Privacy Policy
Last updated: 15 August 2026
Wody does not intentionally target children below the minimum age required to use Discord. Access through Discord is subject to Discord's minimum age for the user's country or region and any higher minimum age required by applicable local law. Where applicable law requires parental or guardian consent for a minor's use of an online service or for a particular processing activity, that requirement applies.
1. Who is responsible for your data
Wody is developed and operated by Păcurar Ancuța-Narcisa, an individual based in Târgu-Mureș, Romania (the “Operator”). The Operator acts as the data controller for processing activities for which Wody determines the purposes and means of processing. You can contact the Operator at teamswody@gmail.com. This Privacy Policy explains what personal data Wody processes through the Discord bot and web dashboard, why it is processed, where it is stored, how long it is kept, and how you can exercise your rights. Where Wody processes information entered into a server by a server owner or authorised administrator, the server owner or administrator may also have responsibilities as a controller for that processing, depending on the feature and the applicable law.
2. Data used when you log in with Discord
Wody uses Discord OAuth2 for dashboard login. After you authorize the application, Wody receives:
- Your Discord user ID, username, global display name, discriminator and avatar identifier.
- An OAuth access token and refresh token issued by Discord. These are stored only on the server and are used to access the Discord resources required by the dashboard.
The dashboard also requests your Discord server list from Discord when it needs to determine which servers you can manage. The server list is fetched from Discord using your access token and is not stored as part of your Wody session record.
Wody does not receive or store your Discord password. The Discord tokens and profile data are not stored in your browser cookies. Your browser receives only a random session identifier with a cryptographic signature. The corresponding session record is stored server side in the sessions collection in MongoDB. The access token and refresh token are used only from the server when the dashboard needs to access Discord resources permitted by the OAuth2 authorization.
3. Data stored by the bot
To provide Wody's modules and features, Wody stores information associated with Discord servers, channels, roles and members. The homepage currently presents 15+ modules, including moderation, automod, welcome and goodbye messages, auto role, tickets, reaction roles, giveaways, levels, suggestions, auto responses, custom commands, embed building, scheduled messages, forums and logging. Depending on the features used, the stored data includes:
- Server configuration and settings created through Discord or the dashboard.
- Welcome and goodbye messages, custom commands and automatic responses.
- Moderation records such as warnings, bans, kicks and timeouts, including the Discord IDs needed to identify the affected member and moderator.
- Level and XP information.
- Suggestions and their moderation status.
- Ticket information, ticket reviews and closed ticket transcripts where the ticket feature is used.
- Giveaway entries and results.
- Scheduled message content and scheduling settings.
- Forum channel automation settings, such as default tags and post cooldowns, where the forums feature is used.
- Premium server configuration backups where the backup feature is enabled.
- Your lifetime Wody vote total associated with your Discord user ID, where the voting feature is used.
- Audit records for relevant settings changes and Premium administration, including the Discord user ID of the person who made the change where recorded.
- Premium key and activation records needed to issue, validate, limit or revoke Premium access.
Wody does not store general Discord chat history as a separate archive. Message content is stored only where a feature requires it, such as configured messages, scheduled messages or ticket transcripts. Wody does not use analytics, advertising or behavioral profiling, and the dashboard does not use third-party tracking cookies.
4. Where your data is stored
Wody stores its application and bot data in MongoDB Atlas. This includes the server configuration, feature data and server-side dashboard sessions. The dashboard application is hosted on Vercel. Authentication cookies are stored in your browser. Discord separately processes data on Discord's own systems when you use Discord or complete the OAuth2 login process. Wody does not use analytics, advertising, behavioral profiling or third-party tracking cookies on the dashboard.
5. How the dashboard session works
The dashboard uses a server side session. The wody_session cookie does not contain your Discord access token, refresh token or profile. It contains a random session identifier and a cryptographic signature used to detect tampering.
The session record containing your cached profile, Discord access token, refresh token and expiry time is stored in the sessions collection in MongoDB. The browser cookie can remain for up to 7 days, but the server-side session is not necessarily valid for the full 7 days. Its expiry is calculated from the Discord access token lifetime and is set 60 seconds before that token expires. When the server-side expiry is reached, the session is rejected; when that expired session is checked, its database record is removed. Logging out removes the session record and the session cookie immediately. The current implementation stores the refresh token but does not use it to refresh an expired access token.
6. How we protect the data
Dashboard authentication cookies are HttpOnly, so normal page JavaScript cannot read them. They are marked Secure and are sent only over HTTPS. They use SameSite=Lax to reduce cross site request risks. The cookie values are cryptographically signed and a modified value is rejected. OAuth login also uses a separate short lived state value to verify that the login response corresponds to a login started by the same browser.
Access to server settings is checked against the permissions returned by Discord. A user must be the server owner or have Administrator or Manage Server permission for the server being managed.
7. Why we process this data
We process this information to authenticate dashboard users, determine which Discord servers they can manage, operate the bot features requested by server owners and members, keep dashboard changes synchronized with the bot, maintain configuration and moderation records, provide Premium functionality, prevent unauthorized access and keep the service secure and operational. Depending on the processing activity, the legal basis may be the performance of a contract or steps requested before entering into a contract (Article 6(1)(b) GDPR), compliance with a legal obligation (Article 6(1)(c) GDPR), or the Operator's legitimate interests in operating, securing and protecting the service (Article 6(1)(f) GDPR). Where consent is required by law for a particular processing activity, Wody will rely on consent instead.
8. Who processes the data
Wody does not sell your personal data, use it for advertising or behavioral profiling, or use analytics on the dashboard. The service relies on the following providers:
- Discord, for authentication and access to Discord resources through its API.
- MongoDB Atlas, for the database used by the dashboard and bot.
- Vercel, for hosting and delivering the dashboard.
These providers may process information under their own terms and privacy documentation. Depending on the service and the processing involved, a provider may act as a processor or as an independent controller. Discord remains an independent controller for the data it processes on its own platform.
9. How long data is kept
The wody_session browser cookie has a maximum lifetime of 7 days. This is the lifetime of the browser cookie, not a guarantee that the server-side session or Discord tokens remain valid for 7 days. The server-side dashboard session has its own expiry based on the Discord access token lifetime and is normally set to expire 60 seconds before that token. An expired session is rejected and its database record is removed when the session is checked. The wody_oauth_state cookie expires after 10 minutes and is removed immediately after the OAuth2 response is checked. Bot configuration and feature data are kept while they are needed to operate the relevant server features. Server owners can request deletion of applicable records by contacting us. Some records may need to be retained where required by law, necessary to establish or defend legal claims, or reasonably necessary for security, moderation history or Premium validation.
10. Your rights
Where applicable under GDPR and other data protection law, you may have the right to request access, correction, deletion, restriction of processing, objection to processing and data portability. Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise your rights or ask what information is associated with your Discord account, contact teamswody@gmail.com. We may ask you to verify your Discord identity before providing account information or processing a request. You may also lodge a complaint with the competent data protection authority, including ANSPDCP in Romania.
11. Data relating to other server members
If you use Wody as a server owner or authorised staff member, the dashboard and bot may display or store information about other members when required by the features you use, such as moderation records, levels, tickets, suggestions or giveaways. This information may come from Discord, from the member directly, or from the server owner or staff using Wody. Server owners and staff are responsible for using that information lawfully and only for appropriate server management purposes. Depending on the feature, the server owner may be the controller for member data entered or managed through Wody, while Wody may process that data on the owner's behalf.
12. International processing
Discord, MongoDB Atlas and Vercel may process information in countries outside Romania or the European Economic Area. Where a transfer to a third country is subject to GDPR Chapter V, the transfer is made only where an applicable legal mechanism is available, such as an adequacy decision or appropriate safeguards including standard contractual clauses, where applicable. Information about the relevant safeguards can be requested from the Operator at the contact address above.
13. Sources and automated decisions
Personal data may be obtained directly from you, from Discord when you authorise the Wody application, or from server owners and authorised staff when they configure and use Wody. Wody does not use your personal data for automated decision-making or profiling that produces legal effects or similarly significant effects on you.
14. Changes to this Policy
This Policy may be updated when the service or its data processing practices change. The revision date shown above identifies the current version. Material changes may also be announced through the official Wody community channels where appropriate.
15. Contact
For privacy, legal, or data protection questions, contact Păcurar Ancuța-Narcisa, the Operator, at teamswody@gmail.com.