💬 Chat 🏛️ 3D Art Showroom

Privacy Policy

Privacy Policy (GDPR)
Imprint·Privacy Policy

Last updated: 27 June 2026 · RenderDen / Secret HQ / ArtChain is a non-commercial, private hobby project. Provided in English for our international community.

📋 The full, authoritative privacy policy for our community & Discord bots is at secret-hq.de/impressum.html. This page supplements it with the RenderDen platform specifics (login, chat mirroring, collectibles).

1. Controller

Ferris Sakura Ehre, Kuchenbergstr. 108, 66540 Neunkirchen, Germany · it@fanatix.de. Full details in the Imprint.

2. What data we process

To run the platform we process: your Discord ID, your Discord display name and your avatar, your points, ranks, artworks and NFTs/collectibles, and a technical login session token (signed cookie/localStorage) so you stay logged in. If you sign in with a RenderDen account, also the account data stored there.

Member cache (for moderation & leave log): our bots keep a small profile cache per member — Discord ID, username & display name, server nickname, avatar, Discord account-creation date, server-join date, server roles, Discord badges (public flags) and, if applicable, server-boost date. We need it because Discord's "member left" event contains only a user ID; without the cache we could neither show who left nor reliably delete the right record. As soon as you leave the server, your cache entry is deleted automatically — that leave event is exactly what lets us erase it immediately; the cache is also refreshed about every 14 days. We do not store your online/presence status.

Activity, points & likes: level/points (XP earned by taking part), ranks, likes given/received and challenge scores, linked to your Discord ID — we store these values, not your messages.

Messages, moderation & AI: message content in public channels is processed in real time for anti-spam & moderation (incl. automatic NSFW image screening), translation and a °C/°F converter. Optional features send your message or image to an external AI provider that returns only a result (inference): AI character chat, idea/"spark" bot, emoji suggestions, AI translation, and AI evaluation and image moderation. We do not use your messages to train our own AI models, and we do not authorize the providers to do so either. Apart from the consent-based chat mirroring (see below) we do not permanently store message content. Automated moderation can lead to removal of a post and, for abuse (e.g. image spam), to a temporary timeout/penalty role; a human reviews flagged content and you can appeal.

3. Chat mirroring Discord ↔ RenderDen (consent only)

The Discord main chat can be mirrored publicly to RenderDen and vice versa. Your messages are mirrored ONLY if you have explicitly agreed beforehand (consent on first opening the chat). Without consent your content is not mirrored. Only the operator and project-owned bots are exempt. What is mirrored then: display name, avatar, message text and attached images/GIFs. Legal basis: your consent (Art. 6 (1)(a) GDPR), which you can withdraw at any time with future effect (contact above). If you delete a message in Discord, the copy on RenderDen is deleted too. The feed is only visible on our login-protected website, and the mirrored entries are auto-deleted after 7 days. If you withdraw, we stop mirroring and remove your existing feed entries.

4. Purposes & legal bases

Providing the platform, points/ranks/NFTs, linking your Discord↔RenderDen account, showing your profile and leaderboards: to perform / carry out your use (Art. 6 (1)(b) GDPR) and our legitimate interest in operating the community platform (Art. 6 (1)(f) GDPR). Chat mirroring is based solely on your consent (lit. a).

5. Sources & third parties

We do not sell data. Core data such as Discord ID, name and avatar come from Discord (Discord Inc.) via its API — Discord's privacy policy also applies; avatars/images are partly loaded directly from Discord's CDN. For GIFs we use KLIPY. For the AI features above, OpenAI (AI chat/idea/emoji-fallback, AI evaluation, image-moderation second opinion), Groq (image analysis for emoji suggestions) and Prodia (automatic NSFW image moderation) process content solely to return a result (inference, no training). Hosting: Contabo GmbH, Germany (Art. 28 GDPR data-processing agreement); servers in Germany/the EU. Some providers may process data outside the EU/EEA (e.g. the USA); such transfers rely on appropriate safeguards (EU Standard Contractual Clauses in those providers' agreements).

6. Cookies & local storage

We set a strictly necessary login session token (cookie nft_uid / localStorage) so you stay logged in and we recognise it's you. We also store your login status and consent decision briefly in the browser. There is no tracking and no advertising.

7. Retention

We keep data only as long as needed for the respective feature. The member cache is deleted automatically when you leave the server (and reconciled about every 14 days), the chat mirror after 7 days, server log files after at most 14 days. Points, ranks, likes and collectibles are kept while your account/participation exists and are deleted or de-identified once no longer needed or when you ask. As this is a hobby project, data may also be reset or deleted at any time (see Terms).

8. Your rights

You have the right to access, rectification, erasure, restriction, data portability and objection, and the right to withdraw a given consent at any time (with future effect). You also have the right to lodge a complaint with a data-protection supervisory authority. For any request, an email to it@fanatix.de is enough.

9. Minors

Our community is for users aged 13 and over (Discord's minimum age; a higher minimum age may apply under the law of your country). If we learn that a member is under 13, we remove them and delete all the data we hold about them. Any mature / R13+ content is only in an optional, age-gated area you actively enter.

10. Data security

Connections are encrypted in transit (TLS); a single bot reads the server events and passes them internally to our other bots over a private, encrypted connection, so privileged access happens in one place only. Data we store on our own servers (member cache, feed) is encrypted at rest.

Note: this is a private hobby project; this notice describes the actual data processing to the best of our knowledge.