LobbyOutPost
English convenience translation · Last updated September 7, 2026

Privacy Policy

1. Controller and contact

Raik Haker
c/o IP-Management #9783
Ludwig-Erhard-Str. 18
20459 Hamburg
Germany

Contact for privacy and data requests: business@kiarflow.de

2. Scope and infrastructure

LobbyOutPost is a Discord application for configurable game News, release and countdown information, Lobby Pulse, a private Game Hub, regional Game Radar discovery, My Games, short-lived Community Lite play intent and Public Play Beacons, guild-local Squad coordination, and an explicitly activated temporary Squad Wait notification.

The static website is hosted by Hostinger. The bot and its SQLite database run on infrastructure hosted by IONOS. Discord's own processing is additionally governed by Discord's privacy terms and the user's relationship with Discord.

3. Data for core operation

LobbyOutPost processes and stores data needed for deliberately used features. This includes:

Removing the bot disables configured News and records the removal lifecycle but does not automatically erase operational history. An uninstall can be temporary, and historical records support recovery, attribution integrity, audit, and duplicate prevention.

Community Lite does not enumerate members, infer Presence, or create cross-server player discovery. Its private participant list contains only members who explicitly activated the same game in the same server. A Public Play Beacon shows the game and expiry but no username, avatar, Discord ID, participant list, or member mention. Join stores only the clicking member's own short-lived intent and creates no Campaign Attribution or server configuration authority.

4. Wait Notify

Wait Notify is activated only by an explicit user action. A Wait applies to exactly one Discord guild, one Discord user, and one canonical game and remains active for no more than two hours.

Only data necessary for this function is stored:

Discord guild and user IDs are not anonymous. They are needed to associate the Wait with the right user in the right server for the right game and to attempt a private notification. LobbyOutPost does not combine Wait data into a cross-guild player profile.

Wait Notify stores no username, display name, chat or DM content, Presence, voice history, friend list, IP address or device information for this feature, permanent player profile, inferred preference, cross-guild player profile, or Wait analytics.

When a matching new Squad becomes available, LobbyOutPost may make exactly one private Discord DM attempt. The message contains the game, an availability notice, and a link to the original public Squad card. It is not a private Join transaction, seat reservation, or slot guarantee. There is no public fallback, role ping, or mass mention.

Discord processes the technically required user ID and the message delivered through Discord. A delivered DM is also subject to Discord's own processing and retention; LobbyOutPost does not remotely delete it.

A user can end a Wait before expiry. It becomes immediately logically inactive after Stop, completion, or expiry. Terminal and expired local Wait rows remain for a short technical window, currently about 24 hours, and are then physically deleted by cleanup. If the runtime is stopped, deletion may be delayed until the next cleanup. Stop cannot recall a message already handed to Discord.

5. Optional product measurement

Product Metrics is disabled by default. If deliberately enabled after publication of the reviewed policy, LobbyOutPost stores domain-separated SHA-256 pseudonymous guild and user actors and controlled product events. These measure Setup start/completion, bounded Setup steps/duration, and explicit use of Game Hub, Trending, Upcoming, Playing Here, My Games, Pulse, News actions, Follow/Unfollow, and Squad creation/joining.

Generic product events contain no selected game, command name, arbitrary metadata, free text, message or question content, raw Discord user or guild ID, server/channel name or ID, username, display name, avatar, email, IP address, device identifier, country, or inferred location. The hashes are pseudonymous, not anonymous. Reports remain local; no external product analytics, advertising, fingerprinting, or data broker is used. Wait data is not used for Product Metrics.

6. My Games, Playing Here, and game activity

My Games is separate from generic product measurement and works while Product Metrics is disabled. It stores a domain-separated pseudonymous global member hash and only the game or reviewed Radar candidate the member explicitly adds. No library is inferred from chat, profile, Presence, or passive server membership. Removing one game deletes that choice; confirmed Clear Library deletes all My Games choices for that hash.

Trending and Playing Here use a separate purpose-specific activity projection with a pseudonymous guild hash, a user hash scoped to that guild, exactly one game or Radar candidate, one controlled explicit LobbyOutPost signal, UTC day, event/expiry times, and the explicit server region at capture. The same user has a different hash in each guild. Small groups are suppressed by a minimum threshold.

7. Region and location

Region comes only from an approved provider's explicit scope, an optional administrator-selected server region, or the current private Game Hub session. The session choice is user-and-server-bound, memory-only, expires with the session, and is neither persisted nor added to Product Metrics.

LobbyOutPost does not infer region, country, nationality, or location from an IP address, timezone, Discord locale, language, username, display name, avatar, profile, guild name, ordinary chat, Presence, device, campaign, or another region's data. It performs no IP geolocation.

8. Discord access and monitoring boundaries

Discord provides the installation, interaction, server, channel, user, and message identifiers and API processing needed for deliberately used functions. LobbyOutPost does not monitor ordinary Discord chat, enumerate guild members, or build username/avatar profiles. It does not request the Message Content, Guild Members, or Presence privileged intents.

Slash-command options and component interactions are processed because a member explicitly invokes them. Customer data remains server-scoped where required, and central Review remains limited to the configured operator server.

9. News sources and external Radar providers

Configured public or official News sources receive bounded technical HTTPS requests, not Discord member activity. When deliberately configured, Twitch, YouTube, and CHZZK receive only server-side authentication and bounded request fields for their approved Game Radar scope. They receive no Discord user or guild IDs, LobbyOutPost actor hashes, My Games choices, or guild/member activity identifiers.

Provider data is limited to bounded external game/category identities, mappings, ranks or normalized scores, explicit provider/country/region scope, health/freshness timestamps, and hashed unmapped identities. Raw provider bodies, video titles/descriptions/tags, creator/channel profiles, viewer identities, credentials, and tokens are not retained in SQLite or deliberately logged. Game Radar shows attention/discovery only and cannot approve or deliver a News claim.

10. Campaign Attribution and Ask Lobby

When enabled, first-party Campaign Attribution stores campaign metadata, a SHA-256 hash of a short-lived one-time install state, the installed Discord server ID, install/setup/removal timestamps, and bounded server member counts for campaign qualification. It does not retain the installer's username or user ID, email, IP address, Discord messages, OAuth access or refresh tokens, or an external analytics profile. Later campaigns cannot overwrite existing first-touch attribution.

Ask Lobby is disabled in the currently intended rollout. If enabled, an explicit question and bounded already-safe LobbyOutPost facts go only to the operator-configured local Ollama service. LobbyOutPost stores no question, answer, conversation, or embedding and performs no AI web search. A provider or data-practice change requires prior policy review.

11. Recipients and service providers

Wait data is not disclosed to advertising networks, external analytics, data brokers, tracking services, or third-party matchmaking providers.

12. Legal bases

Where the GDPR applies, processing relies on:

13. Retention, deletion, backups, and logs

Non-identifying historical daily counters may remain for continuity. Server configuration, Squad history, source/Intelligence/Review/publication data, delivery history, Campaign Attribution, provider mappings/candidates, and other operational/audit data may be kept longer without a fixed application timer where needed for operation, recovery, safety, attribution integrity, audit, or duplicate prevention.

Runtime logs and backups follow the operator's infrastructure rotation; no separate fixed automatic backup-retention period is promised here. A database backup may contain a Wait row that existed when the backup was made, and that copy remains until the corresponding backup leaves the rotation. Wait Notify stores no DM content or free-form error message as functional Wait data.

14. Requests and data-subject rights

Privacy and data requests can be sent to business@kiarflow.de. The operator may request the information needed to identify the relevant Discord server or member and verify authority.

Depending on applicable law, data subjects may have rights to access, correction, erasure, restriction, data portability, objection, and complaint to a competent supervisory authority. Legal conditions and exceptions apply.

15. Security and changes

LobbyOutPost uses least-privilege Discord permissions, server-scoped queries, bounded inputs, prepared SQLite statements, process locking, additive migrations, idempotency controls, and backups. No system can guarantee absolute security. General privacy and data requests use the contact above; no separate data protection officer or security contact is designated in this policy.

Material data-practice changes are reviewed and published with an updated date before they take effect. Discord's requirements and applicable law continue to apply independently.

16. Language

The German privacy policy is authoritative. This English translation is provided for convenience. If the versions differ, the German version takes precedence.