Privacy Policy

Argos · Security & moderation bot · Updated: July 2026EspañolPortuguêsРусский

Argos is a security and moderation bot that operates inside a Discord server. This policy explains what data it processes, for what purpose and for how long. By using the server or the bot's web portal, you accept what is described here.

1. What data we process

2. What we use the data for, and our legal basis

Exclusively for the security and moderation of the server: applying and auditing sanctions, detecting raids and alternate accounts, preventing attacks (anti-nuke/anti-raid) and giving staff investigation tools.

Our legal basis is the legitimate interest in protecting the community against abuse, attacks and sanction evasion (Art. 6(1)(f) GDPR), and the enforcement of the server rules you accept by taking part. Processing is limited to what is strictly necessary for that security purpose.

We never sell or share your data with third parties for commercial purposes, we do not run advertising or commercial profiling, and we do not use it to train artificial intelligence models.

3. Browser fingerprint and cookie (web verification)

Changing your IP address is trivial and free (restarting the router, using mobile data, another wifi network). That is why a sanctioned person can come back again and again by creating new accounts. To prevent this, the verification portal measures technical characteristics of your browser: browser and system model, language, time zone, screen size and density, number of cores and approximate memory, whether the device is touch-enabled, and the result of two standard graphics tests (a canvas drawing and your graphics card model).

Security cookie. The portal also stores a single cookie (argos_id) containing a random number that identifies your browser, for the same purpose: detecting that a sanctioned account is coming back. It is a strictly necessary cookie for the security of the service: it is not advertising, it does not track you outside this portal and it is not shared with anyone. It is HttpOnly (no script on the page can read it), lasts one year, and you can delete it from your browser whenever you want.

Virtual machine detection. From your graphics card model we infer whether the session appears to run inside a virtual machine, which is common in automated attacks. By default this only raises an internal notice for staff and does not block anyone, precisely because an old computer or a browser with hardware acceleration turned off produce the same signal.

4. Third-party services

To classify an IP as a VPN or proxy we use network reputation services (proxycheck.io, or failing that ip-api.com). Those services receive only your IP address for analysis; they do not receive your Discord identity, your browser fingerprint or any other data. Each one handles that query under its own privacy policy.

To detect the TOR network we periodically download the public exit-node list from the Tor Project and compare it on our own server: that check sends no data about you to anyone.

Authentication is done through Discord's official login (OAuth2), which only gives us your basic identifier.

5. Where data is stored and for how long

Data is stored on our own, access-restricted server, not on third-party devices. Retention:

Every server is isolated. Connection or device blocks only take effect on the server where you were sanctioned. One server blocking you does not block you on any other server that uses Argos, and moderation teams cannot see other servers' data or sanctions.

6. Enhanced monitoring (exceptional staff use)

The moderation team can enable closer monitoring of one specific account when there is a well-founded suspicion of abuse. Depending on the option chosen, this may log their reactions or copy their public messages to a private staff channel in real time.

This is an exceptional, targeted measure visible only to staff. It reaches public server content only: never private messages, nor conversations outside the server, nor the content of voice calls.

7. Your rights and how to exercise them

You have the right to access your data, to rectify it, to request its deletion, to object to the processing and to request the portability of what you provided. You do not need to write a formal request: you can exercise these rights from Discord itself.

We resolve requests within a maximum of 30 calendar days from the moment they are recorded.

7.1. What is deleted and what is not

If your request is approved, your ordinary activity is deleted: your messages logged when edited or deleted —including the re-hosted attachments, which are removed from disk—, your joins, your name and nickname changes, your reactions, your voice activity and the record of which invite you used.

There are two things that are not deleted on request, and we want to be transparent about why:

These two exceptions rely on the limits that data protection law itself places on the right to erasure: the legitimate interest in community security and fraud prevention, and the defence of legal claims. They are not a blanket refusal: everything else is deleted.

If you believe a connection or device block has affected you by mistake, tell the staff: an appeal system exists and the block can be lifted, which erases both the connection and the device associated with it.

7.2. Who decides on your request

Deletion requests are resolved by the bot operator or by a person they have authorised expressly and by name. Deliberately, holding a role as administrator or moderator in a server is not enough: if it were, someone with access to a role could erase the evidence of a sanction by presenting it as an exercise of the right to be forgotten. Every approval or rejection is logged with the identity of whoever resolved it.

You may also lodge a complaint with the data protection supervisory authority of your country if you consider that we have not handled your request properly.

8. Minors

As with Discord, the service is intended for people who meet the minimum age required by Discord's Terms (13 years, or higher where your country requires it).

9. Changes

We may update this policy. The date of the last update appears at the top of the document.

10. Who is accountable for your data, and contact

Two roles are worth distinguishing, because they determine who to approach:

To exercise any of the rights in section 7, the fastest route is /mis-datos and /borrar-mis-datos, or contacting the administration team of the server. If you get no response, you can reach whoever operates Argos through the support server linked on the bot's website.