Last updated: August 28, 2026
Apollo is operated by Apollo Calendar Engine Ltd., a corporation registered in British Columbia, Canada (“Apollo”, “we”, “us”, “our”).
This policy explains what personal information we collect when you use the Apollo Discord bot, the Apollo dashboard at app.apollo.fyi, and our websites, why we collect it, who we share it with, how long we keep it, and how you can have it deleted.
Questions or requests: support@apollo.fyi
1. Who this policy covers
This policy applies to:
- Server members who interact with Apollo in a Discord server (signing up for events, responding to reminders, being listed on an event).
- Server administrators who add Apollo to a server, configure it, and use the dashboard.
- Subscribers who purchase Apollo Premium.
- Visitors to apollo.fyi, docs.apollo.fyi, and feedback.apollo.fyi.
Apollo operates inside Discord. Discord Inc. has its own privacy policy governing your Discord account and everything you do on the platform. We are not affiliated with Discord Inc., and this policy covers only what Apollo does.
2. Our role: when we are a controller, and when we are a processor
This distinction matters for your rights, so we state it plainly.
We act as a controller for account and commercial data: your Discord user ID and username, your email address, your subscription and billing records, your support correspondence, and our product analytics. We decide why and how that data is processed.
We act as a processor for the event data inside a Discord server: events created by that server’s administrators, signups, responses, attendance, and uploaded images. The server’s administrators decide what events exist and who can see them. We process that data on their behalf in order to run the bot.
In practice this means that if you want your signups removed from a specific server’s events, the fastest route is usually the server’s administrators. You can also come to us directly and we will action it, as described in section 9.
3. What we collect
From Discord
Apollo uses the Discord API with the following gateway intents: Guilds, Guild Emojis and Stickers, and Guild Members.
We collect and store:
- Your Discord user ID and username
- Your Discord display name, so we can show a readable name on events
- Server (guild) IDs, names, channel IDs, role IDs, and message IDs for events Apollo has posted
- Server emoji and sticker data used to render event reactions
We do not collect or store message content. Apollo does not use the Message Content intent, and cannot read the messages in your server.
Avatars and some display name data are held only in a temporary in-memory cache to render events. That cache is not written to disk and is lost whenever the bot restarts.
From you
- Event data: titles, descriptions, dates and times, recurrence settings, capacity limits, and locations you enter
- Location text you type into the event location field, which is sent to Amazon Web Services for address autocomplete and geocoding
- Signups and responses: which events you signed up for, your response type, any comment you add, and (where the feature is enabled) attendance
- Images you upload to an event
- Email address, when you sign in to the dashboard or subscribe to our newsletter
- Support correspondence you send us
Automatically
- Usage events in the dashboard and on our websites, recorded through PostHog and associated with your Discord user ID
- Technical error data through Sentry, including error traces and internal identifiers such as event IDs and guild IDs
- Server logs from our hosting infrastructure
We have disabled IP address collection in both PostHog and Sentry. Our hosting providers and Cloudflare process IP addresses as a normal part of delivering traffic.
From payment providers
- Billing details from Stripe: name, email, country, subscription status, invoice history, and (for business customers) a VAT or business number where you provide one
- Legacy subscription records from Patreon, for a small number of subscribers who signed up several years ago
We never see or store your full card number. Card data goes directly to Stripe.
4. Why we process it, and our legal basis
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Running the bot: creating events, posting them, handling signups and reminders | Performance of a contract, and legitimate interests in providing the service to the server that installed Apollo |
| Dashboard login and account management | Performance of a contract |
| Taking payment, managing subscriptions, handling refunds | Performance of a contract |
| Transactional email (deletion notices, billing notices, service changes) | Performance of a contract |
| Marketing email and our newsletter | Consent, which you can withdraw at any time |
| Product analytics to understand and improve the service | Consent for non-essential cookies, and legitimate interests for aggregate product analysis |
| Error monitoring, abuse prevention, and security | Legitimate interests in keeping the service running and secure |
| Keeping financial records | Legal obligation (Canadian tax law) |
We do not sell your personal information. We do not share it for cross-context behavioural advertising. We do not use your data, or any Discord API data, to train machine learning or AI models.
5. Who we share it with
We use the following service providers. Each has access only to what it needs, and is contractually restricted to using it on our behalf.
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Discord Inc. | The platform Apollo runs on | Everything Apollo posts or reads through the API | United States |
| Amazon Web Services | Application hosting, database, file and log storage, address autocomplete | All core service data | United States (us-east-2) |
| Cloudflare | Proxy and CDN for our domains, and R2 storage for uploaded images | Traffic data, uploaded images | Global |
| DigitalOcean | Hosting for part of our API infrastructure | Service data handled by that component | United States |
| Render | Hosting for our marketing site and documentation | Website visit data | United States |
| Stripe | Payment processing and subscription billing | Name, email, country, billing details, tax identifiers | United States and global |
| Patreon | Legacy subscription billing | Name, email, subscription status | United States |
| PostHog | Product analytics | Discord user ID, usage events | United States |
| Loops | Transactional and newsletter email | Email address, name, subscription status | United States |
| Sentry | Error monitoring | Error traces, internal identifiers | United States |
| FeatureOS | Our public feedback and roadmap portal | Email address, feedback you post | United States |
| MXroute | Email hosting for our support inbox | Anything you email us | United States |
| Notion | Internal notes, including customer research interviews | Name and contact details of customers who take part in research | United States |
We may also disclose personal information where we are legally required to, or to establish or defend legal claims. If we are ever involved in a merger, acquisition, or sale of assets, personal information may transfer as part of that transaction, and we will give notice before it becomes subject to a different privacy policy.
6. International transfers
We are based in Canada and our infrastructure is primarily in the United States. If you are in the UK, the EEA, or Switzerland, your personal information is transferred outside your region. We rely on the European Commission’s adequacy decision for Canada where applicable, and on Standard Contractual Clauses with providers located in the United States.
7. Uploaded images: read this
Images uploaded to events are stored in Cloudflare R2 and served from images.apollo.fyi at a randomly generated URL.
Anyone who has the URL can view the image, including people who are not members of your Discord server. The URL is not guessable, but it is not access-controlled. Do not upload anything to an Apollo event that you would not be comfortable being seen by someone outside the server if the link were shared.
When an event is deleted, its images are deleted with it.
8. How long we keep things
| Data | Retention |
|---|---|
| Account data (Discord ID, username, email) | Until you ask us to delete it. Accounts with no activity for 24 months are purged automatically |
| Events on a paid workspace | For the life of the workspace |
| Events on a free workspace | Deleted 12 months after the event’s end date |
| Events you delete | Recoverable for 30 days, then permanently deleted |
| Signups, responses, and attendance | Deleted with the event they belong to |
| Uploaded images | Deleted with the event they belong to |
| All data for a server, after Apollo is removed | Deleted within 90 days |
| Cached avatars and display names | In memory only, discarded on restart |
| Billing and tax records | 6 years, as required by Canadian tax law |
| Product analytics (PostHog) | 12 months |
| Error data (Sentry) | 90 days |
| Application logs | 30 days |
| Newsletter and email contacts (Loops) | While you are subscribed. If you unsubscribe we keep your address on a suppression list so that we do not email you again |
| Support correspondence | 24 months |
| Database backups | Deletions take effect in our live systems within 30 days, and in backups as those backups expire on their normal rotation |
9. Your rights, and how to delete your data
Depending on where you live, you have the right to access the personal information we hold about you, to have it corrected, to have it deleted, to receive a copy of it, to object to or restrict certain processing, and to withdraw consent you have given.
Deleting a server’s data
Remove Apollo from your Discord server. We delete all data associated with that server within 90 days. If Apollo is added back before that window closes, the deletion is cancelled and the server’s events are restored.
Deleting your own data
Email support@apollo.fyi from the address on your account, or tell us your Discord username, and we will delete your personal information. We respond within 30 days.
Some data survives a deletion request:
- Billing records we are legally required to keep for 6 years
- Your email address on our email suppression list, kept so that we do not contact you again
- Events you created that other people have signed up for, which are the server’s data and are handled by the server’s administrators, though we will remove your identifying information from them
We may ask you to confirm your identity through Discord before actioning a request, so that we do not delete someone’s data at a stranger’s request.
Complaints
If you are unhappy with how we have handled your information, contact us first at support@apollo.fyi. You also have the right to complain to a supervisory authority: the Office of the Privacy Commissioner of Canada, your EU member state’s data protection authority, or the UK Information Commissioner’s Office.
10. Cookies and analytics
Our websites and dashboard use cookies for two purposes:
- Essential cookies, which keep you signed in and keep the service secure. These cannot be turned off.
- Analytics cookies, set by PostHog, which let us understand how people use Apollo so we can improve it. In the EEA and the UK we ask for your consent before setting these, and you can change your choice at any time.
We do not record your screen or session. We do not use advertising cookies or trackers.
Our feedback portal at feedback.apollo.fyi is operated by FeatureOS and sets its own cookies.
11. Security
- All traffic is encrypted in transit using TLS.
- Our database is encrypted at rest and is not reachable from the public internet.
- Access to production systems is limited to the small number of people who operate Apollo. Apollo is a small company, and in practice that means very few people have access.
- Payment card data never touches our systems.
- We monitor errors and unusual activity, and we keep our dependencies patched.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach that creates a real risk of significant harm to you, we will notify you and the relevant authorities as required by law, including the Office of the Privacy Commissioner of Canada and, where the GDPR applies, within 72 hours.
12. Children
Apollo is not intended for anyone under 13, or under the higher minimum age that applies to Discord in your country. We do not knowingly collect personal information from children below that age.
If you believe a child has provided us with personal information, email support@apollo.fyi and we will delete it.
13. Changes to this policy
We may update this policy. When we make a material change, we will update the date at the top, note the change below, and give notice by email or in the dashboard before it takes effect.
Changelog
- August 28, 2026: Complete rewrite. Added a full list of service providers, retention periods for every category of data, a clear deletion process for individual users as well as servers, disclosure of how uploaded images are accessible, our legal bases for processing, and our roles as controller and processor.
- Before August 28, 2026: Original short-form policy.
14. Contact
Apollo Calendar Engine Ltd. British Columbia, Canada support@apollo.fyi