Privacy policy
Version dated 26 July 2026, effective 26 July 2026.
This policy explains how Auto Threads processes personal data under the EU General Data Protection Regulation (“GDPR”) and the Swiss Federal Act on Data Protection (“FADP”).
Data controller
Auto Threads is managed personally by Christopher Calcoen, known by the pseudonym Arcoz, project manager and data controller. Auto Threads is not a company or another legal entity.
Contact for privacy questions and requests: privacy-auto-thread@arcoz.dev.
People and data concerned
Auto Threads may process data about administrators and members of Discord servers where the bot is installed:
- technical Discord server, channel, message, and thread identifiers;
- language, channel configuration, permissions, modes, and rename rules;
- display name and username, in memory only when Author Name mode creates a title;
- message content and the first HTTP(S) URL, in memory only when URL Title mode needs to find a link;
- execution outcome, limited error code, timestamps, and a contextual author HMAC used for rename authorization;
- usage counters aggregated by server and mode;
- legal-document acceptance evidence, Premium grants, and, later, minimal billing references;
- information voluntarily provided in a support or data-rights request.
Message content, URLs, fetched HTML, produced titles, images, and attachments are not stored in PostgreSQL and must not appear in logs or Sentry. Discord snowflakes are technical identifiers and are treated as personal data when they can be linked to an individual.
Purposes and legal grounds
- Providing and securing the service: configuring channels, creating and renaming threads, preventing duplicates, and managing beta Premium. Processing is necessary to perform the service requested by an administrator (GDPR Article 6(1)(b)) and for the legitimate interest in providing a reliable and secure bot (Article 6(1)(f)).
- Preventing abuse and diagnosing incidents: minimized technical logs, execution outcomes, and error codes, based on the legitimate interest in protecting the service and its users (Article 6(1)(f)).
- Measuring usage: aggregated statistics needed for capacity and limits, on the same legitimate-interest basis.
- Handling requests and complying with law: support, rights requests, security, and legal duties (Article 6(1)(c) and (f)).
Legitimate interests are balanced against members’ rights through minimization, pseudonymization, short retention, no advertising, and the right to object. Under the FADP, processing follows the principles of lawfulness, proportionality, transparency, security, and privacy by design.
URL mode
Auto Threads reads the first HTTP(S) URL in memory and contacts that site to retrieve its title. The site necessarily receives the Auto Threads server IP address and ordinary network information. No cookie, token, authorization header, Discord referer, or Discord identifier is sent. Private and reserved destinations are blocked. The domain is used as fallback when no title is available.
Artificial intelligence
No AI or image-processing mode has been implemented yet. This is the current state of development, not a beta-specific prohibition. No message is currently sent to Mistral. Launching such a mode, including during the beta, will require an up-to-date notice, visible member information, explicit administrator confirmation, an effective individual opt-out, and the necessary contractual checks. See the AI notice.
Recipients, hosting, and transfers
Access is limited to necessary providers and the project manager:
- Hostinger infrastructure selected in Frankfurt, Germany hosts Coolify, the bot, website, and PostgreSQL;
- Infomaniak Swiss Backup in Switzerland receives encrypted backups through S3-compatible storage;
- Proton AG — Proton Mail in Switzerland hosts the
@arcoz.devaddresses used for support, abuse reports, and rights requests; Proton processes sender and recipient addresses and technical email metadata, with encrypted storage that may be located in Switzerland, Germany, or Norway; - Discord receives events and publishes threads under its own terms;
- external sites opened by URL mode receive the minimal network data described above;
- Sentry, in its European region, receives filtered technical errors and logs plus operational and runtime metrics without raw Discord identifiers, after message content, URLs, prompts, images, attachments, tokens, and secrets are systematically removed.
Production data is primarily located in Germany. Backups are transferred to Switzerland, which the EU recognizes as providing adequate protection; Germany provides adequate protection for transfers from Switzerland. Appropriate data-processing agreements and security measures must govern these providers throughout their use. The current list appears on the Subprocessors page.
Retention
- execution records and author HMAC in the database: 30 days;
- encrypted PostgreSQL backups: 30 days, then automatically rotated;
- daily statistics: 13 months;
- aggregate totals, configuration, Premium grants, and legal evidence: while the bot remains installed;
- deleted channel configuration: 30-day recovery period;
- bot removal: immediate unavailability, followed by cascading deletion after 30 days;
- minimal Stripe events once billing is enabled: 90 days, excluding records subject to a separate legal duty;
- requests received through Proton Mail: for the time needed to handle them and defend legal claims, followed by deletion or limited archiving.
Production deletions propagate to backups as they rotate. A restored backup must immediately run the scheduled privacy purge.
Security
Measures include access control, encryption in transit, encrypted backups, service separation, HMAC pseudonymization, URL-destination validation, log minimization, and restore tests. No system can guarantee zero risk.
Where a breach is likely to create a risk, the controller documents it and gives the notices required to the competent authority and, where necessary, affected individuals.
Your rights
Depending on your circumstances, you may request access, correction, erasure, restriction, disclosure or portability, or object to processing based on legitimate interests. You may withdraw any future consent without retroactive effect. Auto Threads makes no decision with legal effect based solely on automated processing.
Write to privacy-auto-thread@arcoz.dev and identify the relevant server and information needed to locate the data. Proportionate identity evidence may be requested. A response is generally provided within one month under the GDPR and 30 days under the FADP.
You may also complain to the data protection authority for your residence, workplace, or the alleged infringement in the EEA, or to the Swiss Federal Data Protection and Information Commissioner in Switzerland.
Changes
Material changes receive a new version and date. Where required by law or the processing, administrators are notified and must confirm the new version before the relevant feature can be re-enabled.