Privacy Policy
This policy explains what Xevra ("Xevra", "we") collects when you use our Discord bot or the dashboard at https://xevra.org, why we collect it, who we share it with, and how to have it removed.
1. Who is responsible
Xevra, based in Switzerland, is the controller of the data described here. For anything in this policy, contact support@xevra.org.
Note that a server owner who invites Xevradecides which features to enable and what gets logged in their server. For that configuration they act as controller of their members' data, and we process it on their behalf.
2. What we collect
Identifiers
- Discord user IDs and server (guild) IDs
- Channel and role IDs referenced by your configuration
- Cached usernames and avatars, so the dashboard can show names rather than raw numbers
Configuration
- Module settings, command prefixes, enabled features and permission rules
- Ticket panels, custom commands, auto-responders and welcome messages you create
- Branding you set: colours, embed text, images
- Server structure snapshots, if you use
/backup create
Activity generated by features you enable
- Moderation history — warnings and cases, and which staff member issued them
- Security incidents recorded by anti-raid and anti-nuke protection
- Leveling and XP totals, birthdays, AFK status
- Ticket transcripts and application answers
- Giveaway entries, poll votes, starboard and reaction-role state
Subscription data
- The Discord user ID of the subscriber, and the server the subscription applies to
- Stripe customer and subscription identifiers, the plan, and its renewal date
- We never receive or store card numbers. Card details go directly to Stripe, our payment processor.
Technical data
Our hosting providers process IP addresses and request logs in the ordinary course of serving the website, and we keep short-lived operational logs to diagnose errors.
3. Message content
The bot reads messages in servers where it has been given permission, because features you enable require it — detecting spam and blocked words, awarding XP, noticing an @mention while you are AFK.
Message content is processed as it arrives and is not retained, except where a feature you switched on exists specifically to keep it: ticket transcripts, message logs and starboard entries. Turning those features off stops the retention.
4. Why we are allowed to process it
- Performing our contract with you— running the features you asked for, and administering your subscription.
- Legitimate interests— keeping the Service secure, preventing abuse, and fixing faults.
- Legal obligation— retaining payment records for as long as tax and accounting rules require.
5. Who we share it with
- Discord — the platform the Service operates on
- Stripe — payment processing and subscription management
- Our hosting and database providers — to run the bot and website
We do not sell your data, and we do not share it for advertising. We may disclose data where legally required, or to protect the rights and safety of users.
Some of these providers operate outside Switzerland, so data may be transferred abroad and protected by the safeguards those providers put in place.
6. How long we keep it
- Configuration and feature data are kept while the bot is in your server. Removing the bot begins deletion of that server's data.
- Moderation records and ticket transcripts are kept as the server's accountability record until deleted by a server administrator.
- Payment records are kept as long as tax and accounting law requires.
- Operational logs are short-lived and rotate automatically.
7. Your rights and controls
Run /privacy-delete-my-data in any server to immediately delete your own leveling, birthday, AFK, giveaway-entry and poll-vote data from that server.
Moderation records, tickets and applications are the server's safety record rather than yours alone, so removing them is a decision for that server's administrators — contact them, or us, about those.
Depending on where you live you may also have the right to access, correct, delete, restrict or object to our processing of your data, to receive a portable copy, and to complain to your data protection authority. To exercise any of these, email support@xevra.org.
8. Children
The Service is not directed at anyone below Discord's minimum age for their country. If you believe a child has provided us with personal data, contact us and we will delete it.
9. Security
We use access controls, encrypted connections and hosted infrastructure with its own security measures. No system is perfectly secure, and we cannot guarantee absolute security, but we will tell affected users about a breach where we are required to.
10. Changes to this policy
We may update this policy. The date at the top shows when it last changed. Material changes will be announced before they take effect.
11. Contact
Privacy questions and data requests: support@xevra.org