Privacy Policy: GG-Bot and GEM
Version: 1.7
Effective date: 9 October 2026
Operated by: YD Great Media (sole trader, Sunshine Coast, Queensland, Australia) — ABN 97 516 623 849
The short version
This policy covers two products: The Gaming Gate Bot ("GG-Bot"), a Discord bot that surfaces public gaming data, such as Steam profiles, game deals and live-stream alerts, inside your Discord server, and The Greatest Embed Maker ("GEM"), its web companion, where you can design embeds and save templates and images. We built both to collect as little about you as possible.
The main personal identifier we store is your Discord user ID, alongside the Discord profile details described in §2.11, and we never sell them or share them for advertising. It exists so the bot knows who ran a command and can send the response back to the right person. If you use GEM's saved templates or images, we also store that content, which is yours and may contain personal information you choose to put in it (see §2.9). GEM also keeps basic usage statistics for everyone who visits it, signed in or not (see §2.12). Where you get the default setting, this uses a random ID stored in your browser, linked to your Discord account if you sign in. If you are in the EEA, the UK or Switzerland, or your browser sends a Do Not Track or Global Privacy Control signal, GEM stores nothing on your device and only counts the visit, using a random code that is forgotten when you leave the page and is never linked to you or your Discord account. In the EEA, the UK and Switzerland you can choose to turn on the stored, account-linked version when you sign in. We do not store your IP address in those records. Everything else we store is either operational telemetry (which you can opt out of) or your own configurable settings. We don't use your files or content to train AI models.
We do not collect your email. We do not see your private Steam data. We do not read or log your general chat or your DMs. The only exception is GEM's import feature, where a message is fetched only when an authorised user chooses it (see §1).
1. What we do not collect
- Email addresses. None are requested, stored, or processed by GG-Bot at any point.
- Private Steam data. GG-Bot reads only what is publicly visible on your Steam profile. If you have set your library, play history, friends list, or wishlist to private in Steam's own privacy settings, the bot cannot see it and will say so. Your Steam privacy settings are entirely under your control.
- Message content or DMs. GG-Bot does not read, scan or log the general chat in your server or your DMs. The one exception is GEM's import feature. When an authorised user (the server owner, an administrator, or a member of the server's GEM IMPORT role) deliberately chooses a specific message to import, GG-Bot fetches that single message's embed and component data so it can be rebuilt in the editor. Users can only import from channels they already have access to. Imported data is saved only as part of that user's GEM design and can be deleted at any time with "Delete all" in GEM. It is never used for any other purpose.
- Payment card data. GG-Bot commands are free. If you buy GEM Pro, payment is handled by Lemon Squeezy (see §3). We never receive or store your card details. Lemon Squeezy, as merchant of record, holds your billing details and sends us confirmation of your subscription status.
2. What we do store
Bot and account data is stored in AWS DynamoDB, and GEM saved templates and images are stored in AWS S3 (and served through CloudFront for images), with the core storage in region ap-southeast-2 (Sydney, Australia). All of this data is encrypted at rest using AES-256, including GEM images that are public by link. Encryption at rest protects the stored copies on AWS; AWS decrypts data only when it is served to you or to Discord. Your Discord user ID is used internally only and is never sold or shared with third parties other than our processors listed in §3.
2.1 Discord user ID
What it is: Your Discord snowflake ID (a numeric identifier Discord assigns to every account).
Why we store it: The bot needs to know who ran a command so it can send the embeds and responses back to you. We also use it, occasionally, to send you a direct message on the operator's behalf, in one of four categories: a roughly-monthly Owner Announcement (server owners), a rare major-feature User Announcement (anyone who's used a GG-Bot command), a Personal Account Message (a targeted, personal message from the GG-Bot team about your account, such as a competition win), or — only if you've explicitly opted in — a curated game Recommendation with current pricing and a storefront link, capped at 5 in any 7 days. It is not shared with any third party.
Owner Announcement and User Announcement messages never carry pricing, discounts, or affiliate links. Recommendation messages do, but only ever reach you once you've turned Recommendations on — see §4 of the Terms of Service for what that content may include. Personal Account Messages are about you and your account, and are sent only to the people they concern.
How to remove it: Run /gg link action:unlink-clear — this deletes your GG-Bot user record, which is where your Discord user ID and profile details are kept (see §4 for exactly what is deleted and what is anonymised). It does not delete GEM storage: GEM is a separate product that uses GG-Bot, and files you saved in GEM are covered separately in §2.9. You can delete them at any time using "Delete all" in GEM. To turn any of the direct messages described above on or off without unlinking anything else, run /gg notifications and click the Opt-in or Opt-out button next to the category you want to change. Each category is changed on its own, and turning off Owner Announcements or Personal Account Messages asks you to confirm first. All four categories are global (account-wide), so a change applies everywhere no matter whether you run the command in a server or in a direct message.
2.2 Linked Steam ID and Steam display name
What it is: When you opt to link your Steam account via the /gg link command, we store your Steam 64-bit ID and your Steam display name as it appeared at link time.
Why we store it: So commands like /gg games, /gg playwhat, and /gg profile know which Steam account to look up without you typing your URL every time.
Auto-populated country code: When you link, if your Steam profile publicly exposes a country code, we read it once and store it as a two-letter ISO code (e.g., AU) in your preferences, used only to display prices in your local currency. You can clear or change it at any time via the /gg settings command.
How to remove it: Run /gg link action:unlink-clear to remove your Steam link, along with the rest of your GG-Bot user record (see §4).
2.3 Per-user preferences
What it is: Configurable settings you set via /gg settings — preferred store (Steam, GOG, Epic), country/currency, minimum discount threshold, deal sort order, play recommendation filters, timezone, and leaderboard participation choices.
Why we store it: So the bot remembers your preferences between sessions.
How to remove it: Run /gg settings to reset preferences, or /gg link action:unlink-clear to delete your preferences along with the rest of your GG-Bot user record (see §4).
2.4 Operational usage data (opt-out available)
What it is: Standard operational telemetry — counts of which slash commands you use, daily snapshots, leaderboard participation figures. Stored against your Discord user ID for the limited purpose of keeping the bot healthy and improving the features people actually use.
Leaderboards: Leaderboard entries are saved only for people who use GG-Bot: you, and anyone you compare yourself with who already uses GG-Bot. Other people shown in a comparison, such as friends who don't use GG-Bot, are displayed in the result but are never saved. Leaderboard rows previously saved for people who don't use GG-Bot have been cleaned up.
Why we store it: To understand which features are used, to keep operational metrics meaningful, and to power the optional /gg leaderboard feature. Aggregate, bot-wide statistics are maintained separately and are not keyed to your user ID.
Opt out: Open /gg settings and turn off usage tracking. This stops per-user collection immediately. Running /gg link action:unlink-clear deletes your leaderboard entries, and it anonymises your existing usage stats and history: they are kept, but moved to a random anonymous ID, so they no longer point to you (see §4).
Retention: Usage stats rows carry a 31-day sliding TTL — inactive rows auto-expire. Daily snapshots also expire after 31 days. Leaderboard rows carry a 90-day TTL and auto-expire if not refreshed.
2.5 News tracker
What it is: A list of Steam app IDs for games you have searched news for via /gg news, plus the timestamp of each search. Stored inside your UserLinks record.
Why we store it: So the bot can deliver a personalised news feed for the games you track.
How to remove it: Removed when you run /gg link action:unlink-clear.
2.6 Guild schedules and alert subscriptions
What it is: Discord server (guild) IDs, channel IDs, and schedule configuration set by server administrators using /gg schedule and /gg alertlive. These are server-level configuration records, not personal data.
Retention: Persist until removed by a server admin or until the bot is removed from the server.
2.7 Cached public game and price data
What it is: Publicly available data fetched from Steam and our third-party data sources — game names, prices, reviews, genres, tags, player counts, screenshots. This is not personal data; it is the same information anyone can view on those services' websites.
Retention: Cached with TTLs ranging from a few hours (prices, reviews) up to 30 days (genre/tag data). Auto-expires via DynamoDB TTL.
2.8 Broadcast and service-announcement DMs
What it is: A record of the direct messages described in §2.1 — which category was sent, when, and the outcome (delivered, skipped because you'd opted out, or failed). The text of the messages themselves, and the broadcast header, are covered separately in §2.10. For the Recommendations category specifically, we also keep a record of your consent: the date you opted in, and how you opted in. Records created before 02 Oct 2026 may show that you opted in as part of an "ALL" selection (a button that no longer exists); from that date Recommendations can only be turned on individually, so new records will show an individual opt-in. Separately, on your account record, we keep the date of your very first GG-Bot direct message and the date of your most recent message in each category. None of these three record types — the recommendations consent record, your first-message date, or your per-category last-message dates — are time-limited (see Retention below).
Why we store it: To avoid sending you the same message twice, to enforce the cadence caps described in §2.1, to honour your opt-in and opt-out choices, to be able to show when and how you consented to Recommendation direct messages if that's ever in question, and to show the one-time welcome notice only on your genuinely first GG-Bot direct message.
What these messages contain: Owner Announcement and User Announcement direct messages never carry pricing, discounts, or affiliate links. Personal Account Messages are about you and your account. Recommendation direct messages — sent only once you've opted in — carry the same pricing and affiliate storefront links a channel post would; see §4 of the Terms of Service.
Opt in or out: Run /gg notifications — the panel shows all four categories (Owner Announcements, Personal Account Messages, User Announcements, Recommendations) with a direct Opt-in or Opt-out button next to each. Each category is changed individually; there is no single control that changes every category. Turning off Owner Announcements or Personal Account Messages asks you to confirm first. All four categories are global: they apply to you account-wide, whether you run the command in a server or in a direct message with GG-Bot, and none is specific to a single server. Your opt-in and opt-out choices are kept indefinitely, so you won't need to repeat them.
Retention: The record of an individual message (your user ID, category, and outcome) is kept for 90 days, then automatically deleted. Your Recommendations opt-in record, your first-message date, and your per-category last-message dates are kept for as long as your account record exists — no automatic expiry, the same lifecycle as your opt-in/opt-out preferences. Aggregate counts of how many people a given message reached are kept indefinitely for our own records but do not identify you.
2.9 GEM saved templates and images
Optional online storage. Saving things online in GEM is your choice. You can use GEM without saving anything, and we store only the templates and images you choose to save. Each user gets a limited amount of storage, assigned to your account. Your saved templates can be reached only through the GEM website, when you are signed in. Images work differently, because they have to be public so Discord can display them (see "Images are public by link" below).
What it is: Templates you save in GEM and images you upload, plus the details needed to run them: item name, type, size, dates, and your Discord user ID. We also keep an account and activity record: how much you have stored, how many items, your plan, and the date your GEM Pro plan ended, if it did, and the date you last signed in to or used GEM. Templates and images may contain anything you put in them, including personal information about you or others. The free tier allows 1 MB and 2 templates, and images count toward the 1 MB. If you use GEM's import feature (see §1), the embed and component data of the message you chose becomes part of the template you save, and is stored, kept and deleted in the same way as the rest of that template.
Why we store it: Your templates and images are stored because you chose to save them. We keep the account and activity record so we can apply your plan's storage limits and, where they apply, the rules in §5A of the Terms for when a GEM Pro plan ends or a free account is inactive.
Where and how: On AWS in ap-southeast-2 (Sydney, Australia), encrypted at rest. Templates are private and reachable only through your signed-in GEM account. They are not end-to-end encrypted, so the operator can technically access them, and does so only to run and secure the service, to help you at your request, to investigate abuse or a report, or where the law requires. We don't use your files or content to train AI models, and we do not keep separate backups of them.
Images are public by link. Images used in embeds have to be publicly reachable so Discord can display them. Each image gets a long, random, unguessable web address on gem-media.ydgreatmedia.com. It is not listed or searchable, but anyone who has the address can view the image. Images are still encrypted at rest in storage (see §2). The image stays linked to your account, and it is served through a content delivery network that keeps cached copies at locations around the world. Images can carry hidden metadata (EXIF), which can include location and device information. We remove location and device metadata (EXIF) from images when you upload them.
Retention: Kept while your account is active, unless we delete them under the rule for inactive free accounts below. Unlinking or clearing GG-Bot does not delete GEM files. On a free account, we may delete your GEM saved templates and images if you have not signed in to GEM or used GEM while signed in for 6 months (see §5A of the Terms). We reserve this right so that we do not keep files longer than we need to. We have not built this and may never use it. If we do, we will try to give you notice and a chance to download your items first, but we do not promise to. This does not apply to GEM Pro accounts or to accounts whose GEM Pro plan has ended, which follow the schedule below. If your GEM Pro plan ends, counting from the day it ends: weeks 0 to 8, your items are read-only (you can still read and delete them); weeks 8 to 12, your items are locked (no reading or saving, but you can still delete them); at the end of week 12, all of your GEM saved templates and images are permanently deleted, together with your account and activity record and the related name records. You can download an archive package of everything you have stored at any time during the whole 12 weeks, at no charge. Renewing GEM Pro before deletion restores access. Deleted items are removed from storage promptly; an image address stops working, subject to short cache expiry.
How we tell you: GEM shows a warning icon on the PRO button and, on the PRO screen, your usage and a countdown. We may also send a reminder by other means, but we do not promise to.
How to remove it: Delete individual items, or use "Delete all", in GEM at any time, including while your items are read-only or locked. You can also contact us.
2.10 Stored message text, recipient lists and broadcast headers
What it is: When the operator sends a broadcast through GG-Bot (any type: owner, user, recommendation or Personal Account Message), GG-Bot stores two things.
- The message record: one copy of the message text for that broadcast. For a Personal Account Message sent to specific people, the list of Discord user IDs it was sent to is stored on the same record.
- The broadcast header: the broadcast ID, category, audience type, who sent it (the operator), when it was sent, a fingerprint (hash) of the message, delivery counts, status, the reason if it was stopped, and the Discord user IDs of any test recipients the operator sent a test to. The header does not contain the message text or the list of people an individual Personal Account Message was sent to.
Why we keep it: To run the service, to resend or finish a broadcast that was interrupted, to avoid sending the same message twice, and to investigate complaints or misuse. Our basis is performing the service and our legitimate interest in accountability.
Your opt-outs: Personal Account Messages are an ordinary category. You can switch them off in /gg notifications, after a short confirmation (see Terms §5). The operator does not send direct messages that ignore your opt-outs.
Retention: The stored message text, and any recipient list kept with it, is deleted automatically after 90 days. The per-recipient records described in §2.8 are also kept for 90 days. The broadcast header is kept indefinitely, without the message text. That includes any test-recipient user IDs it holds, for as long as the header exists. If you ask us to delete your data, we will delete or anonymise anything that identifies you, including a test-recipient ID in a header, unless we need to keep it to handle a complaint or a legal claim.
How to remove it: Contact us.
2.11 Discord profile details and server details
What it is: Alongside your Discord user ID, GG-Bot keeps the following Discord profile details on your user record: your Discord username, your display name and your avatar hash. The avatar hash is a short identifier that Discord assigns to your avatar. We build the image link from it only when needed. We never download or store the image itself. On its server records, GG-Bot keeps the Discord server's name and the Discord user ID of the server's owner. These details are public Discord information that Discord provides to the bot.
When we capture it: When GG-Bot sends you a direct message; when the operator looks a user up in the admin tools; and when someone posts from GEM (in which case the details of the poster, and of the server posted to, are recorded).
Why we store it: So the operator can tell who a message was sent to or who an account belongs to, and which server a record relates to, instead of working from bare numeric IDs; to investigate delivery failures, complaints and misuse; and to keep GEM posting and the admin tools accurate. It is not used for advertising or profiling, is not sold, and is not shared with anyone other than our processors in §3.
Lawful basis: Our legitimate interest in running, securing and supporting the service and in being accountable for messages we send, and performing the service you asked for when you post from GEM.
Retention: Your profile fields are kept for as long as your GG-Bot user record exists, and are deleted when you run /gg link action:unlink-clear. Server records are kept while GG-Bot is in the server. GG-Bot does not yet detect when it has been removed from a server, so a server record may remain after removal, and may be kept afterwards for record-keeping unless you ask us to delete it.
How to remove it: Your profile fields (username, display name and avatar hash) are removed when you run /gg link action:unlink-clear. Server details (the server's name and its owner's Discord user ID) are not removed by that command; contact us to have them removed.
2.12 GEM usage statistics (everyone who visits GEM)
What it is: When you use GEM, whether or not you are signed in, it records basic usage so we can see which features people use and fix problems. It works in one of two ways, called device mode and visit mode.
Device mode. This is the default for visitors outside the EEA, the United Kingdom and Switzerland, unless your browser sends a Do Not Track or Global Privacy Control signal. In the EEA, the United Kingdom and Switzerland it applies only while you are signed in and only if you have chosen "Accept all", or turned on "Help improve GEM", in the privacy preferences GEM shows when you sign in. GEM records:
- A random device ID. A random code (a UUID) that GEM stores in your browser's local storage on that device, under the name
gem_aid. It is not made from your name, your device details or your IP address, and it is not shared with any other website. - A session ID. Another random code, stored under the name
gem_sess, which changes after 30 minutes of inactivity. - Usage events, and country and device type (described below).
- If you sign in with Discord: your Discord user ID is attached to events during signed-in use, and we record a link between your device ID and your Discord user ID. We do not rewrite or backfill events from before you signed in, but because of the link, the operator can see earlier activity from that device together with your account's activity.
Visit mode. GEM uses this if you appear to be visiting from the EEA, the United Kingdom or Switzerland (or we cannot tell where you are) and you are signed out, or you have not turned on "Help improve GEM"; and also if your browser sends a Do Not Track or Global Privacy Control signal (from anywhere). GEM still counts the visit, but:
- It uses a random code generated each time the page loads and kept only in your browser's memory. Nothing is written to your browser's storage or cookies, and the code is forgotten when you leave or reload the page. It cannot be recognised on a later visit.
- It is never linked to your Discord account, even if you are signed in. GEM sends these records without cookies, and our servers refuse to attach a Discord user ID to them.
- It records usage events, country and device type (described below), and nothing else.
- Because these records are not linked to you, we cannot find or delete an individual visit's records. They are deleted automatically after 90 days.
Usage events. What you did in GEM, for example: opened GEM (the page, and the website you arrived from, as a host name only); started a new design; loaded a design from a file or from pasted text; exported; imported an existing Discord message; updated or posted a message (each with whether it worked, and whether the design uses classic embeds or the newer components format); signed in or signed out; switched between the JSON, edit and design views; opened or closed a panel; and how far you got through the welcome tour. Each event also carries a time, the GEM version, and a label showing whether it was recorded in device mode or visit mode. Events do not include the content of your designs, messages, text or images, file names, or server or channel names.
Country and device type. Your country only, taken from the content delivery network's country header, and a device type of desktop, mobile or tablet, worked out from your browser's identification string. We do not keep the browser identification string itself.
What we do not do: We do not store or forward your IP address in these usage records. (Like any website, the AWS network that delivers the request handles your IP address momentarily to complete it; we have configured GEM not to log it for these requests.) We do not use cookies for this, fingerprint your browser, use third-party analytics or advertising tools, build advertising profiles, or sell or share this data. We do not try to re-identify visit-mode records. Requests from known bots and crawlers are discarded.
Why we store it: To understand which GEM features are used, to find and fix problems, and to plan improvements. It is not used for advertising or for any decision about you personally.
Where and who sees it: The records are stored by GG-Bot in AWS DynamoDB in ap-southeast-2 (Sydney) and are viewed only by the operator, in our internal admin dashboard.
Lawful basis: Our legitimate interest in running and improving GEM. In the EEA, the United Kingdom and Switzerland, storing a device ID on your device and linking your usage to your Discord account (device mode) is based on your consent, which you give in the privacy preferences shown when you sign in. Visit mode stores nothing on your device and is not linked to you.
Retention: Usage events, in both modes, are deleted automatically 90 days after they are recorded. The link between your device ID and your Discord user ID is deleted automatically after 90 days without a sign-in, and immediately when you run /gg link action:unlink-clear.
Your choices: GEM has no general on/off switch. You can limit what it does in these ways:
- Browser signals. If your browser sends a Do Not Track or Global Privacy Control signal, GEM uses visit mode: no ID is stored on your device and nothing is linked to your account. No privacy preferences panel is shown. If a device ID was already stored, GEM deletes it.
- EEA, UK and Switzerland. While you are signed out, GEM uses visit mode. When you sign in, GEM shows a privacy preferences panel with "Accept all", "Essential only" and "Manage preferences". "Essential" (signing in and saving your designs) is always on. "Help improve GEM", which stores a random ID in your browser and links your usage to your Discord account, is off unless you turn it on, and signing in and saving designs never depend on it. If you choose "Essential only", GEM stays in visit mode. You can change your choice at any time using "Privacy preferences" in the account menu. Turning "Help improve GEM" off deletes the device ID and session ID from your browser and removes the link between them and your Discord account. When you sign out, GEM stops using the device ID and deletes it. Your choice is remembered in your browser under the name
gem_consent; if a different Discord account signs in on the same browser, GEM asks again. - Clear your browser data. Clearing local storage for this website removes the device ID, session ID and your saved choice (
gem_aid,gem_sessandgem_consent). Outside the EEA, UK and Switzerland a new random ID will be created on your next visit, so to stop device mode altogether, use the browser signals above. - Elsewhere. There is no on/off switch. Use the browser signals above, clear your browser data, or contact us.
- Ask us. Contact us (see §4) and we will delete the device-mode records we can match to you.
- Signed-in data. Running
/gg link action:unlink-clearremoves the device link. Events that carry your Discord user ID expire within 90 days, and we will delete them sooner on a written request (see §4).
3. Third-party services
There are two distinct categories of third party to be aware of:
A. Services your data may reach:
| Service | What reaches them | Their privacy policy |
|---|---|---|
| Steam Web API (Valve) | Your Steam ID — only when you've linked an account and a command requires looking up your public profile data. No other personal data. | store.steampowered.com/privacy_agreement |
| Discord | GG-Bot operates inside Discord. We receive your Discord user ID, username, display name and avatar reference (see §2.11) as part of slash command interactions. Discord's own Privacy Policy governs everything else about how Discord handles your data. | discord.com/privacy |
| AWS (Amazon Web Services) | Acts as our data processor. Your stored data lives on AWS DynamoDB in ap-southeast-2 (Sydney). AWS does not access or use your data for its own purposes. | aws.amazon.com/privacy |
| AWS S3 and CloudFront | Your saved GEM templates and images, stored in S3 in ap-southeast-2 (Sydney) as our processor. Images are also cached on CloudFront edge servers around the world so they load quickly. CloudFront also delivers the GEM website and tells us your country (see §2.12). | aws.amazon.com/privacy |
| Lemon Squeezy | Payment and billing details for GEM Pro. Lemon Squeezy is the merchant of record and handles payment processing, tax and invoicing; we do not receive your card details. We receive confirmation of your subscription status. | lemonsqueezy.com/privacy |
B. System-side data sources (no user data sent):
From time to time, the bot retrieves game data, pricing data, and stats from third-party services such as IsThereAnyDeal (ITAD), CheapShark, and SteamSpy. These queries are made from our infrastructure using our own API keys — your identity is not sent to any of them, and the set of services we use may change over time as the bot evolves.
4. How to access or delete your data
You have the right to request access to, correction of, or deletion of the personal data GG-Bot holds about you.
Self-service (instant):
/gg link action:unlink-clear— makes you no longer identifiable in GG-Bot. It is available to everyone at any time, whether or not you have linked a Steam account. It is not a "delete all my data" button, and GG-Bot has no self-service "delete my account" feature.- Deleted: your GG-Bot user record (your Steam link, preferences, news tracker, counters, and your Discord username, display name and avatar hash), your leaderboard entries, the links between you and your servers, and the link between you and any GEM device IDs (see §2.12).
- Anonymised, not deleted: your command usage stats and history are kept, but moved to a random anonymous ID so they no longer point to you.
- Not touched: GEM saved files and GEM's own records (see below). Server details (see §2.11) also remain unless you contact us. GEM usage events that carry your Discord user ID expire on their own within 90 days (see §2.12).
/gg settings— adjust or reset preferences, opt out of usage tracking, opt out of leaderboards.- GEM usage statistics — in the EEA, UK and Switzerland, use "Privacy preferences" in the GEM account menu. Elsewhere GEM has no on/off switch: turn on Do Not Track or Global Privacy Control in your browser, clear this website's local storage, or contact us (see §2.12).
GEM saved files (self-service): In GEM you can delete any saved template or image, or use "Delete all", at any time, including if your GEM Pro plan has ended and your items are locked. If your plan has ended you can also download an archive package of everything you have stored, at no charge, for the whole 12 weeks before deletion (see §2.9). Otherwise, contact us for a copy of your data.
Contact request:
If you want assistance, confirmation of what's stored against your Discord user ID, a copy of your data, or deletion of anything the self-service options above don't cover, contact us via the YD Great Media Contact Page.
We will respond to data access and deletion requests within 30 days. Your data request also covers the records of direct messages sent to you, including stored message text, recipient lists and broadcast headers that identify you (see §2.8, §2.10 and §2.11). Because a GEM device ID is not tied to your name, we can only find device-mode usage events if you give us the device ID (it is visible in your browser's local storage for the GEM site, under the name gem_aid) or if you were signed in when they were recorded. Visit-mode records cannot be matched to you, so we cannot find or delete them; they expire on their own after 90 days.
5. GDPR and international users
GG-Bot is operated from Australia and is not directed at EU residents as a primary audience. However, we recognise that EU and UK users may use the bot, and we apply the following principles consistent with GDPR Article 5 regardless:
- Lawful basis: Legitimate interest (providing the service you requested) and your consent (linking your Steam account is entirely voluntary).
- Lawful basis for direct messages: Owner Announcement, User Announcement and Personal Account Message direct messages rely on legitimate interest (informing you about a service you already use, or about something that concerns your account). Recommendation direct messages rely on your explicit consent, given when you opt in via
/gg notifications(clicking Opt-in on Recommendations, which can only be done individually), which you can withdraw at any time via the same panel's Opt-out button. Recommendations consent and withdrawal are always account-wide — there is no server-specific version of this setting, so opting in or out affects you the same way no matter which server (or DM) you ran the command from. Consent records created before 02 Oct 2026 may show an "ALL" opt-in from the earlier panel; these remain valid records of your consent. - Right to object: You can object to any processing based on legitimate interest — including Owner Announcement, User Announcement and Personal Account Message direct messages — at any time via
/gg notificationsor by contacting us. - Data minimisation: We store only what is needed to deliver the bot's functionality.
- Storage limitation: Retention periods are defined and enforced via TTLs or explicit deletion, except for the account preferences and broadcast headers described in §2.8 and §2.10, which are kept until you ask us to delete them. The core UserLinks record persists until you choose to unlink — your control, on your timetable.
- Right to erasure:
/gg link action:unlink-clearinstantly deletes your GG-Bot user record, leaderboard entries and server links, and anonymises (rather than deletes) your usage history so it no longer identifies you. GEM files can be deleted with "Delete all" in GEM. For anything else, or if you want your data deleted rather than anonymised, we will honour a written request (see §4). - Data portability: GEM saved files can be downloaded as an archive package (see §2.9). For everything else, on request we can provide a summary of the data we hold against your Discord user ID.
- Lawful basis for GEM storage: Performing the service you asked for (saving and serving your items), and our legitimate interest in keeping GEM secure and free of abuse.
- Lawful basis for GEM import: Performing the service you asked for, when an authorised user deliberately chooses a message to import. The message data is not used for any other purpose.
- Lawful basis for GEM usage statistics: Our legitimate interest in running and improving GEM (see §2.12). For visitors who appear to be in the EEA, the UK or Switzerland, storing a device ID and linking usage to your Discord account is based on your consent, given when you sign in by choosing "Accept all" or turning on "Help improve GEM". It is off by default, signing in and saving designs do not depend on it, and you can withdraw it at any time using "Privacy preferences" in the GEM account menu, which is as easy as giving it. Until you consent, GEM uses visit mode only, which stores nothing on your device and is not linked to you; you can object to that at any time by turning on Do Not Track or Global Privacy Control in your browser, or by contacting us.
- Your content and other people's privacy: If you upload images or templates containing other people's personal information, you are responsible for having the right to do so (see Terms §6).
- International transfers: GEM storage and usage statistics are hosted in Australia. If you are in the EU or UK, your data is transferred to Australia to provide the service. Images may also be cached at AWS edge locations worldwide.
- Retention for GEM: see §2.9 and §2.12.
Requests should be directed to the contact page linked above.
6. Children
GG-Bot is not directed at children under 13. Discord's own Terms of Service prohibit users under 13 from creating accounts. We do not knowingly collect data from children under 13. If you believe we have inadvertently done so, please contact us for immediate removal.
7. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will:
- Update the version number and effective date at the top of this document.
- Always publish the latest version of this policy, up to date, on the GG-Bot page at https://www.ydgreatmedia.com/gg-bot.html. Use the "Privacy policy" and "Terms of service" links at the bottom of that page.
- For material changes that affect how existing data is handled, publish the updated policy on that page at least 14 days before the change takes effect.
- Version 1.7 (9 October 2026): added usage statistics for GEM (new §2.12). GEM now records, for everyone who visits it whether or not they are signed in, usage events (such as opening GEM, creating, loading, exporting, importing, updating and posting designs, signing in and out, switching views, opening panels and welcome tour progress), together with your country and device type (desktop, mobile or tablet). It works in two modes. In device mode (the default outside the EEA, UK and Switzerland) it uses a random device ID kept in your browser's local storage and a session ID, and when you sign in with Discord your Discord user ID is added to events and your device ID is linked to it; earlier events are not rewritten. In visit mode (used while signed out in the EEA, UK and Switzerland, when we cannot tell where you are, and whenever your browser sends a Do Not Track or Global Privacy Control signal) it uses a random code held only in browser memory for that page load, stores nothing on your device, sends no cookies, and is never linked to your Discord account. In the EEA, UK and Switzerland, when you sign in GEM shows a privacy preferences panel (Accept all, Essential only, Manage preferences); device mode applies there only if you consent, it is off by default, and you can change it at any time with "Privacy preferences" in the account menu. We do not store or forward your IP address in these records, we use no cookies, third-party analytics or advertising for this, and requests from known bots are discarded. Events are deleted after 90 days and the device link after 90 days without a sign-in. Outside the EEA, UK and Switzerland there is no on/off switch: you can use Do Not Track or Global Privacy Control, clear your browser data, or contact us. Sections 2.12 (new), the short version, 3, 4 and 5 are updated to match, and
unlink-clearnow also removes the link between you and your GEM device IDs. This is new collection and does not change how existing data is handled or how long it is kept. - Version 1.6 (07 Oct 2026): updated for the reworked
/gg link action:unlink-clear. It is now available to everyone, not only people with a linked Steam account, and its purpose is to make you no longer identifiable, not to delete everything. It deletes your GG-Bot user record (Steam link, preferences, counters, and your Discord username, display name and avatar hash), your leaderboard entries and the links between you and your servers. Your command usage stats and history are no longer deleted: they are kept but moved to a random anonymous ID, so they no longer point to you. Sections 2.1 to 2.4, 2.11, 4 and 5 are corrected to match, including "Right to erasure" in Section 5; written deletion requests are still honoured, and there is no self-service "delete my account" feature. Section 2.4 now says leaderboards save only people who use GG-Bot, that other people shown in a comparison are displayed but never saved, and that older leaderboard rows for people who don't use GG-Bot have been cleaned up. Section 2.11 now says only Discord's avatar hash is stored (the image is never downloaded or stored), that profile fields are removed by unlink-clear, that server details are removed by contacting us, and that server records may remain after the bot is removed from a server. GEM records are still not touched by unlink-clear. There is no change to what we collect or how long we keep it, apart from the usage history now being kept in anonymised form. - Version 1.5 (06 Oct 2026): added GEM's import feature, clarified that GEM's online storage is optional, and reserved a right to delete the saved templates and images of inactive free GEM accounts. For import: Section 1 now says GG-Bot still does not read, scan or log general chat or direct messages, with one exception: when an authorised user (the server owner, an administrator, or a member of the server's GEM IMPORT role) deliberately chooses a specific message, GG-Bot fetches that single message's embed and component data so it can be rebuilt in the editor. The short version is updated to match. Section 2.9 now says imported data becomes part of the saved template and follows the same storage and deletion rules, and Section 5 adds a lawful basis for GEM import. Imported data is never used for any other purpose and can be deleted at any time with "Delete all" in GEM. For storage: Section 2.9 now opens by saying that saving online in GEM is optional, that you can use GEM without saving anything, that only what you choose to save is stored, that each user gets limited storage assigned to their account, and that saved templates can be reached only through the GEM website when signed in. Section 2.9 also now says more clearly that images used in embeds must be publicly reachable so Discord can display them, that each image sits at a long, random, unguessable address that anyone who has it can view, and that the image stays linked to your account. Section 2 now states that all stored data, including public images, is encrypted at rest using AES-256. For inactive free accounts: Section 2.9 now says that on a free account we may delete your GEM saved templates and images if you have not signed in to or used GEM for 6 months. We have not built this and may never use it, we will try to give notice and a chance to download first but do not promise to, and it does not apply to GEM Pro or plan-ended accounts. Section 2.9 also now lists the date you last signed in to or used GEM as part of your account and activity record. Section 2.9 now calls the GEM usage record the account and activity record and explains more clearly why we store your items and that record. The short version now gives the full product names, The Gaming Gate Bot (GG-Bot) and The Greatest Embed Maker (GEM). Apart from this reserved right, there is no change to what data we collect or how long we keep it.
- Version 1.4 (02 Oct 2026): section 7 now says the latest version of this policy is always published on the GG-Bot page via the "Privacy policy" and "Terms of service" links at the bottom of that page, instead of promising a posted notice. Advance notice of material changes that affect how existing data is handled is now given by publishing the updated policy on that page at least 14 days before the change takes effect. There is no change to what data we collect, how we use it or how long we keep it.
- Version 1.3 (02 Oct 2026): updated the GEM saved templates and images section (§2.9) for the lower free tier storage allowance of 1 MB (previously 2 MB). The free tier limit of 2 templates is unchanged. There is no change to what data we collect, how we use it or how long we keep it.
- Version 1.2 (02 Oct 2026): updated for the new
/gg notificationspanel. The ALL (Opt-in) and ALL (Opt-out) buttons are removed, so each category is switched on or off individually and there is no single control to turn everything off; Owner Announcements is now one global setting rather than per-server, so all four categories are global; turning off Owner Announcements or Personal Account Messages asks for confirmation; Recommendations can only be turned on individually (older consent records may show "ALL") (updated §2.1, §2.8, §2.10, §5). Added §2.11 covering the Discord usernames, display names and avatar references kept on user records, and the server names and owner IDs kept on server records, including when they are captured, why, our lawful basis and retention; updated the short version and §4 to refer to it. - Version 1.1 (01 Oct 2026): added GEM saved templates and images (§2.9), including the free tier, the 12-week plan-ended lifecycle and archive download, and our commitment not to use your files or content to train AI models; added AWS S3/CloudFront and Lemon Squeezy to §3; corrected earlier statements that we store only a Discord user ID and that no payment processing occurs; clarified that
unlink-cleardoes not delete GEM files; updated §4 and §5 for GEM; retitled to cover GEM. Added a fourth direct-message category, Personal Account Messages (targeted, personal messages from the GG-Bot team about your account, such as competition wins), which you can switch off in/gg notifications(updated §2.1, §2.8, §5). Added §2.10 (stored message text, one copy per broadcast for 90 days, with the recipient list for individual sends on the same record; broadcast headers kept without the message text, including any test-recipient IDs). - Version 1.0 (21 May 2026): initial policy.
Continued use of the bot after the effective date of a revised policy constitutes acceptance of the updated terms.