Pokémon HavenSolace
POKÉMON HAVEN | SOLACE

Privacy Policy

What Solace stores, why we need it and how you can exercise your rights.

Updated: 11 October 2026

1. Controller and contact

The controller for Pokémon Haven | Solace is Benjamin Arndt. For privacy questions, access, correction or deletion requests, contact mail@pokemonhaven.xyz. This policy covers the website, Solace Discord bot and their shared account storage.

2. Sign-in and essential cookies

Discord sign-in requests the identify scope. We receive your Discord user ID, display name, avatar reference and language/locale. We do not request your email address, physical location or list of servers. A locale is a language preference, not proof of where you live. The user OAuth access token is used during the sign-in callback and is not saved as an account access or refresh token.

The essential station.oauth cookie protects the sign-in flow and expires after 10 minutes. The station.session cookie and server session expire after 7 days; the server keeps a hash of the session identifier and a CSRF value. The solace.locale preference cookie can remember your public-page language for up to one year. Theme and interface preferences can also be remembered in browser storage. These support sign-in, security and the options you choose; we do not use advertising or analytics cookies.

3. Accounts, collections and requests

We store your account ID, profile preferences, permissions, account status, saved builds and teams, collections and trackers, submitted Pokémon files or sets, trade request status, generation/download records and statistics. Collection entries you add yourself are user statements. Verified milestones use the relevant server-recorded native file or completed-trade evidence; this is not independent proof of owning a shiny on a physical console. Simulation statistics stay separate.

Staff may store support notes, account adjustments and administrative audit entries. Authorised staff can inspect the data needed to manage accounts, entitlements, trades and support. Access is restricted by the application’s admin and ticket permissions.

4. Tickets, moderation and invitations

Tickets can contain form answers, participants, ratings, timestamps and their history. Where ticket archiving is enabled, bounded exports of Haven-managed ticket channels can include messages, edits, deletion markers, files, images, audio, stickers and their metadata. We do not use this feature to archive general server channels or private direct messages. Avoid sharing unnecessary sensitive information; an attachment may contain information about other people.

Moderation records can include case details, restrictions, appeal outcomes and the role snapshot needed to restore access. Sticky-role records allow permitted roles to be restored. Invite logging keeps inviter and invited-user IDs, join times, hashed invite-code references and attribution confidence. Attribution may be uncertain; we do not treat a guessed invite source as established fact. Public server actions remain subject to Discord’s own visibility and storage.

5. Payments and other providers

Stripe processes hosted checkout and subscription management. We store the customer and subscription references, selected pack and game groups, subscription status and period, and the entitlement information needed for your account. Your Discord ID and selected pack/game metadata may be sent to Stripe to associate the purchase with your account. We do not store full payment-card numbers. Sandbox events are test events, not proof of a real payment.

Discord provides identity, messaging and attachment delivery; Stripe provides payment processing. Their own processing is explained in Discord’s Privacy Policy and Stripe’s Privacy Policy. We disclose data to authorised staff, service providers needed for the requested service, or authorities where legally required; we do not sell account data.

Some tools load images, sounds or references directly from external providers such as GitHub, PokeAPI, Discord’s CDN or Game8. Those requests can expose your IP address and request metadata to that provider. Cached illustrations are served by Haven. These legal pages use local assets and make no automatic third-party media requests. External providers may process data outside the EEA; their applicable safeguards and policies depend on the provider.

6. Purposes and legal bases

Account, requested tools, support and any purchased entitlements are processed to provide or take steps towards the service you request (GDPR Article 6(1)(b)). Security, abuse prevention, limited audit trails, moderation and invite attribution use our legitimate interests in operating a safe, reliable community (Article 6(1)(f)); we consider members’ privacy and use restricted access and limits. Statutory records and lawful authority requests use Article 6(1)(c). Where an optional feature separately requests consent, you may withdraw that consent for the future (Article 6(1)(a)).

Data needed for an account or request is required for that function. You can read public pages without signing in. You do not have to buy a pack to use the free tools.

7. Retention and deletion

The following periods are the application’s normal access and cleanup limits. Some files are pruned when the relevant store is next written or a cleanup runs, rather than at the exact expiry time. Inactive stores can physically retain expired entries longer; staff must include them when handling deletion requests.

  • Terminal trade-request records: 14 days from creation.
  • Full generation/download receipts: available for 1 day. File-history access: 180 days and at most 2,000 entries per account; expired records are pruned on a subsequent store write.
  • Closed tickets and their archived content: normally 30 days after closure. Closed Discord ticket channels are normally removed after 24 hours.
  • Released sanction cases: normally 365 days after release; administrators can select 30–730 days. Active cases remain available while needed.
  • Sticky-role records: normally 90 days; the period is configurable.
  • Accounts, workspaces, cumulative statistics, milestone evidence and invite records have no scheduled automatic expiry; they remain until the relevant data is deleted or no longer needed.
  • Operational logs rotate at 10 MiB with up to five rotated copies; this is a size limit, not a fixed time period. Backups currently have no global automatic expiry.

Ticket and community retention settings can change within the supported limits. We review deletion requests, remove data that no longer has a lawful purpose and explain any required exception, such as a statutory record or an unresolved security case. Backup copies require separate review; deleted data must not be silently reintroduced during restoration. A sign-out, account suspension or role removal is not a whole-account deletion. There is currently no automatic whole-account deletion button.

8. Security and automated moderation

We use HTTPS for the public service, restricted account/staff access, protected sessions, CSRF checks for relevant changes and private file permissions. These measures do not establish that NAS storage or backups are encrypted at rest; that protection is not yet verified. No system can promise absolute security.

Configured spam traps and milestone rules can trigger automatic bans or role changes. A server restriction can open a private appeal ticket. If you contest a decision, contact staff in that ticket or mail@pokemonhaven.xyz for human review. No decision about credit, employment or a similar life-affecting service is made by these community rules.

9. Your rights

Subject to the applicable legal conditions, you can request access, correction, erasure, restriction or portability of your personal data. You can object to processing based on legitimate interests and withdraw consent where processing relies on it. You may complain to the competent data protection supervisory authority.

Email mail@pokemonhaven.xyz with the request and the Discord user ID concerned. Do not send passwords, bot tokens or OAuth secrets. We verify identity proportionately, respond within the applicable legal deadline and explain any exception. A staff member handles the request; disabling your account is not a substitute for addressing it. You may also need to contact Discord or Stripe for data those providers control independently.

10. Policy updates

We update this page when data handling changes and give appropriate notice of material changes. The date above identifies the current version. Contact mail@pokemonhaven.xyz if a description does not match what you see in Haven.