1Who this covers
This policy is issued by the creators of Armilla ("Armilla", "we", "us"), and describes how we handle information relating to visitors of armilla.dev and, once the service opens, the people and communities who use it.
Armilla is an independent project. It is not affiliated with, endorsed by, or sponsored by Discord Inc. Your use of Discord itself is governed by Discord's own privacy policy, which we do not control.
Armilla is not directed at children. Discord's own terms set the minimum age for using the platform, and we do not knowingly collect data from anyone below it. If you believe we hold data about a child, tell us and we will delete it.
2The short version
- This website sets no cookies, runs no analytics, and embeds nothing from third parties.
- We do not sell personal data, and we do not use it for advertising or profiling.
- When the service opens, we intend to hold the minimum needed to make it work: identifiers, configuration, and operational records.
- We do not read, mine, or store message content beyond what a feature you have deliberately switched on requires.
3The service, when it opens
This section is a statement of intent, not a description of something running today. When Armilla launches, we expect to process the following categories:
- Discord identifiers. Numeric IDs for servers, channels, roles, and users, so that settings and permissions can be attached to the right place. IDs are supplied by Discord and are not secret.
- Configuration. The choices an administrator makes: enabled features, thresholds, templates, routing, and similar. This is the bulk of what we store.
- Operational records. Logs of actions taken, errors, and rate-limit accounting, needed to run the service, debug it, and show administrators what happened and why.
- Feature-specific data. Where a feature cannot work without retaining something — for example a moderation record that must persist to be reviewable, or a scheduled item that must persist to fire later — we retain the minimum that feature requires.
- Integration credentials. Where you connect Armilla to an external service, the tokens or keys needed to talk to it. These are held encrypted at rest and are never shared with third parties.
We do not build advertising profiles, sell data, or use community content to train machine-learning models.
4Why we process it
For anyone covered by the UK GDPR or EU GDPR, our lawful bases are:
- Performance of a contract — to provide the service an administrator has asked us to provide.
- Legitimate interests — to keep the service secure, available, and free of abuse, and to diagnose faults.
- Consent — for anything optional, which we will ask for separately and which you can withdraw.
- Legal obligation — where we must retain or disclose something by law.
5Hosted apps
The following applies when the service opens.
Armilla will let you run your own Discord application through our infrastructure instead of using our public instance. If you do that:
- You supply the application's token so that we can operate it on your behalf. Tokens are stored encrypted at rest, used only to run the connection you asked us to run, and never shared with other users.
- You remain the controller of your own application and are responsible for its conduct and for what you tell your own community about it. We act as a processor for that connection.
- You can revoke access at any time by regenerating the token in Discord's developer portal, or by asking us to delete it. We will remove the stored credential and stop the connection.
6How long we keep it
The following applies when the service opens.
- Configuration — while Armilla is present in your server, and for a short grace period after removal so an accidental kick does not destroy your setup.
- Operational logs — a rolling window, kept short and measured in weeks rather than years.
- Credentials — until you revoke them or remove the integration.
- Correspondence — as long as needed to handle the matter and keep a reasonable record.
Exact retention periods will be stated in the final policy published at launch. Removing Armilla from a server and waiting out the grace period deletes its configuration.
7Who else is involved
We keep the list of third parties deliberately short. Today, with only this website running, it is one:
- Cloudflare — serves this website and processes request logs.
The following applies when the service opens. Armilla operates on Discord, so any data that travels over Discord is also handled by Discord under its own policy. If we add anyone else — a hosting provider or a database host, say — they will be named here before they start processing anything.
We do not disclose personal data to anyone else except where we are legally required to, or where it is necessary to investigate abuse or protect the rights and safety of others.
8Where it is processed
Armilla is served from a global content network, so requests are handled by whichever location is nearest to you, and our providers may process data outside your country. Where we transfer personal data out of the UK or EEA, we rely on an adequacy decision or on standard contractual clauses with the provider concerned.
9Your rights
If you are covered by the UK GDPR or EU GDPR, you have the right to ask us for a copy of the personal data we hold about you, to have it corrected or erased, to have our processing restricted, to object to processing we carry out under legitimate interests, and to receive data you gave us in a portable form. Where we rely on consent, you can withdraw it at any time without affecting what we did beforehand.
Ask at contact@armilla.dev and we will respond within one month. Some of what we hold is keyed to a Discord identifier rather than to a name, so we may need you to demonstrate control of that account before we act.
Where an administrator runs their own app on Armilla, they are the controller of that connection and we are the processor — so a request about data held there is one we will pass to them rather than decide ourselves.
If you think we have handled your data badly, tell us first and we will try to put it right. You also have the right to complain to your data protection authority — in the UK, the Information Commissioner's Office; in the EU, the supervisory authority for the country you live in.
10Security
We use encryption in transit, encryption at rest for credentials, access controls on our infrastructure, and least-privilege defaults. No system is perfectly secure, and we will not pretend otherwise; if a breach affects your data and the risk warrants it, we will notify you and the relevant regulator as required by law.
11Changes
We will update this policy as Armilla develops. The date at the top always reflects the current version. If a change materially affects how we handle your data, we will make that clear rather than quietly editing the page.
12Contact
Questions, requests, or complaints: contact@armilla.dev.