Privacy Policy
Last updated: 09/01/2026, Version 1.1
This policy covers only the additional data processing carried out by the Discord bot and web dashboard A.S.T.R.A. (Astrometica Support, Tools & Resources Assistant). For your use of Discord itself, Discord's own Privacy Policy also applies.
1. Data Controller
The operator and data controller for A.S.T.R.A.'s data processing is leech (Astrometica Community Manager, as also credited in the dashboard footer).
Contact: [email protected]
For questions about this policy or to exercise your rights (see Section 6), please contact us by email at the address above. Please include your Discord user ID or username in your message - without it, we can't look up what's stored under your account.
2. What Data Is Processed, Why, and For How Long?
Message content across the server. To detect spam/compromised accounts (honeypot system), handle ban appeals, and still show what a deleted message originally said in the Audit Log, A.S.T.R.A. reads and temporarily caches the content of messages sent anywhere on the server, not just in specific channels. The internal cache for deleted/edited messages is automatically deleted after 90 days. Ban appeal conversations are kept for as long as necessary to keep the decision traceable.
Form submissions (Bug Reports, Feedback, Suggestions). When you report a bug, submit feedback, or suggest an idea through A.S.T.R.A., either via Discord or the web dashboard, we store the submitted text and any attachments. Approved submissions may be publicly visible on the dashboard; unapproved submissions and internal evidence images for warnings are only accessible to the mod team. Currently retained indefinitely unless manually deleted.
Moderation data. For warnings, bans, timeouts, or kicks, we store the affected account, the acting mod, the reason, the timestamp, and any evidence images, to document moderation history, process appeals, and identify repeated violations. Currently retained indefinitely unless manually deleted.
Server member data. To run the Audit Log, automatic role assignment, and mass-join detection, A.S.T.R.A. regularly reconciles the member list, role memberships, and profile changes. Audit Log entries are retained indefinitely.
Dashboard login sessions. Logging in via Discord creates a session tied to your Discord identity so you stay logged in. This expires automatically and is then deleted. The access token used during login is not stored persistently.
Creator registration. If you register as a content creator, we store your linked Twitch login or YouTube channel ID (only connections actually verified through Discord) and your chosen card design. Publicly visible on the dashboard, stored until you remove it yourself via a Discord command.
Stream history and Steam player counts. We query Twitch, YouTube, and Steam for publicly available livestream status and player counts. Stream statistics are kept indefinitely; Steam player counts only for about 24 hours.
Message translator. When a moderator right-clicks a single message and selects "Translate," only that message's text is sent to DeepL for translation - not entire conversations, and not automatically. This feature is mod-only. It adds no storage of its own: the translation itself is never stored, and the original message follows the same 90-day cache described above regardless of whether it gets translated. This feature uses DeepL's free API tier ("DeepL API Developer") - under DeepL's own terms for this tier, DeepL reserves the right to store submitted content and its translation indefinitely, and use of this tier for personal data is contractually excluded on DeepL's side. See DeepL's Terms and Conditions, Sections 3.3.2 and 8.3.11.
Honeypot image scanning (VirusTotal). When someone posts an image attachment in the honeypot channel, A.S.T.R.A. first checks the file's hash against VirusTotal - only the hash is sent at this step. If VirusTotal doesn't already know that hash, the image file itself is uploaded along with its filename for scanning. This applies only to honeypot attachments; evidence images from /warn and ordinary bug report attachments are never sent to VirusTotal. What VirusTotal does with an uploaded file afterward is VirusTotal's own processing - see their Terms of Service and Privacy Policy.
3. Recipients and Third-Party Transfers
| Service | What's Transmitted | Purpose |
|---|---|---|
| VirusTotal | File hash always; full image file and filename only if the hash is unknown to VirusTotal (honeypot attachments only) | Malware scanning |
| DeepL | Text of a single message a moderator selects for translation | On-demand translation |
| Twitch API, YouTube API | Creator identifier or channel ID | Live status lookup |
| Steam API | No personal data (app ID only) | Player count display |
| Discord (OAuth) | Requested permissions, received profile data | Login and account linking |
No further sharing beyond this takes place.
Hosting infrastructure. A.S.T.R.A. runs on Discloud. According to Discloud's own Terms of Service and Privacy Policy, they do not access data stored inside hosted applications except where necessary for platform security/stability or to meet legal obligations. Discloud's terms are governed by U.S. (Florida) law; no EU-specific data processing agreement is stated in their published terms.
4. Legal Basis for Processing
Processing is based on legitimate interests (Art. 6(1)(f) GDPR) - moderation functions, protection against spam/abuse, and operating the features you actively use. Where you actively use a feature (e.g. registering as a creator or submitting something), processing also serves to provide that specific service (Art. 6(1)(b) GDPR).
5. Retention Periods at a Glance
- Message cache (Audit Log): 90 days, automatic
- Login sessions: until expiry, automatic
- Steam player counts: ~24 hours, automatic
- OAuth access tokens: not stored
- Bug reports, feedback, suggestions: indefinite, until manually deleted
- Moderation data, Audit Log entries: indefinite, until manually deleted
- Creator registration: until self-removed
- Stream statistics: indefinite
6. Your Rights
You have the right to access, rectify, and erase your data (unless a legal retention obligation prevents this), restrict processing, object to processing based on legitimate interest, and lodge a complaint with a data protection supervisory authority. To exercise these rights, contact the email above - please include your Discord user ID or username so we can find your data. For some registrations (e.g. creator status), you can also remove your own data directly via the corresponding Discord command.
7. Changes to This Policy
This policy may be updated as A.S.T.R.A.'s data processing changes. The current version with its date is shown at the top of this page.