Privacy Policy
Last updated: 24 July 2026
1. Controller and contact
The controller within the meaning of Art. 4(7) GDPR for the operation of Noxa — consisting of the web dashboard, the API and the Discord bot — is noxa-bot.org – Jan Eder, c/o Online-Impressum #9754, Europaring 90, 53757 Sankt Augustin. For any privacy question and to exercise your rights as a data subject, contact us at noxa-bot.org@mail.online-impressum.de. We answer requests within the statutory period of one month (Art. 12(3) GDPR).
2. Two roles — and why that matters to you
Noxa processes personal data in two roles that must be kept strictly apart in law. Which one applies to you depends on how you come into contact with Noxa, and it determines who you address your rights to:
- As a dashboard user (you sign in, manage a server, or were invited to a team), we are the controller towards you. This policy applies directly, and you contact us.
- As a member of a Discord server that has Noxa installed (you receive a warning, open a ticket, vote in a poll), we process your data solely on behalf of, and on the instructions of, that server operator. The controller is then the server operator, not us — we are their processor under Art. 28 GDPR. In that case, address your requests to the operator of the server in question first; we support them and forward without delay any request that reaches us.
- The contract governing this processing is public and is entered into with every server operator: see our Data Processing Agreement (DPA).
3. Signing in with Discord (OAuth2)
Signing in to the dashboard happens exclusively through Discord OAuth2 using PKCE — there is no separate Noxa password, and we never receive your Discord password. Discord passes us your Discord user ID, username, display name and avatar, and with the "identify guilds" scope the list of servers you are a member of — the latter solely so we can show you which servers you can manage. For the public appeal page (section 11) we use a deliberately narrower scope ("identify") that gives us no access to your server list. Access and refresh tokens issued by Discord are stored encrypted with AES-256-GCM only, and are never returned in API responses. From that list we store the server id, name and icon of every server you are allowed to manage — including servers Noxa is not installed on. That is the only way the “My servers” overview can offer to add Noxa there. Servers Noxa was never installed on are deleted automatically once nobody entitled to manage them has signed in for 90 days. The legal basis is Art. 6(1)(b) GDPR (performance of the usage contract).
5. Your Discord server data (processing on your behalf)
When you add Noxa to a Discord server, we process data about that server members for the features you enable. We do so exclusively on your instructions, which you give through the dashboard configuration — we do not analyse this data for our own purposes, do not pass it on, and do not use it for profiling. Sections 6 to 18 describe each of these processing activities. As the server operator you are the controller for them; in particular, you must inform your server members about the features you have enabled. The legal basis towards members is usually your legitimate interest in organising and moderating your server (Art. 6(1)(f) GDPR).
6. Moderation
For warnings, timeouts, kicks, bans and internal notes we store the Discord user ID and username of the person concerned and of the acting team member, the time, the type of measure, and the stated reason. Free-text fields — reasons and notes — are stored encrypted with AES-256-GCM using a separate key per server, so they are not held in the database in plain text. Access is limited to those holding the corresponding permission for that server in the dashboard. Retention: three years from creation of the case (see section 24).
7. Automatic moderation (AutoMod)
AutoMod rules check messages in real time for patterns such as excessive repetition, mention floods or unwanted links. This check happens transiently in memory: the content of the checked message is never stored. What is stored permanently is only the rule configuration you chose and — if a rule triggers a measure — the resulting moderation case described in section 6.
8. Bot trap and automated decisions
If you enable the bot trap, a channel is set up as bait: anyone posting there is banned automatically and their messages are removed across the server. This is aimed at compromised accounts that spread advertising automatically. The content of the triggering message is not stored — the fact that anything was posted at all is enough for the decision. This decision is made without human involvement. In our assessment, exclusion from a Discord server produces no legal effect within the meaning of Art. 22(1) GDPR; independently of that, we have provided for human review: those affected are informed by direct message about the reason and the procedure before the ban, the appeal route (section 11) is active by default, and a human decides on the appeal. Other bots, webhooks, the server owner and roles exempted by the operator do not trigger the trap. Server operators can disable the appeal route — we expressly advise against it, because it removes the human review.
9. Support tickets
When a member opens a ticket we store their Discord user ID, the course of the conversation, attached images and the processing status. Message contents are stored encrypted with AES-256-GCM (separate key per server). Internal team notes are never visible to the ticket author and are filtered out of any transcript before it is generated. Access is limited to those holding the permission for the server concerned and — where the operator has set up ticket groups — for the group concerned. Retention: 90 days from closing the ticket.
10. Verification of new members
To guard against automated sign-ups, the server operator can require captcha verification. We process the Discord user ID, the generated check code, the number of attempts and a hashed form of the IP address — the IP address itself is not stored in plain text. Retention: 30 days after the session expires.
11. Public ban appeals
Anyone banned from a server can submit an appeal through a public page. This route exists because Discord technically refuses every direct message to a banned member — without it there would be no way to be heard. You sign in for this using Discord OAuth with the narrow "identify" scope; we compare your Discord ID with that of the banned account and, if they match, create a separate session limited to that single case (cookie noxa_appeal_session, valid for one hour). That session grants no access to the dashboard or to other servers. Your appeal text and the subsequent correspondence are stored encrypted and shown only to the moderation team of the server concerned. If your appeal is accepted, a single-use invite link may be shown to you.
12. Browser notifications about your appeal (optional)
Because Discord does not deliver messages to banned members, you can optionally have your browser notify you on the appeal page as soon as the team replies. This happens only if you actively enable it and confirm your browser prompt — the legal basis is your consent under Art. 6(1)(a) GDPR. We store the push address generated by your browser and the associated keys; that address identifies your device. Delivery runs through your browser vendor push service (such as Google, Mozilla, Apple or Microsoft), which generally operates servers in the USA. The notification deliberately contains no content of your appeal or the reply, only a note that there is something new plus a link — because notifications also appear on locked screens. You can withdraw your consent at any time with effect for the future, via "Disable" on the appeal page or in your browser settings; the stored address is then deleted immediately. If you enable nothing, nothing happens — the page simply refreshes itself while you keep it open.
13. Polls
For polls we store, for each vote cast, the Discord user ID of the voter, the option chosen and the time. This is technically necessary to prevent multiple voting and to allow a vote to be changed. A poll is therefore not anonymous towards the server moderation team. We expressly point out to server operators: polls on health, political opinion, religious belief, trade union membership, ethnic origin or sexual orientation capture special categories of personal data under Art. 9 GDPR and are unlawful without the explicit consent of participants. Votes are deleted together with the poll.
14. Giveaways
When a member enters a giveaway we store their Discord user ID, the time of entry, the entry status and the number of tickets they hold, including the roles that grant bonus tickets. After the draw we additionally store who won, and log draws and re-draws so they remain verifiable. Winners are notified by direct message where Discord permits it. The data is deleted together with the giveaway.
15. Automations
Automations run sequences defined by the server operator — for example assigning a role when a member joins. In doing so we process the Discord user ID of the triggering person and the details needed to evaluate the conditions (such as existing roles), and we log each run for traceability and troubleshooting. No assessment of individuals and no profiling takes place; the rules come entirely from the server operator.
16. Temporary voice channels
Members can create their own voice channel through a hub channel. We store the Discord user ID of the owner, the channel name they chose, the size limit, the lock status and the user IDs of those admitted by password. Conversation content is never processed: Noxa does not join the voice channel and holds no permission to listen in or record. A room password is not stored; it is kept only as a scrypt hash with a random salt and compared in constant time. The record ends with the channel; the password hash and the admission list are deleted immediately when the channel is unlocked.
17. Stream notifications
If a server operator adds a Twitch or YouTube channel to be watched, we retrieve only information the platforms publish openly: channel identifier, display name, title and category of the running stream, viewer count and live status. The operator can optionally store a Discord user ID so the announcement mentions the associated member. There is no access to the watched person account, no sign-in on their behalf, and no evaluation of their behaviour beyond the individual announcement. The data is deleted as soon as the operator removes the entry.
18. Statistics
The dashboard shows how a server develops over time — such as member count, ticket volume and moderation cases. These evaluations rest exclusively on daily totals per server. A member-level behavioural profile — who writes how much, or how long they spend in voice channels — is neither created nor stored.
19. Team access
Server operators can grant other Discord users access to specific areas of the dashboard without having to give them administrator rights on Discord. For this we store the Discord user ID of the invited person, who invited them and which areas are enabled. Further account data only comes into being once that person signs in themselves. The operator can withdraw access at any time.
20. Payments via Lemon Squeezy
The paid Pro plan is sold through Lemon Squeezy. Lemon Squeezy acts as the seller in its own name (merchant of record): the payment transaction is concluded between you and Lemon Squeezy, and Lemon Squeezy handles billing, VAT and invoicing. For that processing Lemon Squeezy is a controller in its own right; their privacy policy applies (lemonsqueezy.com/privacy). We never receive or store your payment details — card or account data. From Lemon Squeezy we receive only a customer and subscription identifier, the billing interval chosen, the payment status and the next renewal date, in order to unlock and later withdraw Pro access for the relevant server. The legal basis is Art. 6(1)(b) GDPR. Lemon Squeezy is based in the USA (see section 23).
21. Logging, troubleshooting and operational monitoring
To run the service safely we log technical events: error messages including stack traces, access to security-relevant functions, and operational metrics of our servers. Our logging system strips known secret fields such as tokens and keys before output, and content from tickets, appeals or direct messages does not flow into logs. The monitoring system itself is reachable only internally and is not accessible over the internet. Access to these internal tools is logged with time, acting person and IP address. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning service). Retention: 90 days.
22. Recipients and processors
We pass on personal data only where operationally necessary. Beyond the following parties there is no disclosure; in particular we do not sell data, run no advertising networks, and use no external analytics or tracking services:
- Hetzner Online GmbH, Germany — operation of the servers and the database. Processor under Art. 28 GDPR. All application data is stored exclusively in Germany.
- Discord Inc., USA — the platform the bot runs on. This transfer is technically unavoidable and not ours to choose: every bot function goes through the Discord API. Discord is itself the controller for the platform towards you.
- Lemon Squeezy, USA — handling payments as seller in its own name, as its own controller (section 20).
- Browser vendor push services (Google, Mozilla, Apple, Microsoft) — solely as the delivery path for the optional notifications in section 12, and only if you enabled them.
- Twitch (Amazon) and YouTube (Google) — only when retrieving public streaming data under section 17. No data about our users is transmitted in the process.
23. Transfers to third countries
Discord, Lemon Squeezy, the push services, Twitch and YouTube are based, or have their parent company, in the USA. For transfers there these providers rely, by their own account, on the European Commission adequacy decision for the EU-US Data Privacy Framework or on standard contractual clauses under Art. 46(2)(c) GDPR. You can check any provider current certification status yourself at dataprivacyframework.gov. We state openly that the transfer to Discord cannot be avoided as long as Noxa runs as a Discord bot — it is inseparable from using Discord itself and would take place without Noxa too.
24. Retention periods
We delete personal data automatically after the following periods. Deletion runs as a daily background process and requires no request from you:
| Type of data | Period | Starting point |
|---|---|---|
| Sessions and refresh tokens | 30 days | Expiry or revocation |
| Audit log | 12 months | Creation of the entry |
| Tickets including messages and transcript | 90 days | Closing of the ticket |
| Moderation cases including appeals | 3 years | Creation of the case |
| Verification sessions | 30 days | Expiry of the session |
| Error and technical logs | 90 days | Creation of the entry |
| Polls, giveaways, voice channels | with the item itself | Deletion by the operator |
| All data of a server | 30 days | Removal of the bot from the server |
| Servers without an installation (picker only) | 90 days | last sign-in of someone entitled to manage them |
| Database backups | 30 days | Creation of the backup |
25. Your rights
Towards the respective controller (see section 2) you have the following rights: access to the data processed (Art. 15 GDPR), rectification of inaccurate data (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on a legitimate interest (Art. 21). Where processing rests on your consent, you may withdraw it at any time with effect for the future, without affecting the lawfulness of processing carried out until then. As a dashboard user you can trigger a full export of your data and the deletion of your account yourself, at any time and without asking us, under "Account → Your data". For anything else, contact noxa-bot.org@mail.online-impressum.de.
26. Right to lodge a complaint
Independently of the above, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. The authority responsible for us is das Bayerische Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach.
29. Data security
We protect your data with technical and organisational measures under Art. 32 GDPR. These include in particular: TLS encryption of all connections; field-level AES-256-GCM encryption for ticket and appeal content, moderation reasons and stored OAuth tokens, each with a separate key per server; session tokens and room passwords stored only as hashes, never in plain text; server-side permission checks on every single request rather than merely hiding things in the interface; a fine-grained role and permission system; signature verification of incoming webhooks; and operational monitoring reachable only internally. The measures in use are listed in full as an annex to the Data Processing Agreement.
30. Changes to this policy
We update this policy when we change features or when the legal situation changes. We add new processing activities here before putting them into service, not afterwards. The version published on this page, bearing the date given above, is the authoritative one.