Loot Goblin DE

Legal

Privacy policy

As of 12 September 2026 · Loot Goblin 1.8.8 · GDPR / TTDSG

1. Controller

Joscha Alhelm
c/o Autorenglück ID 60084
Albert-Einstein-Str. 47
02977 Hoyerswerda
Germany
Email: gamesgamble@loot.rocks

Loot Goblin is provided at loot.rocks. Controller for processing is the operator named above. Discord Inc. is a separate controller for the Discord platform.

2. Hosting and website

The public website and dashboard run at https:/loot.rocks. Visits produce ordinary server logs (IP address, time, URL, user agent, status code). They serve security (abuse, flooding, bots) and are not used for profiling. Unless logs are needed to investigate attacks, they are deleted or rotated promptly.

The page /status shows operational state (gateway, pause, music, connected servers, heartbeat) without personal data. /health provides the same state as JSON for uptime checks.

Legal basis: Art. 6(1)(f) GDPR (integrity and availability of the service); for security logs possibly (c) together with statutory duties.

3. Discord bot — which data

Once the bot is invited to a server it processes data Discord sends via the gateway and REST API, to the extent modules are enabled. This may include:

Storage is the operator’s database (MariaDB in production). Legal basis: Art. 6(1)(b) GDPR (use of the bot on the server), (f) (safe moderation, abuse prevention) and — where the server admin pursues a legitimate interest of the community — also (f). Inviting the bot and setting intents is done by the server admin.

4. Web dashboard

Sign-in stores username, password hash (PBKDF2-HMAC-SHA256), role, assigned server ID, module grants and session data (random session secret as hash, CSRF token, expiry, IP and user agent of the session). The plaintext password is not stored. Optional Discord sign-in (OAuth2): Discord user ID, display name, avatar and the servers on which the user has “Manage Server”, for sign-in and assignment. Session cookie aether_sid: HttpOnly, SameSite=Lax, optionally Secure on HTTPS, typically 12 hours. A second cookie protects CSRF at login. Legal basis: Art. 6(1)(b) and (f) GDPR; for cookies without tracking TTDSG § 25(2) no. 2 (strictly necessary).

Failed attempts are counted; after several failures the account is locked temporarily. Honeypot fields and IP rate limits defend against bots — without marketing tracking.

5. Optional integrations

Only if an admin configures them:

Operations: Prometheus metrics and Alertmanager. Incident notices (container or service unreachable) may go to a Discord webhook of the operator. No chat or profile content is sent.

Third parties have their own privacy policies. The operator recommends storing only needed tokens with minimal rights.

6. Retention

7. Recipients, third countries

No disclosure for advertising. Recipients are: Discord (USA, data processing under Discord), depending on the module Twitch/YouTube/X and other APIs the admin connected. There is no separate transfer to third countries for marketing.

8. Obligation to provide

Without the IDs Discord supplies the bot cannot reply. The dashboard does not work without an account. There is no tracking pixel and no third-party analytics cookies on loot.rocks.

9. Rights of data subjects

You have the right of access, rectification, erasure, restriction, data portability and objection (Art. 15–21 GDPR) and the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in Germany typically the state data protection commissioner of the operator’s seat. Requests to gamesgamble@loot.rocks.

Users can kick the bot from the server. The operator deletes dashboard accounts on request.

10. Automated decisions

No profiling systems, no automated decisions with legal effect under Art. 22 GDPR. Automod rules (spam, flood) are filters configured by the admin.

11. Children

The bot is aimed at guilds whose Discord servers meet Discord’s age requirements. Data of children is not collected knowingly.

12. Changes

This policy applies to the current bot version. The text is at /datenschutz.