← Back to home Français →
WhisperWatch

Privacy Policy

Last updated: June 14, 2026

This policy explains what data WhisperWatch processes, why, for how long, and what your rights are under the General Data Protection Regulation (GDPR). This English text is provided for convenience; the French version prevails in case of discrepancy.

1. Data controller

The WhisperWatch service is operated by RDTvlokip ("we"). For any question about your data or this policy, you can contact us at: contact@rdtvlokip.fr.

2. Data we process

WhisperWatch processes the minimum data required to operate:

Category Examples
Discord identifiers Server ID, monitored bot IDs, channel IDs, ID of the user who configured the monitoring
Monitoring configuration Custom messages, embed titles and colors, roles/users to mention, grace and silence periods, instability thresholds
HTTPS monitoring (Beta) The addresses (URLs) you choose to monitor, their display name, the check interval and the associated alert configuration, as well as the availability history (status, latency, HTTP response code, incidents)
Security check (local) If you trigger it for a monitored URL, we compute a security verdict (risk score, detected issues) with an in-house engine and cache it. The analysis is local: no URL is sent to a third party.
Operational data Online/offline status, incident history, uptime statistics, server settings (report channel, panel, server Premium status) and the user's Premium status
Public status pages (optional) If you explicitly enable it for a bot or a URL, a publicly accessible status page (via a link) shows its name, state and uptime statistics. This is off by default and revocable at any time.
Dashboard authentication Sign-in via Discord OAuth2 (identify and guilds scopes). A signed session token is stored in a secure browser cookie; we do not store your Discord password.

We do not collect the content of your Discord messages and do not read your conversations.

HTTPS monitoring: for this feature, WhisperWatch periodically sends HTTP(S) requests to the addresses (URLs) you configure, identifying itself with a User-Agent header of the form WhisperWatch/1.0 (+https://whisperwatch.rdtvlokip.fr). We do not store page content: only availability (up/down), latency and the HTTP response code are retained.

Security check (local): on your request, WhisperWatch assesses a monitored URL's security with an in-house engine — heuristic analysis of the address, matching against public blocklists that we download and store on our side, and inspection of the target's TLS certificate and redirects. No URL is sent to a third-party service. To estimate the domain's age, only the domain name (public data) may be queried from the relevant registry via the RDAP protocol. The result is cached so that each URL is checked only once.

3. Purposes and legal bases

  • Providing the service (monitoring, notifications, statistics, dashboard) — legal basis: performance of the contract (our Terms of Service).
  • Security and proper operation (technical logs, abuse prevention) — legal basis: legitimate interest.

We do not perform advertising profiling and make no automated decisions with legal effect concerning you.

4. Hosting and data location

Data is hosted within the European Union, in Germany (Falkenstein), with Hetzner Online GmbH. No data is transferred outside the European Economic Area, except the optional RDAP query described above (which only concerns a public domain name and may reach a registry located outside the EEA).

5. Retention period

  • A monitored bot's or URL's data is retained as long as monitoring is active.
  • If a monitored bot leaves a server, or if WhisperWatch is removed from a server, the relevant data (including monitored URLs and their history) is retained for 30 days (to allow a return without loss of configuration) and then automatically and permanently deleted.
  • You can immediately delete a bot's data via /unwatch, a URL's data via /unwatchurl, or from the dashboard.
  • The dashboard session token automatically expires after 7 days.

6. Data sharing

We do not sell or rent your data. It is shared only with the providers strictly necessary for operation: Discord (the API the service relies on) and our host Hetzner. We may disclose data where required by law.

7. Administrative access

The service operator has a secured administration dashboard, restricted to their own account (Discord authentication, logged and rate-limited access), allowing them to view the data described above (servers, monitored bots and URLs, configurations) for operation, support and abuse prevention.

The operator does not modify the configuration of a monitored bot or URL without the prior consent of the user who set it up: any change made from this dashboard requires an explicit confirmation from that user, requested via a Discord direct message and valid for at most one hour. Without that consent, no modification is possible.

For proof of consent and security purposes, access requests, consents given and changes made are recorded in an audit log (timestamp, the Discord identifiers and usernames involved, server and bot IDs, IP address). These entries are kept for one year and then automatically deleted.

8. Your rights (GDPR)

You have the following rights over your data:

  • right of access, rectification and erasure;
  • right to restriction of, and objection to, processing;
  • right to data portability.

You can exercise most of these rights directly via /unwatch or the dashboard, or by writing to contact@rdtvlokip.fr. You also have the right to lodge a complaint with your local data protection authority (in France, the CNIL).

9. Cookies

WhisperWatch uses a single strictly necessary cookie: a session cookie (session), HttpOnly and time-limited, used to keep you signed in to the dashboard. No advertising or third-party tracking cookies are used.

10. Security

We implement reasonable technical measures to protect your data: encryption in transit (HTTPS), signed sessions, access restrictions and rate limiting. As no system is infallible, we cannot however guarantee absolute security.

11. Minors

The service is intended for users who meet the minimum age required by Discord. We do not knowingly collect data concerning individuals below the required age.

12. Changes

This policy may be updated; the last-updated date appears at the top of the page. In the event of a significant change, we will endeavor to inform you by an appropriate means.

13. Contact

For any question about this policy or your data: contact@rdtvlokip.fr.