This Privacy Policy describes how Majestic4991 ("the Bot," "we," "us," or "our") collects, uses, stores, and protects your personal data when you use our services. By using the Bot, you consent to the data practices described in this policy.
We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Children's Online Privacy Protection Act (COPPA).
Important: The Bot is not affiliated with, endorsed by, or in any way officially connected to Discord Inc. We are an independent third-party application developer.
1. Data Controller
The data controller responsible for your personal data is @braandn, who can be contacted via Discord or through the website at https://majestic.bot.
2. Age Restrictions
The use of the Bot is not permitted for minors under the age of 13, or under the age of 16 if you reside in the European Economic Area (EEA). This is in compliance with Discord's Terms of Service, COPPA, and GDPR requirements.
We do not knowingly collect personal information from children under these age thresholds. If we become aware that a user is underage, we will take immediate steps to delete all stored data associated with that user.
If you believe an underage user is using the Bot, please contact us immediately.
3. Data We Collect
The Bot collects and processes various types of data to provide its functionality. Below is a comprehensive overview:
| Data Category |
Description |
Purpose |
Opt-Out Available |
| Message Activity |
Message send events (not content), timestamps, channel IDs, and message edit/deletion events |
Leveling system and activity tracking |
No (core functionality) |
| Message Content |
Actual message text (only for edited/deleted messages) |
Logging in designated server logging channels (discord only) |
Configurable by server admin |
| Voice Activity |
Time spent in voice channels, channel IDs, join/leave timestamps |
Leveling system and analytics |
No (core functionality) |
| User Interactions |
Reactions given and received, button clicks, command usage |
Feature functionality and leveling |
No (core functionality) |
| Command Usage |
Commands issued, parameters, timestamps, user IDs |
Monitoring, analytics, and feature improvement |
No (core functionality) |
| Online Status |
User presence (online, idle, offline, DND) |
Activity analytics |
Yes (via server settings) |
| Game Activity |
Names of games/applications shown in your Discord presence, plus per-session start/stop times and total play time. Custom status text and rich-presence details are not collected. |
Game leaderboards and play-time analytics shown on the server dashboard |
Yes (server admins enable/disable the "Game & Music Analytics" module) |
| Music Activity |
Spotify listening data that Discord exposes in your presence (track title, artist, album, cover art, Spotify track ID/URL, track length) and the start/stop times of each listening session. We do not connect to your Spotify account or collect anything Discord does not already expose. |
Music leaderboards and listening-time analytics shown on the server dashboard |
Yes (server admins enable/disable the "Game & Music Analytics" module) |
| Invite Tracking |
Server invites created, used, and associated users |
Tracking server growth and invite attribution |
No (core functionality) |
| User Profile Data |
Discord user ID, username, discriminator, avatar |
User identification and display |
No (required for operation) |
| Server Data |
Server ID, name, settings, channel structure, roles |
Bot configuration and operation |
No (required for operation) |
Game & Music Analytics — Visibility and Control
- Single opt-in toggle: Game and music tracking are both governed by one server-level setting, the "Game & Music Analytics" module, which is disabled by default. A server administrator must explicitly enable it. Disabling it stops all new game and music collection for that server and closes any in-progress sessions.
- Who can view it: Aggregated game and music leaderboards (top games and tracks, with play/listening time and counts) are shown on that server's dashboard to members of the server. Per-member game and music detail is restricted to authenticated server members and is never exposed publicly.
- What is excluded: We deliberately do not record custom status text, rich-presence button URLs, free-text "watching/listening" strings, or any presence data Discord does not expose. Sessions shorter than 60 seconds are discarded as presence noise.
- Third-party game art: To display game cover art, the game's public name may be sent to SteamGridDB to look up matching artwork. No user identifiers are sent — only the game name. See Section 7.
4. Legal Basis for Processing
We process your personal data based on the following legal grounds under GDPR:
- Legitimate Interest (Article 6(1)(f) GDPR): Processing is necessary for the operation and improvement of the Bot's core functionality, including providing leveling systems, analytics, and event logging.
- Consent (Article 6(1)(a) GDPR): For optional features such as game and music activity tracking and online status monitoring, which a server administrator can enable or disable through server settings.
- Contractual Necessity (Article 6(1)(b) GDPR): Processing necessary to fulfill our obligations under the Terms of Service when you choose to use the Bot.
5. How We Use Your Data
Your data is used exclusively for the following purposes:
- Providing and maintaining the Bot's core functionality (leveling, analytics, logging)
- Generating server and user statistics
- Improving and optimizing the Bot's performance and features
- Troubleshooting technical issues and debugging
- Detecting and preventing abuse or violations of our Terms of Service
- Complying with legal obligations and responding to lawful requests
We do NOT:
- Sell, rent, or trade your personal data to third parties
- Use your data for advertising or marketing purposes
- Share your data with third parties except as required by law or as necessary to provide the service (e.g., hosting providers)
6. Data Storage and Retention
Active Data Storage
- User Data: Personal data associated with active server members is retained as long as you remain in a server where the Bot is present and the relevant tracking features are enabled.
- Historical Data: Activity logs, statistics, and leveling data are retained for analytical purposes while you remain an active user.
Game & Music Analytics Retention
- Raw sessions: Individual game and music listening session records (start/stop times and durations) are retained for 90 days, then automatically deleted.
- Daily aggregates: Per-day, per-user summaries used to build the dashboard leaderboards are retained for 365 days, then automatically deleted.
- Deletion also follows the per-server and per-user triggers below, and disabling the "Game & Music Analytics" module stops further collection immediately.
Data Deletion Triggers
- User Leaves Server: When you leave a Discord server, all your personal data associated with that specific server is automatically deleted within 24 hours.
- Bot Removal: When the Bot is removed from a server, all associated server data and user statistics are retained for 7 days to allow for potential re-addition, after which all data is permanently and automatically deleted.
- User Request: You may request immediate deletion of your data at any time (see Section 8 - Your Rights).
- Account Deletion: If your Discord account is deleted, we will delete all associated data within 30 days.
Backup Systems
Data may persist in backup systems for up to 30 days after deletion from production systems. However, backup data is not actively used for any processing and is maintained solely for disaster recovery purposes. Once backups are rotated out according to our schedule, the data is permanently deleted.
7. Data Sharing and Third Parties
We may share your data only in the following limited circumstances:
- Service Providers: We use trusted third-party service providers (such as hosting providers) to help us operate the Bot. These providers have access to your data only to perform specific tasks on our behalf and are obligated to protect your data and not use it for any other purpose.
- SteamGridDB (game artwork): When the "Game & Music Analytics" module is enabled, the public name of a played game may be sent to SteamGridDB solely to retrieve matching cover/grid artwork for the dashboard. No user, server, or other personal identifiers are sent — only the game name.
- Legal Requirements: We may disclose your data if required to do so by law or in response to valid requests by public authorities (e.g., court orders, subpoenas, law enforcement requests).
- Protection of Rights: We may disclose data when we believe it is necessary to protect our rights, property, or safety, or the rights, property, or safety of others.
- Business Transfers: If we are involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you via a prominent notice on our website or through the Bot before your data is transferred and becomes subject to a different privacy policy.
We do NOT share your data with:
- Advertisers or marketing companies
- Data brokers or analytics companies for their own purposes
- Any third party for purposes unrelated to the Bot's operation
8. Your Rights Under Data Protection Laws
Under GDPR, CCPA, and other applicable data protection laws, you have the following rights regarding your personal data:
Right of Access
You have the right to request a copy of all personal data we hold about you. We will provide this in a structured, commonly used, and machine-readable format (typically JSON).
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data.
Right to Erasure ("Right to be Forgotten")
You have the right to request deletion of your personal data under certain circumstances, including:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw your consent (for consent-based processing)
- You object to processing based on legitimate interests
- The data has been unlawfully processed
Right to Restriction of Processing
You have the right to request that we restrict processing of your personal data under certain circumstances.
Right to Data Portability
You have the right to receive your personal data in a portable format and to transmit it to another controller.
Right to Object
You have the right to object to processing based on legitimate interests. Optional tracking features — game activity, music activity, and online status — can be turned off by a server administrator through server settings (the "Game & Music Analytics" module governs both game and music tracking).
Right to Withdraw Consent
For processing based on consent, you have the right to withdraw your consent at any time by disabling features in server settings or removing the Bot from your server.
Right to Lodge a Complaint
You have the right to lodge a complaint with your local data protection authority if you believe we have violated your data protection rights.
How to Exercise Your Rights:
To exercise any of these rights, please contact us via Discord at @braandn. We will respond to your request within 30 days (or as required by applicable law). You may need to verify your identity before we can fulfill your request.
Data Access/Deletion Request Process:
- Contact us on Discord with your request
- Provide your Discord User ID for verification
- Specify which rights you wish to exercise (access, deletion, etc.)
- We will process your request and respond within 30 days
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption: Data is encrypted in transit using TLS/SSL protocols and at rest using industry-standard encryption methods
- Access Controls: Strict access controls ensure that only authorized personnel can access personal data
- Regular Security Audits: We regularly review and update our security practices
- Secure Infrastructure: Our servers and infrastructure are hosted with reputable providers that maintain high security standards
- Monitoring: We actively monitor for security threats and suspicious activity
However, please note that no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security.
10. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from the laws of your jurisdiction.
When we transfer data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses approved by the European Commission
- Ensuring the recipient country has an adequacy decision from the European Commission
- Other legally approved transfer mechanisms
11. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You have the right to request information about the categories and specific pieces of personal data we have collected about you in the past 12 months
- Right to Delete: You have the right to request deletion of your personal data
- Right to Opt-Out: You have the right to opt-out of the "sale" of your personal data. Note: We do NOT sell personal data.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights
To exercise these rights, please contact us using the contact information provided in Section 14.
12. Website Data Collection
When you visit our website at https://majestic.bot, we collect the following data:
Cookies
- Essential Cookies: We use only strictly necessary cookies to operate the website. These cookies cannot be disabled as the site cannot function without them. We do not use any tracking, analytics, or advertising cookies.
- Cookie Information:
- Authentication cookies - store your login state after Discord OAuth; automatically refresh after 14 days or are removed immediately when you log out
- OAuth callback cookies - used temporarily during Discord authentication to prevent request forgery; discarded after login completes
- Cloudflare Authorization (
CF_Authorization) - set by Cloudflare Zero Trust to verify access; strictly necessary for site security
- Referral cookie (
__Host-ref_code) - optional; set only when you visit a referral link (/referral?code=…) while not logged in, so your referral credit is preserved across the login flow. Automatically deleted once the code is applied to your account, or immediately if you click "Decline" on the cookie banner. Never set without a referral link visit.
Log Data
Our web servers automatically collect standard log data, including:
- IP addresses
- Browser type and version
- Pages visited and time spent
- Referring URLs
This data is used solely for security purposes, troubleshooting, and improving the website experience. It is retained for a maximum of 90 days.
13. Changes to This Privacy Policy
- Right to Modify: We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.
- Notice of Changes: When we make material changes, we will notify you by:
- Posting a prominent notice on our website
- Updating the "Last Updated" date at the top of this policy
- Providing at least 30 days' notice for material changes affecting your rights
- Continued Use: Your continued use of the Bot after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
- Review Responsibility: We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.
14. Contact Information and Data Protection Officer
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
For Data Subject Requests (Access, Deletion, etc.):
Please include the following information in your request:
- Your Discord User ID
- The nature of your request (access, deletion, rectification, etc.)
- Any relevant server IDs (if applicable)
- Verification of your identity
15. Compliance Summary
This Privacy Policy complies with:
- General Data Protection Regulation (GDPR) - EU Regulation 2016/679
- California Consumer Privacy Act (CCPA)
- Children's Online Privacy Protection Act (COPPA)
- Discord Developer Terms of Service and Developer Policy
- Discord Terms of Service and Privacy Policy
By using Majestic4991, you acknowledge that you have read, understood, and agree to this Privacy Policy and consent to the collection, use, and processing of your personal data as described herein.