Legal
Privacy policy
Last updated: 30 August 2026
Who we are
AverisStatusPage ("ASP", "we") is an independently operated Discord application and website. The service is provided by the ASP operator, reachable at the contact address in section 12. We are the data controller for the information described below. We are not affiliated with, endorsed by, or operated by Discord Inc.
What we collect
We collect the minimum needed to deliver status updates into your channels.
- Discord account data, when you sign in with Discord: your user ID, username, global display name, avatar hash, and the list of servers your account belongs to together with your permissions in them (OAuth2 scopes identify and guilds).
- Server configuration: server ID, channel IDs, message IDs created by the bot, the status page URLs you bind, component filters, alert roles and schedule settings.
- Status history: the state, response time and incident text returned by the pages you asked us to watch, stored as a timeline.
- Technical logs: IP address, user agent, timestamp and requested path for requests to this website and our API, plus bot error traces. Logs exist for abuse prevention and debugging.
What we never collect
- Message content. The bot runs without the message content intent and cannot read your conversations.
- Your email address, phone number, payment details or friends list.
- Voice data, attachments, or member lists beyond the roles needed to check permissions.
- Behavioural advertising or third-party analytics identifiers. There is no tracking pixel on this site.
Why we process it
Where the GDPR applies, our legal bases are: performance of a contract, for everything required to run a binding you created; legitimate interests, for security logging, abuse prevention and service diagnostics; and consent, where you explicitly authorize the Discord connection. You can withdraw that consent at any time by revoking the application in Discord's authorized apps settings.
Cookies
We set one strictly necessary cookie, asp_session, which holds a signed session identifier after you sign in with Discord. It is HttpOnly, Secure and SameSite=Lax, and it expires after 7 days or when you sign out. Your language choice is stored in your browser's local storage and never leaves your device. We use no advertising, profiling or analytics cookies, so there is no consent banner to click away.
How long we keep it
- Session data: until logout or 7 days, whichever comes first.
- Server configuration: while the binding exists. Removing the bot from a server or unbinding deletes it within 30 days.
- Status history: rolling 90 days, then aggregated or discarded.
- Technical logs: 30 days, except entries retained for an ongoing abuse or security investigation.
Who else sees it
We do not sell, rent or trade any data. It is shared only with the parties strictly required to operate the service: Discord Inc., because the bot communicates through their API; our VPS hosting provider, which stores the encrypted database and logs; and the status pages you choose to watch, which receive an outbound HTTP request from our server. If we are ever legally compelled to disclose data, we will do so only to the extent required.
Security
Transport is HTTPS only, with HSTS. The database is not exposed to the public internet and sits behind a firewall on a single dedicated host. Tokens and secrets are stored in environment variables outside the web root, backups are encrypted at rest, and access to the host requires key-based authentication. No system is perfect; if we discover a breach affecting your data, we will notify affected server administrators without undue delay and, where required, the competent supervisory authority within 72 hours.
Your rights and deletion
You may request access to your data, correction, erasure, restriction of processing, portability, or object to processing based on legitimate interests. Two ways to act immediately:
- Remove the bot from a server, or delete the binding from the dashboard. Configuration and history for that server are queued for deletion.
- Revoke the application in Discord under User Settings, Authorized Apps. Your session and stored account data become invalid.
For anything else, email us from an address you can prove control of, or open a ticket in the support server. We answer within 30 days. If you are in the EEA or UK and unhappy with the outcome, you may complain to your local data protection authority.
Age limits
The service follows Discord's minimum age requirements, which is 13 years in most regions and higher where local law demands it. We do not knowingly process data from anyone below that age. If you believe a minor's data reached us, contact us and it will be removed.
Changes
When this policy changes materially, we update the date at the top and announce it in the support server before the change takes effect. Continued use after that date means you accept the revised policy.
Contact
Email support@averisstatuspage.com, or join the support server. Mark data protection requests with "GDPR" in the subject line so they get routed correctly.