Privacy Policy
Last updated 14 August 2026
ControlDeck handles Discord account data and the answers people give in applications. This page explains exactly what is stored, why, who it is shared with and how to get it removed.
Who is responsible
ControlDeck is operated by Georgi Mushatov, an individual established in Bulgaria. For the data described below, that operator is the data controller under the EU General Data Protection Regulation (GDPR).
One important distinction: when you run ControlDeck on your own Discord server, you decide what questions to ask applicants and who on your staff can read the answers. For that application content you act as the controller and ControlDeck acts as a processor on your behalf.
Contact: [email protected] or our Discord support server. Please use email for data-protection requests so there is a written record.
What we collect from Discord
Signing in uses Discord OAuth. We request only these scopes: identify, guilds and guilds.members.read. We do not request your email address, and we never receive your Discord password.
- Your Discord user ID, username and avatar.
- The list of Discord servers you belong to, and your roles within them, so we can show only the servers you may manage.
- An access token and refresh token, stored so the dashboard can act on your behalf while you are signed in.
What we collect when the service is used
- Applications: the answers submitted to a form, along with the applicant’s Discord ID and username.
- Review activity: reviewer votes, staff notes and tags attached to an application.
- Restrictions: bans and cooldowns a server’s staff apply to a user, including any reason given.
- Audit log: staff actions recorded with the acting user, the target of the action and the IP address the action came from.
- Server metadata: the Discord server name, icon and owner, so the dashboard can display it.
The audit log deliberately records IP addresses. It exists so a server owner can see who on their staff took a moderation action, which is only meaningful if entries can be attributed reliably.
Why we may process this data
- To provide the service you asked for — processing necessary to perform our agreement with you (Art. 6(1)(b) GDPR).
- To keep the service secure and accountable, including the audit log, rate limiting and abuse prevention — our legitimate interests (Art. 6(1)(f) GDPR).
- To diagnose faults through error reports — our legitimate interests in a working service (Art. 6(1)(f) GDPR).
We do not use your data for advertising, profiling or automated decision-making, and we do not sell it.
Who else can see it
Application answers are visible to the staff of the Discord server the application was submitted to, according to the roles that server has configured. Beyond that, data reaches only these service providers:
- AMPHosting — hosting for the servers and database that run ControlDeck.
- Cloudflare — sits in front of the site for TLS termination, caching and abuse protection, and therefore processes connection metadata such as IP addresses.
- Sentry — receives automatic error reports when something breaks, which can incidentally include identifiers present in the failing request.
We may also disclose data where we are legally required to, or to establish or defend legal claims.
How long it is kept
We want to be accurate rather than reassuring here: ControlDeck currently has no automatic deletion schedule. Applications, review activity, restrictions and audit-log entries are retained until they are deleted by the staff of the server they belong to, or until you ask us to remove them.
Sign-in tokens are kept while your session is active and are replaced when refreshed. Removing the ControlDeck bot from a Discord server stops any further collection for that server, but does not by itself erase data already stored — email us if you want it deleted.
Your rights
Under the GDPR you may ask us to:
- Confirm what personal data we hold about you and give you a copy.
- Correct data that is inaccurate or incomplete.
- Delete your data, where we have no overriding reason to keep it.
- Restrict or object to how we process it.
- Provide it in a portable, machine-readable format.
Email [email protected] and we will respond within one month. If you believe we have handled your data improperly, you may complain to the Bulgarian Commission for Personal Data Protection (cpdp.bg) or to the supervisory authority where you live.
One practical note: if your data sits in a Discord server run by someone else, that server’s staff control it. We will help, but we may need to direct your request to them.
Security
Traffic is encrypted with HTTPS, dashboard access is restricted by Discord role, and staff actions are logged. No service can promise perfect security, and we do not claim to — but if a breach affects your personal data and is likely to put you at risk, we will notify you and the relevant authority as the GDPR requires.
Children
ControlDeck is not directed at children. Discord’s own Terms of Service require users to meet a minimum age in their country (13 in most places, higher in some). If you believe a child has given us personal data, contact us and we will remove it.
Changes to this policy
If this policy changes we will update the date at the top of the page. Where a change materially affects how your data is handled, we will give notice in the dashboard or the support server before it takes effect.