GuildRyx uses data needed to authorize administrators, operate requested Discord features, protect the service and provide support. We do not ask for your Discord password, sell Discord API data, use it for behavioral advertising, or train AI models on Discord message content.
This policy covers GuildRyx Core, Guard, Music, Beacon, Desk, Rank, Economy, Arcade, Flow, Pulse and Vault, plus the GuildRyx website, dashboard, status, documentation and support surfaces.
The categories below are feature-dependent. If a module is not enabled, GuildRyx does not collect that module's operational data merely because the module appears in the catalog.
1. Scope and responsibility
This Privacy Policy describes how BiOs Play handles personal information when operating the GuildRyx website, dashboard, Discord applications, support and related services. BiOs Play is responsible for GuildRyx's own processing and can be reached at support@biosplay.fun.
This is a separate, GuildRyx-specific policy. BiOs Play's separate privacy policy applies to its gaming, hosting and broader account surfaces. GuildRyx can use the existing BiOs Play Discord session so you do not need a second password. Where that shared identity service is used, both policies apply to their respective processing.
Discord independently controls its platform and accounts. Review Discord's Privacy Policy for Discord's practices. A Discord server owner or administrator also decides which GuildRyx modules to enable and may independently control community content, logs or transcripts.
2. Information we handle
| Category | Examples | When it is handled |
|---|---|---|
| Discord identity | User ID, username, display name, avatar, and servers returned by the approved identify and guilds scopes. | When you sign in, authorize an application or open an authenticated workspace. |
| Server and installation data | Server ID and basic profile, selected channels and roles, application ID, permission state, feature configuration and readiness timestamps. | When an authorized administrator connects or configures a Discord server. |
| Core, Guard and Desk data | Configured welcome or role actions; moderation subject, actor, reason, rule match and case history; ticket participants, form responses, messages, attachments and transcripts. | Only when the relevant feature is enabled or a user interacts with it. |
| Music and Beacon data | Voice or channel IDs, queue and request metadata, playlist or history entries, subscribed feed URLs, webhook templates and delivery results. | When an administrator enables the integration or a member requests it. GuildRyx does not need to store live voice audio. |
| Rank, Economy and Arcade data | Activity or XP events, levels, virtual balances, inventory, rewards, game participation and results. | When the corresponding progression or game feature is enabled. |
| Flow, Pulse and Vault data | Automation definitions and run results, operational analytics, configuration snapshots and Discord metadata needed for a permitted restore. | When an administrator creates a workflow, views analytics or requests a snapshot. |
| Support and communications | Email address, Discord identity, ticket content, attachments and the history needed to answer or resolve a report. | When you contact GuildRyx or report an issue. |
| Technical and security data | IP address, browser and device details, page or API request, timestamp, session identifier, bot connection state, errors, rate-limit and abuse signals. | When you use the site, dashboard, applications or APIs. |
3. Where information comes from
- You: information you submit, configure, authorize or send to support.
- Discord: OAuth profile data, server metadata, interactions, gateway events and API responses allowed by the scopes, intents and permissions in use.
- Server owners and members: community configuration, tickets, moderation actions, commands and other module interactions.
- Connected services: feeds, webhooks or supported integrations that an administrator deliberately enables.
- Our systems: session, request, bot health, diagnostic, security and abuse-prevention records generated while operating GuildRyx.
We do not buy personal data from data brokers. We do not ask Discord users to provide their Discord password or account token.
4. Why we use information
| Purpose | Typical legal basis where one is required |
|---|---|
| Authenticate you, connect an authorized server and deliver requested modules. | Performance of our agreement with you, or steps you request before using the Service. |
| Apply administrator-configured moderation, support, workflow, notification and community functions. | Performance of the Service; the server owner may need a separate lawful basis for its community configuration. |
| Protect accounts, users, Discord, infrastructure and the public from fraud, abuse and security incidents. | Our legitimate interests in a safe, reliable service and, where applicable, legal obligations. |
| Diagnose failures, understand reliability and improve features using necessary or appropriately limited operational data. | Our legitimate interests in operating and improving GuildRyx; consent where local law requires it for non-essential analytics. |
| Respond to support, privacy, legal and enforcement requests. | Performance of the Service, legitimate interests and compliance with legal obligations. |
| Send optional communications outside Discord. | Your consent, which you may withdraw, unless the message is necessary to provide requested support or security notice. |
These bases are provided for jurisdictions that use concepts such as contract, legitimate interests, consent and legal obligation. The exact basis can depend on the feature and your location. We do not use Discord API data for a purpose unrelated to GuildRyx's stated functionality.
5. Cookies, sessions and website analytics
The shared BiOs Play sign-in uses a secure, HTTP-only session cookie so the website can recognize an authenticated user. It is used for account access and security, not to expose a Discord credential to browser scripts. Local storage or similar browser storage may be used for interface preferences.
| Name | Where and why | Normal lifetime |
|---|---|---|
bios_session | A signed, HTTP-only, SameSite=Lax session shared on .biosplay.fun so GuildRyx can use the existing Discord identity without another account. | Up to 7 days, or until logout or invalidation. |
bios_oauth | A temporary, HTTP-only OAuth security value used to validate the Discord sign-in callback and return destination. | Up to 10 minutes and cleared after callback. |
bios-theme | A first-party local-storage preference for the selected light or dark interface theme. | Until you change it or clear site storage. |
GuildRyx does not currently load Google Analytics or another non-essential analytics tracker on its public host. BiOs Play may use analytics on its separate website under the BiOs Play privacy policy. If GuildRyx introduces optional analytics later, this policy and the site controls will be updated before that tracking is enabled, and consent will be requested where applicable law requires it.
We do not use Discord API data for targeted advertising and do not disclose it to advertising networks or data brokers.
6. When information is shared
We disclose information only as reasonably necessary to:
- Discord: send interactions, commands and requested actions through Discord's platform;
- service providers: host, secure, monitor or support GuildRyx, subject to appropriate access limits;
- administrator-enabled integrations: deliver a webhook, fetch a subscribed feed or use another service the administrator intentionally connects;
- server owners and authorized staff: show configuration, tickets, cases, logs or analytics their Discord permissions allow them to access;
- legal and safety recipients: comply with lawful process, protect rights and safety, investigate abuse or respond to an emergency; and
- a successor: support a legitimate reorganization or transfer, with continued protection and notice where required.
GuildRyx uses restricted, operator-managed services to provide the product. We do not sell personal information or Discord platform data.
7. Retention, deletion and backups
In the current app-suite release, Guard warning records are limited to the newest 500 per server and queried for up to 90 days. Rank stores member IDs, XP, and award timestamps, not message contents. Economy stores server-specific virtual balances and daily-claim timestamps. Arcade stores short-lived questions and aggregate scores. Pulse stores aggregate daily join and departure counts for a rolling 30-day reporting window, with temporary deduplication hashes. Vault keeps the newest ten Guildryx settings snapshots per server. Cleanup runs during service startup and relevant app activity; these are not promises of immediate physical erasure from every backup.
Core stores its server configuration, published panel references, and recent activity for up to 30 days, limited to the newest 100 actions per server. When suggestions are enabled, it stores submitted suggestion text, author and voter identifiers, votes, staff decisions, responses, and delivery references so the community can continue reviewing ideas across restarts. Suggestions remain until an eligible deletion request is processed; pausing Core does not erase them. Event reminder delivery claims are retained for up to 30 days. Welcome cards use Discord avatars for delivery and are not stored as a separate avatar archive. Uploaded welcome backgrounds are stored as resized images for that server; previews require dashboard access, and the saved background is included in welcome cards delivered to Discord. Restoring the default removes the selection without deleting older uploads. Contact support for removal of stored uploads.
Desk stores ticket identifiers, participants, channel references, and state, not copied transcripts. Closing a ticket keeps its channel and messages in Discord; a server manager must manage Discord’s retained channel history separately. Turning an app off stops future collection or new actions but does not itself delete existing records. Use the privacy contact below to request deletion of eligible stored data.
We keep information only while it is reasonably needed for the purpose described, the server owner's available configuration, security, dispute resolution, backup recovery and applicable law. Retention therefore depends on the data and enabled module rather than one misleading universal period.
- Identity and server configuration generally remain while the account or server is connected and for a limited recovery period after removal.
- Moderation cases, tickets, transcripts, workflow runs, activity records and snapshots remain according to the available server setting, operational need and legal requirements.
- Short-lived session and diagnostic records are rotated when no longer needed, but security or traffic records may be preserved longer when an incident, dispute or applicable law requires it.
- Backups roll out of service on a separate cycle, so a deleted item may remain temporarily in a protected backup and will not be restored except for disaster recovery or a legal requirement.
Deleting a Discord account, leaving a server or removing a bot does not automatically identify and erase every GuildRyx record. Contact us with your Discord user ID and relevant server ID. We will verify the requester, evaluate records controlled by the server owner, and delete or de-identify eligible information. Some traffic or security records may need to be retained for a statutory period under applicable Pakistani law.
8. How we protect information
GuildRyx uses safeguards designed for the risk and current service stage, including protected sign-in sessions, limited application permissions, encrypted connections where applicable, access controls, security records and recoverable backups. Private service credentials are not intentionally sent to your browser.
No system is perfectly secure. Use strong account security and multi-factor authentication in Discord, limit administrator roles, review connected applications and report suspected compromise promptly. Do not email or paste secrets into support tickets.
9. International processing
GuildRyx is operated from Pakistan. Discord, Google and administrator-enabled integrations may process information in other countries where they or their providers operate. Those countries may have different privacy laws from yours.
Where a transfer safeguard is legally required, we will use an available lawful mechanism or stop the affected processing. We do not claim that every destination has been declared adequate by your local regulator. Contact us for information about a transfer relevant to your request.
10. Your choices and privacy rights
Depending on your location and the circumstances, you may be entitled to:
- ask whether we process your personal information and request access to it;
- correct inaccurate information or complete incomplete information;
- request deletion, restriction or a portable copy of eligible information;
- object to processing based on legitimate interests;
- withdraw consent for future processing where consent is the basis; and
- complain to an applicable privacy or data-protection authority.
Send a request to support@biosplay.fun or use GuildRyx support. Include the Discord user ID and server ID relevant to the request, but never send a password or token. We may ask for reasonable verification and may need to involve a server owner when that owner controls the record. We will explain if a legal exception or another person's rights prevent a request from being fulfilled.
You can also disconnect GuildRyx through Discord, remove the applications from servers you control, revoke authorized access, adjust module settings and use browser controls for analytics.
11. Discord server owners, administrators and members
A server owner or administrator chooses whether to install GuildRyx, which modules to enable, where outputs are sent and which staff can access them. For some community records, that owner may be an independent controller or decision-maker under local law. Members should first contact server staff for community rules, a moderation case or a transcript the server controls, and contact us for GuildRyx's own processing.
Administrators must provide notices and obtain consent where required, avoid collecting unnecessary sensitive data, configure appropriate retention and access, and keep a human review path for consequential moderation. GuildRyx does not authorize an administrator to disregard member rights.
12. Age requirements
GuildRyx is not directed to children under 13 or anyone below the higher minimum age for Discord in their country. We do not knowingly use Discord API data from a person who is not permitted to use Discord. If you believe an underage person's information has been handled, contact us with enough non-sensitive detail to investigate. We may coordinate with the relevant server owner and Discord and remove eligible information.
13. Automated moderation and decisions
GuildRyx modules may apply administrator-configured filters, scores, workflows or moderation actions. GuildRyx does not use those tools to make decisions that produce legal or similarly significant effects such as credit, employment, housing or insurance eligibility. Automated signals can be wrong and are not a substitute for human review.
For a server moderation action, contact that server's staff and use its appeal route. For a GuildRyx platform restriction or suspected system error, contact GuildRyx support.
14. Policy changes, incidents and contact
We may update this policy as GuildRyx activates modules, changes providers or responds to law and security needs. We will change the “last updated” date and give reasonable notice of a material change through the site, dashboard, Discord or another appropriate channel when practicable.
If a security incident creates a reportable risk, we will investigate, contain it and notify affected people, Discord or authorities as applicable. Report a suspected incident, privacy concern or request to support@biosplay.fun or GuildRyx support.