Legal
Privacy Policy
Last updated: July 5, 2026
This Privacy Policy explains what information the LAVA Discord bot ("LAVA," "the Bot," "we," "us") collects, how we use it, and the choices you have. It applies to anyone who uses LAVA's commands or is in a server or voice channel where LAVA is active. It should be read alongside our Terms of Service.
LAVA is operated by Ghimici Denis-Constantin, an individual sole trader based in Romania ("we," "us," "our"). For the purposes of the EU/UK General Data Protection Regulation (GDPR) and equivalent laws, Ghimici Denis-Constantin is the data controller of personal data processed through LAVA and this website (lavabot.site).
LAVA is an independent, third-party bot built on the Discord API. It is not created, operated, or endorsed by Discord Inc. Discord's own Privacy Policy and Terms of Service continue to apply to your use of Discord itself.
1. Information We Collect
Information you provide directly. When you run a command, we process what you type or select — for example, song names or URLs given to /play and /search, names you assign to saved queues, the reasons and durations you give to /mute, /ban, and /kick, and the text you submit through /bugreport or /requestpremium.
Information Discord gives us automatically. To operate at all, the Bot receives your Discord user ID and username, the ID and name of the server and channel a command is used in, and your voice-channel presence — but only for servers LAVA has been added to, and only at the moment a relevant command or event occurs.
Information we store persistently. Most of what LAVA does — the live queue, playback position, volume, loop/autoplay state — lives only in memory and disappears once the Bot disconnects or restarts; it's never written to disk. The exceptions, kept in a local database file, are:
| Stored | Why |
|---|---|
| Server IDs with Premium status | Unlocks premium-only commands |
| Server IDs that are blacklisted | Blocks that server from using LAVA |
| Your user ID, plus any saved queues (queue name and each track's title, artist, URL, duration, and artwork link) | Lets /savedqueue save and reload queues for you |
Saved queues are tied to your Discord user ID, not to a specific server — so they follow you into any server that has LAVA, and aren't automatically deleted if LAVA is removed from the server where you first saved them.
What we don't collect. We don't read, log, or store your regular chat messages — only the slash commands you run and their options. We also don't access your Spotify, Apple Music, YouTube, or SoundCloud account, library, or listening history; track requests are resolved anonymously against those platforms' public search/streaming endpoints.
2a. Payments and Billing Data (LAVA Premium)
When you purchase a LAVA Premium subscription on this website, checkout, billing, and payment processing are handled by Stripe Payments Europe, Limited ("Stripe"). Stripe — not us — collects and processes your payment details (card or other payment method information), billing address, and related transaction data.
We do not receive or store your full payment card details. From Stripe we receive limited information necessary to provision and manage your subscription, including: your Stripe customer ID, subscription and price IDs, subscription status, and the Discord server ID you selected at checkout so we can activate Premium on the correct server. When you sign in with Discord to pick a server, we also receive your Discord user ID, username, avatar, and the list of servers you can manage (via the identify and guilds OAuth scopes).
Stripe's own processing of your data is governed by Stripe's Privacy Policy.
2. Privileged Intents
LAVA requests the Guilds, Guild Voice States, Guild Messages, and Message Content intents from Discord. The Message Content intent is enabled for reliability and possible future features — LAVA does not currently read or act on the text of ordinary messages. We'll update this Policy if that changes.
3. How We Use This Information
Only to: run the command you invoked, enforce the blacklist/premium systems described above, investigate bugs you report and respond to premium requests, and notify LAVA's operator when the Bot joins or leaves a server (for basic administration and abuse prevention). We don't use your information for advertising or behavioral profiling.
4. How We Share Information
We do not sell your information. We share it only:
- With Discord, as an unavoidable part of using the Discord API
- With music platforms (YouTube, Spotify, Apple Music, SoundCloud) — as a bare search term or track URL, passed through our self-hosted Lavalink audio server so it can locate and stream the track. Your Discord identity is not sent to these platforms.
- With Stripe, our payment processor, for LAVA Premium checkouts, subscription management, invoicing, and (where enabled) tax calculation
- With hosting and infrastructure providers (site hosting, database/backend, and the self-hosted Lavalink audio server) acting as processors under our instructions
- With LAVA's operator, for the bug reports, premium requests, and join/leave notices described above
- With professional advisers (e.g. legal, accounting) where necessary
- When legally required to do so
4a. Legal Bases for Processing (GDPR)
If GDPR or the UK GDPR applies to you, we rely on the following legal bases:
- Performance of a contract — to run the commands you invoke, deliver LAVA Premium, process your subscription, and provide support (Article 6(1)(b)).
- Legitimate interests — to operate, secure, and improve LAVA, prevent abuse, enforce the blacklist, and receive join/leave and bug-report notifications (Article 6(1)(f)).
- Legal obligation — to comply with tax, accounting, and other applicable legal requirements (Article 6(1)(c)).
- Consent — where you voluntarily submit information via
/bugreport,/requestpremium, or by contacting us (Article 6(1)(a)).
5. Data Retention
- Premium/blacklist status: kept until manually removed by LAVA's operator
- Saved queues: kept until you delete them (
/savedqueue delete <name>) or ask us to - Bug reports and premium requests: kept in our private support channel or DMs until manually deleted
- Subscription and billing records: kept for as long as your subscription is active and afterwards for as long as required by tax, accounting, and other legal obligations (typically up to 10 years under Romanian law)
6. Your Rights and Choices
You can delete an individual saved queue yourself at any time with /savedqueue delete <name>, or contact us (Section 10) to request deletion of all data tied to your user ID or your server. You can also ask what data we hold about you, or ask us to correct it. If you're in the EU/UK, you have the rights to access, rectification, erasure, restriction, data portability, objection, and to withdraw consent at any time; we aim to respond within one month. You also have the right to lodge a complaint with your local supervisory authority (in Romania, the ANSPDCP). If you're in California or elsewhere with its own privacy law, we'll honor equivalent requests regardless of where you're located. For requests concerning your billing data, you may also contact Stripe directly using the details in Stripe's Privacy Policy.
Removing LAVA from your server does not automatically delete saved queues created by individual members, since those are tied to a user ID rather than the server — contact us if you'd like those cleared too.
7. Children's Privacy
LAVA is meant to be used consistently with Discord's own Terms of Service, which set Discord's minimum age requirement (13, or higher in some countries). We do not knowingly collect information from users below that age beyond what Discord itself already exposes to bots operating on its platform.
8. Data Security
We take appropriate technical and organisational measures to protect the information described above, including access controls, HTTPS/TLS in transit, and limiting who on our team can access the backend. Payment data is handled directly by Stripe under Stripe's own PCI-DSS-compliant security program. No method of storage or transmission is completely secure, and we can't guarantee absolute security.
8a. International Data Transfers
LAVA's infrastructure and Stripe may process personal data outside your country, including outside the UK/EEA. Where that happens, we and our processors rely on lawful transfer mechanisms such as the European Commission's Standard Contractual Clauses (or the UK equivalent) and adequacy decisions where available.
9. Changes to This Policy
We may update this Policy as LAVA's features change. Material changes will be reflected by updating the date at the top of this page.
10. Contact Us
Questions or requests about your data:
- Data controller: Ghimici Denis-Constantin (Romania)
- Support server: https://discord.gg/K8Vgd6nNcz
- Source code: https://github.com/Ghimel9112/LAVA
