Kanade Privacy Policy
This policy explains which personal data the Discord bot Kanade ("the bot", "the service") processes, for what purpose, where and for how long it is stored, and how you can exercise your rights. The bot runs on a server located in Azerbaijan, and many of its users are in Türkiye. This notice is therefore intended to meet the information obligations under the Republic of Azerbaijan's Law "On Personal Data" ("Fərdi məlumatlar haqqında" Qanun) and, for users in Türkiye, under Law No. 6698 on the Protection of Personal Data ("KVKK").
1. Data controller and contact
Data controller: Revan Mustafayev (individual developer, Azerbaijan)
Contact and requests: kanadebot@outlook.com
Support server: discord.gg/R9tBdnKaH6
You can write to this address to exercise your rights. Please include your Discord username and user ID. Requests are answered free of charge within 30 days at the latest. Your rights are:
- to learn whether your personal data is processed and, if so, to request information about it and a copy of it,
- to learn the purpose of processing and whether data is used accordingly,
- to know the third parties, in the country or abroad, to whom data is transferred,
- to request correction of incomplete or inaccurate data,
- to request deletion or destruction of data and notification of this to third parties to whom it was transferred,
- to withdraw your consent at any time,
- to object to an outcome against you resulting solely from automated analysis,
- to claim compensation for damage caused by unlawful processing.
If you are not satisfied with the response, users in Türkiye may complain to the Personal Data Protection Authority (KVKK), and users in Azerbaijan to the competent Azerbaijani state authority for personal data.
You can do most of this yourself inside the bot (see section 7).
2. Data we collect
Discord identifiers. Your Discord user ID and the IDs of servers the bot is in. Your username and avatar are not stored; they are only read from Discord on the fly when building messages and card images.
Spotify activity (via your Discord status). If you share Spotify as your Discord status, the bot reads it from Discord: track name, artist, album, album cover URL, Spotify track ID and the track's start time. The bot does not connect to your Spotify account and does not receive any data directly from Spotify.
Message content. The content of your messages is processed only to detect commands and is never stored. For experience points (XP), only the time a message was sent is used.
Command usage and game data. If you are a player: your cards, Plak and Shard balances, XP and level, daily reward streak, box allowances and counters, quest and set progress, and profile bio.
Server settings. The language, whether Spotify tracking is on/off, and the announcement channel chosen by server admins.
Technical records (logs). Logs kept for debugging and abuse prevention may contain user and server IDs, command names and error details.
3. Players and non-players
A player is a user who presses Join in the /start command. Personal game data is kept only for players.
Songs played by non-players are added to the server's song pool anonymously; their user IDs are not written to any record. For these songs only aggregate counters that are not linked to a person (for example, in how many servers a song was seen) are increased.
4. Purposes and legal bases
- Providing the game (cards, rewards, quests, leaderboard, profile): the explicit consent you give by pressing Join (KVKK art. 5(1); consent of the data subject under the Law "On Personal Data"). You can withdraw consent at any time with
/privacy delete-my-data. - Server song pool and card catalog (anonymous): legitimate interest in operating the service (KVKK art. 5(2)(f)).
- Rarity calculation: card tiers are derived from the track ID; aggregate, non-personal listener counts may also be used in the future.
- Security and abuse prevention (logs, limits, account age check): legitimate interest (KVKK art. 5(2)(f)).
No extra data is collected for the account age check; the creation time embedded in the Discord user ID is used.
5. Retention
- Listening summary (player + track): deleted if not seen again for 180 days.
- Daily counters and quest records: deleted after 30 days.
- Game profile and cards: until you delete them (
/privacy delete-my-data) or the service ends. - Data of a server the bot was removed from (song pool and settings): deleted 30 days after removal. If the bot is re-added within that time, the pool continues where it left off.
- Logs: kept as daily files and deleted after 14 days.
- Backups: daily database backups are kept on the server for 14 days and the encrypted cloud copy (see section 6) for 30 days, and are then deleted. When you delete your data, it disappears from all backups within 30 days at the latest; backups are only used to restore the service after a failure and are not opened for any other purpose during that time.
- Opt-out record: contains only your user ID and a date; kept after you delete your data so that you are not tracked again, until you turn tracking back on.
6. Where data is processed and transfers
- Hosting (Azerbaijan): The bot, database, logs and backups run and are stored on the data controller's own server in Azerbaijan. Only an encrypted copy of the backups is kept with the cloud service named below.
- Cross-border transfer for users in Türkiye: When you use the bot from Türkiye, your personal data is processed outside Türkiye, in Azerbaijan; this constitutes a transfer abroad within the meaning of KVKK art. 9. By joining the game with the Join button you explicitly consent to your data being processed in Azerbaijan for this purpose. If you do not join, no personal data is kept about you (see section 3); you can withdraw consent with
/privacy delete-my-data. - Discord: The bot runs on Discord's infrastructure. All communication between the bot and Discord (your commands, the bot's messages and card images) passes through Discord's servers; this data is subject to Discord's own privacy policy and may be processed by Discord in other countries (for example, the United States).
- Cover images: When a card image is rendered, the cover is downloaded from its stored URL (usually Spotify's image servers). No user ID or other personal data is sent in these requests.
- Encrypted cloud copy of backups (Microsoft OneDrive): To protect against failure or loss of the server, a copy of the daily database backup is stored in Microsoft OneDrive (Microsoft Corporation). The backup is encrypted before it leaves the server with passwords set by the data controller (content as well as file and folder names); the passwords are not held by Microsoft, so Microsoft cannot read the backup's content. This copy may be kept in Microsoft's data centres in countries chosen by Microsoft (for example, the United States or the European Union) and is deleted after 30 days. For users in Türkiye this is also a transfer abroad and is covered by the explicit consent described above.
Your data is not sold, not used for advertising, and not shared with anyone other than those listed in this section. It may be shared with competent authorities where required by law.
7. Your controls
/privacy status: shows what data is stored about you and your tracking status./privacy opt-out: your Spotify listening is no longer added to any server pool (not even anonymously), and listening rewards and stats stop. Your cards and other game data stay./privacy opt-in: turns tracking back on./privacy delete-my-data: after confirmation, deletes all of your game data at once. Where you appear as "discoverer" in other people's records, this is anonymized; songs stay in pools anonymously. The "don't track me from now on" option is on by default.- Server admins can use
/settings tracking offso that no listening is processed through that server.
If you stop sharing Spotify as your Discord status, the bot cannot see your listening at all.
8. Security
Only the data controller can access the server, and access uses keys rather than passwords. The bot runs as a separate system user with restricted permissions; secrets such as the bot token are kept in a file only that user can read. The database is backed up daily and backup integrity is checked; the only copy that leaves the server is the cloud backup, encrypted on the server.
9. Relationship with Discord and Spotify
Kanade is an independent project. It is not affiliated with, endorsed or sponsored by Discord Inc. or Spotify AB. Data that Discord and Spotify process about you is subject to their own privacy policies; this policy covers only data processed by Kanade.
10. Children
You must meet the minimum age to use Discord in your country (at least 13). If you are under 18, we recommend getting the consent of a parent or legal guardian before joining the game. If you become aware that data of a child under 13 is stored, contact us and it will be deleted.
11. Changes
This policy may be updated. Significant changes are announced in the servers the bot is in or in the support server, and the effective date on this page is updated. Continuing to use the game after a change means the current policy applies; if you do not accept it, you can delete your data with /privacy delete-my-data.