Privacy Policy
Last updated: September 29, 2026
This policy explains which personal data Ventura - the Discord bot and this website - processes, why, for how long, and what rights you have. It applies to everyone whose data the bot touches: server owners and admins who use it, and members of servers the bot is on.
Who is responsible#
The controller under the EU General Data Protection Regulation (GDPR) is:
Felix Mueller
c/o IP-Management #3097
Ludwig-Erhard-Str. 18
20459 Hamburg
Germany
Email: support@tmp0.cc
For anything about your data, write to this address.
What the bot does in short#
Ventura backs up Discord servers and restores them, e.g. after a raid or an accident. To do that, it reads the server through Discord's interface - like a member with administrator rights would see it - and stores an encrypted copy. It only reads servers it was added to, and only what Discord shows it there.
Data the bot processes#
When the bot is added to a server#
- The server's ID and name, when the bot joined and - if it left - when it left.
- Whether automatic backups are on, and the Discord ID of the owner who last switched them on or off.
- A welcome message with the first steps is sent to the server owner (by direct message, or in the server's system channel if the owner doesn't accept direct messages).
Backups#
A backup is a copy of the server at one point in time. Besides the server's settings, channels, roles, emojis, stickers, sounds, AutoMod rules and onboarding, it contains personal data of the server's members:
- Members: Discord ID, username, nickname and assigned roles - for every member that has a nickname or roles.
- Permissions: channel permissions set for individual members (their Discord ID).
- Bans: Discord ID and username of banned users, and the ban reason.
- Messages: the newest 100 messages of every channel and thread the bot can read - with their text, author (Discord ID, name and a link to the avatar), attachments, embeds, replies, pins, forwarded messages, stickers and polls (only the number of votes per answer, not who voted). Backups created with
/backup createinclude attached files up to 8 MB each; automatic backups don't include attached files. - Threads and forum posts: name, settings and their author.
- About the backup itself: who created it (Discord ID), when, an optional note and counts (e.g. number of channels and messages).
Backups are created when an admin runs /backup create, and automatically once a day while automatic backups are on (the default - the server owner can switch them off with /backup auto).
Undo copies and transfer codes#
- Right before a backup is loaded onto a server, the bot takes a copy of the server, so the load can be undone. It contains the same kind of data as a backup.
- A transfer code allows loading a backup onto another server. The bot stores only a keyed hash of the code, who created it and when it expires.
Using the bot#
- For running operations (loads, repairs, undos), the bot stores the Discord ID of whoever started them, so an operation can continue after a restart.
- The bot's log files record every command, button and menu used - with the user's name and Discord ID, the server, the channel and the options chosen - and the course of backups, loads and errors. Message contents, transfer codes and anything typed into a form are never logged.
- Unexpected errors get a short error ID, which is shown to you, so you can report it to us.
Why we process the data, and on what legal basis#
- Providing the service to the server owners and admins who add and use the bot - creating, storing, comparing and loading backups, automatic backups, undo copies and transfer codes: Art. 6(1)(b) GDPR (performance of a contract).
- Data of other members contained in backups (messages, nicknames, roles, bans): Art. 6(1)(f) GDPR (legitimate interests). The server's operators - and we, on their behalf - have a legitimate interest in being able to restore their community after an attack, a mistake or an accident. The bot only stores what is already visible on the server to its members, keeps only a limited number of recent messages, encrypts everything and deletes it after fixed periods.
- Log files and error reports: Art. 6(1)(f) GDPR - our legitimate interest in running the bot securely, preventing abuse and fixing errors.
Who receives the data#
- Discord. The bot works entirely through Discord (Discord Inc., USA / Discord Netherlands BV for users in the EU). Everything the bot reads and posts goes through Discord, which processes it under its own privacy policy.
- The server the backup is loaded onto. Loading a backup posts its content back onto the server - by default only onto the server it was taken from. Onto another server only with a transfer code created by the owner of the original server. The members of that server can then see the restored content, as they could before.
- Hosting. The bot, its database and this website run on servers in the European Union. A hosting provider we use for this only processes the data on our behalf and according to our instructions (Art. 28 GDPR).
We don't sell data, don't use it for advertising and don't pass it on to anyone else, unless we are legally required to.
Transfers outside the EU#
We store and process the data in the EU. Discord itself processes data in the USA and other countries - see Discord's privacy policy for how it protects such transfers.
How long the data is kept#
| Data | Deleted |
|---|---|
| Manual backups | When the server owner deletes them, or when a newer one replaces them (at most 5 per server) |
| Automatic backups | As newer ones come in: at most 7 daily and 4 weekly ones, reaching back about 5 weeks |
| All backups of a server | 7 days after the bot left the server (kicked, or the server was deleted) - unless it's re-added within these 7 days |
| Undo copy | 1 hour after the load, or when the next load on the server replaces it |
| Transfer codes | When used, after 24 hours, or with their backup |
| Running operations | When the operation finishes |
| Bot log files | After 14 days |
| Error details | With the next restart of the bot (they remain in the log files, see above) |
| Server record (ID, name, settings) | Kept, so the bot recognizes the server if it's added again - it contains no member data |
How the data is protected#
- Every backup is encrypted with its own key (AES-256-GCM). The keys are derived from a secret that is kept apart from the database, so a copy of the database alone is unreadable.
- As with any hosted backup service, we as the operator can technically decrypt backups. We only do so when it's needed to run the service or to answer a request of yours, e.g. about your rights below.
- Only the server owner can load, delete and move backups; admins can create and inspect the backups of their own server. Backups of other servers reveal nothing.
Your rights#
Under the GDPR, you have the right to:
- access the personal data we hold about you (Art. 15),
- have it corrected (Art. 16) or deleted (Art. 17),
- restrict its processing (Art. 18),
- receive it in a portable format (Art. 20),
- object to processing based on legitimate interests (Art. 21) - on grounds relating to your particular situation,
- complain to a data protection supervisory authority (Art. 77), e.g. the one where you live or the one responsible for us: the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI).
To use these rights, email support@tmp0.cc with your Discord ID (and, if it's about a specific server, its ID). Server owners can also delete their server's backups themselves with /backup delete, or have all of them deleted by removing the bot from the server (after 7 days). Removing your data from a backup can mean that the backup has to be deleted entirely - we'll tell you if that's the case.
If you are a member of a server that uses Ventura, you can also contact the server's owner, who decides whether the server is backed up.
This website#
- Server logs: when you visit this website, the web server records your IP address, the date and time, the page requested, the referring page and your browser's user agent. This is needed to deliver the website and to protect it against attacks (Art. 6(1)(f) GDPR). The logs are deleted after 14 days.
- No cookies, no tracking, no analytics, no external content. The website loads nothing from other servers.
- Theme choice: if you switch between light and dark mode, your choice is saved in your browser's local storage so the website remembers it. It never leaves your device.
Children#
Discord requires its users to be at least 13 years old (or older, depending on the country). Ventura is only meant for people allowed to use Discord.
Changes to this policy#
When the bot or the law changes, we update this policy. The date at the top shows when it was last changed. For significant changes, we'll point it out on this website.
Ventura