YOUR INFORMATION
Privacy Policy
Draft updated: 20 September 2026
What our applications collect, why they collect it, how long it is kept, and how to get a copy or have it deleted.
1. Introduction
This policy explains how information is handled when you use the website at ourapps.ourestate.net, or any application we publish that links to it, including our Discord applications. Together these are “the services” and each one is “an application”. It covers what is collected, why, how long it is kept, who it is shared with, and how you can obtain a copy or have it deleted.
“We”, “us” and “our” mean the operator of Our Apps, the publisher of the services. “Discord” means Discord Inc. and its affiliates. This policy does not describe what Discord itself does with your information: that is covered by Discord’s Privacy Policy, together with the permissions you grant when an application is added to a server or authorised for your account. Our Terms of Service describe how the services may be used.
Our applications are independently operated. They are not endorsed by, affiliated with, or sponsored by Discord.
2. Information We Collect
We collect the least information each feature needs to work. The categories below are those our applications use; a given application uses only the parts its own features require, and an application with no need for a category does not receive it.
Discord account and server data
- Account identifiers — your Discord user ID, username and display name, and your avatar, so an application can recognise your account between sessions.
- Server and channel identifiers — the numeric IDs of the servers (guilds) and channels where an application is installed, and the role information that gates its commands, so it knows where it may respond and who may ask it to.
- Interaction data — the commands, buttons, select menus and modal submissions you send to an application, the options you choose, the text of the message that triggered a command where a feature genuinely needs that text, and the response the application returns.
- Application state — the settings, progress, scores and other records an application keeps for you or for a server, so your progress survives a restart.
- Authorisation tokens — where you authorise an application to act for you through Discord’s authorisation flow, the access and refresh tokens issued for that authorisation, kept in secret storage and removed when you revoke it.
Website and technical data
- Visiting this website — the site sets no cookies, runs no analytics or advertising tags, accepts no form submissions, and makes no requests to third-party domains: its styles, fonts and icons are served from this domain. Our hosting provider processes the network requests needed to deliver and protect the site, which includes technical information such as the request path, timestamps and network addresses in its operational logs, as any web host does.
- Diagnostic records — error reports and service logs from our applications and their host, used to keep the services working and to find faults and abuse.
- Messages you send us — if you contact us about a problem or a privacy request, we hold your message and the contact details you used so that we can answer it.
We neither request nor want special-category information, such as health, political, religious or biometric details. Please do not send it to an application or to us, and do not upload anyone else’s data unless you are entitled to share it.
3. Discord Applications: What We Store, Why, and How to Delete It
Discord’s developer requirements call for a clear statement of what a bot stores, why it stores it, and how a user can have it removed. This section answers those three questions directly; the rest of this policy applies as well.
What our Discord applications store
- Account identity — your Discord user ID, together with the username and display name Discord reports for you, so the bot can tell you apart from other members and keep your records attached to you.
- Placement — the IDs of the servers and channels an application is installed in, plus the permission and role information needed to decide whether a request is allowed.
- Interactions — the commands and component interactions you send, the options you select, and the message text that triggered a command where the game needs that text to answer it.
- Game state — your progress, scores, chosen difficulty and preferences, and any server-level configuration an administrator has set.
- Time-limited credentials — an authorisation token, only where you have authorised the application to act on your behalf, kept for as long as that authorisation is active.
Why the bot stores it
Every item above exists to provide a feature you asked for: to authenticate the interaction and check permissions, to answer the command or message, to keep your progress between sessions, to apply the server’s configuration, and to protect the service from abuse. We do not store this information for advertising or profiling, we do not sell or rent it, and we do not use it to train machine-learning models.
How to have your data deleted
- Send a deletion request to the privacy contact in section 13, or have an administrator of the server send it. Include the Discord user ID or server ID the data belongs to, and what you want removed.
- We reply to confirm receipt. We ask only for the minimum evidence needed to be satisfied that the request comes from the person or server the data belongs to, and we never ask for your Discord password or an authentication token.
- We delete or anonymise the records held for that person or server, remove any stored token for that authorisation, and tell you what we did. We aim to complete a verified request within 30 days.
- You can also act inside Discord straight away: remove the bot from a server, or revoke an application’s access to your account under User Settings → Authorised Apps. This removes access for that server installation or account authorisation. Other server or user installations may remain active. Removing access does not by itself erase stored records or end processing of those records under the retention criteria in section 7; use the deletion request process above to ask for their removal.
If an application is retired, or removed from every server it was installed in, we delete the data it stored as part of shutting it down.
4. How We Use Information
We use the information described above only to:
- provide the game, tool or feature you asked for, and keep your state so that it works across sessions;
- authenticate interactions, verify permissions, and apply the settings that you or a server administrator chose;
- operate, monitor, debug and secure the services, including investigating faults and detecting abuse or attempts to break the rules;
- answer support questions and privacy requests;
- meet our legal obligations, enforce our Terms of Service, and protect the rights of users, of Discord, and of the public.
We do not sell or rent personal information, we do not use it for advertising or to build profiles of you across other services, and we do not make automated decisions about you that produce legal effects. Where an application uses a language model to generate an in-game response, the content needed for that response is processed to produce it, and is not used to train models.
5. Legal Basis and Consent
Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases:
- Performance of a contract — processing needed to provide the feature you asked for when you use an application, including keeping your progress and answering your commands.
- Legitimate interests — keeping the services working, secure and free of abuse, and answering support and privacy requests. We balance those interests against your rights, and you may object (see section 10).
- Consent — where we ask for your agreement, for example for an optional permission or an optional notification. You can withdraw consent at any time by changing the setting, removing the application, or contacting us; withdrawing it does not affect processing that has already taken place.
- Legal obligation — where we must keep or disclose information to comply with the law.
Under the Australian Privacy Act 1988 (Cth), we handle personal information in accordance with the Australian Privacy Principles, collecting it from you or from Discord. Granting an application a permission or scope is how you direct the information the feature needs; you are never required to grant more than a feature needs, and you can go on using Discord without our applications.
6. Data Sharing and Third Parties
We do not sell or rent personal information, and we do not share it with advertising networks, data brokers, or analytics services that track you across sites.
- Discord — an application receives only what Discord sends it for the permissions and scopes you granted. Our applications are independently operated and are not endorsed by Discord, and what Discord does with your information is governed by Discord’s Privacy Policy.
- Hosting, network and infrastructure providers — the website, the bot processes, and the stores that hold application data run on our own server environment and on provider infrastructure, including Cloudflare for delivery and network protection. These providers process information on our instructions, to host, deliver, log and protect the services, and they may process requests in countries other than yours (see section 11).
- Legal, safety and enforcement — we may disclose information where the law requires it, or where it is needed to investigate abuse, fraud or a security incident, or to protect somebody’s safety. Where we are permitted to, we tell the person concerned.
- Places you send results — if you use a feature that posts into a channel, or shares a score or an answer, that content becomes visible to everyone who can see that channel. Sharing it is your choice, and it is no longer private to you.
We do not hand your information to anyone else for their own purposes.
7. Data Retention
We keep personal information only while we need it for the purposes in section 4, and delete or anonymise it once those purposes end. Because the applications differ, we apply these criteria rather than a single fixed period:
- Account data, game state and server configuration — kept while the application is in use for you or your server, and while the progress it holds is useful to you.
- Interaction content — processed to answer the interaction. It is kept beyond that only where a feature stores history on purpose, such as a results or study log you can revisit.
- Authorisation tokens — kept only while the authorisation is active, and deleted when you revoke it or the application no longer needs it.
- Diagnostic logs — kept only as long as needed to investigate faults and security events, then deleted or overwritten on a rolling basis.
- Support and privacy correspondence — kept while the matter is open, and afterwards only as long as needed to show how it was handled.
For a verified request under sections 3 and 10 we delete or anonymise the records concerned, including any stored token, and aim to complete the work within 30 days. Information obtained through the Discord API is never kept longer than the permitted functionality of the application requires.
Two limits are worth stating plainly. First, backups: provider and platform snapshots are overwritten on their normal cycle, so a deletion can take a little longer to disappear from older copies; we do not restore deleted data except for disaster recovery, and the deletion is re-applied afterwards. Second, legal retention: we may keep a minimal record where the law requires it, for example a note that a deletion request was received and actioned.
If an application is discontinued, we delete the data it held, subject to the same two limits.
8. Security
We take reasonable technical and organisational steps to protect the information we hold:
- access to production systems and data stores is limited to the operator, and is not shared with third parties;
- credentials, tokens and keys are kept in dedicated secret storage rather than in source code or committed configuration;
- traffic between your client, Discord, our applications and the website is encrypted in transit using HTTPS/TLS;
- we request the minimum Discord permissions and scopes a feature needs, and remove information we no longer need instead of holding it indefinitely;
- we keep hosting configuration and dependencies current, and monitor the services for faults and abuse.
No method of transmission or storage is perfectly secure, so we cannot promise absolute security. If we become aware of a breach likely to affect your rights, we will tell the people affected and the relevant regulator as the law requires. Please use a strong, unique password for Discord, do not share your account, and never send anyone a password or an authentication token.
9. Children’s Privacy
Our applications are not directed to children. Discord requires its users to be at least 13 years old, and older where local law sets a higher minimum (Discord’s Terms of Service state the age that applies); we apply that same minimum. We do not knowingly collect personal information from anyone below it, and we do not ask for age information beyond what Discord itself provides.
If you are a parent or guardian and you believe a child below the applicable minimum has used one of our applications, contact us using section 13 and we will delete the information held for that account and confirm that we have done so. If you are below the minimum age yourself, please stop using the applications and ask a parent or guardian to contact us.
10. Your Rights: Access, Deletion and Portability
Depending on where you live, you may have some or all of the following rights over the personal information we hold about you:
- Access — to be told whether we hold information about you, and to receive a copy of it.
- Correction — to have inaccurate or incomplete information corrected.
- Deletion — to have your information erased, including any stored token and the records attached to your Discord user ID or your server.
- Portability — to receive the information you gave us in a structured, commonly used, machine-readable format, or to have it sent to another provider where that is technically possible.
- Restriction and objection — to ask us to stop or limit processing, including processing we base on legitimate interests.
- Withdrawal of consent — where we relied on your consent, to withdraw it at any time.
To make a request, use the contact details in section 13. We ask only for the minimum information needed to confirm that the request comes from the person concerned, or from an administrator of the server it concerns. We do not charge for a first request, and we aim to respond within 30 days. If we cannot do what you asked, we will explain why and how to challenge that decision.
If you are not satisfied with our response, you can complain to a regulator: in Australia, the Office of the Australian Information Commissioner (oaic.gov.au); in the United Kingdom, the Information Commissioner’s Office; in the European Union, the supervisory authority for your country of residence. We would rather hear from you first, so please contact us before escalating.
11. International Transfers
We operate from Australia, and the providers that host and protect the services run global networks, so information may be processed in a country other than the one you are in, including the United States. That is inherent in operating a Discord application: Discord itself works internationally, and a request may be handled wherever the nearest infrastructure is.
Where personal information is transferred out of the European Economic Area, the United Kingdom or Switzerland, we rely on a recognised transfer mechanism, such as the standard contractual clauses our providers offer or an adequacy decision covering the destination. Where the Australian Privacy Principles apply, we take reasonable steps to ensure that an overseas recipient handles the information consistently with those principles, and we remain accountable for the information we hold. You can ask which providers are involved, and where they process information, using the contact details in section 13.
12. Changes to This Policy
We review this policy when our applications change, and at least whenever an application begins to process something new. A revision is published at this address with a new “Last updated” date shown at the top of the page, and earlier versions are available on request.
For a material change — a new category of information, a new purpose, or a new kind of recipient — we also announce it in the application or in the server where it is installed, and, where the law requires it, ask for your consent before the change applies to you. For other changes, continuing to use an application after the date shown means the revised policy applies. If you do not accept a revision, stop using the applications and remove them from your servers, and you can ask us to delete your information at any time.
13. Contact
For any privacy question, or a request for access, correction, deletion or portability, contact us by email:
Privacy contact: privacy@ourapps.ourestate.net Placeholder - owner must replace
That address is a placeholder: the owner must replace it with a monitored privacy address before this policy is used as an effective Discord application privacy policy. Put “Privacy request” in the subject line, include the Discord user ID or server ID the request concerns, and say what you want us to do. We reply to confirm receipt, and we never ask for your Discord password or an authentication token — please do not send either to anyone.
If your question is about Discord itself rather than one of our applications — your Discord account, or how Discord handles your data — contact Discord Support or read Discord’s Privacy Policy, because we cannot change what Discord holds. For the rules that apply to using our applications, see our Terms of Service.
Version 1.0, published at ourapps.ourestate.net/privacy.