Rosa Wildlife Reserve
In short: We record what we need to run a moderated realism server: your Discord and Alderon identity, your characters and gameplay, your tickets, and moderation records. In-game chat and combat are logged. Moderation records are kept even if you leave, because that is the point of them. Everything else can be deleted on request.
Rosa Wildlife Reserve is a volunteer-run Path of Titans community. For the purposes of the GDPR, the Rosa staff team is the data controller for the personal data described here.
This policy covers the whole Reserve together: this website, our Discord server, our three Discord applications (Rosa Terminal, Rosa Conservatory, and Rosa Front Desk) and our Path of Titans game server. They share one database, so one policy describes all of it.
It does not cover Alderon Games, Discord or Patreon themselves. Each of them holds data about you under their own policies: Alderon Games, Discord, Patreon.
This document is version 1.16, last updated 26 August 2026.
Every message sent in a ticket channel is recorded as it is sent, including messages that are later edited or deleted. Edits keep their earlier versions. We do this so a ticket can be read back afterwards and so a dispute about what was said has an answer; a deleted message is often the one that matters.
We also record who opened the ticket, who was added to it and by whom, who claimed it, who it was passed on to, who escalated it and when, and what you filled in on the form. How you looked at the time is kept with it: your name, nickname, avatar and role color, so the transcript reads as the conversation did.
Pictures, clips, voice messages and files posted in a ticket are copied to our own storage as they arrive, even where the ticket keeps no transcript. Discord expires its links to them within about a day, and evidence that cannot be opened the next morning is not evidence. See Files you upload below.
This covers a file you linked to as well as one you uploaded, where the link points at Discord's own storage. Pasting a link to a screenshot and dragging the screenshot in are the same act to everybody reading the channel, and the link stops working just as quickly. Links to anywhere else are recorded as links and nothing is copied.
A ticket is read by staff. It can be discussed among them, recorded, and used when a decision has to be made about you or about somebody else. We do not describe a ticket as confidential, because it is not one.
A transcript can be opened by the people who were in that ticket and by staff. Being removed from a ticket removes your access to its transcript as well. Escalating a ticket brings another group of staff into it, and they can read everything already said in it.
Clips, screenshots, and other attachments sent through the bots or this website are posted to a private Discord channel that only staff can see, and we record who uploaded each one, when, and what it belongs to. We keep Discord's reference to the file rather than a copy of the link, because those links expire.
Discord hosts the file itself. Anything uploaded is therefore also covered by their privacy policy.
Pictures put on a sprout page or a character are looked at automatically before a person sees them, to catch nudity and gore. The check runs on our own server, so the picture is not sent anywhere else for it. We keep what the check reported alongside the picture, so that staff reviewing it know what was found and so we can tell afterwards why something was allowed or refused. A picture refused automatically can always be put in front of a person instead.
Our Path of Titans server reports events to us and to private staff channels in Discord. These include in-game chat, damage and kills, logins and logouts, respawns, group activity, nesting activity, quests, purchases, staff commands, and in-game player reports. They are tied to your Alderon ID and, where the server sends them, to your character name, species, growth and location.
We store these ourselves rather than leaving them in Discord, so that staff can search them by player and by date when resolving a dispute. The full message the server sent is kept alongside what we read out of it for fourteen days, and then dropped: it is the one part that is already in a staff channel word for word, and after that the only reason to hold it was to check our own reading of it. What is left, which is who and what and where and when, is kept for thirty days.
Assume that anything you type in in-game chat is recorded. This is how a realism server with permadeath and PVP can resolve disputes about what actually happened.
Some chat lines are commands rather than conversation. Typing something beginning with an exclamation mark, such as !hunger, asks the server a question and is answered in the game. For each of those we keep which command you used, when you last used it and how many times, so that a limit on how often it can be used means anything at all. That record is kept against your Alderon ID and holds no part of what you typed beyond the command itself.
We count page views so we know which parts of the site people read. We do not store your IP address. A one way hash of it, your browser string, and a salt that changes every day lets us tell two visits apart on the same day and is useless for recognizing you the next. That limit is deliberate rather than a shortcoming.
We record the page, whether somebody was signed in (not who), the rough kind of device, and the host of the site you came from if you followed a link. Never the full referring address, because the path you came from can carry your search terms.
This runs in your browser after a page has loaded. With scripts off, nothing about your visit is recorded at all.
Every action staff take through our tools is logged with who did it, what changed, and when. That log protects you as much as it protects us: it is how a disputed penalty can be traced back to a decision and a person.
Our hosting providers keep short-lived server logs that may include your IP address, used for security and to stop abuse. We do not use advertising or cross-site tracking cookies. The only cookies we set ourselves are your sign-in session and a short-lived value that protects the Patreon linking step.
We do not sell your data and we do not share it for advertising. It is processed by:
Some of these are outside the European Economic Area. Where that is the case, transfers rely on the standard contractual clauses in their own agreements.
Within Rosa, access depends on your rank. Moderation records are visible to admins; settings and the full database are limited to founders and the bot developer.
Public reports are visible to sprouts by design: that is what makes them public. Consider that before choosing between a public report and a private ticket.
If you are in the EU or UK, you have the right to:
To exercise any of these, open a ticket in our Discord server. We aim to respond within 30 days. We may ask you to confirm your identity through your linked Discord account first.
Leaving the Discord server removes you from the whitelist and marks you as no longer a sprout, but does not by itself delete your data. Ask us if that is what you want.
The Reserve is not for under-13s, and the minimum is higher where local law requires it. We do not knowingly collect data from children below that age. If you believe a child's data is in our systems, tell us and we will remove it.
Access to our database and staff tools is limited to the people who need it, and staff actions are logged. Third-party tokens are encrypted before they are stored. We are volunteers running a hobby project, not a security company: we take reasonable care, but we cannot guarantee that a breach will never happen. If one does, we will tell affected sprouts and the relevant authority where the law requires it.
We will update this policy as the Reserve grows; the bots described here are still being built. Significant changes are announced in our Discord server, and the version and date at the top of this page change with them.