Privacy Policy
This describes what Picked.gg actually stores. It is written from the code rather than from a template, and it names the things we do not collect as well as the things we do.
Who we are
Picked.gg is an independent directory of Discord bots. It is not affiliated with, endorsed by, or operated by Discord Inc. For anything in this policy, contact us at [email protected].
The site is run by a private individual, not a company, and that person is the data controller for everything described here. Payments are the exception: Polar is the merchant of record and the controller for what it collects to take one.
What we collect
If you sign in
Signing in uses Discord OAuth with the identify and email scopes. We store your Discord user id, username, avatar URL and email address, plus the OAuth tokens Discord issues so the session can be refreshed. We never see or receive your Discord password.
What you create
- Bot listings you submit, including everything on the form.
- Votes you cast, kept as a history so leaderboards can be calculated.
- Reviews and ratings you write, and replies you leave as a bot owner.
- Bots you follow, and announcements you post about a bot you own.
- Screenshots you upload. These are re-encoded on upload, which strips any camera or location metadata your capture tool embedded.
Listings, reviews and announcements are public by design. Your Discord username and avatar appear next to what you post. Your profile shows how many votes you cast; which bots you voted for is shown only to you.
Usage measurement
When someone opens a bot listing we record which bot was clicked, which page they came from, and when. That record contains no user id and no IP address — it is a page-to-bot counter, not a profile. Advertisement views are counted the same way, as a daily total per slot.
We also use Umami for page analytics. Umami sets no cookies and stores no personal data, which is why this site has no cookie banner.
What we deliberately do not store
- IP addresses. Your address is used as a temporary key for rate limiting and is held only in a short-lived cache entry. It is never written to our database and never linked to your account.
- Payment details. When advertising goes live, payments are handled by Polar as the merchant of record. Card details go to Polar and never reach our servers.
- Tracking cookies. We set only the cookies the site needs to work; they are listed in our Cookie Policy.
Error reports
When something breaks, an error report is sent to Sentry so it can be fixed. Reports pass through a filter that removes credentials — API tokens, Discord tokens, database connection strings and session cookies — before they leave our server.
Who else sees your data
To run the service we share only the data each one needs with these service providers. They process it only on our behalf and for the purposes below. You can ask for the current list of providers at [email protected].
- Hosting and database provider — the server the site runs on, the database and backups.
- Storage provider — uploaded screenshots and backups.
- Rate-limiting cache — your IP address, as a short-lived key.
- Email delivery provider — vote reminders and other emails you turn on.
- Error monitoring provider — error reports, with credentials removed.
- Discord — signing you in.
- Payment provider (Polar) — only if you buy advertising; Polar is the merchant of record and a separate controller for what it collects.
- Bot owners — when you vote, the bot's owner receives your Discord user id through their vote webhook and API.
We do not sell your data and we do not share it for advertising.
How long we keep it
Account data is kept while your account exists. Votes, reviews and announcements are kept as long as the listing they belong to. Click and impression counters are aggregates with no personal data in them and are kept indefinitely.
Your rights
Both of these are on your profile page, under your name, while you are signed in.
A copy of your data. “Download my data” gives you a JSON file with your account, your listings, your reviews, your votes, your follows, your notifications and the reports you filed. API tokens and webhook secrets are left out of it on purpose: they are credentials rather than a record about you, and a downloaded file is a way for one to escape.
Deletion. “Delete my account” records the request; we carry it out within 30 days, and you can withdraw it until we do. It removes your profile, reviews, votes, follows and notifications, and every bot listing you own goes with them — along with those listings' reviews, followers and API access.
Two things are kept, and both are for somebody other than you. A report you filed stays with your identity removed from it, because it is about the thing reported and a moderator still has to act on it. Our record of moderation actions stays for the same reason, with your id removed — except where it records a ban on your account, which survives deletion so that deleting an account is not a way to undo one.
To ask for a correction instead, or if you cannot sign in, email [email protected] from the address on your account and we will act within 30 days.
Children
Discord requires users to be at least 13, and older in some countries. This site is not intended for anyone below that age.
Changes
If this policy changes materially we will update the date at the top. See also our Terms of Service.