Privacy Policy

Last updated: 2 October 2026

This policy explains what personal data Nexo (“Nexo”, “we”, “us”) collects, why, who we share it with and what rights you have. Nexo is a Discord bot and web dashboard operated by vszn.s.

1. Who we are and our role

vszn.s operates Nexo and is the controller of the personal data of people who log in to the dashboard and of people who buy Premium. Contact: [email protected].

When a Discord server adds Nexo, that server’s owners and administrators decide which features to switch on and what the bot records (for example moderation cases or ticket transcripts). For data collected through those features, the server is responsible for telling its members and we process the data on the server’s behalf. We decide the purposes only for security, abuse prevention, billing and running the service.

2. What we collect

Dashboard login (Discord sign-in)

When you log in with Discord we ask for the identify and guilds permissions. We store your Discord user ID, username, display name and avatar identifier, the time of your last login, and a list of the servers you belong to that you can manage (used to show the server picker). Discord access and refresh tokens are encrypted before they are stored. We do not request your email address and we do not store your IP address or browser details with your login session.

Servers that use Nexo

Server ID, name, icon, owner ID, member count, the settings server admins save in the dashboard, plan status, and an audit log of dashboard changes (who changed what and when).

Data created by features a server enables

Premium and billing

Payments are handled by Stripe. We never see or store your full card number. We store the Discord user ID of the buyer, the server, plan, status, price and currency, renewal date and the Stripe customer and subscription IDs. Stripe collects the billing details it needs (such as email, name, billing country and card details) under its own privacy policy.

Optional AI features

If a server enables an AI-assisted feature, only the text you submit to that feature is sent to our AI provider (Anthropic) to generate a reply. We do not store that text.

Technical and operational data

Our servers keep short-lived operational logs (time, request path, status code and IP address) for security and fault-finding, and an error log of failures (which may include server and member IDs). Command usage is counted by command name only.

Owner approval guard, global blacklist and the Nexo team

Cookies

We use only the cookies needed to keep you logged in. See the Cookie Policy. We do not use advertising or analytics cookies or trackers.

3. Why we use it, and our legal bases

PurposeLegal basis (GDPR / UK GDPR)
Log you in and show the servers you managePerformance of a contract (providing the dashboard you asked for)
Run the bot features a server enablesLegitimate interests of the server and of Nexo in running a moderated community; the server’s instructions
Security, abuse prevention, fixing faultsLegitimate interests
Take payment, keep invoices and tax recordsPerformance of a contract; legal obligation
Send AI requests you startPerformance of a contract; your request

We do not sell personal data, do not share it for advertising, and do not use it to profile you or to make decisions with legal effect.

4. Who we share it with

RecipientWhy
Discord Inc.Sign-in, the bot platform itself, and avatar and server icon images loaded from Discord’s servers (Discord sees your IP address when your browser loads them).
StripePayment processing and billing management for Premium.
AnthropicOnly when a server enables an AI feature and you use it.
Hosting provider (London, United Kingdom)Runs our servers and database.

We may also disclose data when the law requires it or to protect users and the service from abuse. Server administrators can see the data their own server’s features record. We do not use any other third-party scripts, fonts, analytics or advertising services on this website.

Data may be processed in countries other than yours. Where required we rely on safeguards such as standard contractual clauses used by our providers.

5. How long we keep it

DataKept for
Login session7 days, or until you log out or delete your account
Server data (settings, cases, transcripts, levels and so on)While Nexo is in the server, and for 30 days after it is removed, then deleted. Admins can delete many items earlier from the dashboard.
Dashboard audit log12 months
Approval prompts (new bots, new accounts)90 days after a decision
Reviewed blacklist requests12 months
Global blacklist entriesUntil we remove them. We review entries on request (see “Your rights”).
Error log30 days
Billing recordsAs long as tax and accounting law requires (commonly up to 7 years)
Operational server logsUp to 30 days

6. Your rights

Blacklist entries. If you are on the global blacklist you can ask us what we hold, ask us to review the entry, or ask us to remove it. We keep entries on the basis of our legitimate interest in keeping communities safe, and we will remove entries that are inaccurate or no longer justified. Erasing your member data with /mydata delete does not remove a blacklist entry for this reason.

Depending on where you live (for example under the GDPR, UK GDPR, the Australian Privacy Act 1988, or US state laws such as the CCPA/CPRA) you may have the right to access, correct, delete, export or restrict use of your personal data, to object to processing, to withdraw consent, and to complain to your data protection authority. We will not discriminate against you for using these rights.

Removing Nexo from your server, or revoking Nexo in your Discord “Authorized Apps” settings, stops further collection.

7. Security

Discord tokens are encrypted at rest, sessions use HttpOnly cookies, connections use HTTPS, and every dashboard action is checked on the server against your live Discord permissions. No system is perfectly secure. If a breach affects your data we will notify you and regulators as the law requires.

8. Children

Nexo is not directed to children and you must meet Discord’s minimum age (13, or higher where your country requires) to use Discord and Nexo. We do not knowingly collect data from children under 13. If you believe we have, email [email protected] and we will delete it.

9. Changes

If we make a material change we will update the date above and, where the change affects how we use your data, give notice in the dashboard or on our support server before it takes effect.

10. Contact

vszn.s
Email: [email protected]