DiscordMCP

Privacy notice

First, because it is the unusual part: these pages load nothing from other servers, with exactly one exception, which is in section 5 and concerns pictures that live at Discord. No fonts, no scripts, no analytics, no ad networks, no embedded video. There is therefore no consent banner either, because there is nothing to consent to.

Who is responsible

Sven Mainka
Eifelblick 11, 56566 Neuwied, Germany
Email: hello@discordmcp.de

What simply visiting produces

The web server records every request: shortened IP address, time, the address requested, the status code and your browser's identifier. That is needed to run the service and to notice attacks. The legal basis is our legitimate interest under Art. 6(1)(f) GDPR. These logs are deleted after seven days.

Cookies

Two, and both are technically necessary. One keeps you signed in, the other remembers your choice of language. There are no analytics cookies, none from third parties, and none that follow you across sites. The session cookie holds a random number and nothing about you.

Signing in with Discord

We offer no password sign-in. You sign in through Discord. We ask for exactly two permissions there, identify and email, which give us: your Discord id, your display name, your email address if it is verified there, the id of your profile picture and, if you have one, the id of the frame around it.

We deliberately do not ask which servers you are on. That is a separate permission at Discord and we do not hold it. What your bot asks Discord for is a different matter and has a section of its own further down.

Your account here is kept under the Discord id, not under the email address. That is deliberate: email addresses change hands, an id does not. The basis is performance of the contract under Art. 6(1)(b) GDPR.

The access Discord grants us at sign-in is kept, in a file of its own on the server, readable only by the service account this portal runs as, and outside the backups of the customer data. It serves exactly one purpose: at most every fifteen minutes, and only while somebody is looking at a page, to ask Discord whether your display name or your picture has changed. It can read no more than that, neither your servers nor your messages, and it can act in your name nowhere. We delete it as soon as you sign out everywhere or close your account, and in any case thirty days after your last sign-in. Using the site does not push that date back.

Pictures from Discord, the one exception

These pages load nothing from other servers, with one exception: pictures that live at Discord. Your browser fetches them from there, and there are four kinds.

Your own profile picture and the frame around it, in the header. Your Discord server's icon and your bot's picture, on the page about your instance. That is all of them, and all four come from the same address.

What Discord learns: that somebody at your IP address fetched a picture at that moment. Not which page you are looking at, because we send no referrer at all. And you are signed in to Discord anyway, or you could not use this service.

We store the ids of those pictures, not the pictures. Where none is set nothing is fetched, and we draw a circle with the initial instead. The page's security policy permits that one address and no other. No fonts, no scripts, no analytics, no ad networks, no embedded video. There is therefore no consent banner either, because there is nothing to consent to.

Your bot token

The token you paste during setup passes through this portal into your own instance's configuration and is erased here the moment the instance reports that it started. What stays behind is a fingerprint, a check value that lets us notice the token has changed and with which nothing can be done. The token itself then lives only in your instance's configuration file.

What your bot asks Discord for

Your bot is your own Discord application and its token belongs to you. What is asked of Discord with it is still processing, so it is written down here.

During setup, once: who the bot is, meaning its id, its name and its picture. Which servers the bot is already on, so that we can recognise your new server without you having to look up an eighteen-digit number. Your server's channels, to create the journal channel or find an existing one again. And a single member search, with which we check whether a Discord setting your assistant will need is switched on; the result of that search is not stored.

Afterwards, while it runs, your instance asks at most every ten minutes for: your server's name and icon, the number of its members, the name of the journal channel, and your bot's name and picture. That is what stops the page showing the photograph taken on setup day for ever when you rename your server.

Everything else your bot does at Discord happens because your assistant called a tool, and it is written into your journal channel.

What we store about your instance

The id, name and icon of your Discord server. The id, name and picture of your bot. The journal channel, your instance's address, its plan and the time it was set up. Pictures always as an id, never as a file.

That is the service itself. Without it there is nothing to run.

Operating data from your instance

So that we can see whether your instance is running, and so that you can too, the server records a reading every few seconds: whether the service is up, whether it answers, how long it has been running, which version, when it was last used, how many tool calls there have been since it started, and the number of members on your server.

Alongside that, which assistant software connected and when: Claude or ChatGPT, say. Your instance knows the name that software gives when it connects, and nothing beyond it. The content of your conversations with the assistant does not pass through us and is stored nowhere: we see the number of calls, not what was in them.

The legal basis is our legitimate interest in running the service and in diagnosing faults, under Art. 6(1)(f) GDPR. These readings are overwritten as they go and are not kept as a history.

Consent for the dangerous tools

When you switch on a capability such as banning or deleting, we record: which capability, when, in which language, the exact wording of the warning that was on the screen, its checksum, and the IP address. That is the evidence that you agreed to a particular wording rather than to some wording. The legal basis is our legitimate interest in being able to prove it, under Art. 6(1)(f) GDPR. We keep these records for as long as the capability is switched on, and for three years after.

Who else sees any of it

The service runs on a rented server in Germany; the provider processes the data on our behalf and may not use it for anything else.

Signing in necessarily involves Discord Inc. in the United States, because a Discord service cannot work any other way. That covers signing in, the pictures in the section above, and every action your bot performs on your server.

Beyond that we pass nothing on. There are no ad networks, no analytics services, and no sale of data.

How long we keep things

Account data for as long as your account exists.

If you delete your account, your instance is switched off immediately: the service stops, the address stops answering, and every session on every device ends. We then hold the switched-off directory for 30 days. In that time you simply sign in again and your account is back; you set the instance up once more and your old state comes back with it.

After 30 days the account, the instance and the directory are deleted for good. That happens by itself and without asking. What commercial and tax law require to be kept, essentially invoices, remains for the statutory periods and is not used for anything else.

Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection. An informal message to the address above is enough; we need no particular form.

You may also complain to a data protection authority, usually the one for your state.

Changes

When the service changes, this notice changes with it. The date above says which version you are reading.

Last changed: August 14, 2026