1. Who is responsible?
The controller for the processing of your data by the Discord bot “Pablo” and on this website is:
Marcel Noah Weixelbaum Leo-Mathauser-Gasse 72, 1230 Wien Email: marcel@pablobot.space
If you have questions about privacy or want to exercise your rights, just write to us at marcel@pablobot.space.
2. The short version
- We only store what Pablo needs for its features – for example your Discord ID for levels or warnings.
- We have no ads, no tracking and no third-party analytics tools.
- We don’t sell data and don’t share it for advertising purposes.
- Premium payments are handled entirely by Discord. We never see payment details.
- You can request access to or deletion of your data at any time.
3. Data when you use Pablo on Discord
Pablo is a Discord bot. Discord gives it the information it needs for each feature. Which of that data we store depends on the features a server has enabled:
- Profile data: Discord ID, username, display name and avatar hash – so we can show you correctly in leaderboards, tickets or the Global Chat.
- Server membership: when you joined or left a server and whether you are verified.
- Levels & activity: XP, level, number of messages and time spent in voice channels per server. Individual XP entries are deleted after 90 days. We don’t store the content of your messages for this.
- Moderation: when moderators or AutoMod take action against you (e.g. warning, timeout, ban), we store the action with reason, time and the responsible moderator.
- AutoMod: to detect spam, Pablo checks new messages automatically. Messages are kept in memory for at most 10 minutes for this and are not stored permanently. If a rule is broken, an excerpt of the message may be posted to the server’s log channel.
- Message logs: if a server has enabled them, Pablo posts deleted or edited messages to a log channel of that server. We don’t store them separately.
- Tickets: messages in ticket channels (text and links to attachments) are stored so that a transcript can be created. Depending on the settings, the transcript can be sent to a channel of the server or to you via direct message.
- Modmail: if you send Pablo a direct message on a server with Modmail enabled, your message is forwarded to a private channel of that server’s team, and the team’s replies are sent back to you. We store who opened the conversation, the channel and when it was opened and closed – not the messages themselves. When the conversation is closed, a transcript of the channel is posted to the server’s log channel and the channel is deleted.
- Global Chat: when you write in a Global Chat channel, your message is forwarded with your name, avatar, server name, level and rank to all connected servers. We store the message and the IDs of the forwarded copies for 90 days so deletions are applied everywhere. You can turn this off at any time with
/globalchat optout. - Birthdays: if you add your birthday with
/birthday set, we store the day and month – and the year only if you enter it (used solely to show your age). You can remove it at any time with/birthday remove. - Giveaways: who entered a giveaway and who won.
- Economy & games: if a server uses the economy, we store your balance, your daily streak, the times of your last daily reward and work shift, counters of won and lost games and the shop items you bought. For the counting channel we store the current count and who counted last; for the flag quiz channel how many flags you guessed correctly.
- Invite tracker: if a server enables it, we store when you joined, through which invite code and who created that invite, whether you left again, and whether your account was younger than the limit set by the server (such joins don’t count).
- Temp voice: which temporary voice channel belongs to whom, as long as the channel exists.
- Ban appeals: if you submit an appeal on this website, we store your answers, the ban reason and the team’s decision so the server team can review it.
- Polls, suggestions, ranks, role panels: your votes, submitted suggestions and assigned ranks.
- Custom commands & auto responses: Pablo checks messages on the server for the triggers the server has set up. Messages are not stored for this; only a usage counter per command is kept.
- Server backups: if a server team creates a backup, we store the server’s roles, channels and permission settings – no messages and no member lists.
- Music & radio: search terms and links you enter with
/playare passed to our music server (Lavalink), which fetches the tracks from the respective platform (e.g. YouTube or SoundCloud) or radio station. We only remember who requested a track while it is in the queue.
We also count per server and hour how many messages, commands etc. there were. These statistics contain no information about individual people. Welcome and rank cards are generated on the fly from your avatar and name and are not stored by us.
4. Data when you use the website or dashboard
Sign-in with Discord: you sign in to the dashboard via Discord. We only request the scopes identify (profile) and guilds (list of your servers). We use the server list solely to show you the servers you are allowed to manage.
Session: after sign-in we set a session cookie. Our database only holds a hash of it, together with your Discord access token in encrypted form. The session expires after 7 days of inactivity; when you log out, we delete it immediately and revoke the token with Discord.
Change log: when you change settings in the dashboard, we log who changed what and when, so server admins can keep track of changes.
Tools: the tools on this website (e.g. looking up an avatar or user ID) query Discord for the requested, publicly available information. We don’t store the results.
Server logs: when you visit the website, the server processes technically necessary data such as your IP address to deliver the page and prevent abuse (e.g. too many requests). We never write credentials or tokens to logs.
7. Legal basis
- Art. 6(1)(b) GDPR – to provide you with Pablo’s features, the dashboard and Premium.
- Art. 6(1)(f) GDPR – our and the server operators’ interest in a safe, spam-free and moderatable server, in preventing abuse and in keeping track of changes.
- Art. 6(1)(c) GDPR – where we are legally required to retain data.
8. Who receives your data?
- Discord – Pablo runs on Discord. Processing by Discord is governed by Discord’s Privacy Policy.
- Other servers – in the Global Chat your messages are shared with the connected servers (see above).
- Server teams – Modmail messages and ban appeals are visible to the team of the server you contacted.
- Music platforms and radio stations – for
/playand/radioour music server fetches content from these providers. - YouTube and Twitch – for social notifications Pablo checks the public channels a server has added. No data about you is sent for this.
- Bot lists – if you vote for Pablo on a bot list with rewards (e.g. top.gg or botlist.me), the list tells us your Discord ID and the time of the vote so we can grant the vote rewards. We store this for 90 days. We send these lists only Pablo’s server count, no personal data. The flag quiz loads flag images from
flagcdn.comthrough Discord. - Hosting – the bot, database and website run on servers we operate ourselves or rent from a hosting provider, who processes the data only on our behalf.
Discord is a US company. Data may be transferred to the USA in the process; Discord relies on its own safeguards for this (e.g. Standard Contractual Clauses).
9. How long do we keep data?
- Sign-in cookie: 10 minutes · Dashboard session: until logout, at most 7 days of inactivity
- Individual XP entries and Global Chat messages: 90 days
- AutoMod message history: at most 10 minutes, in memory only
- Birthdays: until you remove them or the server stops using Pablo
- Bot-list votes: 90 days
- Levels, moderation cases, tickets, appeals, ranks, economy, backups and server settings: as long as the server uses Pablo or until you or the server team request deletion
- When Pablo leaves a server, its data is marked as inactive and deleted on request
10. Your rights
You have the right at any time to:
- access the data stored about you (Art. 15 GDPR)
- rectification (Art. 16 GDPR) and erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object to processing based on legitimate interests (Art. 21 GDPR)
To do so, write to us at marcel@pablobot.space and include your Discord ID so we can find your data. You can also lodge a complaint with .
Some things you can do yourself: /globalchat optout stops your messages from being forwarded, /birthday remove deletes your birthday, and “Log out” in the dashboard ends your session immediately.
11. Minimum age
Pablo is intended for users who are allowed to use Discord. Discord requires a minimum age depending on your country (14 in Austria for consenting to online services). We don’t collect age information beyond an optional birth year for the birthday feature.
12. Changes
When Pablo gets new features, we update this policy. The current version is always available here. See also our Terms of Service.
Last updated: September 29, 2026 · Imprint