Bloom Monitors

Legal

Privacy Notice

Last updated 8 October 2026 · applies to the free beta

The short version: to put you in the Discord server we need to know which Discord account is yours, so we keep your Discord user ID, your username and the email address Discord confirms for you. That is very nearly all of it. There is no payment, no analytics, no tracking pixel, no advertising and no newsletter, and this site makes no requests to any third-party domain at all.

1. Who is responsible for your data

The data controller is Bloom Monitors (formerly Backdoored Monitors), a service operated under that name by a private individual established in Italy. There is no company behind it, and no data protection officer is appointed, none being required at this scale.

Privacy questions and requests: privacy@bmonitors.com. If you need the operator’s full identity in order to exercise one of the rights in section 8, or to complain to a supervisory authority, ask at that address and it will be given to you.

2. What we collect, and why

DataWhere it comes fromWhy we have it
Discord user IDDiscord, when you authoriseIt is your identity here. It is how we add you to the server, apply your role, and take it away again.
Discord usernameDiscord, when you authoriseSo a support conversation can find you. Display only, and never used to identify you.
Email addressDiscord, and only if Discord reports it as verifiedTo reach you about the server if Discord is unavailable, and to tell you before pricing is ever introduced. If your address is unverified we store nothing.
A session token, stored as a one-way hashCreated when you joinSo the site can recognise your browser. The token itself exists only in a cookie; we hold the hash.
Browser user-agent stringYour browser, when a session is createdSupport, and spotting an account being used from many places at once.
A hashed counter keyed on your IP addressAutomatically, on API requestsRate limiting. It is a count, not a log: it holds no address you could read back, and it is deleted as soon as its one-minute window closes.

What we deliberately do not have

3. Cookies

The site loads no third-party scripts and contacts no other domain, because the fonts and logos are served from here. There is no analytics package and no advertising network. That is enforced by the site’s Content-Security-Policy rather than offered as a promise.

Nothing is stored on your device if you only read the site. Signing in sets a small number of strictly necessary cookies, and nothing else does. Each holds a random token and nothing more: no identifier, no email, no record of what you looked at. We keep only a one-way hash of it, so the cookie itself exists nowhere but your browser. Their only job is to let the sign-in and Discord steps recognise the browser that started them, and they last at most 30 days.

They are strictly necessary under the ePrivacy Directive: without them the thing you asked for cannot be delivered. That is why there is no cookie banner. There is nothing here to consent to or refuse, and nothing is set before you ask for it.

Discord’s own login page is operated by Discord on its own domain and sets its own cookies under its own policy.

4. Legal bases (GDPR Article 6)

We process no special category data and carry out no automated decision-making or profiling that produces legal effects for you.

5. Who else processes your data

ProcessorWhat they handle
CloudflareHosting, CDN, DDoS protection, and the database holding the records above
DiscordDelivery of the Service itself, and your account with them

That is the complete list. We do not sell your data, we do not share it for anyone else’s marketing, and no email marketing platform is involved because no marketing email is sent.

6. Transfers outside the EEA

Both processors are US-headquartered and may process data outside the EEA. Those transfers rely on the European Commission’s Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.

7. How long we keep it

Note that your Discord account, your membership of the server and anything you posted there belong to your relationship with Discord. Deleting your data here removes your role; it does not delete your Discord account or your messages.

8. Your rights

Under the GDPR you may ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, or to have it in a portable format. Email privacy@bmonitors.com and we will respond within one month.

Deletion also removes your access. Your account record is what tells us to keep your role applied, so erasing it takes the role off and removes you from the members-only channels. We do both together rather than leaving you with access we no longer have a record of.

You also have the right to complain to a supervisory authority: in Italy the Garante per la protezione dei dati personali (garanteprivacy.it), or otherwise the authority in the EU country where you live.

9. Security

The site is served over HTTPS only, with HSTS and a strict Content-Security-Policy. Every token is stored as a one-way hash, never in the clear. The Discord authorisation step is protected against cross-site request forgery, and one Discord account can be attached to exactly one member. Our security contact and reporting process are at /.well-known/security.txt.

10. Children

The Service is not intended for anyone below the minimum age for a Discord account in their country. We do not knowingly collect data from children. If you believe a child has joined, email us and we will remove the account.

11. Changes

If this notice changes materially we will announce it in the Discord server and update the date at the top of this page.