Privacy

Privacy Policy

This policy explains what information Nexora processes, why it is needed, when it is stored and the choices available to users and server administrators.

Last updated: 13 August 2026

1. Who this policy applies to

This policy covers the Nexora Discord bot, public website and web dashboard. Nexora is operated from the United Kingdom. For questions about privacy or data rights, contact the address listed at the end of this policy.

Discord server owners and administrators also control how they choose to configure Nexora in their communities. They may have their own privacy obligations for logging, moderation, tickets or other features they enable.

2. Information Nexora processes

Depending on the features you use, Nexora may process:

  • Discord account data: user ID, username, display name, avatar and the server/permission information needed to authenticate dashboard access.
  • Server configuration: Discord server IDs, channel IDs, role IDs, feature settings, subscription state and other configuration selected by server administrators.
  • Moderation and security records: case numbers, Discord user/moderator IDs, action types, reasons, timestamps and security incident information needed to provide moderation, Anti-Raid and Anti-Nuke features.
  • Community feature data: ticket records, suggestion records and votes, giveaway state and entries, custom command/autoresponder configuration, Levels & XP profiles (Discord user IDs, display names, XP totals, XP-earning message counts and level activity timestamps), Counting state (including the last counter/breaker user IDs), Starboard source and destination message IDs, QOTD posting state/questions, timed poll questions/options/votes, invite-use and inviter/join records, temporary voice ownership/channel state, application form questions and submitted answers, role-menu configuration and selections, automation definitions and run metadata, global NexCoins balances/transfer and reward activity, activity events and similar feature data.
  • Message content when required: message content may be processed for enabled features such as AutoMod, autoresponders, message logging and ticket transcripts. Content is stored only where the relevant feature requires a stored record.
  • Support information: information you provide when contacting support, including relevant server/user IDs, screenshots or troubleshooting details.
  • Billing information: for paid plans, Nexora stores Stripe customer/subscription/Price identifiers, provider status, billing-period dates, verification timestamps and the purchasing Discord user ID needed to map a subscription to one Discord server. Card numbers, CVV/security codes and other raw card credentials are collected by Stripe's hosted payment pages rather than stored by Nexora.

3. Why Nexora uses this information

  • to authenticate users and show servers they are allowed to manage;
  • to save and apply server configuration;
  • to perform moderation, security, ticket and automation features;
  • to maintain case history, activity history and auditability;
  • to prevent abuse, investigate incidents and protect the service;
  • to operate subscriptions and enforce server-plan entitlements;
  • to provide support and troubleshoot faults;
  • to comply with legal obligations where applicable.

4. Lawful bases

Where UK data-protection law applies, the lawful basis depends on the purpose. Nexora may rely on performance of a contract where processing is necessary to provide a requested service, legitimate interests for service security, reliability and abuse prevention, legal obligations where processing is required by law, and consent where the law requires consent for a particular activity.

A server administrator's decision to enable a feature does not replace any consent or other lawful basis that administrator may independently need for their own community.

5. Discord and third-party services

Nexora relies on Discord's APIs and OAuth authentication. Information sent to or received from Discord is also subject to Discord's own terms and privacy practices.

Nexora may also use infrastructure providers needed to operate the service, including database hosting such as MongoDB Atlas, website/bot hosting, monitoring or email providers, and Stripe for paid subscription checkout, invoicing and customer billing management. Providers receive only the information reasonably necessary for their role and are expected to protect it appropriately.

6. When information may be shared

Nexora does not sell personal information to advertisers.

Information may be disclosed:

  • to service providers acting on Nexora's behalf;
  • to the relevant Discord server and its authorised staff where a feature is designed to show them that information;
  • where reasonably necessary to investigate abuse, protect users or infrastructure, or enforce the Terms;
  • where disclosure is required by law or valid legal process;
  • as part of a business reorganisation, acquisition or transfer, with appropriate protections where required.

7. Retention

Nexora keeps information only for as long as it is reasonably needed for the feature, security, support, billing, dispute or legal purpose for which it was collected. Different categories therefore have different retention criteria.

  • Guild configuration is generally retained while Nexora is configured for that server and may be retained for a reasonable period after the bot leaves to support reactivation, safety or support needs.
  • Moderation, security, ticket, suggestion, giveaway, Levels & XP, Fun & Engagement, polls, invite tracking, applications, role menus, automations, temporary voice metadata, global economy and activity records may be retained to provide history, progression and auditability. Dashboard display limits do not necessarily represent deletion dates.
  • Premium ticket transcript text is stored only where that transcript feature is used and is subject to size/sanitisation limits.
  • Data may be retained longer where reasonably necessary to establish, exercise or defend legal claims, investigate abuse or meet a legal obligation.

8. Security

Nexora uses reasonable technical and organisational safeguards, including permission checks for dashboard actions, rate limits and access controls. No internet service can promise absolute security.

9. International processing

Discord and some infrastructure providers may process information in countries outside the United Kingdom. Where data-protection law requires safeguards for an international transfer, Nexora will use an applicable legal transfer mechanism or rely on another permitted basis.

10. Your data-protection rights

Depending on where you live, the law and the lawful basis used, you may have rights including access, correction, deletion, restriction, objection and data portability. You may also have the right to complain to a data-protection regulator.

Some records may be controlled or primarily visible to the Discord server that configured Nexora. We may need the relevant Discord user ID and server ID to locate a record and verify the request without asking for unnecessary personal information.

11. Younger users

Nexora is intended for people who are permitted to use Discord under Discord's requirements and applicable local law. If we learn that personal information was collected in circumstances where it should not have been, we will take appropriate steps to address it.

12. Changes to this policy

We may update this policy when Nexora's features, providers or legal obligations change. The latest revision date appears at the top of this page. Material changes may also be communicated through the website, dashboard or Discord where appropriate.

13. Privacy contact

Privacy questions and data-rights requests can be sent to [email protected]. Please include only the information needed to identify the relevant Nexora/Discord records.