Last Updated: 2025-10-14
This Privacy Policy is GDPR-compliant and applies to all users of index-cord services.
At index-cord, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our Discord message management and indexing platform.
This Privacy Policy applies to all users of the index-cord service and should be read in conjunction with our Terms of Service.
We are committed to complying with the General Data Protection Regulation (GDPR) and Spanish data protection laws. If you are located in the European Union or European Economic Area, you have specific rights regarding your personal data, which are detailed in this policy.
By using index-cord, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and processing of your data as described herein.
For the purposes of GDPR and other data protection laws, the data controller is:
Legal Entity: Fogges S.L
Legal Form: Sociedad Limitada (SL)
CIF: ESB70788245
Registered Address: Calle Diseminado N 266, 39626, Cantabria, Spain
Email: contact@fogges.com
As the data controller, we determine the purposes and means of processing your personal data. We are responsible for ensuring that your data is processed lawfully, fairly, and transparently.
For data protection inquiries, you may contact our Data Protection Officer at the email address above with the subject line "Data Protection Inquiry" or "GDPR Request".
We collect and process the following categories of personal data:
When you create an account via Discord OAuth, we collect:
When you connect a Discord server to index-cord, we collect:
We collect and index Discord messages from connected servers:
Important: We only collect messages from Discord servers (guilds), not direct messages (DMs). We only process text messages; we do not collect or store voice chat data, video calls, or file attachments.
When you subscribe to a paid plan, we collect:
Note: We do not store your complete credit card information. Payment data is securely processed and stored by Stripe, our payment processor.
We automatically collect certain technical information when you use our Service:
If you contact us for support or other inquiries, we collect:
Under GDPR Article 6, we process your personal data based on the following legal grounds:
Contract Performance (Article 6(1)(b))
Processing is necessary to perform our contract with you (Terms of Service) and provide the index-cord service, including account management, message indexing, search functionality, and billing.
Legitimate Interests (Article 6(1)(f))
We process certain data based on our legitimate interests in operating and improving our service, preventing fraud and abuse, ensuring security, and providing customer support. We balance these interests against your rights and freedoms.
Legal Obligation (Article 6(1)(c))
We process billing and tax data to comply with Spanish tax laws and EU financial regulations, including the requirement to retain invoices for 10 years.
Consent (Article 6(1)(a))
For certain analytics and optional features, we may request your explicit consent. You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
We use your personal data for the following purposes:
We share your data with the following third-party service providers to operate our service. All providers are carefully selected and required to protect your data in accordance with GDPR.
Purpose:
Authentication (OAuth), accessing guild data, and retrieving messages through Discord's API.
Data Shared:
Discord user ID, Discord server/guild information that you authorize us to access.
Privacy Policy:
Purpose:
Payment processing for subscriptions and billing.
Data Shared:
Email address, billing information, transaction details. Credit card data is collected directly by Stripe and never stored on our servers.
Privacy Policy:
Purpose:
Transactional email delivery (account notifications, password resets, billing emails).
Data Shared:
Email address, name, email content necessary for transactional communications.
Privacy Policy:
Purpose:
Privacy-focused web analytics to understand website traffic and usage patterns.
Data Shared:
Aggregated, anonymized usage data. No personal identifiers or cookies. All data is processed in the EU.
Privacy Policy:
Purpose:
Product analytics to understand feature usage and improve user experience.
Data Shared:
User interactions, feature usage events, technical data (browser, device type). Personal data is minimized.
Privacy Policy:
We use Metabase for internal business intelligence and data analysis. Metabase is self-hosted within our EU infrastructure and does not share data with external parties. It is used solely for internal operations and reporting.
We do not sell, rent, or trade your personal data to third parties for marketing purposes. We only share data with service providers necessary to operate our service, and only to the extent required.
All user data, including Discord messages, account information, and analytics, is stored on servers located within the European Union. We use EU-based cloud infrastructure providers to ensure compliance with GDPR data residency requirements.
Your data is stored in secure PostgreSQL databases with the following protections:
Our hosting infrastructure is located in EU data centers, ensuring that your data never leaves the European Economic Area during normal operations. We regularly review and audit our infrastructure providers for security and compliance.
We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy or as required by law. Specific retention periods are:
Account Data
Retained while your account is active. After account deletion, retained for 30 days to allow for recovery, then permanently deleted.
Discord Message Data
Retained while your Discord server is connected to index-cord. After server disconnection or account deletion, retained for 90 days, then permanently deleted. You can request immediate deletion by contacting us.
Billing and Invoice Records
Retained for 10 years as required by Spanish tax law (Ley General Tributaria). This includes invoices, payment records, and tax-related documents.
Analytics Data
Plausible Analytics data is retained for 26 months. PostHog data is retained according to their retention policies. Internal Metabase analytics are retained for operational purposes.
Support Communications
Email correspondence and support tickets are retained for 3 years for customer service and legal purposes, then deleted.
Backup Data
Backups are retained for disaster recovery purposes for up to 90 days. Backup data is subject to the same security measures as production data.
If you wish to request early deletion of your data (except where legal retention requirements apply), please contact us at contact@fogges.com.
If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR):
You have the right to request a copy of all personal data we hold about you. We will provide this information in a structured, commonly used, and machine-readable format.
You have the right to request correction of inaccurate or incomplete personal data. You can update most account information directly through your account settings.
You have the right to request deletion of your personal data under certain circumstances:
Note: We may retain certain data where we have a legal obligation (e.g., 10-year retention of billing records for tax purposes).
You have the right to request that we restrict processing of your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller. We provide data export functionality for your Discord messages and account data.
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we have compelling legitimate grounds that override your rights.
Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your residence, workplace, or where an alleged infringement occurred.
In Spain, the supervisory authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos - AEPD):
Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan, 6
28001 Madrid, Spain
Website: www.aepd.es
Phone: +34 901 100 099
To exercise any of these rights, please contact us at contact@fogges.com with the subject line "GDPR Request" and specify which right you wish to exercise.
We will respond to your request within 30 days of receiving it. In complex cases, we may extend this period by an additional 60 days and will inform you of the extension.
We may ask you to verify your identity before processing your request to ensure the security of your personal data.
We do not charge a fee for exercising your GDPR rights unless your request is manifestly unfounded or excessive.
We implement industry-standard technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.
While we implement strong security measures, you also play a role in protecting your data:
While we strive to protect your personal data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we continuously work to improve our security measures.
index-cord is intended for users who are at least 13 years old, in accordance with Discord's Terms of Service. We do not knowingly collect personal data from children under 13 years of age.
If you are between 13 and 18 years old (or the age of majority in your jurisdiction), you must have your parent or legal guardian's permission to use index-cord and agree to this Privacy Policy.
If we discover that we have collected personal data from a child under 13 without parental consent, we will take steps to delete that information as quickly as possible.
If you believe we have collected data from a child under 13, please contact us immediately at contact@fogges.com with the subject line "Child Privacy Concern".
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we are committed to:
If we notify you of a data breach, we will provide:
We will notify affected users via email to the address associated with their account, and may also post a notice on our website or within the Service.
All primary data storage and processing takes place within the European Union. Our infrastructure is hosted in EU data centers, ensuring compliance with GDPR data residency requirements.
Some third-party services we use may process data outside the EU:
When data is transferred outside the EU/EEA, we ensure appropriate safeguards are in place:
You have the right to request information about the safeguards we have in place for international data transfers. Contact us at contact@fogges.com for more information.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
When we make material changes to this Privacy Policy, we will:
Your continued use of index-cord after the effective date of the revised Privacy Policy constitutes your acceptance of the changes. If you do not agree with the changes, you must stop using the Service and may request deletion of your account and data.
Previous versions of this Privacy Policy are available upon request by contacting contact@fogges.com.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
index-cord - Data Controller
Legal Entity: Fogges S.L
CIF: ESB70788245
Registered Address: Calle Diseminado N 266, 39626, Cantabria, Spain
Email: contact@fogges.com
For GDPR-related inquiries, data subject requests, or privacy concerns, contact our Data Protection Officer:
Email: contact@fogges.com (Subject: Data Protection / GDPR Request)
We aim to respond to all inquiries within 5 business days. For GDPR data subject requests, we will respond within 30 days as required by law.
If you are not satisfied with our response or believe we are processing your data unlawfully, you have the right to lodge a complaint with the Spanish Data Protection Agency:
Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan, 6
28001 Madrid, Spain
Website: www.aepd.es
Phone: +34 901 100 099
Email: ciudadano@aepd.es
At index-cord, we are committed to protecting your privacy and being transparent about our data practices. We believe in:
Last Updated: 2025-10-14
This Privacy Policy is compliant with GDPR, Spanish LOPD-GDD, and EU ePrivacy Directive.
index-cord is operated by Fogges S.L | CIF: ESB70788245 | Registered in Spain