Privacy Policy — Hearthhall for Discord

Last updated 6 September 2026.

This covers the Hearthhall Discord application — the bot a server administrator adds to their server in order to bring that server’s roleplay history into a Hearthhall campaign. The website has its own notice at Privacy, and everything there still applies to your account here. This page is about what the bot reads while it is in your server.

1. Who is responsible

Tom Kremser is the data controller for both Hearthhall and its Discord application.

Čajkovského 1481/11, 746 01 Opava-Předměstí, Czech Republic
Privacy enquiries: support@hearthhall.com

The server administrator who adds the bot decides that an import happens and which channel it reads. We decide how the software works and where the data is stored, so the obligations in this notice are ours regardless of who pressed the button.

2. What the bot reads

Only what an import needs, and only from channels an administrator has explicitly chosen. The bot does not listen to your server, does not receive messages as they are sent, and holds no connection to Discord between imports. It reads history when it is asked to and is otherwise inert.

From the channels selected for an import:

  • Message content — the text of the messages. This is what an import is for, and it requires Discord’s Message Content intent.
  • Who wrote each message — the Discord user ID, display name and avatar URL of the author. Where a message was posted through a webhook by a proxy bot such as Tupperbox or PluralKit, the character name and avatar that webhook carried.
  • When it was written — the message timestamp, which becomes the imported post’s date so the archive reads in the right order.
  • Message, channel, thread and server IDs — so an import can be resumed and so importing the same channel twice does not duplicate anything.
  • Attached files, and their names. Pictures and documents posted in the channel are copied into the campaign’s own private storage and appear in the imported post where they were posted: PNG, JPEG, WebP and GIF images, and PDF, plain text and Markdown documents, each up to 10 MB. Everything else — video, audio, archives, anything larger — is not copied, and the imported post says so by name, so a file that was left behind is visible rather than silently missing. A file that was copied is readable only by the people that campaign’s owner has admitted, exactly like the post it sits in.

The bot does not read voice channels, direct messages, or group direct messages. It cannot: a bot has no access to them.

3. Why, and on what legal basis

Legitimate interests (GDPR Article 6(1)(f)). The interest is a community’s in keeping its own history when it moves: a group that has played in a Discord server for years should not have to abandon what it wrote in order to continue somewhere else.

We think that balance is defensible because of what an import produces. Imported writing lands inside a private campaign, visible only to the people that campaign’s owner admits — the same people who could already read it in the Discord server it came from. It is not published, not indexed, and not used to train anything.

If you disagree in your own case, section 7 is the part you want, and objecting does not require you to have an account here.

4. If you never signed up

This is the part that deserves to be plain. If someone imports a channel you wrote in, your Discord display name, your avatar and your messages are copied into a Hearthhall campaign without anyone asking you first. That is a real thing to be told about, so here are the limits on it.

  • It is visible only inside that one private campaign, to people the campaign’s owner has admitted.
  • You are not given an account, and no account is created in your name. You are a name on some posts, nothing more.
  • If you later sign in to Hearthhall with the same Discord account, we tell you the writing is here and offer to attach it to you. That is a choice offered to you, not a claim made on your behalf.
  • You can have it removed. See section 7.

5. Where it goes, and who else touches it

Imported writing is stored in the same database as the rest of Hearthhall, in the European Union. Copied files are stored beside it, in a private store that is not public, not listed and not indexed: every request for one is checked against whether the person asking is a member of that campaign, the same check the post itself passes. The processors involved are the site’s own, listed in full on the site privacy notice; the ones an import touches are:

ProcessorWhat it doesWhere
SupabaseDatabase, authentication, and file storageEuropean Union
VercelApplication hosting, content delivery, and counting page views. The analytics part sets no cookie and keeps no identifier that outlives the day it was made.European Union / United States

Discord itself is not our processor. It is the source the bot reads from, and your relationship with Discord is governed by Discord’s own privacy policy.

Imported writing is never sold, never used for advertising, and never used to train AI.

6. How long it is kept

  • Imported posts last as long as the campaign does. They are that campaign’s history, and deleting the campaign deletes them.
  • Copied files last exactly as long, and go with the campaign when it is deleted — the files themselves, not merely the records of them.
  • The link between a Discord account and a name on those posts lasts until the campaign is deleted, until you claim it, or until you ask us to remove it.
  • The record of an import job — which channel, when, how many messages — is kept while the campaign exists, so a GM can see what was brought in and when.

7. Removing your writing, or your name from it

Write to support@hearthhall.com from the email address on your Discord account, or tell us your Discord username and the server the import came from. You do not need a Hearthhall account to ask.

Two different things you can ask for, and they are worth separating:

  • Remove my name. We strip the Discord ID, display name and avatar. The posts stay, attributed to nobody. This is what we do by default. In place of the ID we keep a one-way fingerprint of it, scrambled with the campaign it was in, so that if that campaign imports the same channel again your name cannot come back with it. The scrambling only goes one way, so your Discord ID cannot be read back out of it; and because the campaign is mixed in, the value kept in one campaign is unrelated to the value kept in any other, so it cannot be used to recognise you across them.
  • Remove my messages. We delete the imported posts themselves, and any files that came with them.

We default to the first because of what the second costs other people. An imported scene is usually a conversation, and deleting one voice from it leaves the others answering somebody who is no longer there. That is not a reason to refuse — it is your writing and you may have it removed — but it is a reason to offer the narrower remedy first and to say why.

You also have the rights the site privacy notice sets out in full: access, correction, erasure, restriction, portability and objection. We answer within one month.

8. Complaining

If you think we have handled your data badly, tell us first at support@hearthhall.com — it is usually quicker. You can also complain to a supervisory authority. Ours is the Úřad pro ochranu osobních údajů (Czech Data Protection Authority), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic. If you live elsewhere in the EEA you may complain to your own country’s authority instead.

9. Children

Hearthhall is for people aged 16 and over, and so is the bot. We do not knowingly import the writing of anyone younger. If you believe we hold a child’s data, write to support@hearthhall.com and we will remove it.

10. Changes

The date at the top says when this last changed. If the bot starts reading something new, this page changes before that happens, not after.

The terms governing use of the bot are at Discord bot terms.