Privacy Policy

Last updated: 26 August 2026

This policy explains what the Stally Discord bot does with personal data, who is responsible for it, and what you can ask for. It is written to be read, not to be survived.

Who is responsible

Stally is run by Nicolò Castellin, an individual, in Italy. Under the General Data Protection Regulation (GDPR) that makes him the data controller for the data described here.

Contact for anything in this policy: stally@castellin.dev

The short version

What Stally can and cannot see

This is a property of how Stally is built rather than a promise about how it behaves, so it is worth stating precisely.

Stally connects to Discord over HTTP interactions, not the gateway, and has no privileged intents enabled. In practice that means:

Stally never receivesConsequence
The content of messages in your serverNothing anyone types in a channel reaches Stally unless it is typed into one of Stally's own commands or forms
Reactions, typing, presence, voice activityThese are not delivered to it at all
The member list of your serverIt only learns about people who use it
Your IP addressDiscord's servers deliver every interaction, so requests reach Stally from Discord, never from you

What data Stally holds

WhatExamplesWhere it comes from
Your Discord user id123456789012345678Discord, attached to every command you run
Your display name at the timeAldricDiscord, stored as a snapshot so old records still read correctly if you rename later
Your ordersItem, quantity, price agreed, status, timestamps, and any note you wroteYou, when you place an order
Work you claimedWhich orders you took, when, and any note you left when marking one readyYou, when you use the crafter commands
Events and sign-upsEvents you created or lead, whether you said you are coming, and the role you pickedYou, when you create an event or press a sign-up button
Market settingsWho owns a market, who its crafters are, its prices and its configurationThe server admins and market owners who set them
Server and channel identifiersServer id and name, channel id, ids of messages Stally postedDiscord, so Stally knows where a market lives
A history of changesThat an order was created, claimed, released, or delivered, and by whomGenerated as you use it, so a market's history is auditable
Installation recordsThat Stally was added to or removed from a server, by which user id, and whenDiscord's webhook events

A note about free text. Order notes, crafter notes and event descriptions are yours to write, and Stally stores whatever you type. Please do not put personal information in them that you would not want the market's crafters and admins to read.

What Stally does not hold at all: email addresses, real names, phone numbers, payment details, IP addresses, location data, message content, or anything about you from outside the server where you used it. There is no advertising, no tracking, no cookies and no analytics, because Stally has no website or app to put them in.

Why Stally is allowed to hold it

Under Article 6 of the GDPR, the lawful basis is legitimate interests (Article 6(1)(f)): running the service that a server has chosen to install, and that you have chosen to use by placing an order or signing up to an event.

The balancing test behind that, stated plainly: the data is the minimum needed for the feature to work at all, you provide it by deliberately using a command, it stays inside the server you used it in, and none of it is used for anything beyond showing it back to that server. A queue that cannot remember who ordered what is not a queue.

Where a server admin configures Stally, the same basis covers the settings they save.

How long it is kept

DataKept for
Open orders and active eventsAs long as they are open
Completed and cancelled orders30 days in the live queue, then moved to an archive and deleted 12 months after that
The change history of an orderAlongside the order, and deleted with it
Sign-upsWith their event
Market settingsWhile the market exists
Messages Stally posts in your channelDeleted automatically after the market's retention setting, 24 hours by default. A market's live summary message stays while the market does
Installation recordsWhile Stally is installed, and for 30 days after it is removed
Everything for a serverDeleted 30 days after Stally is removed from that server

Two deletions happen on request rather than on a clock:

A record that a market was deleted is kept: the market's name, the server's name, the date, and the Discord user id of the admin who did it. Deleting a market destroys history belonging to everyone who used it, so that one act stays attributable; nothing else about any member survives it.

Where it is stored, and who else can see it

Stally runs on Cloudflare Workers, and all of its data lives in Cloudflare's D1 database, KV store and Durable Objects. Cloudflare acts as a processor under a data processing agreement that incorporates the European Commission's Standard Contractual Clauses, which is the safeguard for any transfer of data outside the European Economic Area.

Discord is where the data comes from and where it is displayed. Discord is an independent controller of your account data, governed by its own privacy policy, not by this one.

The operator — Nicolò Castellin — can access the database directly, and does so to fix faults and answer requests under this policy. Operational alerts about failures are sent to a private Discord channel he controls; those carry server and market names and internal identifiers, never member data.

The price source receives nothing. Item prices are fetched from a public community data source (gaming.tools). Stally reads from it; it never sends anything to it, so no information about you leaves that way.

Nobody else. No data is sold, rented, shared for advertising, or handed to any third party, except where the law requires it.

Automated decisions

Stally makes no decisions that produce legal or similarly significant effects, and does no profiling. It automates only housekeeping: nudging an order nobody has claimed, releasing a claim that has gone quiet, and tidying its own messages away.

Your rights

Wherever you live, Stally applies the same standard: the rights below are given to everyone, not only to people in Europe.

If you are in California, the same requests cover the CCPA's rights to know, delete, and correct. Stally does not sell or share personal information as those terms are defined there, so there is nothing to opt out of.

To exercise any of these, email stally@castellin.dev. Include your Discord user id — Settings → Advanced → Developer Mode, then right-click your name and Copy User ID — because it is the only thing that reliably identifies your records. A reply will come within 30 days.

There is one limit worth stating honestly: deleting your data removes it from Stally, but it cannot remove what other people have already seen, and it cannot delete messages elsewhere in Discord that were never Stally's.

Complaints

If you think your data has been mishandled, please email first — most things are a misunderstanding that a reply can fix.

You also have the right to complain to a supervisory authority. In Italy that is the Garante per la protezione dei dati personali (https://www.garanteprivacy.it). If you live elsewhere in the European Economic Area or in the United Kingdom, you may complain to your own country's authority instead.

Children

Stally is not directed at children. Discord's own terms require users to be at least 13, and older in some countries — 14 in Italy. If you believe a child below the applicable age has used Stally and left data behind, email the address above and it will be deleted.

Changes to this policy

If this policy changes in a way that matters, the new version will be posted here with a new date and announced in Stally's #changelog channel. Continuing to use Stally after that means the new version applies.

This policy is published in English, which is the authoritative version.