01Who we are
Auragon is a gaming community on Discord. We run three things this policy covers: AuraKitten, our Discord bot; AuraDash, its dashboard at dashboard.auragon.gg; and this website, auragon.gg. Auragon is based in the Netherlands and is the controller of the personal data described here.
- Privacy questions and data requests: [email protected]
- Anything else: [email protected]
We haven’t appointed a data protection officer; [email protected] reaches the people who run Auragon.
02What this policy covers
This policy covers:
- AuraKitten in any Discord server that uses it, including the commands you run and the features server staff switch on.
- AuraDash, where members see their progress and server staff set AuraKitten up.
- The web casino, which is only offered in the Auragon Discord.
- This website, auragon.gg.
It doesn’t cover Discord itself, or Twitch, YouTube and Ko-fi. They have their own privacy policies. Server staff can see some data about members through AuraKitten (see who can see your data) and are responsible for how they use it in their server.
03What we collect
From Discord, when you’re in a server that uses AuraKitten
- Your Discord user ID, username, display name, server nickname and avatar.
- Your roles, when you joined and left the server, and which invite you joined with.
- Your activity: messages you send (see messages and member data), time spent in voice channels, and the commands and buttons you use.
- The age of your Discord account, which is worked out from your user ID.
What you give us
- Intro posts and images you post in quest channels (such as an introductions or selfie channel), so AuraKitten can check that they count for the quest.
- Voice messages you ask AuraKitten to transcribe.
- Scam reports you send.
- Accounts you choose to link. For example: a Minecraft account, or the accounts connected to your Discord profile (like Steam, Twitch or X), which Discord shares with us when you use AuraKitten’s account-linking page.
- If you’re a creator: your Twitch or YouTube channel, when server staff add it for live and upload alerts.
What AuraKitten creates as you use it
- XP, levels, ranks, Shards ◆, quests, streaks, Seasons, competitions, giveaway entries and web casino results.
- Invite and referral records: who invited whom, and whether the new member became active.
- Moderation records: risk scores, alerts and the actions staff took (see automated moderation and AI).
- Usage analytics: events such as “sent a message” or “completed a quest”, with your user ID, the channel and details like message length. Not the message text.
From other services
- Twitch: when a creator’s channel is linked, AuraKitten reads that channel’s chat and live status for creator stats and viewer rewards. It records the Twitch username of people who chat there, even if they aren’t on Discord.
- YouTube: notifications about new uploads on linked channels.
When you log in to AuraDash or the web casino
You log in with Discord. AuraDash only receives your Discord user ID, username and avatar, plus the list of servers you’re in and a login token, so it can show you the right servers. It doesn’t ask Discord for your email address.
When you visit auragon.gg
The website has no accounts or ads. It uses Cloudflare Web Analytics to measure page visits and performance without analytics cookies or individual visitor profiles. Like any website, the servers that deliver it (Cloudflare and our host, OVH) see your IP address and basic request details. Some pages show a live strip of the Auragon Discord, which loads member avatars straight from Discord’s image servers.
04Messages and member data
Discord calls two kinds of data “privileged” and asks bots to explain why they need them. AuraKitten uses both. Here is what for.
Message content
AuraKitten reads the text of messages in the servers it’s in, to:
- give XP and check whether a message counts for a quest;
- check intro posts and images in quest channels;
- spot scams, phishing links and spam bots;
- keep a moderation log of deleted and edited messages, if the server’s staff switched moderation on.
Most of this happens in memory and the text is thrown away straight after. What is stored: the deleted and edited message log (30 days), intro posts that were rejected (kept for staff to review), and short message previews inside moderation alerts. We don’t use your messages to train AI models.
Server members
AuraKitten uses the member list of the servers it’s in, to:
- welcome new members, with a welcome card that shows your avatar;
- protect the server against raids and brand-new spam accounts;
- show names and avatars on leaderboards and in AuraDash;
- give rank, booster and supporter roles, and track invites.
AuraKitten doesn’t request or use your online status or what you’re playing.
05Why we use it, and on what legal basis
The GDPR asks us to name a legal basis for each use. These are ours:
| Purpose | Data | Legal basis |
|---|---|---|
| Community features: XP, Shards, quests, Seasons, giveaways, welcome cards, leaderboards | Discord profile, activity, progress | Legitimate interest: running the features the server switched on |
| Keeping servers safe: scam, raid and spam protection, moderation logs | Messages, account age, profile, moderation records | Legitimate interest: security and preventing abuse |
| Protecting all servers that use AuraKitten: using ban and moderation patterns across servers to detect scams and ban evasion | Ban records and patterns, such as name patterns of banned accounts | Legitimate interest: protecting communities from scams and ban evasion |
| Keeping security and moderation records after a deletion request | Ban records, moderation alerts, scam reports and time-limited screening/message logs | Legitimate interest: preventing ban evasion |
| Features you ask for: transcription, AuraDash, the web casino | Voice message, login details, game results | Performing our agreement with you (our Terms) |
| Linked accounts and creator alerts | The accounts or channels you link | Your consent, which you can withdraw by unlinking or emailing us |
| Invite tracking and referral rewards | Who invited whom, activity | Legitimate interest |
| Analytics: how features are used, keeping AuraKitten working | Events with user IDs, no message text | Legitimate interest |
| Supporter and booster perks | Supporter and booster roles and history | Performing our agreement with you |
| Answering your requests and meeting legal duties | Your email and what you send us | Legal obligation |
Where we rely on legitimate interest, you can object. See your rights.
06Automated moderation and AI
Sentinel, AuraKitten’s scam and raid protection
When a server uses AuraKitten’s Moderation module, a system called Sentinel scores new members and messages for signs of scams, phishing and spam bots. It looks at things like account age, known phishing links, messages in a trap channel, and raid patterns. Depending on the score, it can:
- only log it, or alert the server’s moderators;
- delete the messages and time the member out for a while;
- put the member in quarantine (a role with limited access);
- ban the member, only in the most certain cases.
A new server starts in Log only: AuraKitten only watches and reports until its staff switch on taking action. Automatic bans stay in a “would ban” test mode until they have proven accurate. Moderators can undo actions and clear alerts.
AuraKitten also learns name patterns from accounts a server has banned, to spot ban evasion. Those patterns only alert moderators or apply a short timeout; they never ban on their own. Ban and moderation patterns, such as the name patterns of banned accounts, may be used across all servers that use AuraKitten, to detect scams and ban evasion and protect those communities. We do this on the basis of our legitimate interest in keeping those communities safe; you can object to it (see your rights). Server staff can also set roles that trigger an action, for example removing a member who is given a role for being under the server’s age limit.
If you think AuraKitten got it wrong, ask the server’s moderators first; they can undo it. You can also email [email protected] and a person will look at it.
AI services
Some checks use outside AI services. They receive only what the check needs:
- Google Gemini: text of messages that look like they might be scams; images posted by very new or flagged accounts; intro posts and quest images, to check they fit the quest (it is told not to identify people or guess ages); usernames of banned accounts, to suggest ban-evasion patterns; players’ names in
/duel, to write the commentary; and voice messages, when Mistral can’t transcribe them. - Mistral: voice messages you ask AuraKitten to transcribe.
We don’t store transcripts. When an AI service is unavailable, AuraKitten falls back to its own rules.
07Who can see your data
- Other members of the same server see what AuraKitten posts there: leaderboards, level-ups, welcome cards, quest progress you share, and recent web casino results.
- Server staff see moderation alerts and logs, and member details in AuraDash, for their own server only.
- Anyone can see a server’s public stats if its staff switched them on: the top members’ names, avatars, levels and XP. auragon.gg shows these for the Auragon Discord.
- Other servers that use AuraKitten benefit from ban and moderation patterns, such as name patterns of banned accounts, to detect scams and ban evasion (see automated moderation and AI).
- Our service providers, listed below, only to run AuraKitten, AuraDash and the website.
- Authorities, only when the law requires it.
We don’t sell personal data and we don’t use it for advertising.
08Service providers and other services
| Who | What for | Where |
|---|---|---|
| OVH | Hosting of AuraKitten, AuraDash and the website | EU (Germany) |
| MongoDB Atlas | AuraKitten’s main database | EU (Germany); US company |
| Cloudflare | Delivering auragon.gg, security and website analytics | Worldwide; US company |
| Backblaze B2 | Encrypted disaster-recovery backups | EU storage region; US company |
| Google (Gemini) | AI checks, see above | US |
| Mistral | Voice message transcription | EU (France) |
| Discord | The platform AuraKitten runs on, and login | US; its own controller |
| Twitch | Chat, live status and viewer rewards for linked creators | US; its own controller |
| YouTube (Google) | Upload alerts for linked creators | US; its own controller |
| Ko-fi | Voluntary support payments | Its own controller |
Discord, Twitch, YouTube and Ko-fi decide themselves how they handle your data; their own privacy policies apply. Ko-fi handles support payments. We don’t receive your card details; we only see the details Ko-fi shows a creator about a supporter, and use them to give you your perks.
09Data outside the EU
We keep our own data in the EU. Some providers above are based in the US or work worldwide, so data can reach them outside the EU. Where that happens, we rely on the safeguards the GDPR allows, such as the European Commission’s standard contractual clauses or the EU-US Data Privacy Framework where the provider is certified under it. Email [email protected] if you’d like to know more.
10How long we keep it
| Data | How long |
|---|---|
| Your profile and progress in a server: XP, Shards, quests, Seasons, referrals, supporter history, linked accounts | As long as the server uses AuraKitten, also after you leave it, so it’s there if you come back. Ask us and we delete it sooner. |
| Everything about a server, after it removes AuraKitten | Deleted 90 days after removal. Re-adding AuraKitten within those 90 days restores it. |
| Deleted and edited message log | 30 days |
| Sentinel risk scores and join checks | 30 days |
| Moderation alerts, bans, scam reports, rejected intro posts, learned name patterns | As long as the server uses AuraKitten |
| Usage analytics | Up to 1 year |
| Accounts connected through AuraKitten’s linking page | Until you ask us to remove them |
| Recent web casino results shown to others | 24h |
| Transcription usage counters | About 2h. Voice messages and transcripts aren’t stored. |
| Technical logs | A short rolling log that is overwritten automatically |
| Encrypted recovery backups | Backblaze B2 versions are locked against deletion for at least 30 days. Older retained backups may remain longer; deletion from live data does not immediately erase backup copies. |
| Minimal recovery record of a deletion request: account/server IDs, scope and dates | Kept while a recoverable backup may still contain the deleted data, to check deletion requests before restored data returns to service. |
11Your rights
Under the GDPR you have the right to:
- get a copy of your data (access), also in a format you can reuse (portability);
- have data that is wrong corrected (rectification);
- have your data deleted (erasure);
- have us limit how we use it (restriction);
- object to uses based on our legitimate interest (objection);
- withdraw consent you gave, such as for a linked account, at any time.
In a server that uses AuraKitten, you can view and delete your own data for that server yourself, with /privacy view and /privacy delete.
For anything else, such as a correction, an objection, or a request that covers more than one server, email [email protected] with your Discord username and user ID, and the server it’s about if it’s about one server. We handle these requests by hand and answer within one month. We may ask you to confirm the request from your Discord account, so nobody else can ask for your data.
After a deletion, the live server data matched to your account is removed, apart from security and moderation records: bans, moderation alerts and scam reports, plus screening and join records and deleted/edited message logs that expire after 30 days. We also keep a minimal recovery record of the deletion request: account/server IDs, scope and dates. The command explains these retained records before you confirm. Data in encrypted recovery backups remains until the backup is removed after its retention period; the 30-day storage lock prevents immediate erasure. Before restored data returns to service, deletion requests must be checked and applied. If their complete history cannot be verified, the restored data must stay out of service.
You can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the authority where you live. We’d appreciate the chance to sort it out with you first.
12Age
AuraKitten and AuraDash are for people who meet Discord’s minimum age: 13, or 16 where local law requires it. We don’t knowingly collect data from anyone younger. If you think we have, email [email protected] and we’ll delete it.
The Auragon Discord itself is a separate matter: it’s an 18+ community, and its staff remove members who are under 18.
13Cookies and browser storage
- auragon.gg sets no cookies of its own. Cloudflare Web Analytics measures visits and performance without analytics cookies or individual visitor profiles. Cloudflare may set a cookie it needs for security.
- AuraDash sets one login cookie, needed to keep you logged in. It lasts until you log out or it expires, after at most 30 days.
- The web casino keeps your login in your browser’s local storage for 8h.
These are strictly necessary, so they don’t need a cookie banner.
14Security
Your browser connects to our websites and AuraDash over HTTPS. Only the people who run Auragon can reach our servers and databases. AuraDash only shows server staff the data of servers they manage. No system is perfectly secure; if a data breach puts your rights at risk, we’ll tell you and the Autoriteit Persoonsgegevens as the law requires.
15VALORANT features
AuraKitten’s VALORANT features are switched off, and no VALORANT data is being collected. Linked-account data from the earlier version (linked Riot IDs and stats) was deleted in September 2026. If these features come back, we’ll update this policy first.
16Changes to this policy
When we change this policy, we update the date at the top. If a change matters for you, we’ll also announce it in the Auragon Discord. Our Terms of service explain the rules for using AuraKitten and AuraDash.
17Contact
- Privacy and data requests: [email protected]
- General support: [email protected]