1. Controller
Antonio Schlömer, Berliner Straße 30, 26506 Norden, Germany. Email: [email protected].
2. Hosting, CDN and security
Disc-Tools is operated on server infrastructure hosted by Hetzner in Helsinki, Finland and delivered through Cloudflare as CDN, DNS/proxy and security provider. IP address, timestamp, requested URL, user agent, referrer and security events may be processed. To detect abuse and fraud attempts (e.g. VPN/proxy bypass), the IP address is sent to the security service proxycheck.io. Legal basis: Art. 6(1)(f) GDPR.
3. Server logs
Web server and API logs are used for troubleshooting, abuse prevention and security. They may include IP addresses, timestamps, HTTP method, path, status code and technical error messages, and are retained only as long as necessary.
4. Discord OAuth and Discord features
When you log in with Discord, we process Discord ID, username, display name, avatar, banner, public flags, guild/role data and a Discord OAuth access token in an httpOnly login cookie. This is used for login, profile pages, admin/team role checks and server-related features. Legal basis: Art. 6(1)(b) and Art. 6(1)(f) GDPR.
5. Discord bot and verification
Our Discord bot logs server joins and leaves by posting messages in a public log channel. This serves security and overview purposes. Additionally, the verification system stores the following data in a database:
– Discord user ID (user_id)
– SHA256 hash of your IP address (ip_hash – the raw IP is never stored)
– Verification timestamp (verified_at)
The IP is only hashed to detect potential alt accounts. The raw IP address is never stored at any point. Legal basis: Art. 6(1)(f) GDPR (security and abuse prevention).
6. Username history
Our Discord bot monitors username changes of server members. When a member changes their Discord username, the old and new usernames are stored together with a timestamp. This data is used to provide the Username History tool on our website, which allows anyone to look up previous usernames of a Discord user by their user ID. Legal basis: Art. 6(1)(f) GDPR (provision of a useful service feature).
7. Premium subscriptions and Stripe payments
When you purchase a Premium subscription or send a Premium gift, payment processing is handled entirely by Stripe. We do not see, store or process your credit card number, bank details or any other full payment instrument data. The following data is transmitted to Stripe and processed by them as a data processor:
- Discord user ID (as
client_reference_id) - Stripe customer ID (assigned by Stripe, stored in our database)
- Stripe subscription ID (assigned by Stripe, stored in our database)
- Payment amount and currency
- Email address (if provided to Stripe during checkout)
The following data is stored in our database for the duration of the subscription and up to 3 years after cancellation for tax and accounting purposes (Art. 6(1)(c) GDPR): Discord user ID, Stripe customer ID, Stripe subscription ID, subscription status (active), start date and expiry date. Stripe's privacy policy applies to all data processed by Stripe: https://stripe.com/privacy.
8. Spotify OAuth and music features
If team members connect Spotify, we store a Spotify refresh token to display currently playing tracks. Spotify track URLs and SoundCloud URLs may also be shown on public profiles. Connection is voluntary and can be deleted on request.
9. Cookies and local storage
- Login token (JWT): httpOnly, secure, SameSite=Strict, up to 7 days.
- Discord OAuth tokens (access + refresh): httpOnly, secure, SameSite=Lax, up to 7 days (required for OAuth redirect flow).
- Session ID: httpOnly, secure, SameSite=Strict, up to 7 days.
- Cookie consent and UI settings may be stored locally in your browser.
- Cloudflare may set technically necessary security cookies.
10. Analytics
We use self-hosted Umami Analytics at umami.Disc-Tools. We do not use Google Analytics. Umami helps measure usage and improve the service on the basis of legitimate interests, Art. 6(1)(f) GDPR.
11. Fonts and external content
Fonts are served locally by Disc-Tools; no Google Fonts are loaded from Google servers. Icons are loaded via Font Awesome/CDNJS. External embeds or services may involve Discord, Spotify, SoundCloud, Cloudflare and Umami.
12. Contact, partnership requests and admin features
For partnership requests we process Discord ID, username, avatar, server/project information, website, description and message content. Admin logs and moderation data are visible only to authorized administrators.
13. Your rights
Under the GDPR you have rights of access, rectification, erasure, restriction, portability and objection. You may also complain to a data protection authority. Requests: [email protected].
14. Deletion
You may request deletion of stored profile, OAuth, Spotify, partnership, username history and verification data by email. Legal retention obligations and security interests may prevent immediate deletion of some log data. Premium payment data (Stripe customer/subscription IDs and transaction records) are retained for the statutory retention period (up to 10 years for tax purposes).
15. GIF uploads
When you upload a GIF to the GIF Upload feature, the following data is processed:
- Discord user ID – to associate the GIF with your account (Art. 6(1)(b) GDPR)
- GIF file – stored on our server (Hetzner, Helsinki) for display and sharing (Art. 6(1)(b) GDPR)
- GIF name, tags and NSFW flag – provided by you for categorization (Art. 6(1)(b) GDPR)
- File size, dimensions, upload timestamp – automatically collected technical metadata (Art. 6(1)(f) GDPR)
- View count – aggregated usage statistic (Art. 6(1)(f) GDPR)
- Moderation status, moderator ID and reason – only for moderated/blocked GIFs, visible to authorized administrators (Art. 6(1)(f) GDPR)
Date of birth – If you choose to view NSFW content, we ask for your date of birth to verify you are 18 or older. This is stored securely and used solely for age verification purposes. Legal basis: Art. 6(1)(c) GDPR (legal obligation to protect minors). You may request deletion of your date of birth at any time, which will result in NSFW content being hidden.
Storage duration: GIFs are stored until you delete them or until they are removed due to inactivity or a violation of our Terms of Service. Date of birth data is retained until you request its deletion.
Public visibility: Uploaded GIFs (including name, tags and NSFW status) are publicly visible on the website. Your Discord user ID is displayed as the uploader identifier.
Last updated: 12 July 2026
