Skip to content

Privacy Policy

Last updated: 24 July 2026

1. Controller and contact

The controller within the meaning of Art. 4(7) GDPR for the operation of Noxa — consisting of the web dashboard, the API and the Discord bot — is noxa-bot.org – Jan Eder, c/o Online-Impressum #9754, Europaring 90, 53757 Sankt Augustin. For any privacy question and to exercise your rights as a data subject, contact us at noxa-bot.org@mail.online-impressum.de. We answer requests within the statutory period of one month (Art. 12(3) GDPR).

2. Two roles — and why that matters to you

Noxa processes personal data in two roles that must be kept strictly apart in law. Which one applies to you depends on how you come into contact with Noxa, and it determines who you address your rights to:

  • As a dashboard user (you sign in, manage a server, or were invited to a team), we are the controller towards you. This policy applies directly, and you contact us.
  • As a member of a Discord server that has Noxa installed (you receive a warning, open a ticket, vote in a poll), we process your data solely on behalf of, and on the instructions of, that server operator. The controller is then the server operator, not us — we are their processor under Art. 28 GDPR. In that case, address your requests to the operator of the server in question first; we support them and forward without delay any request that reaches us.
  • The contract governing this processing is public and is entered into with every server operator: see our Data Processing Agreement (DPA).

3. Signing in with Discord (OAuth2)

Signing in to the dashboard happens exclusively through Discord OAuth2 using PKCE — there is no separate Noxa password, and we never receive your Discord password. Discord passes us your Discord user ID, username, display name and avatar, and with the "identify guilds" scope the list of servers you are a member of — the latter solely so we can show you which servers you can manage. For the public appeal page (section 11) we use a deliberately narrower scope ("identify") that gives us no access to your server list. Access and refresh tokens issued by Discord are stored encrypted with AES-256-GCM only, and are never returned in API responses. From that list we store the server id, name and icon of every server you are allowed to manage — including servers Noxa is not installed on. That is the only way the “My servers” overview can offer to add Noxa there. Servers Noxa was never installed on are deleted automatically once nobody entitled to manage them has signed in for 90 days. The legal basis is Art. 6(1)(b) GDPR (performance of the usage contract).

4. Sessions and cookies

After you sign in we set cookies to recognise you as signed in and to protect form submissions against cross-site request forgery. Every cookie we use is technically necessary to operate the dashboard; none serves analytics, tracking or advertising. Consent under § 25(1) TTDSG is therefore not required (exemption under § 25(2)(2) TTDSG), and for the same reason we show you no cookie banner. The full list is in section 27. We additionally store your IP address and browser identifier with each session so that abusive sign-ins can be detected (Art. 6(1)(f) GDPR, legitimate interest in account security).

5. Your Discord server data (processing on your behalf)

When you add Noxa to a Discord server, we process data about that server members for the features you enable. We do so exclusively on your instructions, which you give through the dashboard configuration — we do not analyse this data for our own purposes, do not pass it on, and do not use it for profiling. Sections 6 to 18 describe each of these processing activities. As the server operator you are the controller for them; in particular, you must inform your server members about the features you have enabled. The legal basis towards members is usually your legitimate interest in organising and moderating your server (Art. 6(1)(f) GDPR).

6. Moderation

For warnings, timeouts, kicks, bans and internal notes we store the Discord user ID and username of the person concerned and of the acting team member, the time, the type of measure, and the stated reason. Free-text fields — reasons and notes — are stored encrypted with AES-256-GCM using a separate key per server, so they are not held in the database in plain text. Access is limited to those holding the corresponding permission for that server in the dashboard. Retention: three years from creation of the case (see section 24).

7. Automatic moderation (AutoMod)

AutoMod rules check messages in real time for patterns such as excessive repetition, mention floods or unwanted links. This check happens transiently in memory: the content of the checked message is never stored. What is stored permanently is only the rule configuration you chose and — if a rule triggers a measure — the resulting moderation case described in section 6.

8. Bot trap and automated decisions

If you enable the bot trap, a channel is set up as bait: anyone posting there is banned automatically and their messages are removed across the server. This is aimed at compromised accounts that spread advertising automatically. The content of the triggering message is not stored — the fact that anything was posted at all is enough for the decision. This decision is made without human involvement. In our assessment, exclusion from a Discord server produces no legal effect within the meaning of Art. 22(1) GDPR; independently of that, we have provided for human review: those affected are informed by direct message about the reason and the procedure before the ban, the appeal route (section 11) is active by default, and a human decides on the appeal. Other bots, webhooks, the server owner and roles exempted by the operator do not trigger the trap. Server operators can disable the appeal route — we expressly advise against it, because it removes the human review.

9. Support tickets

When a member opens a ticket we store their Discord user ID, the course of the conversation, attached images and the processing status. Message contents are stored encrypted with AES-256-GCM (separate key per server). Internal team notes are never visible to the ticket author and are filtered out of any transcript before it is generated. Access is limited to those holding the permission for the server concerned and — where the operator has set up ticket groups — for the group concerned. Retention: 90 days from closing the ticket.

10. Verification of new members

To guard against automated sign-ups, the server operator can require captcha verification. We process the Discord user ID, the generated check code, the number of attempts and a hashed form of the IP address — the IP address itself is not stored in plain text. Retention: 30 days after the session expires.

11. Public ban appeals

Anyone banned from a server can submit an appeal through a public page. This route exists because Discord technically refuses every direct message to a banned member — without it there would be no way to be heard. You sign in for this using Discord OAuth with the narrow "identify" scope; we compare your Discord ID with that of the banned account and, if they match, create a separate session limited to that single case (cookie noxa_appeal_session, valid for one hour). That session grants no access to the dashboard or to other servers. Your appeal text and the subsequent correspondence are stored encrypted and shown only to the moderation team of the server concerned. If your appeal is accepted, a single-use invite link may be shown to you.

12. Browser notifications about your appeal (optional)

Because Discord does not deliver messages to banned members, you can optionally have your browser notify you on the appeal page as soon as the team replies. This happens only if you actively enable it and confirm your browser prompt — the legal basis is your consent under Art. 6(1)(a) GDPR. We store the push address generated by your browser and the associated keys; that address identifies your device. Delivery runs through your browser vendor push service (such as Google, Mozilla, Apple or Microsoft), which generally operates servers in the USA. The notification deliberately contains no content of your appeal or the reply, only a note that there is something new plus a link — because notifications also appear on locked screens. You can withdraw your consent at any time with effect for the future, via "Disable" on the appeal page or in your browser settings; the stored address is then deleted immediately. If you enable nothing, nothing happens — the page simply refreshes itself while you keep it open.

13. Polls

For polls we store, for each vote cast, the Discord user ID of the voter, the option chosen and the time. This is technically necessary to prevent multiple voting and to allow a vote to be changed. A poll is therefore not anonymous towards the server moderation team. We expressly point out to server operators: polls on health, political opinion, religious belief, trade union membership, ethnic origin or sexual orientation capture special categories of personal data under Art. 9 GDPR and are unlawful without the explicit consent of participants. Votes are deleted together with the poll.

14. Giveaways

When a member enters a giveaway we store their Discord user ID, the time of entry, the entry status and the number of tickets they hold, including the roles that grant bonus tickets. After the draw we additionally store who won, and log draws and re-draws so they remain verifiable. Winners are notified by direct message where Discord permits it. The data is deleted together with the giveaway.

15. Automations

Automations run sequences defined by the server operator — for example assigning a role when a member joins. In doing so we process the Discord user ID of the triggering person and the details needed to evaluate the conditions (such as existing roles), and we log each run for traceability and troubleshooting. No assessment of individuals and no profiling takes place; the rules come entirely from the server operator.

16. Temporary voice channels

Members can create their own voice channel through a hub channel. We store the Discord user ID of the owner, the channel name they chose, the size limit, the lock status and the user IDs of those admitted by password. Conversation content is never processed: Noxa does not join the voice channel and holds no permission to listen in or record. A room password is not stored; it is kept only as a scrypt hash with a random salt and compared in constant time. The record ends with the channel; the password hash and the admission list are deleted immediately when the channel is unlocked.

17. Stream notifications

If a server operator adds a Twitch or YouTube channel to be watched, we retrieve only information the platforms publish openly: channel identifier, display name, title and category of the running stream, viewer count and live status. The operator can optionally store a Discord user ID so the announcement mentions the associated member. There is no access to the watched person account, no sign-in on their behalf, and no evaluation of their behaviour beyond the individual announcement. The data is deleted as soon as the operator removes the entry.

18. Statistics

The dashboard shows how a server develops over time — such as member count, ticket volume and moderation cases. These evaluations rest exclusively on daily totals per server. A member-level behavioural profile — who writes how much, or how long they spend in voice channels — is neither created nor stored.

19. Team access

Server operators can grant other Discord users access to specific areas of the dashboard without having to give them administrator rights on Discord. For this we store the Discord user ID of the invited person, who invited them and which areas are enabled. Further account data only comes into being once that person signs in themselves. The operator can withdraw access at any time.

20. Payments via Lemon Squeezy

The paid Pro plan is sold through Lemon Squeezy. Lemon Squeezy acts as the seller in its own name (merchant of record): the payment transaction is concluded between you and Lemon Squeezy, and Lemon Squeezy handles billing, VAT and invoicing. For that processing Lemon Squeezy is a controller in its own right; their privacy policy applies (lemonsqueezy.com/privacy). We never receive or store your payment details — card or account data. From Lemon Squeezy we receive only a customer and subscription identifier, the billing interval chosen, the payment status and the next renewal date, in order to unlock and later withdraw Pro access for the relevant server. The legal basis is Art. 6(1)(b) GDPR. Lemon Squeezy is based in the USA (see section 23).

21. Logging, troubleshooting and operational monitoring

To run the service safely we log technical events: error messages including stack traces, access to security-relevant functions, and operational metrics of our servers. Our logging system strips known secret fields such as tokens and keys before output, and content from tickets, appeals or direct messages does not flow into logs. The monitoring system itself is reachable only internally and is not accessible over the internet. Access to these internal tools is logged with time, acting person and IP address. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning service). Retention: 90 days.

22. Recipients and processors

We pass on personal data only where operationally necessary. Beyond the following parties there is no disclosure; in particular we do not sell data, run no advertising networks, and use no external analytics or tracking services:

  • Hetzner Online GmbH, Germany — operation of the servers and the database. Processor under Art. 28 GDPR. All application data is stored exclusively in Germany.
  • Discord Inc., USA — the platform the bot runs on. This transfer is technically unavoidable and not ours to choose: every bot function goes through the Discord API. Discord is itself the controller for the platform towards you.
  • Lemon Squeezy, USA — handling payments as seller in its own name, as its own controller (section 20).
  • Browser vendor push services (Google, Mozilla, Apple, Microsoft) — solely as the delivery path for the optional notifications in section 12, and only if you enabled them.
  • Twitch (Amazon) and YouTube (Google) — only when retrieving public streaming data under section 17. No data about our users is transmitted in the process.

23. Transfers to third countries

Discord, Lemon Squeezy, the push services, Twitch and YouTube are based, or have their parent company, in the USA. For transfers there these providers rely, by their own account, on the European Commission adequacy decision for the EU-US Data Privacy Framework or on standard contractual clauses under Art. 46(2)(c) GDPR. You can check any provider current certification status yourself at dataprivacyframework.gov. We state openly that the transfer to Discord cannot be avoided as long as Noxa runs as a Discord bot — it is inseparable from using Discord itself and would take place without Noxa too.

24. Retention periods

We delete personal data automatically after the following periods. Deletion runs as a daily background process and requires no request from you:

Type of dataPeriodStarting point
Sessions and refresh tokens30 daysExpiry or revocation
Audit log12 monthsCreation of the entry
Tickets including messages and transcript90 daysClosing of the ticket
Moderation cases including appeals3 yearsCreation of the case
Verification sessions30 daysExpiry of the session
Error and technical logs90 daysCreation of the entry
Polls, giveaways, voice channelswith the item itselfDeletion by the operator
All data of a server30 daysRemoval of the bot from the server
Servers without an installation (picker only)90 dayslast sign-in of someone entitled to manage them
Database backups30 daysCreation of the backup

25. Your rights

Towards the respective controller (see section 2) you have the following rights: access to the data processed (Art. 15 GDPR), rectification of inaccurate data (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on a legitimate interest (Art. 21). Where processing rests on your consent, you may withdraw it at any time with effect for the future, without affecting the lawfulness of processing carried out until then. As a dashboard user you can trigger a full export of your data and the deletion of your account yourself, at any time and without asking us, under "Account → Your data". For anything else, contact noxa-bot.org@mail.online-impressum.de.

26. Right to lodge a complaint

Independently of the above, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. The authority responsible for us is das Bayerische Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach.

27. Audience measurement (cookieless)

On the public pages (landing, feature, pricing and documentation pages) we measure page views with a self-operated, cookieless method — no third party involved, and nothing accessed on or stored in your device (§ 25 TTDSG is therefore not triggered). What is recorded: the page viewed, the language, the domain of the referring site (never the full address), any campaign parameters from the link you clicked (utm_source, utm_medium, utm_campaign), the browser family and the device class. Your IP address is not stored; together with a value that changes daily it feeds into a hash that groups views by the same visitor only within one calendar day and can neither be chained across days nor traced back to a person. If your browser signals "Do Not Track" or "Global Privacy Control", we do not measure the visit at all. The data is deleted automatically after 90 days. The legal basis is our legitimate interest in data-minimal audience measurement of our own pages (Art. 6(1)(f) GDPR). The signed-in dashboard area is not measured.

28. Cookies at a glance

Noxa uses strictly necessary cookies only — no tracking, advertising or analytics cookies (§ 25(2)(2) TTDSG):

CookiePurposeLifetimeAccess
noxa_sessionRecognises your signed-in dashboard session8 hoursServer only (httpOnly)
noxa_refreshExtends the session without signing in again30 daysServer only (httpOnly)
noxa_csrfProtection against cross-site request forgery8 hoursReadable by the page
noxa_appeal_sessionSession for an ongoing ban appeal1 hourServer only (httpOnly)
noxa_appeal_csrfCross-site request forgery protection for appeals1 hourReadable by the page
noxa_localeRemembers your language choice1 yearReadable by the page

29. Data security

We protect your data with technical and organisational measures under Art. 32 GDPR. These include in particular: TLS encryption of all connections; field-level AES-256-GCM encryption for ticket and appeal content, moderation reasons and stored OAuth tokens, each with a separate key per server; session tokens and room passwords stored only as hashes, never in plain text; server-side permission checks on every single request rather than merely hiding things in the interface; a fine-grained role and permission system; signature verification of incoming webhooks; and operational monitoring reachable only internally. The measures in use are listed in full as an annex to the Data Processing Agreement.

30. Changes to this policy

We update this policy when we change features or when the legal situation changes. We add new processing activities here before putting them into service, not afterwards. The version published on this page, bearing the date given above, is the authoritative one.