Privacy Policy
Last updated: 2 October 2026
This policy explains what personal data Nexo (“Nexo”, “we”, “us”) collects, why, who we share it with and what rights you have. Nexo is a Discord bot and web dashboard operated by vszn.s.
1. Who we are and our role
vszn.s operates Nexo and is the controller of the personal data of people who log in to the dashboard and of people who buy Premium. Contact: [email protected].
When a Discord server adds Nexo, that server’s owners and administrators decide which features to switch on and what the bot records (for example moderation cases or ticket transcripts). For data collected through those features, the server is responsible for telling its members and we process the data on the server’s behalf. We decide the purposes only for security, abuse prevention, billing and running the service.
2. What we collect
Dashboard login (Discord sign-in)
When you log in with Discord we ask for the identify and guilds permissions. We store your Discord user ID, username, display name and avatar identifier, the time of your last login, and a list of the servers you belong to that you can manage (used to show the server picker). Discord access and refresh tokens are encrypted before they are stored. We do not request your email address and we do not store your IP address or browser details with your login session.
Servers that use Nexo
Server ID, name, icon, owner ID, member count, the settings server admins save in the dashboard, plan status, and an audit log of dashboard changes (who changed what and when).
Data created by features a server enables
- Moderation: cases (member ID, moderator ID, action, reason, time) and moderator notes.
- Tickets, reports and applications: the member who opened it, status, and the text of the conversation or answers submitted. Ticket transcripts contain the messages sent in the ticket channel.
- Suggestions, polls and giveaways: the text submitted, votes and entries linked to member IDs.
- Leveling and economy: member ID, XP, message and voice counters, balances and inventory.
- Reminders and AFK: the text you ask Nexo to remember and your AFK message.
- Staff tools: staff member IDs, ranks, shift and activity counts.
- Role restore: a list of a member’s role IDs so roles can be restored if they rejoin, where enabled.
- Analytics: daily totals per server (messages, joins, leaves, commands) and which member IDs were active on a given day. Analytics do not store message content.
- Logging and AutoMod: Nexo reads messages in real time to apply the rules a server configures. Message content used for AutoMod is not stored by us. Log entries (for example edited or deleted messages) are posted into a channel chosen by the server and are kept by Discord, not in our database.
Premium and billing
Payments are handled by Stripe. We never see or store your full card number. We store the Discord user ID of the buyer, the server, plan, status, price and currency, renewal date and the Stripe customer and subscription IDs. Stripe collects the billing details it needs (such as email, name, billing country and card details) under its own privacy policy.
Optional AI features
If a server enables an AI-assisted feature, only the text you submit to that feature is sent to our AI provider (Anthropic) to generate a reply. We do not store that text.
Technical and operational data
Our servers keep short-lived operational logs (time, request path, status code and IP address) for security and fault-finding, and an error log of failures (which may include server and member IDs). Command usage is counted by command name only.
Owner approval guard, global blacklist and the Nexo team
- Approval prompts: when a new bot is added, or a very new or globally blacklisted account joins, we record the server ID, the bot or account ID and name, what was asked, who decided (user ID) and the outcome. These prompts are sent to the server owner by direct message or in a channel.
- Global blacklist requests: a server owner can ask us to blacklist a user. We store the reported user’s ID and name, the requester’s ID and name, the server, the reason and evidence the requester typed, and our decision. Only Nexo staff can approve an entry.
- Global blacklist: an approved entry stores the user’s ID, name, a short reason, who approved it and when. Server owners are told when a listed user joins and decide whether to allow or kick them. This is not an automatic ban.
- Nexo team: for people we authorise to use our admin console we store their Discord ID, role and permissions, and a log of what they change.
Cookies
We use only the cookies needed to keep you logged in. See the Cookie Policy. We do not use advertising or analytics cookies or trackers.
3. Why we use it, and our legal bases
| Purpose | Legal basis (GDPR / UK GDPR) |
|---|---|
| Log you in and show the servers you manage | Performance of a contract (providing the dashboard you asked for) |
| Run the bot features a server enables | Legitimate interests of the server and of Nexo in running a moderated community; the server’s instructions |
| Security, abuse prevention, fixing faults | Legitimate interests |
| Take payment, keep invoices and tax records | Performance of a contract; legal obligation |
| Send AI requests you start | Performance of a contract; your request |
We do not sell personal data, do not share it for advertising, and do not use it to profile you or to make decisions with legal effect.
4. Who we share it with
| Recipient | Why |
|---|---|
| Discord Inc. | Sign-in, the bot platform itself, and avatar and server icon images loaded from Discord’s servers (Discord sees your IP address when your browser loads them). |
| Stripe | Payment processing and billing management for Premium. |
| Anthropic | Only when a server enables an AI feature and you use it. |
| Hosting provider (London, United Kingdom) | Runs our servers and database. |
We may also disclose data when the law requires it or to protect users and the service from abuse. Server administrators can see the data their own server’s features record. We do not use any other third-party scripts, fonts, analytics or advertising services on this website.
Data may be processed in countries other than yours. Where required we rely on safeguards such as standard contractual clauses used by our providers.
5. How long we keep it
| Data | Kept for |
|---|---|
| Login session | 7 days, or until you log out or delete your account |
| Server data (settings, cases, transcripts, levels and so on) | While Nexo is in the server, and for 30 days after it is removed, then deleted. Admins can delete many items earlier from the dashboard. |
| Dashboard audit log | 12 months |
| Approval prompts (new bots, new accounts) | 90 days after a decision |
| Reviewed blacklist requests | 12 months |
| Global blacklist entries | Until we remove them. We review entries on request (see “Your rights”). |
| Error log | 30 days |
| Billing records | As long as tax and accounting law requires (commonly up to 7 years) |
| Operational server logs | Up to 30 days |
6. Your rights
Blacklist entries. If you are on the global blacklist you can ask us what we hold, ask us to review the entry, or ask us to remove it. We keep entries on the basis of our legitimate interest in keeping communities safe, and we will remove entries that are inaccurate or no longer justified. Erasing your member data with /mydata delete does not remove a blacklist entry for this reason.
Depending on where you live (for example under the GDPR, UK GDPR, the Australian Privacy Act 1988, or US state laws such as the CCPA/CPRA) you may have the right to access, correct, delete, export or restrict use of your personal data, to object to processing, to withdraw consent, and to complain to your data protection authority. We will not discriminate against you for using these rights.
- Delete your dashboard account data: log in and choose “Delete my account data” on the server picker page. This removes your user record and all your login sessions.
- Delete your member data in servers: run
/mydata deletein any server where Nexo is present to remove your levels, balances, inventory, AFK, reminders, votes and giveaway entries from all servers. Moderation records and ticket transcripts are kept by the server for safety, so ask the server’s staff about those, or email us. - Anything else (access copy, correction, objection): email [email protected]. We reply within 30 days. We may need to confirm your identity first.
Removing Nexo from your server, or revoking Nexo in your Discord “Authorized Apps” settings, stops further collection.
7. Security
Discord tokens are encrypted at rest, sessions use HttpOnly cookies, connections use HTTPS, and every dashboard action is checked on the server against your live Discord permissions. No system is perfectly secure. If a breach affects your data we will notify you and regulators as the law requires.
8. Children
Nexo is not directed to children and you must meet Discord’s minimum age (13, or higher where your country requires) to use Discord and Nexo. We do not knowingly collect data from children under 13. If you believe we have, email [email protected] and we will delete it.
9. Changes
If we make a material change we will update the date above and, where the change affects how we use your data, give notice in the dashboard or on our support server before it takes effect.
10. Contact
vszn.s
Email: [email protected]