Privacy Policy
This explains which personal data we process when you use RZ AI (website, panel and Discord bot), why, and for how long.
1. Controller
RZ AI. Contact: https://discord.gg/PvDPqf3juR.
2. Visiting the website and server logs
When you open rz-ai.eu, the server processes technically necessary data (IP address, date and time, requested page, browser details) to deliver the page and keep operation secure. Legal basis: Art. 6(1)(f) GDPR (security and stability).
For display, fonts from Google Fonts (fonts.googleapis.com, fonts.gstatic.com) and icons from Font Awesome via cdnjs (Cloudflare) are loaded from external servers. These providers technically receive your IP address. Legal basis: Art. 6(1)(f) GDPR (consistent, functional display).
3. Cookies
We use one necessary session cookie (rz_dash_session) that keeps you signed in after login (up to 14 days). It only contains a random session identifier and has no tracking or advertising function. The related session data (sign-in status, Discord profile, your server list, language) is stored server-side in our database so you stay signed in after maintenance and restarts; it is deleted at the latest 14 days after last use or when you sign out. Legal basis: Art. 5(3) of the ePrivacy Directive (in Germany section 25(2) TDDDG) and Art. 6(1)(b)/(f) GDPR. We do not use analytics or advertising cookies.
On your first visit we ask for your cookie choice. We store your decision in a cookie (rz_consent, valid for 12 months) so the notice does not appear on every visit. You can change your choice at any time via "Cookie settings" in the footer.
4. Sign-in with Discord
Sign-in works via Discord (OAuth). We receive your Discord ID, username, avatar and the list of your servers with your permissions (permission “guilds.join”). We only use the server list to show which servers you may manage and store it only for the duration of your session.
When you sign in you are automatically added to our Discord server. You can leave it at any time.
We store a panel account permanently: Discord ID, username, avatar identifier, role, usage limit, credit balance, time of registration and last login and, if banned, ban status and reason. Purpose: providing the panel, permission management, abuse prevention. Legal basis: Art. 6(1)(b) GDPR (use of the service) and (f) (abuse prevention).
5. Public profile, sign-in history and security
Every panel account has a profile page (rz-ai.eu/u/username). It shows username, avatar, role, unlimited status, member since, number of AI questions, daily bonus streak, achievements and redeemed event badges as well as – if you add them – a short bio, a profile colour and a banner you uploaded. Credits, servers and Discord ID are not shown there. Profiles are public by default; you can make yours private and hide individual sections at any time under "My account → Profile & visibility". Legal basis: Art. 6(1)(b) GDPR (service function) and (f) (community feature, with the option to object via the "private" setting).
Uploaded banners are stored on our server until you replace or remove them or your account is deleted. The team can remove inappropriate banners; uploads and removals are recorded in the internal team log. Please only upload images you hold the rights to and that do not show personal data of third parties.
A custom panel background image (shop extra) is only shown to you – it is not public and is only delivered to your signed-in account. It is stored on our server until you replace or delete it or your account is deleted. Display settings such as text size, compact view or background are stored in your account.
Each time you sign in to the panel we store an entry in the sign-in history: time, device type (computer, phone, tablet), browser and operating system – roughly derived from the browser identifier. We do not store an IP address. Purpose: you can see where you are signed in and sign out other devices (account security). Legal basis: Art. 6(1)(f) GDPR. Retention: 90 days; you can delete the history yourself at any time under "My account → Security".
The bot also sends purchased gift codes to you as a Discord direct message unless you have turned this off in the settings.
Invites: if you join the panel via an invite link, we store which link and who invited you, the time and the reward status. To prevent abuse we use the age of your Discord account (from the Discord ID) and the number of days you claimed the daily bonus. The person who invited you sees your username and your progress in their invite list. Per link we count clicks as a plain number, without IP address. Legal basis: Art. 6(1)(b) GDPR (invite programme) and (f) (abuse prevention). Retention: as long as your account exists.
6. Use of the bot
When you write in a channel where the bot is active (or mention it or use a command), we process the message text, any image attachments, your Discord ID, your username and the server ID to generate an answer. Legal basis: Art. 6(1)(b) GDPR (providing the requested answer). Please do not enter sensitive data (e.g. health data, passwords) in messages to the bot.
To generate answers, your message, any attached images (as links), the previous conversation (up to 6 messages), the server settings and selected passages from the website knowledge are sent to the AI provider Groq (processor/recipient based in the USA).
For each answer we store: server ID, your Discord ID, your username, your message, the bot's answer, language, personality and time (conversation history). Retention: 90 days. The history serves conversation context, support and abuse prevention; team members with the corresponding permission can view it.
Messages blocked by the word filter are stored with server ID, Discord ID and content for abuse prevention for 30 days. Usage data (server ID, Discord ID, command/request, time, without message text) is used to limit daily requests and for statistics; the link to your Discord ID is removed after 90 days.
Conversations are not used to train or further develop the AI.
7. Server settings and website knowledge
We store the settings of a server (e.g. channels, personality, server profile, rules, current notice, access rights, custom word filter terms). Server managers can enter one or more website addresses. We fetch these public pages (homepage and up to four subpages of the same domain), convert them to text, store the text and refresh it about every 12 hours. When fetching, your website will see our server IP and the identifier “RZ-AI-Knowledge”. Matching passages are sent to the AI provider as knowledge. Please only enter pages that are public and that you are entitled to use.
Legal basis: Art. 6(1)(b) GDPR. Retention: until changed by the server manager or until the bot leaves the server.
8. Credits, codes and server rewards
For credits, shop, codes and rewards we store: balance, a log of transactions (amount, reason, time, where applicable the team member who triggered it), redeemed codes with your Discord ID, claimed server rewards and the number of AI answers per server. Purpose: operating the credit system and preventing abuse (e.g. repeated redemption, fake servers). Legal basis: Art. 6(1)(b) and (f) GDPR. For abuse prevention, this log remains even after your chat data is deleted, as long as a legitimate interest exists.
9. Recipients and transfers to third countries
- Discord Inc. (USA) for sign-in, bot operation and messages on the platform. Discord's own privacy notices also apply.
- AI provider Groq (USA) to generate answers.
- Hosting and infrastructure providers.
- Google (fonts) and Cloudflare (cdnjs, icons) for delivering website components.
Where recipients are located in the USA, the transfer relies on an adequacy decision (EU-US Data Privacy Framework) or standard contractual clauses. We do not pass data on for advertising or sell data.
10. Retention overview
- Conversation history: 90 days
- Blocked messages: 30 days
- Usage data: link to Discord ID removed after 90 days
- Panel account: until your account is deleted
- Credit log, code redemptions, server rewards: as long as necessary for abuse prevention
- Session cookie and session data: up to 14 days after last use, immediately when you sign out
- Sign-in history (device type, browser, system, no IP): 90 days or until you delete it
- Profile details (bio, colour, visibility) and profile banner: until you change or remove them or your account is deleted
- Internal team log (actions in the panel, no IP): 90 days
11. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21 GDPR). You can withdraw any consent at any time. Write to https://discord.gg/PvDPqf3juR and include your Discord ID so we can match your data.
You also have the right to lodge a complaint with a data protection supervisory authority (e.g. the authority of your place of residence or of our seat).
12. Obligation to provide data, automated decisions
Without the data mentioned, the panel and bot cannot be used. No solely automated decision with legal or similarly significant effect (Art. 22 GDPR) takes place; AI answers are information, not decisions about you.
13. Age
The service is aimed at people aged 16 and over. If you are younger, please do not use it. If we learn that younger people have submitted data, we will delete it.
14. Security and changes
We protect data with technical and organisational measures (e.g. encrypted transmission, role-based access restrictions, protection against requests to internal addresses). We update this notice when features or legal requirements change; the version published here applies.