Privacy
What Communio stores about you, why we store it, how long we keep it, and how you get it out or deleted.
Last updated 1 September 2026. Written in plain English on purpose.
Who is responsible
Communio is run by Greenbo Studios, Denmark. For everything on communio.page itself — your account, your sites, our support — we are the data controller, and you can reach us at privacy@communio.page.
There is a second case worth being clear about. When you visit a community's own website — the ones on yourserver.communio.page or on their own domain — that community decides what to collect and why. They are the controller, and we only process it for them. Our part of that arrangement is written down in the data processing terms. If you are a member of such a community and want your data gone, ask them first, and ask us if they do not answer.
What we store about site owners
- Your name, email address and — if you set one — a password. The password is never stored as you typed it, only as a PBKDF2 hash.
- Your Discord id, username and avatar, if you sign in with Discord.
- The sites you build: their name, text, images, rules, news, appearance and your server address.
- Support tickets you write to us, and the replies.
- Sign-ins: one row per browser you are signed in on, holding only a hash of the session key and when it expires. We do not log the browser, the device or the place.
The legal basis is our contract with you: without this the product cannot do what you signed up for.
What we store about members of a community site
When someone signs in on a community's site with Discord, that community becomes the controller and we store on their behalf:
- Discord id, username, display name and avatar.
- Which sites they have signed in on, and when they were last seen there.
- Their roles on that community's Discord server, when the community has connected one.
- Their profile and characters, if they fill them in: name, age, job, description and a picture.
- Applications they send — whitelist and job applications — with their answers and the decision.
- Playtime on that community's game server, matched by the Discord id or by the name the server reports.
Live player lists
Every two minutes we ask each community's game server who is online. The server answers with a player list that can contain identifiers — a Discord id, a Steam id, a FiveM licence. We keep the Discord id, and only to credit playtime to the right member. The list shown on the website is stripped down to a slot number, the in-game name and the ping. Nothing else from that answer is stored or shown.
How long we keep it
| What | How long |
|---|---|
| Your account and your sites | Until you ask us to delete them |
| Sign-ins (owners) | 30 days, then the row is gone |
| Sign-ins (members) | 60 days |
| Password reset links | 1 hour, and one use |
| Tickets used mid sign-in | 5 minutes |
| Player count history behind the graph | 7 days, deleted by the same job that writes it |
| Support tickets | Until you ask us to delete them |
Cookies
Communio sets three cookies, all of them strictly necessary to sign you in and keep you signed in. There is no advertising, no tracking and no analytics, and therefore no cookie banner to click away.
| Cookie | What it does | Lifetime |
|---|---|---|
| communio_session | Keeps a site owner signed in to the dashboard. | 30 days |
| communio_member | Keeps a member signed in to the community site they logged in on. | 60 days |
| communio_oauth | Protects a Discord sign-in from being hijacked while it is in progress. | 10 minutes |
Fonts are served from our own domain, not from Google, and no third-party script runs on the pages we build.
Who else touches the data
These are the only companies that process data on our behalf:
| Who | What for | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, file storage and outgoing email for the whole service. | EU and worldwide edge network |
| Discord Netherlands B.V. / Discord, Inc. | Sign-in with Discord, and role changes on a community's own Discord server. | EU and United States |
We sell nothing to anyone, and we hand nothing to advertisers. Transfers outside the EU rest on the European Commission's standard contractual clauses.
Your rights
Under the GDPR you can ask for a copy of what we hold, have it corrected, have it deleted, have it handed over in a machine-readable form, or object to how we use it. Write to privacy@communio.page and you get an answer within 30 days — usually the same week.
If you think we handle your data badly and we cannot sort it out between us, you can complain to Datatilsynet, the Danish data protection authority, at datatilsynet.dk.
Keeping it safe
Everything runs over HTTPS. Passwords are hashed and never stored in the clear, and the same goes for session keys and password reset links — the database holds only their hashes, so a copy of it cannot be used to get into an account. Access to the production data is limited to the people who run Communio.
If a breach happens that puts you at risk, we tell you and the authority within 72 hours of finding out.
Children
Communio is a tool for people who run game communities and is not aimed at children. If a child has signed in on a community site and a parent asks us, we delete what we hold.
Changes
When this page changes, the date at the top changes with it. If a change actually affects you — new data, a new purpose, a new processor — we tell account holders by email before it takes effect.