Privacy Policy

Mhanndalorian Bot
Last Updated: June 4, 2026

Mhanndalorian Bot collects and processes certain information necessary to provide its Discord bot, API, website, and related services. This policy describes what information is collected, why it is collected, how long it is retained, and your rights in relation to that information.


Information Collected

Depending on which features a user chooses to use, the following information may be collected and stored:

Discord User IDs
Discord username, display name, and server nickname (as provided via Discord API)
Star Wars: Galaxy of Heroes (SWGOH) allycodes
Guild identifiers and membership information
Command usage logs
API keys issued by the service
Historical game and performance data required to provide reports, analytics, leaderboards, and other bot functionality
Information obtained through voluntary game account authorization
Patreon usernames and subscription tier (for subscribers only)

Not all users will have all categories of data stored.


Purpose of Processing

Information is collected and processed for the following purposes:

Providing bot functionality and services
Associating Discord accounts with SWGOH allycodes
Generating reports, analytics, and leaderboards
Providing API access and related services
Troubleshooting technical issues
Monitoring command usage and improving the service
Preventing abuse and maintaining service security
Verifying Patreon membership status and providing supporter benefits


Legal Bases for Processing

Where the General Data Protection Regulation (GDPR) or similar legislation applies, data is processed on the following legal bases:

Legitimate interest: Processing of Discord User IDs and SWGOH allycodes in the SWGOH Registry is carried out on the basis of legitimate interest, as it is necessary to provide account-linking and game-related functionality requested by users. We have assessed that this processing is necessary for the operation of the service, is limited in scope, and does not override the rights and freedoms of users, as users voluntarily interact with the service and may request deletion of their data at any time.

Consent: Processing of game account data obtained through voluntary authorization commands (such as /eaconnect) is based on the user's explicit consent. Users may withdraw this consent at any time.

Legitimate interest: Command logging for service improvement and troubleshooting is carried out on the basis of legitimate interest and is subject to strict retention limits.

Contract necessity: Processing of Patreon subscriber information (username and subscription tier) is necessary for the performance of a contract in order to verify membership status and deliver supporter benefits associated with an active subscription.


Command Logging

Mhanndalorian Bot logs command usage for the purpose of identifying commonly used features, improving the service, and assisting users with troubleshooting.

Command logs are retained for no longer than seven (7) days and are automatically deleted thereafter.


SWGOH Registry

The SWGOH Registry stores Discord User IDs and associated allycodes. This data is processed under the legitimate interest basis, as it is necessary to provide account-linking and game-related functionality requested by users, under the same balancing considerations described in the Legal Bases section.

Users may request removal of their information from the registry at any time using the contact information at the end of this policy.


Game Account Authorization

Certain features may require users to voluntarily connect their game account through commands such as /eaconnect. When authorization is granted, Mhanndalorian Bot may access and process game-related information necessary to provide requested functionality. Such information is only accessed after user authorization and is used solely for providing requested services.

Users may revoke authorization at any time through available disconnect commands or by contacting the service administrator.


Patreon Integration

Users who subscribe through Patreon may have their Patreon username and subscription tier processed for the purpose of verifying membership status and providing supporter benefits. Payment information is handled exclusively by Patreon and is not accessible to or stored by this service.

In limited cases, Patreon subscription information (such as Patreon username and subscription tier) may be shared with authorized partner developers (including Wookiee Bot) solely for the purpose of reconciling subscriber status and verifying entitlement to shared or cross-service benefits under a contractual agreement. Any shared data is limited to what is strictly necessary for this purpose and is not used for any unrelated processing.

Patreon operates as an independent data controller with respect to payment and account data; please refer to Patreon s own Privacy Policy for information about how they handle your data.


Data Retention

Command logs are retained for up to seven (7) days.
Registry records are retained until removed by the user or no longer required for operation of the service.
Patreon subscriber data is retained only as long as the user maintains an active subscription or as otherwise required to resolve disputes or comply with legal obligations.
Additional operational data (such as configuration settings and internal service metadata) is retained only as long as reasonably necessary to provide requested functionality, comply with legal obligations, or maintain service integrity.


Data Sharing and Transfers

Mhanndalorian Bot does not sell, rent, or trade personal information. This does not include limited sharing of subscriber information with authorized partner developers solely for the purpose of subscription reconciliation and entitlement verification under contractual agreements.

Information may be processed by third-party service providers used to operate the service. Current infrastructure providers include:

Amazon Web Services (AWS) server hosting, located in the United States (US-East/Virginia region)
Cloudflare content delivery network and DDoS protection, which may process data across global points of presence
Patreon subscription management platform
MongoDB database storage provider, used to store ally codes, Discord User IDs, in-game action logs, and API developer access records (including records of developer accounts authorized to access other users' game data)
Google Sheets used as a supplementary data store for in-game performance data and related records

Data is only shared to the extent necessary to provide and maintain the service.

Note for users in the European Economic Area (EEA) or United Kingdom: Data processed by the above providers may be transferred to and stored in the United States or other countries outside the EEA/UK. Where such transfers occur, they are conducted in reliance on applicable legal mechanisms, including the EU-U.S. Data Privacy Framework where applicable, and/or Standard Contractual Clauses. By using the service, EEA/UK users acknowledge that their data may be processed outside their jurisdiction.


Automated Decision-Making

Mhanndalorian Bot does not make automated decisions that produce legal or similarly significant effects on users. Actions such as access restrictions or bans are carried out manually by the service administrator and are not the result of automated processing.


Minors

This service does not impose age restrictions beyond those required by Discord s Terms of Service. Discord requires users to be at least 13 years of age (or older in some jurisdictions). By using this service through Discord, users represent that they meet Discord s minimum age requirements.

If you are a parent or guardian and believe your child has provided personal information through this service without appropriate consent, please contact us and we will take appropriate steps to remove that information.


Security

Reasonable technical and organizational measures are used to protect stored information from unauthorized access, alteration, disclosure, or destruction. However, no method of electronic storage or transmission can be guaranteed to be completely secure.


Your Rights

Depending on your location, you may have the following rights with respect to your personal information:

Right of access
Right to rectification
Right to erasure
Right to withdraw consent
Right to object to processing based on legitimate interest
Right to data portability (where technically feasible)
Right to lodge a complaint with a supervisory authority

Requests may be submitted using the contact information below. We will respond within a reasonable timeframe and in accordance with applicable legal requirements.


Website Information

The website and related services may automatically collect limited technical information, such as IP addresses, browser information, and server logs, as required for security, diagnostics, and operation of the service. No personal information is sold, rented, or traded.


Changes to This Policy

This Privacy Policy may be updated from time to time. The updated version will be posted with a revised effective date. For material changes, reasonable efforts will be made to notify users through the Discord bot or other available channels. Continued use of the service after changes are posted constitutes acceptance of the revised policy.


Contact

For privacy-related questions, data requests, or removal requests, please contact:

[email protected]

Please include your Discord username or User ID in any data request so we can locate your records accurately.