Privacy Policy
Introduction & Scope
At NOIR, we are committed to transparent, responsible, and secure data handling practices. This Privacy Policy details how we collect, process, store, and protect technical metrics and user data when you interact with our Discord bot application, website, and related web dashboard services. By adding NOIR to your Discord server or executing any of its commands, you acknowledge and agree to the operational guidelines outlined herein.
1. Information We Collect by Module
We operate strictly on the principle of data minimization, collecting only technical parameters necessary to power our automated moderation, engagement, and tracking features:
- Server & Channel Architecture: Discord Guild IDs, channel IDs, role IDs, server member counts, and permission bitmasks required to establish permission boundaries, ticket panels, and logging routers.
- User Account Telemetry: Discord User IDs, usernames, global display names, avatar URLs, and guild join/leave timestamps to render user cards and track membership tenure.
- Tracker & Growth Telemetry:
- Message Counts: Quantitative message tallies per user and per channel (message content is not stored in databases).
- Voice Minutes: Time intervals spent in non-AFK voice rooms to calculate active VC leaderboards.
- Invite Attributions: Invite codes, creator IDs, fake/leave tallies, and joins attributed to specific invite links.
- Vanity Status Tracking: Discord custom status bio text to verify presence of designated server invite links and grant cosmetic roles.
- Official Server Tag Tracking: Discord primary guild identity tags to verify official boost server tag wearers and grant cosmetic tag rewards.
- Anti-Nuke & Moderation Audit Logs: Mod action logs, executor IDs, target IDs, timestamps, reason strings, and automated quarantine states to protect guilds against unauthorized mass actions.
- Virtual Marriage & Economy Records: Marital bond partnerships, proposal timestamps, love quiz engagement tallies, wedding certificate metadata, Love Points balances, and virtual boutique inventories.
- Verification & CAPTCHA Data: Temporary cryptographic captcha session tokens and completion verification timestamps. Captcha graphics are generated dynamically in-memory and discarded upon verification.
- Ephemeral Snipe Cache: Recently deleted or edited messages are stored exclusively in short-term volatile RAM cache (never written to permanent disk storage) and automatically expire within 10 minutes or upon subsequent channel deletions.
2. Voice Channel & Audio Privacy
Our music and Join-to-Create (J2C) voice cogs interface directly with high-performance audio nodes (Lavalink):
- Zero Voice Recording: NOIR does NOT record, eavesdrop, transcribe, analyze, or store voice channel conversations, microphone feeds, or audio packets under any circumstances.
- Audio Streaming Telemetry: We only track track titles, requester IDs, duration lengths, and YouTube/Spotify track metadata strictly to maintain current playback queues and DJ controls.
3. How We Use Collected Information
All stored metrics are utilized solely to operate and maintain the bot's functional capabilities:
- Executing automated moderation defense (Anti-Nuke, Anti-Spam, Auto-Responder, and Role Whitelist enforcement).
- Delivering community engagement features (interactive mini-games, leveling cards, love quizzes, and certified marriage documents).
- Maintaining server analytics dashboards, real-time message/voice leaderboards, and invite counts.
- Automating cosmetic reward roles for members representing your server through vanity invite statuses or official server tags.
- Diagnosing database latency, preventing API rate limit bottlenecks, and maintaining server health.
- Ensuring strict compliance with Discord's Developer Terms of Service and Community Guidelines.
4. Data Storage, Security & Architecture
We enforce strict security protocols to prevent unauthorized access, tampering, or disclosure:
- Database Isolation: Configuration files and relational logs are stored in encrypted SQLite databases hosted on secured private virtual containers provided by AXORA CLOUD SOLUTIONS™.
- Access Controls: Database volumes are protected by strict Linux user permission boundaries, container isolation, and firewall filtering. Direct database access is restricted exclusively to authorized development staff.
- No Plaintext Passwords: Message encryption cogs (
;encode/;decode) process ciphers client-side or in volatile memory, never persisting encryption passwords on disk.
5. Data Retention Lifecycle & Automated Purges
We maintain defined data lifecycle schedules to avoid unnecessary data accumulation:
- Active Server Data: Guild configurations, custom roles, and whitelists remain active for as long as NOIR resides in the server.
- Server Departure Purge: When the bot is removed, kicked, or banned from a guild, server configuration rows are marked inactive and permanently deleted within 14 to 30 days.
- Ephemeral Memory Buffers: Deleted message snipe caches and CAPTCHA verification sessions are flushed automatically from RAM within 10 minutes.
- Instant In-Bot Reset Commands: Administrators can instantly wipe module data anytime using built-in commands (e.g.
;logs reset,;levelling reset all,;voicereset,;clearmessages,;tag reset,;vanity reset).
6. Web Dashboard & Cookie Policy
Our web portal utilizes minimal, strictly necessary session cookies:
- Discord OAuth2 Sessions: Encrypted, HTTP-only session tokens are used exclusively to authenticate your Discord identity and verify administrator permissions for server configuration tabs.
- Zero Ad Trackers: We do NOT deploy third-party advertising cookies, fingerprinting pixels, cross-site trackers, or data broker analytics on our website.
7. Third-Party Disclosures & Cloud Partners
We do NOT sell, trade, or monetize user data under any circumstances. Limited technical handshakes occur solely with infrastructure providers:
- Discord Inc.: All bot commands, gateway events, and user interactions pass securely through Discord's official Gateway API.
- Hosting Partner (AXORA CLOUD SOLUTIONS™): Physical and cloud server hardware hosting the Docker container runtime and database instances.
- Cloudflare: Secure reverse-proxy routing and DDoS protection safeguarding API endpoints and the web client.
- Legal Compliance: Data will only be disclosed if legally compelled under binding court order or statutory requirement.
8. Children's Online Privacy (COPPA & Discord Compliance)
In strict compliance with Discord's Terms of Service and COPPA regulations, our service is strictly intended for individuals who are at least 13 years of age (or the legal age of digital consent in their country of residence). We do not knowingly collect or solicit personal data from children under 13. If we become aware that an account belonging to a minor under the legal age threshold has interacted with the bot, all associated data records will be purged immediately upon notification.
9. User Rights & Data Deletion Requests (GDPR Compliant)
In accordance with international privacy frameworks (including GDPR), users retain full ownership of their data:
- Right to Access: Request a comprehensive export of all records associated with your Discord User ID or managed server.
- Right to Rectification: Request correction of inaccurate warning logs, rank parameters, or configuration records.
- Right to Erasure (Right to be Forgotten): Request the permanent deletion of your profile metrics, leveling XP, warning histories, and server configuration records.
- Immediate Opt-Out: Stop all telemetry immediately by removing NOIR from your server or disabling tracking modules.
To submit a data access or deletion request, please reach out directly to developer or open a data privacy ticket in our Official Support Server. All verified deletion requests are processed within 48 to 72 business hours.
