Privacy Policy for the Discord bot Crio

Information about processing Discord data for Crio commands and automatic moderation.

1. Scope, controller, and data source

Document informationApproved publication
Effective fromSeptember 7, 2026
Publication versionsha256-GgV6pub7mV8yFuwW-altVrwk_fY8yxDUifRd0lcM9jA

This Policy applies to Crio (Application ID 1377884733639360633) and Baby Crio (Application ID 1378839517330542682), its beta version.

Both Crio and Baby Crio offer /terms and /privacy, which link to the Crio Terms of Service and this Privacy Policy, respectively. This Policy is also linked in the bot bio. For both server installations and personal (user) installations, Discord displays links to both documents before the installation is authorized.

The controller is:

Jannik Höfler
c/o IP-Management #11515
Ludwig-Erhard-Straße 18
20459 Hamburg
Germany
privacy@fishystuff.fish

Crio receives the data described below through Discord. Jannik Höfler decides how the bots process data and which moderation rules and automatic actions they use. Server administrators can add or remove the bot but cannot configure its moderation rules. Jannik Höfler and authorized members of the moderation team can access the restricted action records to check the bot’s actions and make them transparent within the team. These records are not used to impose additional sanctions following a kick by Crio. Discord processes platform data independently. GDPR means the General Data Protection Regulation.

2. Commands, moderation, and technical logs

Commands and suggestions

Data and source
When someone uses a command or asks Discord for suggestions while typing, Discord may send Crio the user ID and public profile, relevant server and channel, roles and permissions, command, entered text, and information needed for a response. Technical logs may contain the time, affected feature, type of event, and error state, but not command text, message content, or Discord usernames.
Purpose
Perform and answer the requested command or suggestion, find technical errors, and prevent abuse.
Legal basis and interests
Article 6(1)(f) GDPR for processing the requesting person's identifiers, input and command context insofar as necessary to respond to their voluntary commands or suggestions. The legitimate interest is voluntarily providing the particular response requested. This also applies where the requesting person has entered into an installation contract. Technical logs and abuse prevention also rely on Article 6(1)(f), in the interests of secure and reliable operation. A server administrator's acceptance is not consent on behalf of members.
Choice, necessity, and retention
Commands and suggestions are voluntary. Without the required data, Crio cannot respond. Command content remains in memory only until the request ends; Crio keeps no separate command history. Technical logs have a seven-day retention period; deletion completes within eight days.

Automatic moderation

Scope and temporary data
In the MaoMaoPrince Fishing Community server, Crio checks message frequency within and across channels, repeated content, and messages in a channel designated for automatic anti-spam action. These rules detect patterns, not whether a particular link is safe. Crio temporarily holds user, channel, and message IDs, arrival times, and comparison codes in memory, not message text. Message-comparison windows last up to 3 minutes; repeat-action prevention uses the user ID and time for up to 9 minutes after an action. Expired entries are removed by regular automatic cleanup, not necessarily at the exact end of the window.
Purpose and legitimate interests
Stop spam, fraud, phishing, harmful links, harmful advertising, disruption, and resulting security or financial harm; document actions accountably and allow later human review. The interests are protecting members and maintaining a secure, functional community server.
Legal basis and necessity
Article 6(1)(f) GDPR for pattern checks, automated action, and restricted action records. Rapid action limits the spread of repeated or high-volume abuse before human review. Short checks and limited records reduce the intrusion compared with keeping a message history.
Actions and action record
When a spam pattern triggers a rule, Crio may automatically delete that user's recent messages within the rule-specific time and channel scope, including across channels, and attempt to remove the user from the server. The pattern can span several messages; each deleted message need not independently match it. This is a kick, not a ban: Crio does not prevent rejoining. Other server restrictions can still prevent access. Later messages are checked again. Crio sends the action result, user and channel IDs, time, rule, and relevant counts to a restricted Discord channel for moderators; records are scheduled for deletion after 28 days.
Safeguards
Message text is discarded after checking and is not included in action records. Rules can affect legitimate messages too; affected people can challenge an action and request human review through the contacts below. Short retention, restricted records, and the absence of an automatic ban limit the impact.

3. Recipients, external content, and transfers

Depending on the event, recipients are Discord as independent platform controller, Hetzner as processor for the EU-hosted service, authorized server moderators with access to the restricted action-record channel, and authorities, courts or advisers where legally required. Crio responses and warnings posted in a channel are also visible to people with access to that channel.

We send Crio responses, warnings, moderation actions and action records through Discord’s developer API to Discord, Inc. in the United States under the EU-US Data Privacy Framework adequacy decision (Article 45 GDPR). Discord’s certification covers these transfers; see the official register. Discord explains its separate platform processing in its Privacy Policy.

We use Zoho Mail’s EU region for email correspondence, including privacy requests. Occasional remote technical-support access from India is protected by Zoho’s EU Standard Contractual Clauses and supplementary measures, as described in its privacy FAQ.

Further information and, where applicable, a copy of the relevant transfer safeguards can be requested through privacy@fishystuff.fish.

Crio responses may contain links or images hosted by GitHub through github.com or raw.githubusercontent.com. Discord may retrieve or cache a preview. If someone opens a link, GitHub receives ordinary request data and processes them independently.

4. Retention and deletion requests

CategoryRetention
Command, suggestions, and related contextkept in memory only until the request ends
Data used to detect repeated or abusive messagesin-memory comparison window up to 3 minutes
User ID and time kept to avoid repeated actionsin-memory repeat-action prevention window up to 9 minutes
Technical operation and error logsseven-day retention; deletion completed within 8 days
Records of Crio moderation actions in a restricted Discord channelscheduled deletion after 28 days; if a temporary technical problem prevents deletion, until the next successful deletion opportunity

Discord may retain its own interaction, message, audit, security, and backup data for longer under its rules.

Rectification or deletion of data controlled by Crio can be requested through privacy@fishystuff.fish. A user ID, server, channel, and approximate time may be needed to locate an action record. Discord’s privacy and account functions apply to data controlled by Discord. Permanent shutdown does not change the applicable retention limits or deletion rights.

5. Human review and rights

People affected by automatic moderation may request human review by the server moderation team or through contact@karpfen.dev.

For these requests, the operator uses the contact details, explanation, and information needed to locate the action. Human moderation review relies on Article 6(1)(f) GDPR, in the interests of correcting mistakes and protecting members; statutory privacy requests rely on Article 6(1)(c), together with Articles 12–22 GDPR. The shared email and postal providers and correspondence periods are described in sections 5–7 of the FishyStuff Privacy Policy. This does not require a FishyStuff account.

Under the statutory conditions, you can request access to and a copy of your personal data, correction, deletion or restriction of processing.

Data portability under Article 20 GDPR applies to personal data you have provided where processing is automated and based on consent or Article 6(1)(b) GDPR. Processing based only on Article 6(1)(f) does not meet that condition. Access, copies and any independently applicable rights to the return of data remain unaffected.

You can also complain to a data protection supervisory authority, including where you live or work or where you believe an infringement occurred.

Objection: A data subject may object at any time, on grounds relating to their particular situation, to the processing of personal data concerning them based on Article 6(1)(f) GDPR. The operator will then no longer process those personal data unless the operator demonstrates compelling legitimate grounds for the processing that override the data subject’s interests, rights, and freedoms, or the processing is for the establishment, exercise, or defence of legal claims.

This includes processing to answer commands and suggestions, whether or not the requester has entered into an installation contract. An objection is assessed according to the affected data, operations and purposes; it does not automatically terminate that agreement. Where Article 18 GDPR applies, you can request restriction, including while the grounds for an objection are verified.

These privacy notices are provided in German and English. Your statutory data-protection rights apply regardless of the language version. Changes are also available through an optional RSS feed (Download plain text (.txt)).