Legal
Privacy Notice
Last updated 8 October 2026 · applies to the free beta
The short version: to put you in the Discord server we need to know which Discord account is yours, so we keep your Discord user ID, your username and the email address Discord confirms for you. That is very nearly all of it. There is no payment, no analytics, no tracking pixel, no advertising and no newsletter, and this site makes no requests to any third-party domain at all.
1. Who is responsible for your data
The data controller is Bloom Monitors (formerly Backdoored Monitors), a service operated under that name by a private individual established in Italy. There is no company behind it, and no data protection officer is appointed, none being required at this scale.
Privacy questions and requests: privacy@bmonitors.com. If you need the operator’s full identity in order to exercise one of the rights in section 8, or to complain to a supervisory authority, ask at that address and it will be given to you.
2. What we collect, and why
| Data | Where it comes from | Why we have it |
|---|---|---|
| Discord user ID | Discord, when you authorise | It is your identity here. It is how we add you to the server, apply your role, and take it away again. |
| Discord username | Discord, when you authorise | So a support conversation can find you. Display only, and never used to identify you. |
| Email address | Discord, and only if Discord reports it as verified | To reach you about the server if Discord is unavailable, and to tell you before pricing is ever introduced. If your address is unverified we store nothing. |
| A session token, stored as a one-way hash | Created when you join | So the site can recognise your browser. The token itself exists only in a cookie; we hold the hash. |
| Browser user-agent string | Your browser, when a session is created | Support, and spotting an account being used from many places at once. |
| A hashed counter keyed on your IP address | Automatically, on API requests | Rate limiting. It is a count, not a log: it holds no address you could read back, and it is deleted as soon as its one-minute window closes. |
What we deliberately do not have
- Payment details of any kind. The beta is free. No card is requested, no payment processor is involved, and there is no billing record because there is no billing.
- Your IP address, stored. The rate limiter keys on a hash of it and keeps only a count. We do not keep an access log tying you to an address.
- Your Discord password, messages or other servers. The connection asks for
identify,emailandguilds.join: your ID, username, avatar and verified address, plus permission to add you to this one server. Nothing else. We cannot read your DMs and cannot see what other servers you are in. - Your Discord access token. It is used once, at the moment you join, then handed back to Discord to be revoked. It is never written down.
- Any behavioural data. We do not record which alerts you read, which channels you open, or when you are online.
3. Cookies
The site loads no third-party scripts and contacts no other domain, because the fonts and logos are served from here. There is no analytics package and no advertising network. That is enforced by the site’s Content-Security-Policy rather than offered as a promise.
Nothing is stored on your device if you only read the site. Signing in sets a small number of strictly necessary cookies, and nothing else does. Each holds a random token and nothing more: no identifier, no email, no record of what you looked at. We keep only a one-way hash of it, so the cookie itself exists nowhere but your browser. Their only job is to let the sign-in and Discord steps recognise the browser that started them, and they last at most 30 days.
They are strictly necessary under the ePrivacy Directive: without them the thing you asked for cannot be delivered. That is why there is no cookie banner. There is nothing here to consent to or refuse, and nothing is set before you ask for it.
Discord’s own login page is operated by Discord on its own domain and sets its own cookies under its own policy.
4. Legal bases (GDPR Article 6)
- Performance of a contract (Art. 6(1)(b)) covers your Discord ID, username and session. Without them we cannot put you in the server or keep you there, which is the whole of what you asked for.
- Legitimate interests (Art. 6(1)(f)) covers your email address, to reach you about the Service and to give notice before pricing changes; and the rate-limiting counters, to keep the Service available and to prevent access being shared. We have weighed these against your rights: the data is minimal, it is not used for marketing, and you can object at any time.
We process no special category data and carry out no automated decision-making or profiling that produces legal effects for you.
5. Who else processes your data
| Processor | What they handle |
|---|---|
| Cloudflare | Hosting, CDN, DDoS protection, and the database holding the records above |
| Discord | Delivery of the Service itself, and your account with them |
That is the complete list. We do not sell your data, we do not share it for anyone else’s marketing, and no email marketing platform is involved because no marketing email is sent.
6. Transfers outside the EEA
Both processors are US-headquartered and may process data outside the EEA. Those transfers rely on the European Commission’s Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.
7. How long we keep it
- Your account record (Discord ID, username, email): kept while you are a member, and for up to 12 months after you leave, so you can come back without starting over. Ask us sooner and it goes sooner.
- Sessions: 30 days, then deleted automatically. Stored as a hash throughout.
- Join tokens: 7 days or until used, whichever comes first. Stored as a hash; the token itself only ever exists in a cookie.
- Rate-limiting counters: deleted as soon as their one-minute window closes.
Note that your Discord account, your membership of the server and anything you posted there belong to your relationship with Discord. Deleting your data here removes your role; it does not delete your Discord account or your messages.
8. Your rights
Under the GDPR you may ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, or to have it in a portable format. Email privacy@bmonitors.com and we will respond within one month.
Deletion also removes your access. Your account record is what tells us to keep your role applied, so erasing it takes the role off and removes you from the members-only channels. We do both together rather than leaving you with access we no longer have a record of.
You also have the right to complain to a supervisory authority: in Italy the Garante per la protezione dei dati personali (garanteprivacy.it), or otherwise the authority in the EU country where you live.
9. Security
The site is served over HTTPS only, with HSTS and a strict Content-Security-Policy. Every token is stored as a one-way hash, never in the clear. The Discord authorisation step is protected against cross-site request forgery, and one Discord account can be attached to exactly one member. Our security contact and reporting process are at /.well-known/security.txt.
10. Children
The Service is not intended for anyone below the minimum age for a Discord account in their country. We do not knowingly collect data from children. If you believe a child has joined, email us and we will remove the account.
11. Changes
If this notice changes materially we will announce it in the Discord server and update the date at the top of this page.