Privacy Policy
Last updated: 2 October 2026
Only the German version is legally binding. This English translation is provided for convenience. Read the German version
1. Controller
Herukan – Kilian HauberAm Rosengarten 18B
79183 Waldkirch
Germany
Email: [email protected]
2. Scope
Herukan consists of three parts that process different data: this website (herukan.com), the Discord bot that server owners invite to their server, and the dashboard (app.herukan.com) used to configure the bot.
3. This website
When you visit this website, server log files record the requested address, date and time, amount of data transferred, referrer, browser type and version, operating system and your IP address. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure and stable operation). Logs are deleted after 7 days.
Hosting is provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, as a processor under a data processing agreement pursuant to Art. 28 GDPR. Servers are located in Germany.
Fonts are served from our own server; no connection to third-party servers such as Google Fonts is established.
For audience measurement we use OpenPanel, which we run self-hosted on our own server in Germany. The data collected never leaves our infrastructure. OpenPanel works without cookies and does not store IP addresses; sessions are distinguished using a daily-rotating hash derived from IP address and browser identification. No personal profiles are created and no information is stored on or read from your device, so no consent under § 25 TDDDG is required. Legal basis: Art. 6 (1) (f) GDPR.
This website does not set any cookies that require consent.
If you pick a language in the language switcher that differs from your browser’s, we store that choice in the cookie NEXT_LOCALE (content: only the language code, e.g. “en”; lifetime: one year) so the website greets you in the same language on your next visit. This cookie is strictly necessary for a function you explicitly requested and therefore does not require consent under § 25 (2) no. 2 TDDDG. Legal basis: Art. 6 (1) (f) GDPR.
4. The Discord bot
Each server owner decides whether and how Herukan is used on their server and remains responsible for their own server’s content and member data.
Depending on the features enabled, we store:
- Server and configuration data: Discord server ID, server name and icon, when the bot joined, and all settings (enabled features, channel and role IDs, message templates, language).
- Leveling: Discord user ID, XP, level and the time of the last counted message.
- Moderation: warnings including user ID, moderator ID, free-text reason and timestamp.
- Tickets: ticket number, IDs of the member who opened it and of the staff who handled and closed it, status and timestamps, and the messages in the ticket channel (see below).
- Giveaways: Discord user IDs of participants and winners.
- Created content: custom commands, auto responses, scheduled messages, reaction role panels and countdowns, including the Discord ID of the person who created them.
- Game data: for the minigames (Archery, Tic-Tac-Toe, Hangman, Capture, Flipout, Connect Four, Memory, Imposter and Bluff) the user IDs of the players, the course of the game and the result; for Hangman, Imposter and Bluff also the words, hints and statements entered during the game and the votes cast. Finished games are deleted automatically 48 hours after they end.
- Minigame statistics: per server, person and game the number of games played, won, lost and drawn (for Bluff also the points), used for records and leaderboards on that server. Individual games are not part of it. When a person leaves the server they no longer appear on any leaderboard; their statistics are deleted 30 days later unless they return before then. We also count the games played per server and day without reference to any person and delete these counts after 30 (no subscription), 90 (Plus) or 365 days (Ultimate), depending on the server’s plan.
- Server statistics: per server and day, numbers without reference to any person: member count, server boosts, joins and leaves (split into people and bots), messages in total, per channel, per hour and per type (text, image/file, link, reply, sticker), reactions per emoji, commands used per command name and area, and minutes spent in voice channels, in total and per channel. Only these totals are stored — no messages, no user IDs, not who wrote or used what and when. Depending on the server’s plan, the numbers are deleted after 30 days (no subscription), 90 days (Plus) or 365 days (Ultimate). After a subscription ends, its period continues to apply for another 30 days.
- Social notifications: the monitored YouTube, Twitch and Kick channels or Bluesky accounts (public channel or account ID and display name) and the Discord channel used for notifications.
For AutoMod, leveling and auto responses the bot reads messages in the channels where those features are active. This check happens in memory only. Message content is not stored in our database and not shared with third parties — only the result is kept, such as an increased XP count or a warning. The only exception is ticket channels (see below).
When a ticket is closed, the bot creates a transcript and may post it into the server’s log channel; after a transcription recording, the transcript is posted into the channel where the recording was started. In addition, we store both kinds of transcripts in non-public storage at Cloudflare R2 so the server’s team can read them in the dashboard. They are deleted automatically after three years, or earlier when the bot is removed or member data is deleted in the dashboard.
So the server’s team can read and answer open tickets in the dashboard and in the Herukan app, the bot stores the messages in ticket channels while the ticket is open: text, links to attachments, the readable text of embeds, and the Discord ID, display name and avatar of the author. Edits in Discord update the copy; deleting a message in Discord also deletes its content with us. After a ticket is closed these messages are kept for 30 days and then deleted automatically — from then on only the transcript remains. They are deleted earlier when the bot is removed or member data is deleted in the dashboard.
Legal basis: Art. 6 (1) (b) GDPR for performing the usage agreement with the server owner and Art. 6 (1) (f) GDPR regarding the server owners’ interest in operating the selected features. If the bot is removed from a server, we delete that server’s data within 30 days.
5. The dashboard
Sign-in works exclusively through Discord (OAuth2). We request the identify (Discord ID, username, avatar), guilds (list of your servers) and email (the email address stored with Discord) scopes.
Permanently stored from sign-in are your Discord ID, your dashboard language preference and the times of your first and last sign-in (in the dashboard or the app). Name, avatar and server list exist only within your session. After sign-in we set a technically necessary cookie containing your signed session; it is not used for analytics or advertising. Legal basis: Art. 6 (1) (b) GDPR.
If Discord reports your email address as verified, we store it together with your Discord ID and update it on every sign-in. We use it for support only: to answer your requests or to reach you about problems with your account or your servers. We do not send advertising or newsletters to it. Legal basis: Art. 6 (1) (f) GDPR; our legitimate interest is being able to reach you about problems with the service. The address is deleted after 365 days without a sign-in, when you delete your account in the app, or when you ask us to.
Images uploaded in the embed builder are stored with Cloudflare R2 (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA) and served from a publicly accessible address, which is required for Discord to display them. Do not upload images that must not be publicly visible. This constitutes a transfer to a third country based on the EU Commission’s Standard Contractual Clauses in Cloudflare’s data processing addendum.
Uploaded images are deleted together with your server’s other data: when the configuration is reset, and after the 30-day period once the bot has been removed from the server.
The dashboard embeds a feedback widget (Quackback) which we run ourselves on our own infrastructure at feedback.herukan.com. If you use it, your Discord ID and Discord username are transmitted so your feedback can be attributed to you, and the feedback text you enter is stored. Nothing is transmitted to the software vendor or any other third party. Legal basis: Art. 6 (1) (f) GDPR.
Sign-in to the Herukan app for iOS and Android also works through Discord with the same scopes as the dashboard. For each signed-in installation we store your Discord ID, display name and avatar, the access tokens issued by Discord (encrypted), the device name, operating system and app version, and the times of sign-in and last use. We need the access tokens to fetch your server list from Discord on your behalf; they never leave our servers. The app itself only keeps a sign-in token of our own in the device’s protected storage. This data is deleted when you sign out (at the latest one week later), after 60 days without use, or when you delete your account in the app. Legal basis: Art. 6 (1) (b) GDPR.
If you allow notifications, we store your device’s push token together with your Discord ID, operating system and language. We notify you about new tickets and applications on servers you manage; a notification only names the kind, the number or application type and the server name, never any content. Delivery runs through the Expo Push Service (650 Industries, Inc., USA), which forwards it to Apple (APNs) or Google (Firebase Cloud Messaging). Notifications can be turned off per server in the app; the token is removed when you sign out or delete your account.
When someone changes a server’s settings through the dashboard or the app, we store an audit log entry: the Discord ID of the person, the time, whether the change came from the dashboard or the app, the affected area and the changed values before and after. Ending or rerolling a giveaway also stores the Discord IDs of the winners. The log is visible to everyone who may manage the server in the dashboard and lets the team trace changes. Entries are deleted after 365 days, or earlier together with the server’s other data; resetting the configuration deliberately does not delete them. They belong to the server, not to the person, and therefore remain when you delete your account in the app. Legal basis: Art. 6 (1) (f) GDPR.
6. Premium subscriptions
Paid features are sold exclusively through Discord’s subscription system; Discord is the contracting party for the purchase and receives the payment. We receive no payment data — neither card nor billing details. Discord only tells us which subscription tier is active for which server.
7. Custom bot (Ultimate)
With the Ultimate tier you can store your own Discord bot token. It is stored encrypted (AES) and decrypted only to connect your bot to Discord. Only the last four characters are shown in the interface. You can remove it at any time in the dashboard or reset it in Discord.
8. Recipients
- Discord Inc. (USA) — the service cannot work without Discord; all bot actions run through the Discord API.
- Hetzner Online GmbH (Germany) — hosting, processor under a data processing agreement.
- Cloudflare, Inc. (USA) — storage of uploaded images and of ticket and transcription transcripts.
- YouTube, Twitch, Kick and Bluesky — only when social notifications are enabled, and only to query public channel information or public posts of the monitored channels.
- 650 Industries, Inc. (Expo) (USA), forwarding to Apple or Google — only for allowed push notifications of the Herukan app, to deliver them.
There is no external recipient for audience measurement or the feedback widget because we run OpenPanel and Quackback ourselves.
9. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21 GDPR). Contact us at [email protected] and include your Discord ID so we can identify your data.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
10. Changes to this policy
We update this policy when the service or the legal situation changes. The version published here applies; the date above shows the current status.