Privacy Policy

v3.1_02.08.26

Effective and last updated: 2 August 2026

This Policy reflects QREATE's current data flows, including Discord modules, direct messages forwarded to a staff channel, verification signals, AI providers, telemetry and support. It does not claim that data stays only in the EEA.

1. Scope and who is responsible

This Policy applies to qreate.cloud, the QREATE dashboard, Discord bot, verification pages, support, AI Crew, and related services (the “Service”). QREATE is operated by an individual operator established in the Netherlands. For QREATE account, website-security, product-analytics and support processing, QREATE is the controller. Contact: [email protected]. For data that a Discord server administrator chooses to process through enabled community-management modules, that administrator generally determines the purpose and settings and is the controller; QREATE generally acts as processor. QREATE remains controller for processing it determines for its own security, billing, legal compliance and service improvement. This allocation depends on the actual processing, not its label.

2. Data we process

Account and Discord data: Discord user ID, username/display name, avatar, email if Discord supplies it, preferred language, subscription/access status, and IDs, names, icons, member counts and your permission level for servers you can manage. Community and feature data: guild, channel, role, message and member IDs; module settings; commands and actions; XP, levels, reputation, rewards, votes and participation; moderation cases, warnings, notes and audit data; tickets, forms, introductions, suggestions, reminders and other content submitted to enabled modules; message content and before/after copies where a content-dependent automation, logging, moderation, DM-log, support or publishing feature requires it. QREATE does not indiscriminately archive every Discord message. Direct messages you send to the bot: where a guild has enabled DM forwarding, a message you send to QREATE is copied, with your Discord name and ID, into a staff channel of the guilds you share with the bot that have the feature on. Before this happens for the first time, QREATE sends you a notice naming those guilds and a control to refuse; refusing stops the forwarding of your direct messages to every guild and can be reversed by you at any time. If the notice cannot be delivered, nothing is forwarded. Verification and anti-abuse data: verification token/status/attempts, Discord user and guild IDs, timestamp, user agent, a derived IP hash, browser/device fingerprint, persistent verification cookie identifier, and VPN/proxy/Tor or fraud-risk result. When enabled by a guild, these signals may be compared with prior verified sessions in that guild and shown to its moderators. AI and support data: AI Crew prompts, responses, conversation history, optional screenshots/files, limited server configuration/context, saved memories, support email, subject and messages. Do not submit secrets or sensitive personal data that are unnecessary for the request. Uploaded assets: files uploaded to QAssets (currently PNG, JPEG, WebP, GIF, SVG and PDF, up to 15 MB), plus the file name, description, MIME type, size, tags, folder, owner user ID and guild ID. The file object is stored in Cloudflare R2. QAssets deliberately creates a stable public URL under assets.qreate.cloud so the file can be displayed in Discord embeds and other integrations. Anyone who obtains that URL may be able to view the file; do not upload confidential or access-restricted material. SVG files are sanitised and forced to download when opened directly, but that is not a confidentiality control. Technical and telemetry data: IP address available in request/security logs, user agent, session/security events, page or feature actions, command usage, latency, status/error information and identifiers needed to diagnose abuse and reliability. We do not sell personal data or use it for behavioural advertising.

3. Purposes and legal bases

We process data to authenticate users, provide requested bot/dashboard features and maintain accounts (GDPR Art. 6(1)(b)); follow a guild controller's documented instructions (Art. 28); secure the Service, prevent abuse, measure reliability, support users and improve features (Art. 6(1)(f), after balancing the relevant interests); comply with law and valid legal process (Art. 6(1)(c)); and, where required, act on consent (Art. 6(1)(a)). Guild administrators must provide their members with appropriate notice and a valid legal basis for the modules they enable. Consent is not automatically the correct basis for every community feature.

4. Automated checks

Turnstile, IP-risk checks and matching of an IP hash, browser cookie or device fingerprint can flag or block a verification attempt according to the guild's settings. These signals can be imperfect, for example on shared networks or devices. QREATE does not use them to make decisions producing legal or similarly significant effects. A member can ask the relevant guild moderators for manual review and may contact QREATE about processing performed by QREATE. The AI assistant can also act on a server when a guild administrator has enabled it to. By default it prepares changes and a person approves each one; the server owner can raise that level so the assistant carries out some actions directly. The assistant can make mistakes, including acting on a misunderstood instruction, so the level is set by the server owner and the resulting actions are attributed to the person whose account they were made under. QREATE keeps a record of what the assistant applied, which that guild's administrators can review. The assistant is not used to make decisions producing legal or similarly significant effects about individuals.

5. Recipients and service providers

We disclose only what is reasonably needed to: Discord (OAuth, Gateway and API operations); our Germany-based hosting and database/cache infrastructure provider; Cloudflare (proxy, TLS, Turnstile, and R2 object storage/CDN for uploaded QAssets); IPQualityScore, only if a guild enables VPN/proxy risk checks; DeepSeek or Anthropic for AI Crew requests, with the prompt, recent conversation and relevant server context; and YouTube, Twitch, X or another integration when an administrator enables it. A guild-configured webhook receives the event payload that administrator chooses. Guild administrators and authorised staff can access data for their guild according to their permissions. We may also disclose information to professional advisers, a successor to the Service, or authorities where legally required. We do not give infrastructure providers a contractual promise of “no access”; they may process data as needed to provide and secure their service.

6. International transfers

Primary application data is hosted in Germany. Some providers named above are established or operate outside the EEA, including in the United States and, depending on the selected AI provider, China. Their processing therefore may involve an international transfer. Where GDPR requires it, we rely on an adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with supplementary measures where appropriate. If no lawful transfer mechanism and adequate protection can be established for a provider, that processing must be disabled. Provider privacy terms also apply to their independent processing.

7. Retention

We keep data only for the purpose for which it was collected, subject to the current operational rules below: • Browser authentication is held in an encrypted JWT session cookie until expiry, sign-out or cookie deletion; Discord access tokens are used during sign-in and are not stored in the application database. • Pending verification links expire after 7 days. The database currently retains expired and completed verification records and anti-abuse signals until the guild's verification data is deleted or a valid erasure request is completed; expiry of a link is not deletion. • AI Crew memories: task and milestone entries expire 30 days after creation or refresh, while stated facts and preferences about a server are kept until deleted. Expired memories are excluded from prompts; physical cleanup may occur later. Every memory held for a server can be reviewed, edited or deleted at any time from the "What Q remembers" panel in the assistant, where recording can also be switched off per scope (server profile, personal); switching it off stops new memories being stored and stops existing ones being read. AI conversation history currently remains until the user deletes the conversation or the account data is erased. • Deleted-channel recovery snapshots are usable for 30 minutes. Other short-lived reminders, lobbies and scheduled jobs are retained until completion, expiry or operational cleanup. • A QAsset remains in Cloudflare R2 and its metadata remains in Postgres until an authorised guild user permanently purges it or the guild/account data is erased. “Archive” is a soft delete and does not remove the object or disable its public URL. Permanent purge deletes the R2 object and database row; previously cached copies, Discord previews or copies made by third parties may persist outside QREATE's control. • Account, guild configuration, moderation, feature history, telemetry, support and user-generated records currently remain while the account/guild or relevant feature is active and thereafter until deletion/anonymisation is completed following a valid request or operational cleanup. QREATE does not currently promise automatic deletion merely when the bot is removed. • Security and infrastructure logs are retained for the provider-configured operational period; we aim to keep ordinary application logs no longer than 30 days unless needed to investigate an incident. • Records required for tax, accounting, disputes, fraud prevention or legal obligations are kept for the applicable statutory limitation/retention period. Backups may retain residual copies until they rotate and are not restored except for disaster recovery. We will publish more specific automated schedules before representing them as guaranteed. Deletion can be delayed where preservation is legally required or technically necessary for a limited backup cycle.

8. Your privacy rights

Depending on the processing and your location, you may request access, correction, erasure, restriction, portability, or object to legitimate-interest processing; withdraw consent without affecting earlier processing; and complain to a supervisory authority. These rights are not absolute. Email [email protected] with “Data Subject Request”, the relevant Discord user ID and guild ID, and enough information to verify the request without requesting unnecessary identity documents. We normally respond within one month; GDPR permits an extension of up to two additional months for complex or numerous requests, with notice within the first month. For guild-controlled module data, contact the guild administrator first. QREATE will assist the controller as required. You may complain to the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or your local EEA supervisory authority.

9. Cookies and similar storage

The dashboard uses strictly necessary authentication, security, invite, locale and consent-choice cookies. The verification page uses a persistent first-party identifier when anti-alt verification is active and may load Cloudflare Turnstile; it is used for security, not advertising. FingerprintJS runs only in the verification flow to derive a device/browser identifier. We currently do not use advertising cookies or Google Analytics. Rejecting non-essential cookies does not disable security storage that is strictly necessary for a requested verification flow.

10. Children

The Service is not directed to children below Discord's applicable minimum age or the minimum age required by local law. Guild administrators must consider the age and vulnerability of their members before enabling tracking or moderation features. If we learn that data was collected from a child unlawfully, we will take appropriate steps to delete it.

11. Security and incidents

We use measures such as TLS in transit, restricted database access, tenant-scoped authorisation, secret management and access controls. No system is completely secure. Where QREATE is controller, we will notify the competent authority within 72 hours after becoming aware of a reportable personal-data breach, where feasible, and notify affected people without undue delay where the breach is likely to create a high risk. Where QREATE is processor, we notify the relevant guild controller without undue delay.

12. Changes and contact

We may update this Policy as the Service, providers or law changes. The current version and effective date appear on this page. We will use reasonable notice for material changes where appropriate. A privacy policy describes processing; continued use is not treated as consent where GDPR requires a separate affirmative choice. Privacy requests and questions: [email protected] Support: https://discord.gg/qreate Controller establishment: Netherlands QREATE is not affiliated with Discord Inc.