Privacy Policy
1. Who we are
MilsimManager (“MilsimManager”, “we”, “us”) provides roster, rank, and operations management for gaming and milsim communities, delivered through a Discord bot and a companion web dashboard at milsimmanager.com. The service is operated by CG Systems. You can reach us about privacy at privacy@milsimmanager.com.
2. The two roles we play
How we treat data depends on whose data it is:
- For a community’s member data (the roster, ranks, billets, and activity of people in a Discord server that uses MilsimManager), the community’s administrators decide what is tracked. They are the controller; we act as a processor handling that data on their behalf to provide the service.
- For an administrator’s own account and billing data (the person who signs in and sets up a server), we are the controller.
Most of the people MilsimManager holds data about never sign in to this site and never see this page. Their unit’s administrators put them on a roster, and those administrators decide what is recorded. That is why section 3 lists the fields in full: an administrator should be able to read it and know exactly what they are enrolling their members into.
If you are a member of a community that uses MilsimManager and have questions about what is tracked, contact that community’s administrators first; you may also contact us and we will route your request.
3. What we collect
When an administrator signs in (Discord OAuth)
We use “Sign in with Discord” to identify administrators. With your permission Discord shares your user ID, username/display name, avatar, and the list of servers you belong to. We use the server list only to show you the servers you can manage; we store in your signed session your Discord user ID, name, and the subset of servers where you have “Manage Server”. The access token Discord issues is used once to read that profile and is never stored. We never see your Discord password.
What a unit records about its members
For members of a Discord server that uses MilsimManager, we hold:
- Discord user ID, username, nickname, server-membership status and roles, and a history of changes to those.
- Rank, section and billet assignment, qualifications, awards, promotion history and attendance against the unit’s events.
- Where a unit switches on the fuller service record: callsign, MOS, timezone, age, prior-service status, date of entry, date of rank, and issued equipment.
- Where a unit links game accounts: Steam ID, ArmA 3 player ID, and Reforger (Bohemia) UID.
Which of these are used is the unit’s decision, not ours. We do not read Discord message content.
Game server activity
A unit can link its game servers so that attendance is credited automatically. When it does, software on that server reports each player’s join time, leave time, in-game name and platform UID to us. That reporting covers everyone who plays on that server, including people who are not in the unit’s Discord and have never used MilsimManager. Linking a server is the administrators’ decision, and it opts their players into this. If you play on a community’s server and would rather not be recorded, raise it with that community: we hold those records on their behalf.
Support requests
If you open a support ticket we hold what you write, the ticket’s category and status, your Discord ID and name, and any screenshots you attach. Screenshots are stored in our database. Tickets handled in our own Discord support server also exist as a conversation thread there.
Surveys
A unit can run surveys through the bot. On a survey set to record who responded, the responder’s Discord ID is stored with the answers. On a survey marked anonymous, the ID is not stored with the answers; we keep only a one-way hash so the same person cannot answer twice. That hash cannot be turned back into a Discord ID, but it is not the same as keeping no record at all, so treat an anonymous survey as unattributed rather than untraceable.
Technical data
Like any web service we process limited technical data needed to run and secure the site: IP addresses and web-server request logs, which rotate on a 14-day cycle, and a single signed cookie that keeps you logged in. We use no advertising or third-party tracking cookies. Our pages load typefaces from Google Fonts, so your browser contacts Google and Google sees your IP address when a page loads. We also keep an administrative audit trail of actions taken inside a unit’s console: who did what, to whom, and when.
4. Why we use it (legal bases)
| Purpose | Basis |
|---|---|
| Provide the roster/ops service to a community | Performance of a contract / our and the community’s legitimate interests |
| Authenticate administrators | Performance of a contract |
| Credit attendance from linked game servers | The community’s legitimate interests, as decided by its administrators |
| Answer support requests | Performance of a contract / legitimate interests |
| Secure the service, prevent abuse | Legitimate interests |
| Billing (when enabled) | Performance of a contract / legal obligation |
5. Who we share it with
We do not sell personal data. We share it only with service providers needed to run MilsimManager, who process it on our instructions:
- Discord, for identity and as the platform the service runs on.
- Akamai (Linode), for server and database hosting.
- Cloudflare, for DNS and for routing mail sent to our privacy address.
- Anthropic, for the optional AI roster import only. When an administrator uses that tool, the column headers and a small sample of rows from the spreadsheet they upload are sent to Anthropic so the layout can be worked out. The rest of the spreadsheet is read on our own server and is not sent anywhere. If nobody uses the tool, nothing goes to Anthropic.
- A payment processor, when paid plans launch, for handling payments. We will not store full card details.
We may also disclose data if required by law, or to protect our rights, safety, and the integrity of the service.
6. How long we keep it
We keep a unit’s data for as long as it uses MilsimManager. When the bot is removed from a Discord server, that unit becomes dormant and its data is kept for 30 days, so a unit that comes back can pick up where it left off simply by adding the bot again.
After 30 days it is deleted: the roster, member records and service identities, game-session history, surveys, the audit trail, and that unit’s support tickets along with any screenshots attached to them.
Backups are encrypted and kept for 14 days before deletion, so data from a deleted server can survive in a backup for up to that long after it leaves the live database. Web-server request logs rotate on the same 14-day cycle. Account and billing records may be kept longer where required for legal or accounting reasons.
7. Your rights
Depending on where you live (for example under the GDPR or CCPA/CPRA), you may have the right to access, correct, delete, export, or restrict the use of your personal data, and to object to certain processing. To exercise these rights:
- Administrators can update or delete a server’s data directly in the product, or contact us.
- Community members should contact their server’s administrators, who control what is tracked; you may also contact us and we will help.
- Email privacy@milsimmanager.com for any request. Customers can also open a ticket in our Discord support server, which is usually faster, though you never have to join it to exercise a right. We do not discriminate against you for exercising these rights.
8. Data location and transfers
Our infrastructure is operated in the United States and by the providers listed above. If you access the service from another region, your data may be transferred and processed where our providers operate, with appropriate safeguards.
9. Security
We use industry-standard measures including TLS encryption in transit, restricted access to the database, and encrypted backups. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
10. Age
MilsimManager is for people aged 16 and over. We do not knowingly collect data about anyone younger, and administrators should not enter roster data for members under 16. If you believe we hold data about someone under 16, contact us and we will delete it.
Sixteen is higher than Discord’s own minimum age, and that is deliberate: a unit’s service record can include age, prior service, and a full attendance history, which is not something we want to be holding about children.
11. Changes
We may update this policy as the service evolves. We will revise the effective date above and, for material changes, provide reasonable notice.
12. Contact
Questions or requests: privacy@milsimmanager.com, or a ticket in our Discord support server.
MilsimManager is an independent product and is not affiliated with, endorsed by, or sponsored by Discord Inc.