Privacy Policy
This is a courtesy translation. The German version of this Privacy Policy is the legally binding one. Last updated: September 3, 2026
1. General Information & Controller
The operators of this Discord bot take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations (GDPR, BDSG) and this privacy policy.
The controller responsible for data processing via this Discord bot is:
Andreas Lindner
Holunderweg 4
89182 Bernstadt, Germanyinfo@trynexus.de
2. Purpose and Legal Basis of Processing
We operate the bot "Nexus" via the official interface (API) of the Discord platform. Processing of data is required to provide the functions activated by server administrators (moderation, leveling system, virtual points, reaction roles, embed configurations).
Provision of bot functions: Processing of server settings, user IDs and level standings is based on Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures) for users who actively use these functions, as well as on our legitimate interest (Art. 6(1)(f) GDPR) in a functional and secure bot operation.
3. Categories of Data Processed, in Detail
Data category | Purpose | Storage location / duration | Deletion |
|---|---|---|---|
Discord user ID | Technical assignment of actions to a user (e.g. level, warnings). | MariaDB, per server | On leaving/kick/ban from the server, or on request (exception: warnings). |
Discord guild ID | Assignment of all settings and data to a Discord server. | MariaDB, permanent | 7 days after the bot is removed, automated. |
XP and level standing | Provision of the leveling/rank system | MariaDB, per server | On leaving/kick/ban; on request via the delete function |
Warnings | Moderation purposes / traceability of violations for server moderators | MariaDB, per server | On leaving/kick/ban; NOT via the user delete function (see explanation below) |
Server configuration (channel IDs, color, language, enabled modules) | Functionality and personalization of the bot on the respective server | MariaDB, per server | 7 days after the bot is removed from the server, or on manual reset |
AutoMod configuration (e.g. blocked keywords) | Provision of the automatic moderation feature (technically via Discord's native AutoMod interface) | Discord's own infrastructure & reference in MariaDB | Upon deletion/deactivation of the respective rule |
Content of saved embeds (e.g. rule texts) | Allows admins to store reusable or scheduled messages | MariaDB, per server, limited quantity (Free/Premium limit) | Deletable manually by server admins; otherwise automatically 7 days after the bot is removed |
Welcome messages | Storage of custom greeting texts for automatic posting when a member joins the server | MariaDB, per server, limited quantity (Free/Premium limit) | Deletable manually by server admins; otherwise automatically 7 days after the bot is removed |
Dashboard session & profile (user ID, name, avatar) | Authentication and provision of the management interface in the web dashboard. | MariaDB, session-based | On logout or automatically upon expiry. |
OAuth2 tokens (access & refresh tokens) | Authorization of API requests to Discord to look up servers you manage in the dashboard. | MariaDB, session-based | On logout or automatically upon session expiry. |
4. What Nexus Explicitly Does NOT Store
Not stored | Explanation |
|---|---|
Content of regular chat messages | Nexus only reads messages transiently for evaluation (e.g. XP awarding, AutoMod checks via the Discord interface) and does not permanently store the message text |
Voice data / voice chat content | The bot does not process voice communication. |
Payment data (credit card, IBAN, etc.) | Payments for Premium run exclusively through Discord's own payment system; Nexus itself never receives or stores payment data. |
IP addresses of Discord users | Nexus communicates exclusively via the official Discord API and never receives end users' IP addresses. |
5. Special Case: Warnings (Moderation Data)
⚠️ Important exception for warnings: Warnings are deliberately excluded from the general user delete function. Server moderators need this history to identify repeat offenders. Deletion here is only possible manually, via server admins.
6. Automated Deletion Routines
If a user leaves a server (or is kicked/banned), that user's level and warning data for that server is automatically deleted.
If the bot is removed from a server, all server-related data (settings, levels, warnings, reaction roles) is fully and automatically deleted after 7 days, unless the bot is re-added.
If the bot rejoins the same server within these 7 days, the administrator can choose to restore the existing configuration or start fresh.
7. Users' Rights to Access and Deletion
End users (members of a Discord server on which Nexus is active) have the following self-service option:
The "/delete_my_data" command: immediately deletes the calling user's level/XP data on the respective server. Warnings remain in place for the reasons stated in section 5.
8. Use of the Web Dashboard & Discord OAuth2
For configuring the bot, we offer a web dashboard at dashboard.trynexus.de. Login is handled exclusively via Discord Inc.'s official "Discord OAuth2" procedure.
How it works & scopes
When you click the login button, you are redirected to Discord. After your authorization, we receive access to the minimum required permissions:
identify: Access to your Discord user ID, username and avatar to display your profile in the dashboard.
guilds: Retrieval of the servers you are a member of, to determine on which servers you hold the "Manage Server" permission.
Passwords or login credentials for your Discord account are never transmitted to or processed by us. The legal basis for this processing is Art. 6(1)(b) GDPR (performance of a contract to provide the dashboard functions).
🍪 Technically necessary session cookies: For login in the dashboard, a purely technical session cookie is set in your browser. This cookie does not store any tracking or marketing data; it only ensures that you stay logged in during your session. The legal basis is § 25(2) no. 2 TDDDG in conjunction with Art. 6(1)(b) GDPR (performance of a contract to provide the service).
9. Recipients of Data and Transfers to Third Countries
Your personal data is expressly not shared with advertising networks, data brokers, or other third parties for marketing purposes. However, to provide and operate the "Nexus" bot, we rely on external service providers. Data is transferred to the following recipients:
Discord Netherlands B.V. (Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands) and/or Discord Inc. (USA): Since Nexus operates as a bot on the Discord platform, all communication (bot input and output) is technically routed through Discord's infrastructure. Processing by Discord is strictly necessary for using the service. Discord's own privacy policy also applies.
Infrastructure & hosting provider: The MariaDB database and the bot application itself are hosted on servers operated by netcup GmbH (Daimlerstraße 25, 76185 Karlsruhe, Germany). The server location is in Germany. A data processing agreement (DPA) under Art. 28 GDPR has been concluded with the provider. No data transfer to a third country outside the EU/EEA takes place via our hosting provider.
10. Payment Processing (Discord App Subscriptions)
The paid "Nexus Premium" subscription is offered exclusively through Discord's native in-app monetization system (App Subscriptions). The contracting party for payment processing and the purchase of these subscriptions is Discord Netherlands B.V.
Discord acts as the so-called "merchant of record" in this context, issues the corresponding invoices, collects sales tax, and independently handles payments as well as any refunds.
The "Nexus" bot itself never processes, collects, or stores your personal payment or billing data (such as credit card information or bank details). We only receive a purely technical confirmation from Discord as to whether an active Premium status exists for the respective server. The legal basis for this is Art. 6(1)(b) GDPR.