Adventure Kairo Privacy Policy
Last updated: 11 August 2026
0. What this document is about
diskhar.com is the official website of Diskhar World. Of everything being built here, the only thing open to the public today is Adventure Kairo. The Diskhar World RPG, the community bot and the roleplay rooms have not launched yet; when they do, each will bring its own document, and this one will not be used to cover for them.
This document covers Adventure Kairo: the game inside Discord and the part of this website that has to do with it.
Adventure Kairo is an independent Discord application, with its own process and its own database, separate from the other Diskhar bots. You can add it to any server: there is no server allowlist, and the bot does not leave any server on its own.
The website is not just the shop window this text hangs in. It works against the same database as the bot, and this is where the following happens:
- Your Adventure profile. If you sign in with Discord, the site reads your save — progress, name, ranking position — in order to show it to you.
- Support. Opening a ticket stores your Discord ID, the name you appear under, and everything you write in the conversation.
- Server settings. If you administer a server, the language, channels and manager roles you choose are stored alongside the server's ID and the ID of whoever made the change.
- News. It is written here, and the bot publishes it inside Discord afterwards.
- The internal panel of the three founder accounts, which does see player records and who has played recently. It is set out in full under The internal panel and Who can see or delete your data from the inside.
To be blunt: the website does read your save. This same page used to claim the opposite — "the site does not read your save, does not store it and knows nothing about it" — and that was false: the Adventure profile queries your record in the database every time you open it.
Data controller: MB ASIOS, a mažoji bendrija incorporated in Lithuania · legal entity code 307543749 · registered office: Kalvarijų g. 125, LT-08221 Vilnius (Lithuania) · Contact: see Contact, at the end of this page.
1. What we collect
Everything we store hangs off your numeric Discord ID. That number is your key inside the game.
We do not ask for an email address, a phone number, a real name, a postal address, an IP address or payment details.
Opening the Adventure panel once is enough for a record with your ID to exist. You do not have to play or finish the tutorial: the moment you touch the panel, the game creates your record with its starting values. Those records of people who never actually played are real — the code itself calls them "ghosts" and had to filter them out so they would not show up in the leaderboard.
1.1 Your adventurer name
This is the name that appears on your card, in the leaderboard and in your Company's member list.
You can type it yourself: 2 to 20 letters, no digits, with a filter for disallowed words and reserved names.
If you do not choose one, the game copies the one you already have on Discord, without asking: your nickname on that server, or your global name, or your username — in that order.
1.2 Your avatar
We do not store the image: we store an internet address (URL) that points at Discord.
There are two ways to set it:
- Reuse your Discord avatar. Its address is stored.
- Upload an image (PNG, JPG or WEBP, up to 8 MB) from a form inside Discord. The image is hosted on Discord's servers; we only store its address.
If you choose nothing, the game takes your Discord avatar automatically.
An honest warning: those addresses expire. Discord invalidates them after a while, and when that happens your avatar stops showing on the game's cards without anyone telling you. Since we keep no copy of the image, we cannot prevent it.
Every time a card with your avatar is drawn, a request is made to that Discord address.
1.3 Your Company's Sigil — here we do store the image
The leader of a Company can upload an emblem for it (PNG, JPG, WEBP or GIF, up to 4 MB on the way in).
It is the only case in the whole game where we store the pixels of an image. And what you upload is not stored as it is:
- it is downloaded once, with a size cap that cuts the download dead;
- it is rejected if it is larger than 4096 pixels on a side;
- it is re-encoded into a PNG of ours, 128 × 128, cropped to a circle;
- that PNG of ours is stored, and only if it weighs less than 48 KB.
In other words: the file you uploaded stops existing as soon as the process ends. What is kept is the image we generate. It is stored in its own part of the database, separate from the rest of the game state.
The leader picks it and everyone sees it: the emblem is drawn on the Company card and in the public Companies table, which any player can open.
When it is deleted: when the last member leaves and the Company is dissolved. There is also a sweep of orphaned emblems — those of Companies that no longer exist — which runs inside the global wipe performed by administrators (see Who can see or delete your data from the inside). Resetting your tutorial does NOT delete the Sigil.
1.4 Your language
If you choose a language with the button, we store your choice: Spanish or English.
If you have not chosen one, the game checks your server roles at that very moment to decide which language to speak to you in. That check is instantaneous and is not stored: we do not keep your roles.
We do store a technical list about the server, which has nothing to do with your roles or your save. It is explained in the next section.
1.5 Data about the server where you play
This is not yours: it belongs to the Discord server. We store it so that whoever administers it can configure the bot from our website, because only the bot itself knows a server's list of channels and roles.
Every few minutes we record, for each server the bot is in:
- Its identifier and its name.
- How many people it has, if Discord gives us that.
- A list of its text channels — identifier and name — capped at the first 60, and only those the bot can write in.
- A list of its roles — identifier and name — capped at the first 40, excluding the default role and those managed by other applications.
We do not read or store messages, nor who is in each channel, nor who holds each role. Only the names of channels and roles, which on Discord are public to anyone who joins the server.
When it is deleted: when you remove the bot from the server, it stops appearing in that list at the next refresh.
1.6 Your game progress
Tools, backpack, in-game Khron, continent reached, portals, bosses defeated, level and experience, points and achievements, hearts, illness, wounds, daily errands, Almanac, streak and game statistics.
1.7 Things that involve other players
- Trade offers: your ID, the recipient's ID, the materials deposited and the price in Khron.
- Companies: which Company you belong to, how much you have contributed and when you joined. The contribution history is not deleted even if you leave: whoever put something into the Ark is recorded there.
- Server firsts: if you are the first on the server to reach a milestone, your ID is recorded as the first and a prize is set aside for you.
- Loot on public cards: the result of a roll is tied to its message ID, so the "Refresh" button keeps working after the bot restarts. The last 150 are kept.
1.8 Chests
Chests do not appear from chatting. That trigger was removed: today they appear when you have been playing the Adventure for a while in a channel.
For that we store, per channel, a list of recent game actions with your ID and a timestamp. And, per player, a chest history: how many you have won today and this week, when the last one was and how many tips you have — it feeds the caps that stop one person taking every chest. No text is stored, because the bot does not receive it (see The bot cannot read your messages). Chests only work inside the official Diskhar server.
And the first to press does not win: the first people to press (up to 10 places) enter a draw, in which the first counts triple. The winner is announced in the channel with a mention, and the number of entrants is stated.
1.9 The action log, and only in the official server
Inside the official Diskhar server the bot records what happens in the game: who tracked, dug, bought, sold or summoned a boss, with their Discord ID and a timestamp. It goes to a channel only the team can see.
In other people's servers nothing at all is logged. And it does not depend on us remembering to switch it off: the check is against a server identifier written into the code, not a setting, precisely so that it cannot be turned on from outside by accident. What people play in someone else's house belongs to them.
What it is for: knowing what breaks and when. When somebody writes "this failed for me", what they did just before is right there.
1.10 The internal dashboard
Three founder accounts have a dashboard showing which servers the bot is in and who is playing. It is built from what is already described above: the technical list of servers and the player records.
It is our own analytics, and we say so because it exists. What there is none of is third-party analytics: no external measurement service, no tracking pixels, nothing that leaves here.
1.11 What we do not collect
- The content of your messages. We cannot: see The bot cannot read your messages.
- Your IP address.
- Your email address.
- Payment details. Nothing in Adventure Kairo is bought with real money.
- Nothing for advertising or analytics. There is no third-party measurement, tracking or statistics system in the application.
- We do not check anyone's age (see Minors).
2. The bot cannot read your messages — and that is not a promise of ours
Discord requires every application to declare in advance what information it wants to receive. Adventure Kairo starts up asking for one single thing: basic server information.
It does not ask for the privileged message content permission, nor for the member list one. Without them, Discord simply does not send it the text of what you write. It is not that we decided not to read it: it never reaches us.
What that means in practice:
- The bot only finds out what you do when you press one of its buttons or use one of its commands.
- An ordinary message of yours in a channel is invisible to it.
- It is not even needed to upload your avatar: the image is sent from a form inside Discord, precisely so as not to depend on that permission.
It is the strongest guarantee in this document, because it does not depend on our good will but on what Discord grants us.
3. What we use what we collect for
- Running the game: saving your progress between sessions, applying cooldowns, resolving your actions.
- Addressing you: mentioning you when you win a chest or claim a first; drawing your name and your avatar on your cards.
- Leaderboards and Companies: ordering the board, showing the Companies table, working out your global position.
- Trading and invitations: carrying an offer from sender to recipient, holding what was deposited and returning it if it expires or is rejected.
- Language: speaking to you in Spanish or in English.
- Preventing cheating: daily caps, per-action limits and progress checks.
- Knowing what breaks and how the game is doing: the official server’s action log and the internal dashboard used by the three founder accounts.
We do not use any of this to profile you, nor for advertising, nor do we sell it or hand it to anyone beyond what is described in Where it is stored and who processes it.
4. What is public inside Discord
Adventure Kairo is a social game. A good part of what you do is posted in the channel where you play, in view of whoever is there.
What is posted:
- Your rolls. Every track and every dig produces a card in the channel with your mention, your Discord avatar and what you found. This is the default behaviour. The only switch to turn it off is global and lives in the administration panel: you do not have an individual option to play privately.
- Your milestones. When you open a Portal, defeat a boss, complete the Atlas of the Veil or beat the Avatar, the game announces it with your mention in the activity channel (or wherever you are playing, if that channel does not exist on your server). It happens to anyone, not only to the first.
- Server firsts: if you are also the first on the server to reach it, that is announced separately.
- Chests: the winner of the draw is mentioned in the channel.
What is NOT posted, even though it may look like it. Everything else answers only you: Discord calls it an ephemeral reply and only the person who pressed sees it. That covers your /profile card, the leaderboard, the Companies table, the shop, your backpack and every panel in the game. The only two exceptions are the ones above: your track and dig rolls, and milestone announcements.
Mind what that implies: they are not posted on their own, but any player can open them. There you can see your name and your progress, and your Company's emblem, treasury and members with what each one contributed.
And about other players: anyone can look up another player's card with a user picker. That reply is private: only the person who asked sees it.
An uncomfortable but real detail: if someone in your Company resets their tutorial, they are left with no stored name, and the Company card draws them as # followed by the last 4 digits of their Discord ID, in view of the other members.
We publish none of this outside Discord. But a message posted in a channel can be copied by anyone who sees it, and that is no longer in our hands.
5. Where it is stored and who processes it
| Who | What they do |
|---|---|
| Discord | The platform. Everything you see and press goes through their servers. Avatar images are hosted on their content delivery network. |
| Supabase | The database. A project of Adventure Kairo's own, separate from that of any other product of ours. |
| Railway | The hosting for the bot's program. |
| Vercel | The hosting for the website (diskhar.com): it is what serves your sign-in and the pages that read your Adventure record. |
Plus a copy on the machine's disk. Every time something is saved, the bot also writes a JSON file to the disk of the server it runs on, with .bak copies and temporary files. It is a safety net: if the process dies suddenly, your last save is not lost.
Nobody else receives your data. There is no third-party analytics, no advertising, and no other external service we send anything to: the application talks to no servers other than Discord's and its database's.
A technical detail we would rather tell you than hide: the state of every player lives in a single row of the database, which is read and rewritten whole every time anyone interacts. Company emblems and chest data live in separate rows.
Where all of this physically is. Our Supabase databases are hosted inside the European Union — in Stockholm (Sweden) and in Ireland.
The bot's program, however, runs in the United States (Railway, region
us-west2, Oregon). That is where what you do while playing is processed, even though the data ends up stored in the European Union. That is an international transfer, and it relies on the data processing agreement we have with Railway as our processor.We say it this plainly because this same page used to claim that your data did not leave the European Economic Area, and that was not accurate: the databases did not, the program's hosting did.
6. Who can see or delete your data from the inside
- The team with access to the project's database.
- Three founder accounts have an administration panel with a button that wipes the Adventure for EVERY player at once: records, firsts, open trades, Companies and prizes.
- Before that wipe, the system stores a global backup that contains everyone's save. That copy stays inside the database until the next wipe or until it is used to undo one.
- That same panel allows maintenance mode to be switched on and global game settings to be changed.
7. How long we keep it
Bluntly: there is no purge by time or by inactivity. What we store is stored for as long as the game exists.
| Data | How long it lasts |
|---|---|
| Your record, progress, name, avatar and language | Indefinite |
| A Company's emblem (Sigil) | Until the Company is dissolved |
| Your contributions to a Company | Indefinite, even if you leave |
| Server firsts and prizes | Indefinite |
| Trade offers | 48 hours * |
| Company invitations | 48 hours * |
| Loot tied to public cards | The last 150 |
| Game activity for chests | 30-minute window per channel * |
Global backup taken before a wipe (avResetBak) | Until the next wipe |
* These deadlines are applied lazily: there is no timer. The cleanup runs when someone opens that panel again or acts in that channel. If nobody touches it, the entry is still there after the deadline.
Apart from this, the messages the bot posts in Discord — cards, announcements, chests — stay in the channel like any other message. We do not delete them.
8. Your rights and how to exercise them
You have the right to access your data, to have it corrected, to ask for it to be deleted, to restrict its use and to object to its processing.
Now the important part, without decoration:
Today the game has no button to delete your account.
- "Reset tutorial" is not an account deletion. It wipes your save — progress, backpack, name, avatar — but leaves behind: your stored language, your prizes, your ID recorded in the server's firsts, your Company membership and what you contributed, your open trade offers and the Company's emblem. And as soon as you open the panel again, a new record is created for you with the same ID.
- There is also no button to change your name or your avatar once initial setup is finished. Those controls only appear while setup is incomplete. After that, they are requested by contacting us.
- The only total wipe that exists inside the game is the administrators' one (see Who can see or delete your data from the inside), and it wipes all players at once. It does not work as an individual deletion.
That is why, to exercise any right, you have to write to us — see the Contact section at the end of this page. We do it by hand.
How it works in practice:
- Write to us stating your Discord ID (or your adventurer name, if you have set one).
- We check that the request comes from that account.
- Access: we send you what is stored about you.
- Correction: we change whatever is wrong, including the name and the avatar.
- Deletion: we delete your record and everything that hangs off your ID.
Limits we cannot get around, and which you should know before asking:
- We cannot delete messages already posted on Discord beyond what Discord allows us to. A card with your name posted months ago in a channel stays there.
- Some of your data is part of another person's save: a trade you made, or what you contributed to a Company's Ark. That part is not deleted without breaking other people's game.
- Deletion may take time to disappear from our providers' backups.
We reply within a maximum of one month from receiving your request, which is the deadline in art. 12.3 GDPR. If the request is complex we may extend it by two further months, and in that case we tell you within the first month, explaining why.
Legal basis for each processing operation (GDPR). MB ASIOS is established in the European Union, so Regulation (EU) 2016/679 applies in full:
What for Legal basis Storing your save, your progress, your backpack and your Company Performance of a contract (art. 6(1)(b)): without that data there is no game to play Your adventurer name and your avatar in leaderboards and cards Performance of a contract (art. 6(1)(b)): they are part of what the game shows The Sigil uploaded by a Company leader Performance of a contract (art. 6(1)(b)), at their request Farming caps, anti-cheat guards and abuse records Legitimate interest (art. 6(1)(f)): so that a cheater does not ruin the game for everyone else Backups and not losing your progress Legitimate interest (art. 6(1)(f)) The official server’s action log and the internal dashboard Legitimate interest (art. 6(1)(f)): knowing what fails, being able to fix it, and seeing whether the game holds up We do not use your data for advertising, we do not sell it, and we do not hand it to third parties beyond the providers in Where it is stored and who processes it, and there are no automated decisions that affect you legally.
Complaining to the supervisory authority. If you believe we handle your data badly, you can complain to the Lithuanian data protection authority, the Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate): L. Sapiegos g. 17, 10312 Vilnius, Lithuania · ada@ada.lt · vdai.lrv.lt. Before that, we would appreciate you telling us: almost everything is sorted out faster.
9. Minors
Adventure Kairo runs inside Discord, and Discord requires you to be at least 13 years old, or older depending on the country.
We do not check anyone's age. The game does not ask for it and has no way of knowing it.
If you are a parent or legal guardian and believe a minor in your care has a record here, write to us (see Contact) with their Discord ID and we will delete their record by hand. It is the same process as in Your rights and how to exercise them.
10. Changes to this policy
If we change this policy, we update the date at the top and publish the new version on this same page.
If a change affects something important — new data, a new recipient, a use different from the ones already here — we will also announce it inside Discord before it takes effect.
11. Contact
Email: asiosmb@gmail.com — write from wherever you like, but tell us your Discord identifier or your adventurer name: without that we cannot know which record is yours and we will not be able to help you.
Official Discord server: https://discord.gg/zZkdgU6QMr — it is the fastest route.
Write stating your Discord ID if your request has to do with your data.

