Privacy

Effective 2026-07-12.

Guild Masters is built to only know what your guild tells Discord. We won't read your messages, we won't touch your WoW account, and we don't collect more than the dashboard needs to run your guild.

Signing in

Signing in runs Discord OAuth with three scopes: identify(your Discord user ID, username, and avatar, so we know who's signed in and can show your name in the dashboard), guilds (the list of Discord servers you administer, so you can pick which one to connect), and bot(installs the Guild Masters bot into the server you choose, so it can post in your channels). That's the identity Guild Masters runs on: no separate account, no separate password, and no email required just to sign in.

We don't request access to your Discord messages, your DMs, or any server you haven't connected. Installing the bot only happens for the server you explicitly pick; we don't see or join anything else.

What we store for a connected guild

The configuration an officer sets up (which modules are turned on, application question templates and the answers applicants submit, vote tallies, raid signup templates and the responses members give them) is stored server-side, scoped to your guild, so it's there across browsers and devices instead of living in one tab's storage.

We also store your Discord user ID, display name, and avatar for each administrator, and the Discord server (guild) ID and name for each server you connect - that's the identifier your guild's dashboard is scoped to - plus which of those servers you administer, so the dashboard shows you the right ones.

Applicants verify with Discord before they can submit an application. That sign-in reads their public profile basics only (Discord user ID and username - never their servers, messages, or email), and we store that ID and username on the application itself so the guild's officers can actually reach them. An applicant's verified identity lives with the rest of that guild's application data and leaves on the same retention schedule described below.

The roster module stores your guild's member list server-side too: each member's handle, rank, and class, the officer note on them if one is written, and, when an officer links one, the Discord account behind the handle. Officers build that list by hand or by pushing a snapshot of your Discord server's roles into it. Either way it lives in our database, scoped to your guild and walled off from every other guild's at the database layer, and it changes only when an officer edits or re-syncs it, not by watching your server.

What we don't collect

Who we share data with

We don't sell your data, and we don't share it beyond what actually runs Guild Masters. Four parties currently touch it, each doing one job: Discord (sign-in and the bot itself - unavoidable, it's the platform Guild Masters runs on), Stripe (billing, once subscriptions launch - Stripe sees payment details, not your guild data), our hosting provider (runs the servers Guild Masters is deployed on), and Cloudflare (delivers all of the site's traffic on its network, and will run the bot-check on our public forms when we turn that on). None of them get access beyond what their one job requires.

We haven't designated a separate EU representative. Our processing of EU and UK players' data is recurring but not large-scale at our current size, and we don't collect any special-category data (health, biometric, political opinion, or similar) - the "no politics" rule on our public pages reinforces that. We'll revisit this the same time we revisit moving off self-hosted infrastructure, not on a fixed calendar date.

Server logs

Our web server keeps standard access logs: IP address, user agent, request path, and HTTP status, held for a limited time for debugging and abuse prevention. They aren't used to build a profile of you and aren't shared with anyone. Because the site is delivered through Cloudflare, Cloudflare's network sees those same connection details in transit, under Cloudflare's privacy policy; we don't get a per-visitor report out of that.

Wowhead tooltips

On the Loot module, every item name links to Wowhead and shows the in-game item card when you hover it. To do that, the loot page loads Wowhead's tooltip widget and fetches each item's data from Wowhead's servers (wow.zamimg.com, nether.wowhead.com, wowhead.com). As a result, Wowhead receives your IP address and which items you hover or click, the same as if you visited Wowhead directly. That is governed by Wowhead's privacy policy, not ours. The widget loads only on the Loot page, and clicking an item opens Wowhead in a new tab.

Your data rights

If you have a Guild Masters account, Export my data and Delete my account on your Account page already do this yourself, on demand: no email, no waiting on us. Export my data hands you a copy of everything tied to your account, across every guild you administer; Delete my account removes your sign-in and profile immediately, with guild data you left behind kept for 60 days in case a guild you administer needs to recover, then anonymized: your personal details are stripped out and only an anonymized version tied to your guild's Discord server ID stays, so the guild keeps its own history. An officer can offboard a whole guild the same way, from that guild's Settings page.

That covers anyone with an account. If you don't have one - you applied to a guild, or you're a member whose roster data an officer manages - or your request falls outside what the self-serve tools above do, email [email protected] and we'll handle it by hand. We commit to responding within one month, the standard GDPR turnaround, extendable once by up to two more months for a genuinely complex request.

Anonymous voting

Votes are anonymous to your guild. When a guild turns anonymous voting on, officers see the tally, not who cast which vote. That is a promise about what your officers see, not a promise that no record exists: our system keeps a sealed record of who voted, and that record is opened only to investigate abuse, never shown on a dashboard or shared with the guild.

Cookies

Two cookies, both strictly functional. The first is a session cookie set when you sign in with Discord, used only to keep you signed in. It's a __Host- prefixed cookie the browser never exposes to page scripts, and the value stored server-side is hashed, not the raw token. It expires after 7 days, or after 24 hours with no activity, whichever comes first. The second, __Host-gm_oauth_state, is an anti-forgery token that exists only while you're midway through the Discord login round-trip; it expires on its own after ten minutes at most. No ad trackers, no analytics pixels, no third-party marketing cookies.

Disconnecting the bot

Removing the Guild Masters bot from your Discord server stops it from doing anything there, but it doesn't by itself delete your guild's data - the two aren't linked. To actually remove your guild's data, an officer uses Offboard this guildon the Settings page. That follows the same path as Your data rights above: applications, votes, roster notes, and every other record for that guild stay intact for 60 days in case that was a mistake, then get anonymized rather than deleted outright, with your guild's Discord server ID kept as the one thing that survives so the guild keeps its own history.

Questions

Email [email protected] with anything this page doesn't answer.

Guild Masters is operated by LLMATIONS LLC.