Skip to content
BlindBlue
Home Statistics My stats Suggest FAQ
Log in
🇬🇧 · 🇺🇸 EN ▾
🇫🇷 Français🇬🇧 · 🇺🇸 English

Privacy Policy

Last updated: September 26, 2026 · Applies to the BlindBlue bot and to blindblue.fr

In short, in plain language:

  • No, we don't read your private conversations. The bot only reads messages you type in the game channel while a round is actively being played, to check if you guessed right.
  • The text of your message is never stored, never shown to anyone else, never used to train any AI/ML model, and never sold or shared with third parties. Only the result (right/wrong, how fast) is kept.
  • We don't use any advertising or analytics cookies - the website has none, at all.
  • Payment for VIP goes 100% through Discord; we never see your card details.

Contents

  1. Who we are
  2. How we use Discord message content
  3. Data we collect
  4. Why we use it, and on what legal basis
  5. Who has access to your data
  6. International data transfers
  7. How long we keep it, and deletion
  8. Cookies
  9. Your rights
  10. Security
  11. Minors
  12. Changes to this policy
  13. Discord's own privacy policy
  14. Contact

1. Who we are

BlindBlue is developed and operated by Milanne Onym, an individual developer based in France, not operating as a registered company (the "data controller" under GDPR, "we"/"us"). You can reach us at team-support@blindblue.fr or via our Discord support server for anything in this policy, including exercising your rights (section 9).

2. How we use Discord message content

This is the part that matters most, so we're being as precise as possible:

  • When: the bot only reads the text content of messages sent in the specific text channel configured for the game, and only while a blind-test round is actively in progress in that channel. It never reads messages anywhere else, in any other channel, or outside of an active round.
  • What it does with it: each message is compared, in memory, against the expected answer using a fuzzy string-matching algorithm (the Levenshtein distance), to decide whether the guess is correct. This comparison happens in real time and the raw message text is discarded immediately afterwards.
  • What is stored: as of today's architecture, the raw text of your message is never written to our database, never logged (we use no error-tracking or monitoring tool that could capture it either), and never kept in any form. What we do store is limited to: whether the guess was correct or not, how long it took (in milliseconds), your Discord user ID, the Discord server ID, and the ID of the song/clip being played.
  • What we don't do with it: we never share message content with any third party, never use it for advertising or profiling, and never use it to train, fine-tune, or evaluate any artificial intelligence or machine learning model, ours or anyone else's.

This is the entire scope of the Discord "Message Content" privileged intent as used by BlindBlue: real-time, in-channel, in-round answer checking - nothing else.

3. Data we collect

DataSourceWhy
Discord user IDDiscordIdentify you for stats, leaderboards, and VIP status
Discord server (guild) IDDiscordRun the game per-server, per-server leaderboards, VIP status
Whether an answer was correct/incorrect, and response timeDerived from message content in real time, see section 2Scoring, in-Discord leaderboards (/rank), personal stats page
Team you joined in a team game (color, with your Discord user ID)You, through the lobby buttons, or assigned by the botShow team scores and the winning team during and at the end of the game; replay with the same teams
Song/clip ID playedOur own song databaseLink a guess to which song it was about
VIP status: expiry date, days grantedDiscord entitlement notificationsActivate and track the paid VIP option
Amount associated with your VIP purchase (indicative)Computed by us from the price we set for the offer purchased - never received from Discord, and never your actual banking data; may not perfectly match the final billed amount (taxes, currency conversion)Internal tracking, statistics
Discord entitlement ID of each VIP purchase, with its date and the buyer's user IDDiscordPrevent the same lifetime purchase from being claimed twice; date your last purchase, which counts as activity (section 7)
Discord username and avatar (website only, not stored)Discord OAuth2, read live at loginShow who's logged in on the website; not written to our database
Songs and themes you suggest on the website, your votes, their date and your Discord user IDYou, on the /suggest pageCollect and rank suggestions for the catalog; limit each player to 10 new suggestions per day and one vote per suggestion
Technical logs: command used, Discord username, server name, dateDiscord, when a bot command is used or the bot joins/leaves a serverDebugging and abuse prevention

We do not collect your email address, real name, IP address logs, payment details, or the content of any message outside an active game round.

4. Why we use it, and on what legal basis

Under GDPR, we rely on: performance of a contract (Art. 6(1)(b)) - running the game you asked to play, tracking your VIP purchase; and legitimate interest (Art. 6(1)(f)) - maintaining leaderboards and stats as a core, expected part of the game, collecting suggestions to improve the catalog, and preventing abuse. We do not rely on consent for any of this, and we do not need to, because we don't use any tracking, advertising, or profiling cookies (section 8).

5. Who has access to your data

Data is not sold or shared with advertisers. It is accessible to: the Developer (for running and maintaining the Service); Discord, which necessarily receives your messages and interactions as the platform BlindBlue runs on, and processes entitlement/purchase data for VIP (see Discord's own privacy policy, section 13); and our hosting provider, OVHcloud (section 6), which hosts the bot, the website and the database as our data processor and does not access them for its own purposes. Database backups are not entrusted to any third party (section 6).

Nothing that identifies you is published on the website. The public pages only ever show aggregate figures and per-song statistics, never a name next to a score: your Discord username appears on blindblue.fr only on your own /me page, once you have signed in, and that page is excluded from search engine indexing. This is why BlindBlue has no public leaderboard on the website - ranking players by name on an open page would make every player identifiable to anyone. Rankings stay inside Discord (the /rank command), visible only to the people you play with. Suggestions (/suggest) are shown to signed-in visitors with their vote count, never with who suggested or voted for them.

6. International data transfers

The bot, the website and the database run on a server rented from OVH SAS (OVHcloud), a French hosting provider, in a data center located in France. Database backups are kept in France, on private storage that is not entrusted to any third-party provider. Your data therefore stays within the European Union and is not transferred outside of it. We do not use any other hosting, storage or data-processing service.

7. How long we keep it, and deletion

Your game statistics and scores (section 3) are anonymized automatically, every day, under two independent delays, without the song and server statistics disappearing:

  • Inactive player: 12 months after your last activity (last game or answer, first command, last VIP purchase - a running subscription counts every day - or last vote on a suggestion), your Discord ID is replaced everywhere by a shared anonymous ID, and the team you had joined is erased; your votes on suggestions are kept only as an anonymous count. Your answers and scores keep counting in the totals, but are no longer tied to you, and the time of each answer is reduced to the day so it cannot be matched against the messages the bot posted.
  • Server that removed the bot: 12 months after its last game, and only once the bot is no longer there (nothing is triggered while it is), the server and channel IDs are replaced the same way and its settings are deleted. Its players' global statistics stay intact. A server whose paid VIP is still running is kept until it ends.

These delays are counted from October 1, 2026 at the earliest. Once anonymized, this data no longer identifies anyone and may be kept indefinitely. The ID of a VIP purchase is kept (a "lifetime" purchase must not be claimed twice), but the player and server IDs attached to it are anonymized under the same delays. Technical logs (section 3) are deleted after 6 months. Database backups are kept for 14 days: deleted or anonymized data disappears from them at most 14 days later.

You can request deletion of your data at any time by contacting us (section 14) with your Discord user ID; we will delete your stored scores/statistics and VIP-adjacent records tied to your account within a reasonable time (typically within 30 days), except where we are legally required to keep a minimal record (e.g. to prevent a fraudulent duplicate VIP claim). This is currently a manual process handled by the Developer directly, rather than a fully automated self-service tool.

If you delete your Discord account, any data we retain tied to that ID becomes non-identifiable as a result - the ID no longer resolves to anyone through Discord. We do not receive any notification when this happens, so this isn't an active detection on our part, just a natural consequence of how Discord works (see also section 13 on Discord's own policy).

8. Cookies

The website uses exactly three cookies, all strictly necessary for it to work - no advertising, analytics, or tracking cookies exist on this site, so no cookie consent banner is required or shown.

CookiePurposeDurationContains
bb_sessionKeeps you logged in after "Login with Discord" (httpOnly, secure, sameSite=lax)7 daysYour Discord ID, username and avatar URL - no password, no Discord access token
bb_oauth_stateProtects "Login with Discord" against forged login requests (one-time security token, httpOnly, secure, sameSite=lax); deleted as soon as you come back from Discord10 minutesA random value, nothing about you
bb_langRemembers your preferred site language1 yearA language code (e.g. "en")

9. Your rights

Under GDPR, you have the right to: access the data we hold about you, correct it, request its erasure, restrict or object to some processing, and receive a copy of it in a portable format. To exercise any of these, contact us (section 14) with your Discord user ID. If you are unsatisfied with our response, you may lodge a complaint with the French data protection authority, the CNIL, or with your own country's supervisory authority.

10. Security

We take reasonable technical measures appropriate to an individual, non-commercial project to protect your data (access restrictions, secure/httpOnly cookies, no plaintext password storage - we don't handle passwords at all, since login is entirely delegated to Discord's own OAuth2). No system is perfectly secure, and we cannot guarantee absolute protection against every possible attack.

11. Minors

We do not set an age limit of our own beyond what Discord itself requires to hold a Discord account and use its platform; if you are not old enough to use Discord under Discord's own Terms of Service, you should not use BlindBlue.

12. Changes to this policy

We may update this policy from time to time, notably to reflect changes to the Service or to applicable law. The "Last updated" date at the top reflects the latest revision.

13. Discord's own privacy policy

Using Discord itself, independently of BlindBlue, is governed by Discord's own Privacy Policy, which applies in addition to this page. We do not control how Discord itself processes your data on its platform.

14. Contact

For anything in this policy, including exercising your rights: team-support@blindblue.fr, or our Discord support server.

Terms of service Privacy Support Invite the bot

© 2021–2026 Milanne Onym