1. Who and what this policy covers
MyOneSecret provides community management tools for the Casa-Grande community. This policy covers the MyOneSecret website and administration panel, the Discord application Secret (ID 1217753305455919156), its companion Secret Listener (ID 1477520422361895053), and connected MyOneSecret administration features. The service is operated by the MyOneSecret project operator identified in the contact section.
Secret provides commands, forms and interactive controls. Secret Listener handles background events, moderation journals, scheduled administration and support or complaint archives. Both applications use shared service infrastructure. Available features depend on the server, channel permissions and configuration.
Discord and other external services process information under their own policies. This policy describes MyOneSecret's processing; it does not replace Discord's Privacy Policy.
2. Information we process
- Discord identifiers and profiles: user, server, channel, role and message identifiers; usernames, display names, nicknames, avatar links, account creation and server join dates; server membership and roles relevant to the features.
- Messages and moderation evidence: message text, authors, channel and time information, attachments and their filenames, URLs, sizes and types, embeds and stickers. In the configured Casa-Grande server, Listener records non-bot messages it receives and preserves text from cached edit and deletion events. Its initial user record and message counter update also runs for non-bot messages received outside that server, including direct messages.
- Support and complaints: submitted questions, complaint reasons, responses, thread participants and identifiers, outcomes, transcripts, reactions and referenced messages. Closing workflows can copy complete thread histories and download attachments and embedded or linked images into server-side archives.
- Community administration: warnings, mutes, bans and other moderation actions, reasons, responsible moderators, audit events, role changes, staff applications and activity statistics. Forms may contain information you submit, such as game nicknames, linked forum or VK profiles, age, city and supporting evidence.
- Feature progress: message counts, voice-channel participation metadata and duration, XP, levels, achievements, in-service balances, transactions, role or channel subscriptions, staff reward calculations and related histories. Voice-state processing does not record voice audio.
- Selected service messages: Secret can read configured administrative announcement channels to build reports and store extracted appointment or removal details, reasons, names and supplied profile links. It also reads chat responses to a requested CAPTCHA and message length for the restricted level-testing feature.
- Website and account data: Discord sign-in profile information obtained through the
identifyscope, local account credentials in hashed form, permissions, session identifiers, IP addresses, browser information or its hash, login history, security events and information submitted through the panel. - Connected administration services: when configured and used, Telegram administration features process Telegram account/chat identifiers, commands, linked accounts and operational records. Regular Telegram chat logging can retain incoming private message text and edits, and group moderation can retain message or caption excerpts. Separately enabled Telegram Business archive features can retain messages, media and edit/deletion history from connected business conversations. Optional game, forum and VK integrations process the identifiers and records needed for the requested administrative workflow.
- Optional school integration: the permission-restricted OpenSchool feature uses a separate session for each authorized Telegram account to retrieve grades, homework, schedules and attendance. A user may either import OpenSchool session cookies or choose an optional interactive Gosuslugi/ESIA sign-in flow. In that flow, login, password and one-time confirmation codes are used only transiently to complete the requested sign-in, are excluded from the MyOneSecret chat log, are not stored in MySQL, and the bot attempts to delete the corresponding Telegram messages immediately after reading them. The resulting OpenSchool session cookies, selected snapshots and notification records can be stored and linked to the Telegram account.
We receive information from Discord events and API requests, your direct submissions, configured integrations and activity on the website. Bots can only access Discord resources available to their accounts and permissions. Do not submit passwords for external services or unrelated sensitive information in tickets, forms or ordinary messages. The only intended exception is the explicitly initiated optional school sign-in flow described above, which treats credentials as transient input and does not persist them in MyOneSecret storage.
3. How we use information
We use this information to provide moderation and incident review, manage member roles and community resources, process support requests and complaints, maintain accountable administrative records, calculate configured activity and reward statistics, deliver requested reports, authenticate panel users and operate, troubleshoot and secure the service.
Message text and attachments support moderation evidence and case archives. Secret's report workflow extracts structured information from administrative posts. Message counts alone do not require message text; the restricted XP feature also checks text length. These are separate processing activities.
The applications do not track users' online/offline status, games or other Discord Presence activities. A bot displaying its own status is not user Presence tracking.
The reviewed Discord application workflows do not sell Discord API data, supply it to advertising networks or use message content to train machine-learning or artificial-intelligence models. They do not send Discord message content to an AI service for inference.
5. Retention and deletion
The current Discord message, moderation and case-archive workflows do not impose a single automatic expiry period. Records can remain until the operator removes them. Session expiry, diagnostic-log rotation and configurable backup cleanup are separate mechanisms; they do not automatically delete all related personal data.
Telegram chat logs have their own configurable retention setting (90 days by default); Telegram group message excerpts have a seven-day cleanup routine. Actual removal depends on the relevant cleanup running. These periods do not apply to Discord records or separate Business archives.
You can request access, correction or deletion using the contact below. Requests are handled by the operator; there is no automatic self-service command that erases all records across both applications. A request should identify the affected account and, where known, the server, ticket or message. We may need proportionate verification of the requester's identity.
Our deletion process must cover relevant live database records, transcripts, downloaded files and generated exports, and account for retained backups. Data must be removed when it is no longer needed for the service, when a valid deletion request requires it, or when the service stops operating, subject to applicable legal requirements. The operator will explain any legally required retention and the handling of remaining backup copies. We do not promise an automatic deletion deadline that the service does not implement.
6. Choices and privacy requests
There is currently no general per-user opt-out switch for message-content processing in channels accessible to the applications. Not using a command does not prevent Listener from logging a message in a monitored channel. Restricted level testers can ask an administrator to remove their tester access, but that does not opt them out of separate moderation logging.
Server administrators can restrict the applications' channel access or remove them from the server to stop future access in those locations. You can stop using optional forms and integrations and revoke the website's Discord authorization in Discord settings. These actions do not automatically erase records already retained; contact the operator for deletion.
Depending on applicable law, you may have rights to access, correct, delete or obtain a copy of your information, or to object to or restrict processing. Use the same contact for privacy concerns and reports about misuse of the applications.
7. Website cookies and security
The website uses session cookies for authentication and request-forgery protection. It records login and security events to manage access and investigate problems. Blocking required cookies may prevent panel sign-in. Local passwords are hashed, and application access checks restrict administrative functions. These controls do not eliminate all security risks.
Security depends on the deployed infrastructure as well as application controls. This policy makes no claim that all databases, files or backups are encrypted at rest. Report suspected unauthorized access using the contact below so the operator can investigate and make any required notifications.
8. Age requirements and policy updates
The Discord applications are intended for people who meet Discord's minimum age requirements in their country. Contact the operator if you believe the service has collected information from someone who does not meet those requirements.
We will update this page when our processing changes. The date above identifies the latest revision. Material changes should be communicated through the service's available announcement channels.
9. Contact the operator
For privacy questions, data access, correction, deletion or reports of misuse, contact the MyOneSecret operator on Discord (user ID 835055128057872416). If direct messages are unavailable, ask the Casa-Grande server administration to pass your request to that operator.
Include your Discord user ID and the feature or record concerned. Do not send your password, access token or unnecessary identification documents.