Laguno

Legal

Privacy Policy

Last updated: 28 June 2026

Terms of ServicePrivacy Policy

1. Data Controller

The controller of the personal data collected by Laguno is its individual creator, who can be contacted at r.amarelinho@gmail.com.

This policy applies to the Laguno bot on Discord and to its web dashboard. It complies with the General Data Protection Regulation (GDPR — Regulation EU 2016/679).

2. Data We Collect

Laguno collects and stores only the data strictly necessary for its features to work:

  • Server (guild) IDs — to associate settings and records with each server.
  • Channel and role IDs — to know where to send messages and which roles to assign automatically.
  • User IDs — to record warnings (warns) and moderation actions applied to members.
  • Server settings — the preferences administrators set in the dashboard (log channels, welcome messages, etc.).
  • OAuth2 session data — Discord username, avatar and list of administered servers, obtained temporarily when logging in to the dashboard.

We do not collect, read or store: message content (public or private), passwords, payment details, email addresses, geographic location, or any other personal information outside the context described above.

3. Legal Basis for Processing (GDPR / LGPD)

The processing of the data collected rests on the following legal bases:

For users in the European Union — GDPR (Regulation EU 2016/679):

  • Performance of a contract (art. 6(1)(b)) — server, channel, role and user IDs are necessary to provide the service requested by the administrator when adding the bot.
  • Legitimate interests (art. 6(1)(f)) — OAuth2 authentication data is processed on the basis of the legitimate interest of verifying that the user has permission to manage the server in the dashboard.

For users in Brazil — LGPD (Law no. 13.709/2018):

  • Performance of a contract (art. 7, V) — processing necessary for the performance of the contract to provide the bot service.
  • Legitimate interest (art. 7, IX) — OAuth2 authentication and platform security, with respect for the fundamental rights and freedoms of the data subject.

4. How We Use the Data

The data collected is used exclusively to:

  • Provide Laguno's features (moderation, welcomes, logs, reaction roles, tickets).
  • Save each server's settings between sessions.
  • Authenticate server administrators in the dashboard via Discord OAuth2.
  • Keep records of moderation actions (warns, bans) for administrators to consult later.

We do not sell, share or hand over your data to third parties for commercial or advertising purposes.

5. Dashboard Authentication

The dashboard uses the Discord OAuth2 protocol for authentication. When you log in, Discord shares with us your user ID, username, avatar and the list of servers where you have administrator permissions.

This data is used exclusively to show the correct interface and to check whether you have permission to manage a given server. It is not stored permanently in our database — the session is kept in memory and expires automatically after logout or after a period of inactivity.

6. Sub-processors and Infrastructure

To provide the service, we rely on the following infrastructure providers, which may process data within the scope of their functions:

  • MongoDB Atlas — the database where settings and moderation records are stored. The data may be hosted on servers in Europe or in the USA with adequate safeguards (SCCs).
  • Vercel — hosting platform for the web dashboard. It may record technical access logs (IP, user-agent) for security and diagnostic purposes.
  • Discloud — hosting platform for the Discord bot.
  • Discord Inc. — the platform the bot runs on. The data shared by Discord through its API is subject to Discord's Privacy Policy.

7. Data Retention

Server settings are kept for as long as Laguno remains in the server. When the bot is removed, the configuration data is left inactive and its deletion can be requested.

Moderation records (warns) are kept indefinitely until the administrator deletes them manually through the dashboard or the bot's commands.

OAuth2 session data is not persisted — it is discarded automatically at the end of the session.

8. International Data Transfers

Some of our sub-processors (namely MongoDB Atlas and Vercel) may store or process data outside the European Economic Area (EEA) or Brazil. In these situations, transfers are protected by adequate mechanisms:

  • For EU users — Standard Contractual Clauses (SCCs) approved by the European Commission, under the GDPR.
  • For users in Brazil — transfers carried out in accordance with art. 33 of the LGPD, with adequate guarantees of protection equivalent to that provided for in Brazilian law.

9. Security

The data is stored in a MongoDB database with access restricted by credentials and network rules. Communication between the dashboard and the bot takes place through an internal API authenticated by a secret key.

We take reasonable technical and organisational measures to protect the data against unauthorised access, loss or destruction. However, no system is 100% secure. In the event of a security breach affecting your data, you will be notified as required by applicable law.

10. Your Rights (GDPR / LGPD)

As a data subject, you have the following rights — guaranteed both by the GDPR (EU) and by the LGPD (Brazil):

  • Access — request a copy of the data we have stored relating to your server or your user.
  • Rectification — correct incorrect or out-of-date data.
  • Erasure / Deletion — request the deletion of all data associated with your server (GDPR: art. 17; LGPD: art. 18, VI).
  • Restriction of processing — request that the processing of your data be restricted in certain circumstances.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection / Withdrawal of consent — object to the processing or withdraw your consent at any time, without prejudice to the processing carried out up to that date.
  • Information about sharing — know which entities your data is shared with (LGPD: art. 18, VII).

To exercise any of these rights, get in touch by email: r.amarelinho@gmail.com. We will reply within 30 days (GDPR) / 15 working days (LGPD).

Users in the European Union — may lodge a complaint with the competent supervisory authority: CNPD — National Data Protection Commission (Portugal).

Users in Brazil — may lodge a complaint with: ANPD — National Data Protection Authority (Brazil).

11. Minors

The service is not aimed at anyone under 13. We do not knowingly collect data from children. If you become aware that a minor has provided data without authorisation, get in touch with us so that we can proceed with its immediate deletion.

12. Cookies and Local Storage

The dashboard may use strictly necessary session cookies to keep the authentication state while you browse. We do not use tracking, advertising or third-party analytics cookies.

13. Changes to this Policy

This policy may be updated to reflect changes in the service's features, in the infrastructure used or in legal requirements. The date of the last update is always visible at the top of this page. Significant changes will be announced through Laguno's official channels.

© @michu & Laguno · 2026 · All rights reserved