Argos is a security and moderation bot that operates inside a Discord server. This policy explains what data it processes, for what purpose and for how long. By using the server or the bot's web portal, you accept what is described here.
HMAC-SHA256); it is never stored in plain text and the record is deleted automatically after 90 days. On IPv6 connections only the network prefix of your connection is processed, not your device's specific address.Exclusively for the security and moderation of the server: applying and auditing sanctions, detecting raids and alternate accounts, preventing attacks (anti-nuke/anti-raid) and giving staff investigation tools.
Our legal basis is the legitimate interest in protecting the community against abuse, attacks and sanction evasion (Art. 6(1)(f) GDPR), and the enforcement of the server rules you accept by taking part. Processing is limited to what is strictly necessary for that security purpose.
Changing your IP address is trivial and free (restarting the router, using mobile data, another wifi network). That is why a sanctioned person can come back again and again by creating new accounts. To prevent this, the verification portal measures technical characteristics of your browser: browser and system model, language, time zone, screen size and density, number of cores and approximate memory, whether the device is touch-enabled, and the result of two standard graphics tests (a canvas drawing and your graphics card model).
HMAC-SHA256). Neither your browser nor your computer can be reconstructed from it.Security cookie. The portal also stores a single cookie (argos_id) containing a random number that identifies your browser, for the same purpose: detecting that a sanctioned account is coming back. It is a strictly necessary cookie for the security of the service: it is not advertising, it does not track you outside this portal and it is not shared with anyone. It is HttpOnly (no script on the page can read it), lasts one year, and you can delete it from your browser whenever you want.
Virtual machine detection. From your graphics card model we infer whether the session appears to run inside a virtual machine, which is common in automated attacks. By default this only raises an internal notice for staff and does not block anyone, precisely because an old computer or a browser with hardware acceleration turned off produce the same signal.
To classify an IP as a VPN or proxy we use network reputation services (proxycheck.io, or failing that ip-api.com). Those services receive only your IP address for analysis; they do not receive your Discord identity, your browser fingerprint or any other data. Each one handles that query under its own privacy policy.
To detect the TOR network we periodically download the public exit-node list from the Tor Project and compare it on our own server: that check sends no data about you to anyone.
Authentication is done through Discord's official login (OAuth2), which only gives us your basic identifier.
Data is stored on our own, access-restricted server, not on third-party devices. Retention:
The moderation team can enable closer monitoring of one specific account when there is a well-founded suspicion of abuse. Depending on the option chosen, this may log their reactions or copy their public messages to a private staff channel in real time.
You have the right to access your data, to rectify it, to request its deletion, to object to the processing and to request the portability of what you provided. You do not need to write a formal request: you can exercise these rights from Discord itself.
/mis-datos — access. We send you by direct message the detail of everything stored and linked to your account in that server. It is never posted in a channel. For security the report does not include the hash of your connection or the accounts linked to it: those are third-party data and would allow probing how evasion detection works./borrar-mis-datos — deletion. This records your request. It is not executed automatically: an authorised person reviews it, and you are told the outcome by direct message, whether it is accepted or rejected (with the reason).We resolve requests within a maximum of 30 calendar days from the moment they are recorded.
If your request is approved, your ordinary activity is deleted: your messages logged when edited or deleted —including the re-hosted attachments, which are removed from disk—, your joins, your name and nickname changes, your reactions, your voice activity and the record of which invite you used.
There are two things that are not deleted on request, and we want to be transparent about why:
If you believe a connection or device block has affected you by mistake, tell the staff: an appeal system exists and the block can be lifted, which erases both the connection and the device associated with it.
Deletion requests are resolved by the bot operator or by a person they have authorised expressly and by name. Deliberately, holding a role as administrator or moderator in a server is not enough: if it were, someone with access to a role could erase the evidence of a sanction by presenting it as an exercise of the right to be forgotten. Every approval or rejection is logged with the identity of whoever resolved it.
You may also lodge a complaint with the data protection supervisory authority of your country if you consider that we have not handled your request properly.
As with Discord, the service is intended for people who meet the minimum age required by Discord's Terms (13 years, or higher where your country requires it).
We may update this policy. The date of the last update appears at the top of the document.
Two roles are worth distinguishing, because they determine who to approach:
To exercise any of the rights in section 7, the fastest route is /mis-datos and /borrar-mis-datos, or contacting the administration team of the server. If you get no response, you can reach whoever operates Argos through the support server linked on the bot's website.