Legal
Privacy policy
Last updated 2 October 2026
Requiem is a web dashboard for a Discord bot. This policy explains what the dashboard does with your information, in plain language. It has two parts: what happens when you browse the public pages, and what happens when you log in.
1. Who is responsible
The dashboard at requiem.devvista.org is operated by ARCH. ARCH is the controller for the information described here.
The software itself is open source and separately licensed; this policy covers the hosted service, not the source code.
2. What is collected
When you log in with Discord
- Discord identity — your user ID, username, display name and avatar URL, as returned by Discord's OAuth flow.
- Server list — the servers you are a member of, and your permissions in them. This is used for one purpose: deciding which servers you are allowed to manage.
- Session data — a signed session cookie that keeps you logged in.
When you save a setting
- Server configuration — the values you change: prefixes, locale, moderator and administrator roles, ignored channels, disabled commands, aliases, custom command responses, and similar settings. These are stored in the bot's configuration database on the server that runs the bot, and belong to the operator of that bot.
- Your Discord user ID — recorded alongside the change so that it can be attributed and audited.
Automatically
- IP address and user agent — recorded by the web server for security and abuse prevention, including a blacklist of addresses that have attacked the service.
- Request logs — the webserver logs requests in the ordinary course of operation.
3. What is never collected
The dashboard does not collect any of the following:
- Message content from Discord, in public channels, private channels or direct messages.
- Your Discord password, email address, phone number or payment details. Authentication happens on Discord's own domain and the dashboard never sees your credentials.
- Advertising identifiers, analytics profiles, or behavioural tracking of any kind. There is no third-party analytics script on any page.
- Biometric or special-category data.
4. Cookies
Cookies are used for two things, and nothing else:
- Session — strictly necessary. Without it you cannot stay logged in. It is cleared when you log out.
- Display preferences — optional. The dashboard remembers a colour, a background theme and a sidenav theme in cookies so the site looks the same next time. They contain no identifier and you can delete them at any time without losing access.
There are no advertising or cross-site tracking cookies, so there is no consent banner, because there is nothing to consent to.
5. Why it is processed
- To provide the service — authenticating you and applying the settings you save.
- Legitimate interests — keeping the service secure, preventing abuse, and understanding whether it is working.
- Legal obligation — where the law requires retention, for example in response to a valid legal request.
6. Who it is shared with
Your information is not sold, and it is not shared for advertising. It is disclosed only in these cases:
- The operator of the bot you are configuring — the settings you change apply to their bot, and they can see their own configuration.
- Discord — as the platform the bot runs on, independently of the dashboard.
- Infrastructure providers — the hosting and network providers that run the service, acting on the operator's instructions.
- Legal requirements — where disclosure is required by law, or necessary to defend legal claims.
7. How long it is kept
- Server configuration is kept for as long as the bot remains in that server, and is deleted with it.
- Session data is kept until you log out or the session expires.
- Access logs are kept for a short period sufficient for security investigation, then discarded.
- Blacklist entries are kept for as long as needed to keep the service available.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your information, and to receive it in a portable form. You also have the right to complain to your local data protection authority.
To exercise any of these, ask in the support server below. Requests are answered within the period the applicable law allows.
If you want your server's configuration removed, removing the bot from the server removes it. If you want your Discord identity forgotten, log out — the dashboard keeps no separate account record beyond the active session.
9. Security
Traffic is served over HTTPS, authentication is delegated to Discord's OAuth flow, and secrets are held in the bot's configuration rather than in the templates. Access to the configuration is limited to the bot's owners. No system is perfect; if you believe you have found a vulnerability, please report it privately in the support server rather than publicly.
10. Children
The service is not directed at anyone below the minimum age for using Discord in their country, and no information is knowingly collected from them.
11. Changes
When this policy changes, the date at the top changes too, and significant changes are announced in the support server. Continuing to use the dashboard after a change means you accept the updated policy.
12. Contact
Support server: https://discord.gg/EDcEdV6svr.