Privacy Policy
Privacy Guarantee
NexuSec operates under strict data minimization standards. We never sell user data, never read or log private DMs, never store raw message content permanently, and never record voice channels. All data handling complies fully with the Discord Developer Policy & Privileged Intent Standards.
1. Overview & Data Controller Identity
This Privacy Policy describes how NexuSec ("the Bot", "Service", "we", "us", or "our") collects, uses, retains, and protects information when added to a Discord server (Guild) or accessed via the NexuSec Web Dashboard.
By inviting NexuSec to your Discord server or using our services, you acknowledge that you have read and understood this Privacy Policy.
Support Server: https://discord.com/invite/QZqmjsbgUJ
Application ID: NexuSec Bot Core Service
2. Discord Gateway Privileged Intents Disclosure
In compliance with Discord Developer Policy, NexuSec requests access to Gateway Privileged Intents solely to deliver essential bot features. The justification, usage scope, and retention boundaries for each intent are specified below:
Functional Purpose: Enables NexuSec to process custom prefix commands (e.g., !play, !help, !playlist), parse chat-triggered music search queries, evaluate auto-moderation word filters, and calculate message activity XP for guild leaderboards.
Data Handling Boundary: Message content is processed strictly in transient RAM memory during execution. Raw message text is never stored in persistent databases, never logged to disk, never trained on machine learning models, and never transmitted to third parties.
Functional Purpose: Enables member join/leave event tracking for custom welcome messages, invite tracking system, level/XP leaderboards, and guild member verification.
Data Handling Boundary: Collects public Discord IDs, usernames, display names, avatar hashes, and join timestamps. Data is cached exclusively to serve server moderation and leaderboard functions.
Functional Purpose: Used exclusively to verify member status for vanity support role automation or special activity perks.
Data Handling Boundary: Presence state is read dynamically and is not saved to any database.
3. Comprehensive Data Inventory Matrix
The following table outlines all categories of data processed by NexuSec:
| Category | Specific Data Collected | Primary Purpose | Storage & Retention |
|---|---|---|---|
| Guild / Server Data | Guild ID, Guild Name, Icon Hash, Channel IDs, Role IDs, Custom Prefix, Dashboard Settings. | Server configuration, dashboard syncing, permission validation. | Encrypted DB while Bot is in server + 30-day purge after kick. |
| User Profile Data | Discord User ID, Username, Discriminator, Avatar Hash, Global Display Name. | Leaderboards, track requesters, invite tracking, command authorization. | Retained while active; purgable upon user deletion request. |
| Music & Voice Metadata | Voice Channel ID, Voice Session ID, Enqueued Track URIs / Titles. | Routing audio streams via Lavalink nodes and managing queues. | Transient session memory; cleared upon queue stop or voice disconnect. |
| Analytics & Logs | Command invocation counts, error traces, timestamp logs. | System stability, debugging music connections, rate limiting. | Anonymized logs retained for max 14 days. |
| Excluded Data | Passwords, Payment details, DMs, Raw Audio Streams, Private Chat Logs. | NOT COLLECTED | Never accessed or stored. |
4. Purpose Specification & Usage
NexuSec processes collected data strictly for the following purposes:
- Bot Core Functions: Executing music playback commands, managing queues, and displaying track progress.
- Server Administration: Maintaining invite tracking statistics, member level systems, and auto-moderation settings configured by guild admins.
- Web Dashboard Integration: Authenticating server administrators via OAuth2 to manage bot preferences securely.
- Service Diagnostics: Identifying music stream reconnect issues and maintaining high system uptime.
5. Third-Party Integrations & APIs
NexuSec integrates with third-party service providers to deliver music metadata and Discord connectivity:
- Discord API & Gateway: Primary infrastructure for command handling and voice connection state.
- Lavalink Nodes: High-performance audio distribution nodes used to stream media audio to Discord voice channels. No personal user data is sent to Lavalink nodes.
- Spotify / YouTube / SoundCloud APIs: Read-only metadata queries used solely to resolve search queries and playlist links into audio tracks.
We do not sell, rent, or trade personal data to advertisers, data brokers, or any third party.
6. Data Retention & Expiration Schedules
NexuSec adheres to strict data expiration schedules:
- Transient In-Memory Data: Prefix message content and voice session tokens are cleared within seconds.
- Guild Removal Purge: When NexuSec is removed (kicked/banned) from a server, all server configurations, invite counts, and custom settings are scheduled for permanent deletion within 30 days.
- User Deletion SLA: Individual user data deletion requests are honored and executed within 7 business days.
7. Security Standards & Data Encryption
We enforce robust security protocols to protect your data against unauthorized access, loss, or alteration:
- Encryption in Transit: All data transmitted between Discord, our web dashboard, and servers uses TLS 1.3 / HTTPS / Secure WebSockets (WSS).
- Access Controls: Database access is restricted strictly to authorized bot infrastructure using environment key isolation.
- Token Security: OAuth2 tokens and bot credentials are stored in encrypted form.
8. User Rights & Data Deletion SLA
Under applicable privacy regulations (including GDPR and CCPA), users have the following rights regarding their data:
- Right to Request Access: You can request a summary copy of all stored data associated with your Discord User ID or Guild ID.
- Right to Erasure (Data Deletion): You can request total erasure of your user profile, leveling history, or server configuration data.
Join our official Support Server and open a support ticket under "Data Deletion / Privacy Request". All requests are fulfilled within 7 business days.
9. Children's Privacy & Age Limits
NexuSec does not knowingly collect or solicit personal information from children under the age of 13 (or the legal age of digital consent in your jurisdiction). Using NexuSec requires compliance with Discord's Terms of Service. If we learn that we have collected personal data from a child under the required age, we will delete that information immediately.
10. Policy Updates & Contact Information
We may update this Privacy Policy periodically to reflect operational, legal, or regulatory changes. Significant updates will be announced in our official Support Server.
For questions, privacy inquiries, or developer compliance audits, please contact us via our official support channel: