Privacy Policy

Last updated: August 17, 2026

1. Overview

This Privacy Policy explains what data Stalkly collects, why we collect it, how long we keep it, and the controls available to you. Stalkly is a community analytics service for Discord servers, operated independently; it is not affiliated with, sponsored by, or endorsed by Discord Inc. This Policy applies globally to everyone whose data the Service processes, using one consistent set of practices rather than region-specific versions.

2. When Stalkly Collects Data

  • Stalkly collects data only from Discord servers that have explicitly enabled it. A server owner, or an administrator holding the Manage Server permission, must add our bot to the server, sign in through Discord's official OAuth login, accept our Terms of Service, and switch tracking on. Until all of those are true, nothing from that server is processed or stored.
  • Every event we receive passes a single check before anything is written: the server must still be enabled, tracking must still be on, and the bot must still be a member. Switching tracking off, or removing the bot, stops collection immediately.
  • We do not collect data from servers our bot has not been invited to. We do not use Discord user accounts, user tokens, unofficial clients, or scraping to obtain data. We reach the Discord platform only through our registered bot and Discord's official OAuth and gateway interfaces.

3. Information We Collect

  • Account data, when you sign in: your Discord user ID, username, display name, avatar, and the email address on your Discord account, provided by Discord's official OAuth login.
  • Message activity metadata, for enabled servers: that a message was sent, by which user ID, in which channel, and when. This produces counts, trends and leaderboards.
  • Voice activity, for enabled servers: joins, leaves and session length per voice channel, with the mute, deafen, camera and streaming state Discord reports for the session.
  • Membership events, for enabled servers: joins, leaves, nickname changes and role changes, used for growth, retention and role-distribution analytics.
  • Presence status, for enabled servers: the online, idle, do-not-disturb or offline status Discord reports, aggregated into activity-timing statistics.
  • Moderation events, for enabled servers: bans, kicks and timeouts recorded from the day the bot joined, shown to that server's moderators.
  • Billing data, if you buy a paid plan: your plan, billing history and invoices. Card and bank details are handled entirely by PayPal and are never seen or stored by us.
  • Technical data: IP address, browser and device information, and cookies, used for security, session management, abuse prevention and remembering your language.

4. What We Do Not Collect

  • Direct messages. Stalkly has no access to DMs or group DMs and never processes them.
  • Anything from servers that have not enabled Stalkly.
  • Rich presence detail such as game titles, listening activity, or custom status text.
  • We never sell Discord data, share it with advertisers or data brokers, or use it for advertising or for profiling unrelated to the analytics features described here.

5. How We Use Your Information

  • To produce the analytics an enabled server's owners, moderators and members see: message and voice trends, member growth, activity timing, role distribution and leaderboards.
  • To authenticate you, maintain your session, and protect your account.
  • To operate the optional notifications you have switched on, for your own activity or for servers you administer.
  • To process payments and issue invoices for paid plans.
  • To contact you about your account, security or purchases. We do not send marketing email.
  • To detect and prevent abuse, and to comply with legal obligations and with Discord's Developer Policy.

6. Legal Bases for Processing

Where data protection law requires a legal basis, we rely on: your consent, for optional features you switch on and for cookies that are not strictly necessary; performance of a contract, for running your account and any paid plan; and our legitimate interests in providing the analytics an enabled server has asked for and in keeping the Service secure, balanced against the rights of the people whose activity appears in it. Where we rely on consent, you can withdraw it at any time without affecting anything done before you did.

7. Your Privacy Controls

  • Hide your profile completely, so that no public page shows your activity.
  • Hide individual categories (voice, messages, activity, or moderation history) and leave the rest visible.
  • Opt out of presence collection, so status changes for your account are discarded on arrival and never stored.
  • Opt out of appearing in other users' activity notifications.
  • Request deletion of the activity data we hold about you.
  • Every control above is free, and none of them is or ever will be behind a paid plan. You reach them all from the Privacy Center on our dashboard, after signing in with Discord.
  • While your profile is hidden, the period spent hidden stays permanently unviewable: switching the setting off again restores visibility going forward, never retroactively over the time you asked to keep private.
  • Server owners and administrators have equivalent controls for the servers they manage: remove the server from all public pages, hide individual categories, or switch tracking off entirely.

8. Data Retention

  • Detailed event records are kept for 180 days and then deleted automatically. Aggregated statistics that hold no per-event detail, such as daily totals and all-time counters, are kept while the server remains enabled.
  • When a server switches tracking off or removes the bot, collection stops immediately and that server's stored data is deleted within 30 days. When you delete your Stalkly account, your account record and activity data are deleted within 30 days.
  • Billing records are kept for as long as tax and accounting law requires. Backups are purged on their own rolling schedule, never more than 30 days behind live data.

9. Data Sharing

We do not sell personal data. We share it only: with PayPal, to process payments; with the hosting and infrastructure providers that run the Service for us, under written confidentiality and data-processing obligations; where you have asked us to, for example by sending a notification to a webhook you own; and where required by law, or to protect the rights, safety or property of Stalkly, our users, or the public. We will tell you on request which providers process data on our behalf and where they are located.

10. Administrative Access

A small, named group of Stalkly administrators can access data beyond a single server or account, strictly to operate the Service, provide support, investigate abuse and maintain security. Access is limited to what the task requires, and privileged actions are logged.

11. Your Rights

  • Access: ask what personal data we hold about you.
  • Correction: ask us to correct data that is wrong.
  • Deletion: ask us to delete your personal data.
  • Restriction and objection: ask us to stop or limit a particular use.
  • Portability: ask for a copy of your data in a machine-readable format.
  • Withdraw consent: turn off any optional feature you switched on.
  • Complain: if you are in the EEA or the UK, raise a complaint with your local data protection authority.
  • The Privacy Center handles most of these immediately. For anything else, write to us using the address in the Contact section; we answer within 30 days.

12. Security

All traffic runs over TLS. Credentials and platform tokens are encrypted at rest, administrative access is restricted and logged, and infrastructure is patched on a regular schedule. No system is perfectly secure and we cannot promise absolute security, but where the law requires it we will notify affected users and the relevant authorities of a breach.

13. Cookies

We use a small number of first-party cookies to keep you signed in and remember your preferences. See our Cookie Policy for the full list and how to manage them.

14. Children

Stalkly is not directed at children. We rely on Discord's own minimum age requirements and do not knowingly collect data about anyone below the minimum age Discord's Terms of Service set for their country. If you believe we hold data about a child in breach of those terms, contact us and we will delete it.

15. Discord Platform Data

Data we receive from Discord remains Discord platform data and stays subject to Discord's Terms of Service, Privacy Policy and Developer Policy. We process it only for the purposes set out above, keep it no longer than stated, and delete it when Discord's rules or a valid request require us to. Stalkly is an independent service and is not affiliated with, sponsored by, or endorsed by Discord Inc.

16. Contact

For any privacy question or request, including access, correction, deletion and objection, write to us at [email protected]. We answer within 30 days.

17. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above, and we will not apply a materially different use to data already collected without a fresh legal basis.

For questions, contact us at [email protected].