Rosa Wildlife Reserve is a volunteer-run Path of Titans community. For the purposes of the GDPR, the Rosa staff team is the data controller for the personal data described here.
This policy covers the whole Reserve together: this website, our Discord server, our four Discord applications (Rosa Terminal, Rosa Conservatory, Rosa Support and Rosa Wildlife) and our Path of Titans game server. They share one database, so one policy describes all of it.
It does not cover Alderon Games, Discord or Patreon themselves. Each of them stores data about you under their own policies: Alderon Games, Discord, Patreon.
This document is version 1.49, last updated 7 October 2026.
- Your Discord user ID, username, display name, and avatar.
- Your roles in our Discord server, which determine what you can access.
- Your Alderon Games ID and in-game username, once you register.
- When you joined our server, and when you left it if you do.
- When you sign in, Discord gives us a token that lets us read your roles in our server. We use it once, at that moment, and we do not store it.
- A session token stored in a cookie and in our database, so you stay signed in.
- Your email address, if your Discord account has one attached.
- Your Patreon user ID, and access and refresh tokens, encrypted at rest.
- Whether you are an active patron, which tier you are on, when your pledge started, and the totals Patreon reports to us.
- We never see your card, bank or address details. Patreon handles payment and does not pass that to us.
- We check your pledge status once a day so that a supporter role is removed when a pledge ends. Unlinking removes the role immediately and deletes everything in this section.
- Reports you file or that name you: who was reported, when the incident happened, which rules were cited, your description of the evidence, and any clips or screenshots attached.
- Whether you filed a report publicly or privately, and where a private one says why, the reason you gave for filing it that way.
- Your side of a report you are named in: the evidence you give and the timestamps you add.
- Investigations, including which staff member handled them.
- Discussions opened about a report: who was in the room, who put them there, and everything said in it.
- Penalties: the level, the rule, the date of the offense, when it expires, and who issued it.
- Moderation on Discord: bans, kicks, timeouts and warnings, with the reason, who carried them out, and whether you were told.
- In-game bans and whitelist removals. These follow from a penalty, from a Discord ban, or from leaving the server, and we keep which of the three it was along with the Alderon ID the ban was aimed at.
- Appeals you submit: which ruling you are disputing, the ground you are claiming, what you wrote, any evidence you attach, and what staff decided.
- Entries on the blacklist, which is the list of people staff have decided must not be let in. An entry stores whichever of these staff had: a Discord ID, an Alderon ID, a Discord username and an in-game name, along with the reason, the evidence it is based on, and who wrote it. A blacklist entry is the one record here that can be about somebody who has never been a member, because the point of an entry is to recognize somebody arriving for the first time. Screenshots, clips and documents can be attached to an entry, and links to clips kept elsewhere can be recorded on it. Files are kept the same way as any other evidence. An entry that is lifted is kept, marked as lifted, with the reason it was lifted.
Every message sent in a ticket channel is recorded as it is sent, including messages that are later edited or deleted. Edits keep their earlier versions. We do this so a ticket can be read back afterward and so a dispute about what was said has an answer. A deleted message is often the one that matters.
We also record who opened the ticket, who was added to it and by whom, who claimed it, who it was passed on to, who escalated or delegated it and when, and what you filled in on the form. We keep how you appeared at the time along with it: your name, nickname, avatar and role color, so the transcript looks like the conversation did.
Pictures, clips, voice messages and files posted in a ticket are copied to our own storage as they arrive, even where the ticket keeps no transcript. Discord's links to them expire within about a day, and we need evidence that still opens the next morning. See Files you upload below.
This covers a file you linked to as well as one you uploaded, where the link points at Discord's own storage. Pasting a link to a screenshot and dragging the screenshot in come to the same thing for everybody reading the channel, and the link stops working just as quickly. Links to anywhere else are recorded as links and nothing is copied.
A ticket is read by staff. A ticket can be discussed among staff, recorded, and used when a decision has to be made about you or about somebody else. We do not describe a ticket as confidential, because a ticket is not confidential.
A transcript can be opened by the people who were in that ticket and by staff. Being removed from a ticket removes your access to its transcript as well. Escalating a ticket brings another group of staff into it, and they can read everything already said in it. Delegating a ticket hands it to another team, such as the team that looks after profiles, and that team can read everything already said in it too.
A letter sent to legal@rosarealism.com is kept as a case, with the address it came from, the name that address carried, the subject, and the text of the letter. Every answer we write is kept beside it, along with who wrote that answer and when. You are sent one automatic reply saying your letter arrived and giving you its case number.
Where the address you wrote from is the one on your Discord account, the case is linked to your record, so whoever answers can see what you are asking about. If you later ask us to remove what you made, the letters stay and stop being linked to you. The record that you asked, and that we did it, is what shows the request was honored. A closed case is deleted with its letters and their files a year after it was closed, as section 4 says.
When you ask by email for a copy of your data or for your data to be deleted, we send you a link to a page on this site where you sign in with Discord and confirm the request. We keep a record of that request: whether it is for a copy or a deletion, a note staff wrote to recognize it, such as the address it came from, the letter it belongs to, which member of staff made the link, which Discord account confirmed it and when, and when and how staff finished it. The secret part of the link is stored only in a scrambled form that cannot be turned back into the link. This record stays when your data is deleted, because it shows the request was checked before it was answered.
When we make you a copy of your data, we keep a record of that copy: who it was for, who made it, when, how often it was downloaded, and the day its link stopped working. When we delete your data, we keep a record of the deletion: who did it, when, the reason they gave, and a line for each kind of thing that was deleted or kept, with how many. That record stores none of what was deleted.
Only the founders and the Game Warden can open these letters. The address exists for people who are not in the Discord server, which is why it is not a ticket.
When a report is taken forward, staff open a room and bring in the people it concerns. That room is recorded the same way a ticket is: every message as it is sent, including messages later edited or deleted, with earlier versions kept, and with how each person looked at the time. Pictures, clips and files posted in it are copied to our own storage as they arrive, for the same reason as in a ticket.
You can write in the room for a day. After that it stays open and readable and only staff can add to it. Nothing is deleted when that time runs out.
Who can read the record afterward depends on how the report was filed. Where the report was public, the record can be opened by anybody signed in to this site with Discord: the report was made in the open, and what came of it is part of how this place is run. Where the report was private, it can be opened only by the people who were in the room and by staff above Front Desk. Being removed from a room removes your access to its record as well. Staff decide at the point of closing which of the two applies, and they can make a record private that started out public.
A case can be handed to the key holders. When that happens the staff who were handling it lose access to the room, and the key holders can read everything already said in it.
Clips, screenshots, documents and other attachments sent through the bots or this website are stored in a private bucket at Cloudflare, and we record who uploaded each one, when, and what it belongs to. Nothing in that bucket has a public address. A picture that staff approve for a page is copied to a second, public bucket at the sizes the site shows it at, and that copy is what a page loads.
Files uploaded before September 2026 are attachments in a private Discord channel that only staff can see, and stay there until they are moved. Cloudflare hosts the new files and Discord hosts the old ones, so anything uploaded is also covered by the privacy policy of whichever of the two stores it.
When a picture is taken down, by you or by staff, its public copy is removed at once. The original stays in the private bucket for fourteen days, so a decision can be looked at again, and is then deleted for good. An upload that never finished is deleted after a day.
Pictures added to a sprout page or a character are checked automatically for nudity and gore before a person sees them. The check runs on our own server, so the picture is not sent anywhere else for it. We keep what the check reported alongside the picture, so that staff reviewing it know what was found and so we can explain afterward why something was allowed or refused. A picture refused automatically can always be reviewed by a person instead.
Rosa Field Kit saves a video from a link onto your own computer. The app runs entirely on that computer. The links you paste, the videos you save, the folders you save them to and how often you use the app are never sent to us, are not recorded anywhere, and pass through nothing we run.
There is one exception, and it happens once. When you unlock the app we record your license key, a one way fingerprint of the computer you unlocked it on, and the name that computer gives itself, such as Kovit-PC - Windows 10.0.26100. The fingerprint is a hash: it cannot be turned back into anything that identifies your machine, and it is only ever compared against another fingerprint from the same one. We keep the day you unlocked it and the last day the app checked in, so a founder can see which key is on which computer.
If you're on the staff team and request a key, we keep the name you gave the device, when you asked, and whether a key was issued or the request was declined. Founders and the Game Warden see your request so they can decide on it.
We also record every attempt to unlock the app: the key that was presented, the fingerprint it came from, and whether it worked. That is how a key being passed around becomes visible, and it is what stops somebody trying key after key. Each attempt is deleted after a year.
The app checks with us each time it opens, so that a key which has been turned off stops working. That check says only whether the key is still good. It carries nothing about what you have used the app for, because the app does not record that either.
When you post in the bug report forum in our Discord, our bot Rosa Wildlife Reserve keeps a copy of your post: its title, what you wrote, its tags, how many people reacted with the bug emoji, and whether it's open, closed or merged into another report. The Game Warden and the founders read these copies on the site to search, sort and merge reports. Pictures and replies aren't copied; the site reads them from Discord when a report is opened.
The copy follows your post. An edit updates it, and deleting the post deletes it. If you ask us to delete your data, your posts in the bug report forum are deleted from Discord along with the copies.
Our Path of Titans server reports events to us and to private staff channels in Discord. These include in-game chat, damage and kills, logins and logouts, respawns, group activity, nesting activity, quests, purchases, staff commands, and in-game player reports. They are tied to your Alderon ID and, where the server sends them, to your character name, species, growth and location.
We store these ourselves rather than leaving them in Discord, so that staff can search them by player and by date when resolving a dispute. The full message the server sent is kept alongside what we read out of it for fourteen days, and then deleted. That message is already in a staff channel word for word, and we keep our copy only long enough to check how we read it. What is left, which is who and what and where and when, is kept for thirty days.
Assume that anything you type in in-game chat is recorded. A record of chat is how a realism server with permadeath and PVP can resolve disputes about what actually happened.
Some chat lines are commands rather than conversation. Typing something beginning with an exclamation mark, such as !hunger, asks the server a question and is answered in the game. For each of those we keep which command you used, when you last used it and how many times, so that we can enforce a limit on how often it may be used. That record is kept against your Alderon ID and stores no part of what you typed beyond the command itself.
Rosa Relay is a bot that writes down what is said in a voice channel and reads messages aloud, for members who cannot hear or cannot read along. It only joins a voice channel when a member runs /join, and when it joins it says in the channel what it is doing. Staff decide in its settings whether each of the two parts is switched on.
When writing speech down is on, the sound of everybody who speaks in that voice channel is sent to Deepgram, a speech-to-text service, while they speak. Deepgram sends back the text. We post that text in the transcript channel in Discord, with the name of the person who said it. We do not save the sound. The posts stay in Discord like any other message, until a member of staff deletes them.
When reading aloud is on, the messages written in the chosen text channel are sent to OpenAI, which turns the text into speech, and the bot plays that speech in the voice channel. When OpenAI cannot be reached, the speech is made on our own server instead.
We count page views so we know which parts of the site people read. We do not store your IP address. A one way hash of it, your browser string, and a salt that changes every day lets us tell two visits apart on the same day and is useless for recognizing you the next day. That limit is deliberate.
We record the page, whether somebody was signed in (not who), the rough kind of device, and the host of the site you came from if you followed a link. Never the full referring address, because the path you came from can carry your search terms.
This runs in your browser after a page has loaded. With scripts off, nothing about your visit is recorded at all.
- When something goes wrong on the website or in a bot, we record the error, where it happened and, if you were signed in at the time, that it was you. The reference on an error page points at that recorded error.
- Which slash commands run, how long they take, and whether they succeed, together with who ran them. We do not keep what you typed into a command; that is stored where it belongs, such as on the report itself.
- Anything you put on it: your pronouns, your time zone, what you write about yourself, and the pictures you upload. All of it is optional and all of it is yours to delete.
- How you have set it up to look: the colors and the shape you picked, the way your name is set, and any stylesheet you wrote yourself. Kept as you left it, so you can come back and change it.
- Who may read what you wrote on your page, which is anybody until you change it. Setting it to nobody keeps back what you wrote, the pictures you added, and anything other people left on your page. That setting does not hide who you are. Your Discord and Alderon names and accounts, when you joined and when you were added to the registry, and the characters you play stay readable, because those are the shared record the rest of the Reserve is built on. A family tree runs through characters that belong to other people, so it would break if one sprout could hide their part of it.
- The day and month of your birthday, if you add it on your page settings, and how many times you saved it. Nobody is asked for this. Staff can see the date on the staff birthday list. On the day itself a cake shows on your page, so anybody who can see your page can tell it is your birthday that day; you can switch the cake off and keep the date. Removing your birthday takes one press. After you have changed it a few times, admins can change it for you when you ask.
- Whether your own page comes first on the sprouts list, if you choose that there.
- Birthday wishes: when somebody presses the button on your page to wish you a happy birthday, we keep who wished you, so you can see it in your birthday envelope. Only you see who wished you. The same goes for the wishes you send. Each wish is deleted three days after it was sent.
- Any suggestion you make: what you wrote, when, and your Discord account, which is also on the post the bot opens for it. The post itself is in a channel other members read.
- How you voted on a suggestion, so you can take a vote back or change it and so nobody votes twice. Staff can see the total; who voted which way is not shown on any screen.
- What staff decided about it, who decided, and what they wrote to explain it. The decision is posted in the thread, so everybody who can read the forum can read the decision.
- Your characters: species, name, gender, skins, subspecies, mutations and conditions, and status.
- Family trees, courtship timers, nesting posts, and genetics rolls.
- Your inventory, currency balance, and purchases.
- Growth codes issued to you.
- Monthly grants paid to you: which grant paid you, the month, how many petals and which item you were given and how many, and when it was paid. We keep this so that nobody is paid twice in the same month. It is deleted when you ask us to delete your data.
- The content of tickets you open, including your answers to the ticket form.
- Transcripts of closed tickets.
- Pictures and files you posted in a ticket, copied to our own storage.
- Anything you write in your personal notepad on the dashboard. Staff cannot read it: it is kept apart from everything they can see, and no staff screen loads it.
- Notes staff keep about you, which you do not see. A note records who wrote it, when, and who last changed it. Notes are where the reasoning behind a decision is written down, and notes are covered by your right to ask what we hold.
- Anything you write about a character: their story, their age, how they died, the updates you post on how they are doing, and your own private notes on them. A character’s page cannot be hidden, because other people’s family trees point at it, but you can keep that character’s story, updates and pictures off it. Each time the writing on your page or a character story is saved, we keep the earlier version as well, with who changed it and when, so staff can see what changed. An earlier version is deleted after ninety days. Staff can still read a story you keep back, for the same reason they can read one on a profile: writing on this site has to be checkable. Your own notes on a character are not read by anybody, staff included.
- What you write where other people can read it, on your page, about a character, under a picture or in a comment, is checked automatically for the words the zero tolerance policy does not allow. When one is found, the site posts the word, the sentence it is in, a link to where it was written and your Discord account in a channel only staff can read. The check does not change or hide anything: staff read it and decide. Your own notes on a character are not checked.
- Applications you submit and how they were reviewed.
Every action staff take through our tools is logged with who did it, what changed, and when. That log protects you as much as it protects us: it lets a disputed penalty be traced back to a decision and to the person who made it.
Our hosting providers keep short-lived server logs that may include your IP address, used for security and to stop abuse. We do not use advertising or cross-site tracking cookies. The cookies we set ourselves are your sign-in session, a short-lived value that protects the Patreon linking step, and two that remember a choice you made on this device: the light or dark theme, and whether the news is shown as a list or a grid.
- To give you access: identity, roles, and session data. Necessary to provide the service you asked for.
- To run the game server fairly: moderation records and game logs. Our legitimate interest in a safe, rule-abiding community, and yours in being treated consistently.
- To make gameplay work: characters, genetics, nesting, and inventory. Necessary to provide the features you use.
- To recognize supporters: your Patreon link, on the basis of your consent, given when you choose to connect it. You can withdraw it at any time by unlinking.
- To answer you: tickets, appeals, and applications.
The periods below are the earliest we delete something. Our clean-up runs once every day, so it can take up to a day longer.
- Moderation records are kept indefinitely, including after you leave. A penalty ladder that reset when someone left and rejoined would not work, and reminders are permanent by design. We do not delete moderation records on request, unless the record was made in error.
- Evidence you attach to an appeal is kept as long as the appeal, which is part of the penalty it is about.
- Tickets, discussions about a report, and their transcripts are kept with no end date, including the earlier versions of messages that were edited. They are the record of what was asked and what was decided, and they are often about other people too.
- Your registry entry stays when you leave our Discord server. Leaving only takes you off the whitelist and marks you as no longer in the server.
- Letters to legal@rosarealism.com are kept while the case is open. A closed case is deleted a year after it was closed, with every letter in it and the files that came with them. If you asked us to delete your data, the record of the deletion stays after the letter is gone.
- The record of a request for a copy or a deletion that you asked for by email is kept with no end date. It stays after the letter is deleted and after your data is deleted, because it shows the request was checked before it was answered.
- Earlier versions of what you wrote on your page or in a character story are deleted after ninety days. What your page shows now is not affected.
- A picture that was taken down or turned down, by staff or by the automatic check, is deleted for good after fourteen days. A picture you asked staff to look at again is kept until they answer.
- A file you uploaded to a form you never sent, such as a screenshot for an appeal you did not send, is deleted after seven days. An upload that never finished is deleted after a day.
- Sessions are removed when you sign out, and an expired one is cleared within two days whether you sign out or not.
- Growth codes that expired without being used are cleared after thirty days. One you redeemed stays, because it is part of the record of what staff granted you and when.
- Your Patreon link is deleted the moment you unlink it.
- What you made, such as your page, your pictures, your characters, your inventory and your own notepad, is deleted on request, as section 6 describes. During an account transfer the data on the old account is removed.
- Game server logs are kept in our database for thirty days. A copy of each one is also posted in a private staff channel in Discord, and that copy is not deleted automatically.
- Page views are deleted after thirty days, and the record of which commands were run after thirty days.
- Errors the site recorded while you used it are deleted thirty days after a developer marks them as fixed. An error nobody has fixed yet is kept until it is.
We do not sell your data and we do not share it for advertising. Your data is processed by these companies:
- Discord: our server, our bots, and all staff channels run on it.
- Railway: hosts our database and bots, in the EU.
- Vercel: hosts this website.
- Cloudflare: stores the files you upload, in Europe, and serves approved pictures to the site.
- Resend: carries the mail to and from legal@rosarealism.com, in the EU. Nothing else is emailed, and no member address is ever sent there unless that member writes to us first.
- Upstash: counts how often a few pages and forms are used, such as the page with a copy of your data, so they cannot be used too often. Some of those counts are kept per IP address. Each count is deleted automatically within a few minutes.
- Deepgram: turns speech into text for Rosa Relay, only in a voice channel where a member asked Rosa Relay to join and writing speech down is switched on.
- OpenAI: turns messages into speech for Rosa Relay, only in a voice channel where a member asked Rosa Relay to join and reading aloud is switched on.
- Alderon Games: operates Path of Titans and the game server software.
- Patreon: only if you link it, and only your pledge status flows to us.
Some of these are outside the European Economic Area. Where that is the case, transfers rely on the standard contractual clauses in their own agreements.
Within Rosa, access depends on your rank. Moderation records are visible to admins; settings and the full database are limited to founders and the bot developer.
Public reports are visible to sprouts by design. Consider that before choosing between a public report and a private ticket.
If you are in the EU or UK, you have the right to:
- ask what we hold about you and get a copy;
- have inaccurate details corrected;
- have data deleted, subject to the moderation exception above;
- object to processing based on legitimate interest;
- withdraw consent you have given, such as for the Patreon link;
- ask for your data in a portable format;
- complain to your national data protection authority.
To exercise any of these, email legal@rosarealism.com. We aim to respond within 30 days. Anybody can put somebody else’s address on an email, so before we make a copy of your data or delete it, we send you a link. On the page it opens you sign in with Discord and press a button to confirm the request. The link works for seven days. This works if you left our Discord server or were banned from it too. Nothing is copied or deleted on an email alone.
When you ask for a copy of your data, we send you a link to a page on this site. The page shows every record we hold about you in plain words, section by section, and has a button to download all of it as one file you can keep or take elsewhere. The link works for fourteen days and the file is deleted after that. Keys, codes and passwords are left out, because they would let somebody sign in as you. So are the internal numbers the site uses to join its records together. Where a record is also about somebody else, such as a report another member filed about you, the other person is named only where you saw their name already. We keep a note that the copy was made, for whom, by whom and when.
When you ask us to delete your data, we delete what you made: your page and everything on it, your pictures and the files behind them, the comments and reactions you left, every earlier version of what you wrote, your characters, your eggs, nests and courtships, what you held in the shop, your votes on suggestions, reports you started and did not send, the count of how often you used each in-game command, your birthday, your playtime, your Patreon link and the supporter roles it gave you, the link to your Alderon account, your place on the whitelist, your post in the registry channel, the posts about nests of yours that are deleted, your sign in to this site, and any copy of your data that has not expired. What we decided about you is kept: your penalties and appeals, including appeals about your page, the reports, discussions and tickets you were part of, the notes staff wrote about you, your applications, the growth codes staff gave you, and your Discord account id and username so those records still say who they are about. A character that is in another member’s family tree is emptied and shown as deleted rather than removed, so their tree stays whole. The same goes for a nest other members hatched from. If staff ever cleared what you wrote on your page, the audit log entry for that still quotes it, because it is the record of what staff removed and why. Events the game server recorded against your Alderon ID, such as your in-game chat, are not deleted on request, because staff use them to check reports. They are deleted automatically after thirty days, as section 4 describes. We keep a record that the deletion was done, and it stores none of what was deleted. If Discord refuses to remove a post or a role, that record says so, and staff remove it by hand.
Leaving the Discord server takes you off the whitelist, clears your Alderon registration, deletes your entry from the registry channel and signs you out of this site. Your record stays: your characters, your tickets and our moderation records are still here, and the Alderon ID that was cleared is kept in the registry history so staff can still look up who it belonged to. Leaving does not by itself delete your data. Ask us if that is what you want.
The Reserve is not for under-13s, and the minimum is higher where local law requires it. We do not knowingly collect data from children below that age. If you believe a child's data is in our systems, tell us and we will remove it.
The website asks every account once whether you are 13 or older. If you answer no, your account on the website is closed and our staff are told. Within eight days we delete your website sign in, which stores your email address. If you sign in again after that, the website stores your email address again, and we delete it again within a day. If you gave the wrong answer, you can correct it on the screen that says your account is closed. Staff decide whether to delete the rest of your data, as described in section 6.
Access to our database and staff tools is limited to the people who need it, and staff actions are logged. The Patreon tokens of a linked account are encrypted before they are stored, and the Discord sign-in token is not stored at all. We are volunteers running a hobby project, not a security company: we take reasonable care, but we cannot guarantee that a breach will never happen. If one does, we will tell affected sprouts and the relevant authority where the law requires it.
We will update this policy as the Reserve grows; the bots described here are still being built. Significant changes are announced in our Discord server, and the version and date at the top of this page change with them.
If you have a question about this privacy policy, write to legal@rosarealism.com. A reply comes back within moments to say the letter arrived, with a case number you can quote if you write again. A person reads every letter and answers it.
You can also open a ticket in our Discord server. Use the address above if you have left the server, because opening a ticket requires you to be in it.
See also our Terms of Service.