Raphael Gazetteer of Edenwelt

Privacy Policy

Raphael collects very little, because it needs very little. This page lists every category of data it holds, the reason for each one, and how to have it corrected or erased.

Effective 8 October 2026 Version 1.0 Operator the sole developer of Raphael

The short version. Raphael has no user accounts, sets no cookies, runs no analytics, no tracking, no advertising and no third-party scripts. The data it holds is a Discord user ID, the fictional nation content players submit, and a short command log. It is used to run the game, and for nothing else.

01 Who is responsible

The data described on this page is controlled by the Operator: the single individual who develops and runs Raphael, publishing under the handle Alicia. The Operator is not a company.

As the person deciding why data is collected and how it is used, the Operator is the data controller for the purposes of the GDPR and the UK GDPR where those laws apply. Queries and rights requests go to the address in section 15.

02 What this covers

This policy covers the Service as a whole: the Discord bot, the public website at raphaelnrp.duckdns.org and the game-master console on that site. It is the counterpart to the Terms of Use.

It does not cover Discord itself. When you use the bot you are also using Discord's platform, which collects data under Discord's Privacy Policy. Discord is a separate controller for that processing and the Operator has no control over it. It does not cover the other bots, websites or services in the Edenwelt server either.

The Edenwelt server's own game content — channels, messages, roleplay posts — belongs to Discord and to its participants, not to Raphael.

03 What is collected

There are two sources of data: what the Service records as a consequence of being used, and what a player or game master deliberately submits to it.

Recorded automatically
Data Where it comes from
Discord user ID and username Read from Discord when you run a bot command, or entered by a game master. A numeric identifier, for example 123456789012345678.
Discord server ID Server configuration, held so commands register in the right server. It identifies the server, not a person.
Command log line Written to a private Discord channel when you use a command. See section 06 for exactly what it records.
Server access logs Ordinary web server records of requests to the website — IP address, timestamp, requested path, user agent — kept by the hosting system for security and diagnostics.
Submitted by players and game masters
Data Detail
Nation identity Nation name, identifier, common name, flag reference, and the Discord ID of its owner where one has been recorded.
Nation written content About 31 free-text fields per nation — motto, head of state, government, religion, allies, rivals, history, doctrine and similar. Each field accepts up to 2,000 characters. This is the game's own creative writing and is the largest category of content on the Service.
Flag image An uploaded PNG, JPEG, WebP or GIF of up to 5 MB. Stored on disk and published at a web address. See section 05.
Selection records Which spirit a nation has selected, and the Discord ID of who selected it.
Administrative records Who was granted game-master rights, when, and by whom; who issued a key, and when it was revoked; who made an edit, with a short note about it.

Raphael does not collect your name, email address, phone number, postal address, payment details, precise location, or contacts. It does not read your direct messages. It has no access to what you type into any field other than the field you typed it into, and it does not read message content anywhere in the server.

04 About your Discord user ID

A Discord user ID is a number Discord assigns to an account. It is a pseudonym: on its own it does not contain your name, your email address or your contact list. It does, however, identify you on Discord, so the Operator treats it as personal data.

Raphael uses it for three things and no others:

  • to record who owns a nation, so that owner can change their own flag without a game master doing it for them;
  • to show a game master who granted, used or revoked game-master rights, and who made an administrative change;
  • to record, in a private channel, which game master used a bot command. Command logs do not record the values you supply.

Raphael has no sign-in, so it cannot ask you to confirm who you are, and it does not attempt to verify that a recorded Discord ID really belongs to the person who later presents it. Access to the game-master console depends on a separate secret key, not on a Discord identity.

05 Flag images are public

A flag uploaded for a nation is written to public storage and published at a direct web address. Anyone who has that address — including a search engine — can fetch and view the image. It is not protected by any login.

The filename is derived from the nation's identifier, so a flag's address can be guessed from the site's own data. Treat an uploaded flag as permanently public.

Nothing else on the Service is published this way. The nation written content, the command logs and the game-master records are served only through the API, and the administrative routes and console require a key that is never sent to a browser that has not been given one.

06 Command logs and audit records

The command log exists so game masters can see which commands were used. Each line looks like this:

Username#0001 used /nation edit

A line records the command name and the person who ran it. It does not record the option values — the nation you named, the text you entered, the numbers you submitted. That exclusion is deliberate: option values carry free text that players and game masters type, and the log is not the place for it.

Administrative records are separate and longer-lived. An audit entry names the person, the time, what changed and a short free-text note from the game master. A note is written by a game master, not by you, and may describe the content you submitted.

07 Why it is used

Every category in section 03 exists to do one of the following. If data on the Service is being used for something not listed here, that is a bug, and it should be reported using the contact details in section 15.

  • To run the game. Holding nations, computing their statistics, advancing the world and displaying the result. Without this data the Service has nothing to show.
  • To let a player manage their own nation. Checking a recorded Discord ID against a flag change, so a player can update their own flag.
  • To keep the game manageable. Knowing who holds game-master rights, recording administrative changes, and letting game masters see what has been used.
  • To keep the Service running and secure. Diagnosing faults, investigating abuse, and responding to reports.
  • To comply with the law. Meeting a legal obligation that applies to the Operator.

Raphael is not used for advertising, and there is no advertising to receive. It is not sold, rented or traded. It is not used for profiling, and no decision is made about you automatically.

08 Who it is shared with

Recipient What they receive
MongoDB, Inc. Database hosting. Nation records, identifiers and audit entries are stored in a managed database under a services agreement that limits the provider's own use of the data.
Hosting provider The virtual machine serving the website and running the bot, including its host access logs.
Discord Inc. Discord holds its own data about its users under its own policy. The Operator does not control that and cannot see it.
Edenwelt game masters Whatever is visible in the bot commands and the game-master console they use to run the server.

These are the only recipients. The Operator does not sell, rent, trade or share data with anyone else, and does not disclose data in response to demands, except where disclosure is required by law or is necessary to establish or defend legal claims.

09 How long it is kept

Category Retention
Nation records and lore For as long as the nation exists in the game, then removed when the nation is deleted — except that published snapshots and rankings may retain derived figures.
Flag images Until replaced or removed, then deleted from storage.
Command logs Retained briefly for troubleshooting, then pruned.
Audit and administrative records Kept while the person holds game-master rights and for a limited period afterwards, as a record of who did what.
Server access logs Short rotation, set by the hosting system's default log rotation.

Because Edenwelt is a long-running roleplay, nation records are generally kept for the life of the nation rather than a fixed period. If you want your association with a nation removed, ask — see section 13.

10 How it is protected

The measures in place, in plain terms rather than as a guarantee:

  • the website and the bot's HTTPS connection are encrypted in transit with TLS;
  • database credentials, the bot token and the master key are held in environment variables and never written into the source code, the bundle served to browsers, or any published document;
  • game-master keys are stored only as a one-way SHA-256 hash. The original value is shown once, at creation, and cannot be recovered from the database;
  • every administrative route requires a key, and no key is embedded in the public site bundle;
  • flag uploads are restricted to image types, size-limited, and named from the nation's own identifier rather than from the submitted filename, so an upload cannot choose where it is written.

No system is perfectly secure. If you find a vulnerability, report it privately to the address in section 15 and give reasonable time to fix it before disclosing it publicly.

11 Where it is processed

The Service is hosted on a single virtual machine and its database is held with a managed provider. The data is therefore processed in the country or countries where that infrastructure sits, which may not be your own.

Where the GDPR or UK GDPR applies and data is transferred outside the UK or European Economic Area, the Operator relies on the providers' standard contractual clauses and equivalent safeguards. Further information is available on request using the contact details in section 15.

12 Cookies and local storage

Raphael sets no cookies. It uses no advertising or analytics cookies, no third-party or embedded content that could set its own, and no tracking of any kind. There is no consent banner because there is nothing to consent to.

The public website stores two values in your browser's localStorage — the part of browser storage that stays on your device and is never sent to the server:

Key What it holds
raphael.theme.v2 Which of the site's colour themes you chose, so the site opens the way you left it. Removing it resets the theme.
raphael.gm.key Set only if you unlock the game-master console: the key you paste in, kept so you are not asked for it on every visit. Locking the console, or clearing site data, removes it. It is not a cookie, so it is not sent automatically — it is attached to requests you make deliberately.

Clearing your browser's site data for this domain removes both values. There is nothing else stored on your device by this site.

13 Your rights

Where the GDPR, the UK GDPR or comparable legislation applies to you, you have the right to:

  • access the personal data held about you;
  • correct anything inaccurate — most directly, your own nation's written content or flag;
  • delete it — removing your Discord ID as a nation's owner, or deleting a nation outright;
  • restrict or object to processing based on legitimate interests;
  • port data you gave us, in a machine-readable form, where processing is based on consent or contract;
  • withdraw consent, where consent is the basis relied on — the main case being newsletter or notification mail, which this Service does not currently send;
  • complain to your data protection regulator. In the UK that is the Information Commissioner's Office; in the EU it is the authority in your country of residence.

The Operator honours these requests regardless of where you live and whether the law that creates the right applies to you. There is no charge, and no identity document is required — but because Raphael has no accounts, the Operator cannot look you up by email. Say which nation you are writing about and what you want done, and the request can usually be resolved in a message.

What "erasure" means here. Deleting a Discord ID removes your link to a nation but does not delete the nation, whose content belongs to the game and to other players. If you want a nation removed entirely, say so — it is possible, but it affects the game for everyone else on that nation.

14 Children

Raphael is not directed at children under 13, or at any age below the minimum at which Discord itself may be used. Nation records are created by game masters of an established server, not collected from children.

Discord sets its own minimum age and enforces it. Where the Operator becomes aware that data from a child under that minimum has reached the Service, it is deleted. A concern about this can be raised using the contact details below.

15 Changes to this policy

This policy may be revised. The current version is always published at raphaelnrp.duckdns.org/privacy with its effective date and version number, and that page is the only authoritative copy. Changes are announced in the Edenwelt server when they alter what is collected or who it is shared with.

16 Contact

Privacy questions, access and deletion requests, and security reports:

legal@raphaelnrp.duckdns.org

The Operator aims to acknowledge a request and to act on it within 30 days. A security report will be acknowledged more quickly.