens”) | Server ID; the Discord user ID of the admin who pressed “Notify me when Premium opens” on the dashboard; when. | To let the server know when Premium upgrades open. | Until Premium upgrades open and the server has been told; also deleted with /data delete, 30 days after Ravenkeep is removed from the server, or at a user's request. |
PaddleEvent (billing notifications) | Every notification Paddle sends us: its type, time and how we handled it, plus its full content — Paddle customer, address and transaction IDs, amounts, currency, country, and the payment method type with the last four card digits (never the full card number), and our custom data (server ID, buyer's Discord user ID). | Proof of what was paid and when; handling each notification only once; troubleshooting. | 3 years after it arrives, then deleted. (Paddle, the Merchant of Record, keeps the billing records themselves.) |
4. What we process but don't store
- Recent messages (text, author, attachment names and links) in servers with logging on, also kept in memory: at most 50 per channel, for up to 1 hours, lost whenever the bot restarts. An encrypted copy is stored for a limited time too — see LoggedMessage in section 3. Messages in ticket categories, ignored channels and log channels, and messages from bots, are not logged or stored.
- Member lists (names, roles, join dates, whether they still have to accept the server's rules) of servers with logging or auto-roles on, in memory: to show what changed in member logs, and to give auto-roles to members who joined while Ravenkeep was restarting or who accept the rules later.
- Discord's audit log, read to show which moderator did something.
- Ticket transcripts are built in memory when a ticket closes and sent to the server's transcript channel and to the member who opened the ticket. We keep no copy.
- Reactions on reaction role panels (who reacted with which emoji) are read from Discord to give or take the role, and when the bot starts, to catch up on what changed while it was offline (compared with RoleReaction in section 3). The IDs of the panel messages are kept in memory.
- Members who join or leave during a mass join (a mention or name each, at most 10per server, for up to a minute) so they can be welcomed in one message instead of flooding the channel. Welcome DMs are sent on the server's behalf with the text its admins wrote; we keep no copy.
- Welcome cards: to draw a new member's card, Ravenkeep downloads their avatar from Discord and uses their name and the server's member count. The card is drawn in memory, sent to Discord and not kept. On the dashboard, the preview is drawn the same way with your own name and avatar.
- Channel and role lists shown on the dashboard, cached in memory for about a minute.
- Messages between the website and the bot pass through Redis on our server and are not stored.
5. Technical records and backups
- Web server logs: IP address, time, page requested and browser, for security and troubleshooting. Kept 14 days.
- Application logs: events such as “added to server X” and error details, which can include server, channel and user IDs. Rotated automatically when they reach their size limit (typically a few weeks to a few months).
- Error alerts: error details (which can include IDs, never passwords or tokens) are sent to a private Discord channel only we can read.
- Database backups: a full copy of the database every day, stored on our server and in our Google Drive, each kept 14 days. Deleted data therefore disappears from backups within 14 days.
- Uploaded pictures (saved messages) are files in a private folder on our server, not part of the database backups; deleting them removes them straight away.
6. Cookies
We use only two cookies, both needed for logging in. No analytics, advertising or tracking cookies.
rk_session— keeps you logged in to the dashboard (until you log out or the login expires, about 7 days).rk_oauth_state— protects the “Log in with Discord” step against forgery (10 minutes).
When you open the Premium checkout, Paddle's checkout may set its own cookies (see Paddle's privacy policy). If you bought Premium for a server, that server's Premium page loads Paddle's script as soon as you open it and gives it your Paddle customer ID, so Paddle Retain (part of Paddle) can show you billing notices there, such as a failed payment.
7. Who else processes data
- Discord — the platform Ravenkeep runs on (Discord Privacy Policy).
- Paddle (Paddle.com Market Ltd) — our reseller and Merchant of Record for Premium. Paddle processes payments, invoices, taxes and refunds and collects your name, email, billing address and payment details itself; we never see your full card number (Paddle Privacy Policy).
- OVHcloud (OVH SAS) — hosts our server in France (EU).
- Cloudflare — protects and delivers this website; sees visitors' IP addresses and requests.
- Google — stores copies of our database backups (Google Drive).
Some of these providers may process data outside the EU/EEA and Ukraine; they use safeguards such as the EU Standard Contractual Clauses. We never sell personal data and never use it for advertising.
8. Legal bases (GDPR)
- Contract — providing Ravenkeep to the servers that use it and Premium to customers (Art. 6(1)(b)).
- Legitimate interests — security, preventing abuse, fixing errors, backups and service statistics; and, for server logs, the server's interest in moderating its community (Art. 6(1)(f)).
- Legal obligation — keeping billing records (Art. 6(1)(c)).
9. Deleting data
- Server admins (Manage Server) can delete all of their server's data at any time with
/data delete. Messages already posted in the server's channels stay there; the server can delete them in Discord. - When Ravenkeep is removed from a server, the server's data is kept for 30 days (in case it's added back) and then deleted automatically.
- Closed tickets are deleted 12 months after they were closed. The transcript posted in the server's transcript channel stays in Discord; the server can delete it there.
- Subscriptions are kept as long as accounting and tax law requires, even after the above. Paddle's billing notifications (PaddleEvent) are deleted 3 years after they arrive.
10. Your rights
Under the GDPR and Ukraine's Law “On Personal Data Protection” you can ask us to access, correct or delete your personal data, to restrict or object to its use, or to receive it in a portable format. Email [email protected] from any address and tell us your Discord user ID; we may ask you to confirm you control that Discord account (for example by sending us a direct message). We reply within 30 days. When you ask us to delete your data, we delete your logins and remove your user ID from ticket records and from ticket and role panels; we keep billing records only as the law requires.
Content posted in a server's channels (log messages, transcripts) belongs to that server — ask its admins or Discord to remove it. You can also complain to a data protection authority: in Ukraine, the Ukrainian Parliament Commissioner for Human Rights; in the EU, the authority of the country you live in.
11. Children
Ravenkeep is for people who meet Discord's minimum age in their country. We don't knowingly collect data from younger children.
12. Security
The website uses HTTPS only. Login cookies are stored as hashes, Discord tokens are encrypted, and the database and Redis only accept connections from our own server. Only the operator has access to the server and backups.
13. Changes
When this policy changes we update the date at the top. For significant changes we also announce them in our support server (join here).
See also the Terms of Service and the Refund Policy.