What Chaffline does with what people say
Chaffline checks messages in the servers that sign up for it. This page sets out what it stores, for how long, and how to have it removed.
- In force since
- 17 September 2026
- Applies to
- The Chaffline bot and chaffline.com
- Questions
- [email protected]
Who is responsible for what
Chaffline is operated from Denmark. For anything on this page, contact [email protected].
Messages inside a server
The people who run a Discord server choose to install Chaffline, choose what it checks for and choose how strict it is. They are the data controller for what their members post; we are their processor, and we handle that material on their instructions and for no other purpose. If you are a member of a server and want something removed, ask the server’s admins first, though you may also come to us directly.
If you run a server on Chaffline, you need a data processing agreement with us. Contact us and we will provide one.
Your account and this website
For the person who registers a server, pays for a plan or contacts support, we are the controller. That covers your Discord account, the servers you registered, your payments and your correspondence with us.
What Chaffline keeps
This is the complete list. If something is not on it, we do not hold it.
| What we hold | Why | How long |
|---|---|---|
| Message content | Checked against the server’s settings as it is posted | Not stored |
| A short extract of a message that was flagged | So that a moderator can review the decision | 30 days |
| The Discord account, channel and message a flag relates to | Records what was acted on | 30 days |
| The outcome of the check and the categories it matched | Records why the message was acted on | 30 days |
| Usage totals for the server | Measures the plan allowance | Retained; contains no personal data |
| The server’s settings | Your configuration | While the bot is in the server |
| Registration details: the account that signed up, the plan and the date | Administers the account | While the bot is in the server |
| A record that these terms were accepted: the account, the version and the date | Records the agreement | While the bot is in the server |
| Changes to the server’s settings, and the account that made them | So a server’s admins can account for a setting | 90 days |
| Support correspondence | Answers your enquiry | 2 years |
| Your customer record with our payment provider, and the Discord account it belongs to | Connects a payment to your account | 5 years |
| Your subscription: the plan, the server it applies to, and the dates it runs | Provides the plan you paid for | 5 years |
| Each payment, refund and chargeback: the amount, the tax and the date | Required by Danish bookkeeping law | 5 years |
| Changes to a subscription: the plan, the server it applied to and the date | Records what you were entitled to and when | 5 years |
| The notices our payment provider sends us about a payment or a subscription | Records what the entries above are based on | 5 years |
The extract exists so that a moderator can look at a removal and tell us it was wrong. That is its only purpose, and it is what allows the service to be corrected over time.
What it never keeps
- Attachments, images, audio and video. Chaffline does not read them, and they are not sent anywhere.
- Direct messages. Only messages posted in a server are checked.
- Servers that have not signed up. The bot may be present in a server indefinitely without checking or recording anything at all.
- Messages the server has excluded. Channels and roles an admin exempts are not checked.
- Messages that were not flagged. Nothing is recorded about them.
We do not sell data, run advertising, or build profiles of individuals. Nothing from your server is used to train a model.
Our legal basis
Each use of personal data below is matched to its legal basis under the GDPR.
- Checking messages — the legitimate interests of the server’s operator in maintaining a safe community, Article 6(1)(f). That decision is theirs; we act on it.
- Operating your account and plan — performance of your contract with us, Article 6(1)(b).
- Retaining payment records — a legal obligation, Article 6(1)(c), under the Danish Bookkeeping Act.
- Maintaining the service and preventing abuse — our legitimate interests, Article 6(1)(f).
You may object to anything we do on the basis of legitimate interests. Section 9 explains how.
Messages that reveal something sensitive
Chaffline checks for hate speech, threats, sexual content and references to self-harm. A message matching one of those categories may reveal information the GDPR treats as a special category, such as health, racial or ethnic origin, religious belief or sexual orientation. We do not seek that information and we draw no conclusions about anyone from it, but the result of the check exists, and we state so here rather than leave it unaddressed.
Two limits apply. We retain only the outcome of the check and a short extract, both deleted after 30 days. And the material originates in a message its author posted to a channel visible to the server, which is the condition Article 9(2)(e) addresses. Where a server’s channels are not open in that way, its operator is responsible for establishing its own condition, and our data processing agreement sets out what that requires.
We recommend that servers route the self-harm category to their log channel for a human to see, rather than to automatic removal.
Automated decisions
Chaffline can decide whether a message is removed without a person reviewing it first. Servers start in report-only mode, where it removes nothing of its own accord: a flagged message is shown to the server’s moderators, and is removed only if one of them chooses to remove it.
The decision is reversible. Moderators can restore a message, and each action is recorded in the server’s log channel with the reason for it. If you believe a message of yours was wrongly removed, raise it with the server’s admins; if that is not resolved, contact us and a person will review it.
Who else handles it, and where
Chaffline is hosted in Frankfurt, Germany. Data is stored there, and backups are encrypted and held within the European Union.
Five providers are involved in delivering the service:
- TypeSafe assesses the content of a message and returns the result. It is the only third party that receives message content.
- Cloudflare protects chaffline.com and processes the technical details of requests to it, including IP addresses.
- Zoho provides [email protected], in its European data centre.
- Polar, in the United States, sells the paid plans. It takes the payment, calculates the tax, issues the receipt and emails you about renewals and failed payments. It holds your payment details; we never see them. Polar’s own privacy policy governs what it holds.
- Discord hosts the servers and messages themselves. Discord’s own privacy policy governs what it does with them.
TypeSafe, Cloudflare and Zoho act on our instructions and are each bound by a contract restricting them to providing that service. Discord and Polar act on their own account. Where a provider processes data outside the EU or EEA, the transfer is made under the European Commission’s standard contractual clauses. We will confirm the current list on request, and it will not change without this page changing first.
How long we keep things
Anything containing message content or a Discord identifier is deleted 30 days after it is created, automatically and whether or not anyone requests it. The record is removed in full.
Usage totals persist beyond that. They record how much work was done for a server and contain no personal data; they are what a plan’s allowance is measured against.
Settings and registration details are held while the bot remains in your server. Support correspondence is deleted after two years. Payment and subscription records must be kept for five years under Danish law, and are the one category we cannot delete on request.
Your rights
Where we are the controller, you may exercise any of the following at no charge. We will respond within one month.
- Access. A copy of the personal data we hold about you.
- Rectification. Correction of anything inaccurate.
- Erasure. Section 10 covers this in detail.
- Portability. A machine-readable copy of the data you provided.
- Restriction. That we hold data without using it while a matter is disputed.
- Objection. That we stop processing carried out on the basis of legitimate interests, which we will do unless we can demonstrate overriding grounds.
For messages within a server, the operator is the controller, so requests should go to them first. If they do not respond, send the request to us and we will act on it directly.
We may ask you to verify which Discord account is yours before releasing anything, so that one person’s data is not disclosed to another.
Getting your data deleted
No request is necessary in most cases: anything containing message content or a Discord identifier is deleted automatically after 30 days. To have it removed sooner, follow the relevant procedure below.
If you posted in a server that uses Chaffline
- Contact the server’s admins. They are responsible for their members’ data, and only they can clear the record Chaffline placed in their log channel.
- Alternatively, email [email protected] with your Discord user ID and the name or ID of the server.
- To find your user ID: in Discord, open Settings, then Advanced, and enable Developer Mode. Right-click your own name and select Copy User ID.
- We will delete every record associated with that ID and confirm by reply, within 30 days. If we hold nothing, we will tell you so.
If you run a server on Chaffline
- Remove the bot from the server. It stops checking messages as soon as it leaves.
- Its settings and registration details are deleted as it leaves; nothing has to be requested. Email [email protected] with the server ID to have its moderation records deleted too, rather than left to expire.
- Within 30 days nothing remains for that server other than the payment records Danish law requires us to keep.
What we cannot delete for you
When Chaffline acts on a message it records the reason in your server’s log channel, and, if the server has asked it to, notifies the author by direct message. Both are held by Discord rather than by us, and clearing them is done in Discord by the server’s moderators.
Cookies and the website
chaffline.com sets cookies only once you sign in with Discord, and only in order to keep you signed in and to carry your answers through setting a server up. Those are strictly necessary cookies under the Danish cookie order and do not require consent. Signing out clears them.
There is no tracking, no advertising and no analytics on the site. Should we ever want a cookie that does require consent, you will be asked before it is set.
Children
Discord requires users to be at least 13, and 13 is also the age at which someone in Denmark may consent to a service of this kind. Chaffline itself is purchased and configured by the adults who run servers.
We do not knowingly hold data concerning a child under 13. If you believe we do, contact [email protected] and it will be deleted.
Changes, and how to complain
If this page changes materially, the date at the top changes with it and anyone with a registered server is notified by email before the change takes effect. Minor corrections are made without notice.
Complaints
Please contact [email protected] first; most matters can be resolved quickly. You are not obliged to, and may complain directly to the Danish data protection authority:
- Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark. [email protected], +45 33 19 32 00, datatilsynet.dk
If you are resident elsewhere in the EU or EEA, you may instead complain to the supervisory authority in your own country.
Version 1.5. Previous versions are available on request.