Skoll is currently in early development — some features may be incomplete or unavailable.
Skoll logoSkoll

Privacy Policy

Last updated: April 6, 2026

1. Controller

Nicolas Böse (operating under the name Prynos)
An der Eisenbahn 8b, 28832 Achim, Germany
Email: contact@skoll.app

This privacy policy applies to the website skoll.app and the associated Discord bot “Skoll”.

2. Data We Collect and Why

2.1 Account data (Discord OAuth2)

When you log in via Discord, we receive from Discord's API: your Discord user ID, username, avatar URL, and email address. We also receive the list of Discord servers where you hold administrator permissions.

This data is stored in our database (Supabase) and is used solely to authenticate you and display your servers in the dashboard.

Legal basis: Art. 6(1)(b) GDPR — performance of a contract (providing the service you requested).

2.2 Bot activity data

When the Skoll bot is added to a Discord server, we store the server ID, server name, and server icon in our database. This data is used to display your servers in the dashboard.

Legal basis: Art. 6(1)(b) GDPR — performance of a contract.

2.3 Payment data (Stripe)

If you subscribe to a paid plan, payments are processed by Stripe, Inc. (stripe.com). We receive from Stripe a customer ID, subscription status, and plan identifier. We do not store or have access to your payment card details.

Legal basis: Art. 6(1)(b) GDPR — performance of a contract.

2.4 Usage analytics (Vercel Analytics)

We use Vercel Analytics to understand how visitors use the website. Vercel Analytics is designed to be privacy-first: it does not use cookies and does not track individuals across sessions. It collects aggregated data including page paths, referrer, browser type, and country derived from IP address. The IP address itself is not stored.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in understanding aggregate usage of the service.

3. Cookies and Local Storage

We use the following cookies and browser storage:

  • Session cookies — set by Supabase to keep you logged in. These are strictly necessary for the service to function. They expire when you log out or after the session timeout.
  • Cookie notice preference — stored in localStorage to remember that you have dismissed the cookie notice.

We do not use advertising cookies, tracking pixels, or third-party analytics cookies.

4. Third-Party Services

We use the following sub-processors to operate the service:

  • Supabase (Supabase Inc., USA) — database and authentication infrastructure. Privacy policy
  • Vercel (Vercel Inc., USA) — web hosting for the dashboard and analytics. Privacy policy
  • Railway (Railway Corp., USA) — hosting for the Discord bot. Privacy policy
  • Stripe (Stripe, Inc., USA) — payment processing. Privacy policy
  • Discord (Discord Inc., USA) — OAuth2 authentication and bot platform. Privacy policy

All US-based processors operate under the EU–US Data Privacy Framework or maintain Standard Contractual Clauses (SCCs) for international data transfers under Art. 46 GDPR.

5. Retention

Account data is retained for as long as your account is active. If you delete your account or request erasure, your personal data (Discord ID, email, username, avatar) is deleted from our database within 30 days. Server data (guild IDs, names) associated with your account is also removed at that time.

Payment records may be retained for up to 10 years to comply with German tax regulations (§ 147 AO).

6. Your Rights

Under the GDPR you have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing based on legitimate interest (Art. 21 GDPR)

To exercise any of these rights, contact us at contact@skoll.app. We will respond within 30 days.

You also have the right to lodge a complaint with the supervisory authority responsible for our registered address: Der Landesbeauftragte für Datenschutz Niedersachsen, lfd.niedersachsen.de.

7. Changes to This Policy

We may update this privacy policy from time to time. Material changes will be notified by updating the date at the top and, where appropriate, by email. Continued use of the service after the updated policy takes effect constitutes acceptance.