Privacy Policy

How we handle your data at NoxBot.

Operator: Thomas Hetznecker & Mario Wulden GbR Last updated: June 24, 2026

Introduction

NoxBot ("NoxBot", "we", "us") is operated by Thomas Hetznecker & Mario Wulden GbR. This Privacy Policy explains how we collect, use, and protect your personal data when you use our Discord bot and dashboard at noxbot.de.

Data We Collect

Account data: We use Discord OAuth for authentication. When you log in, we receive your Discord user ID, username, avatar, and the servers you manage. We do not offer email-based registration and do not collect email addresses for account creation.

Usage data: We collect data about your interactions with the platform, including server configuration changes, feature usage (moderation, leveling, welcome, tickets, and other modules), and general usage patterns to improve our service.

Server data: When an administrator adds NoxBot to a server, we store the configuration of the modules they enable together with Discord identifiers (server, channel, role, and user IDs) and the state those features need, such as XP levels, virtual currency balances, and moderation cases.

Message content: Message content is evaluated in memory to run features such as automod, custom commands, the counting module, and sticky notes, and is then discarded. It is stored in only two cases: transcripts of private ticket channels (which administrators can switch off per server and delete at any time) and messages you deliberately send to our support team.

Custom Bot credentials: Customers on our Custom Bot (white-label) plan provide the token of their own Discord application so that we can run that bot on their behalf. The token is stored encrypted and is used for no other purpose.

Payment data: Payment processing is handled entirely by Paddle.com, our Merchant of Record. We do not store credit card numbers, bank account details, or other payment credentials. Paddle processes and stores your payment information in accordance with their own privacy policy.

How We Use Your Data

We use your data exclusively to provide and improve the NoxBot service. This includes authenticating your identity, managing your server configurations, providing customer support, and sending service-related notifications.

Some optional features rely on AI. When a server administrator actively enables such a feature, the content needed for that result (for example a ticket transcript for an automatic summary, or a flagged image for content moderation) is sent to our AI provider solely to produce that feature. These features are off by default and are controlled per server.

We do not sell your personal data to third parties. We do not use your data for AI model training or any purpose unrelated to the service.

Legal Basis for Processing

We process your personal data under the following legal bases of Article 6 (1) GDPR:

  • Performance of a contract (lit. b) · authenticating you, operating the bot and dashboard, managing your servers, and handling your subscription.
  • Legitimate interests (lit. f) · keeping the service secure, preventing abuse, and measuring aggregate usage to improve the platform.
  • Consent (lit. a) · optional features you actively enable, such as AI modules, and non-essential analytics where consent is required. You can withdraw consent at any time.
  • Legal obligation (lit. c) · retaining billing and accounting records where the law requires it.

Cookies & Analytics

We use cookies for session management (keeping you logged in) and for storing your language preference. We also use a self-hosted analytics tool to understand aggregate usage of the dashboard, such as which pages and modules are used.

You can control cookies through your browser settings. If you object to analytics, contact us at the address below.

Data Retention

Your data is retained as long as your account is active. If you delete your account or request data deletion, we will remove your personal data within 30 days, except where we are legally required to retain it.

Server data is retained while NoxBot is a member of the server. If the bot is removed, we keep that server's configuration and feature data so the settings are restored if it is invited back. Administrators can delete this data themselves in the dashboard, or ask us to erase it immediately at support@swisser.dev.

Ticket transcripts and support conversations are kept for as long as they serve their purpose as a support record, because a transcript that is deleted automatically would defeat the point of the feature. Storing transcripts can be switched off per server, and individual transcripts can be deleted at any time.

Data Security

All traffic between your browser, our servers, and Discord is encrypted in transit using TLS.

Particularly sensitive credentials are additionally encrypted at rest in our database using AES-256-GCM: Discord OAuth access and refresh tokens, Custom Bot tokens, and third-party API keys. They therefore remain unusable even to someone with direct database access. Access to production systems is limited to the operators named in our imprint.

Third-Party Services

We share data with the following third-party services as necessary to operate the platform:

  • Discord · authentication, bot functionality, and message delivery
  • Paddle.com · payment processing as our Merchant of Record
  • OpenAI · optional AI features (such as ticket summaries, content moderation, and the setup assistant), only for servers that enable them
  • Self-hosted analytics · aggregate usage measurement for the dashboard
  • Hosting provider · infrastructure and data storage

International Data Transfers

Some of our processors (in particular our payment provider Paddle and our AI provider OpenAI) may process data on servers outside the European Economic Area, including in the United States. Where this happens, the transfer is based on appropriate safeguards such as the EU Standard Contractual Clauses or an applicable adequacy decision.

Your Rights

Under applicable data protection laws (including the GDPR), you have the right to access, correct, delete, or export your personal data. You may also object to or restrict certain processing, and where processing is based on consent, you can withdraw that consent at any time with effect for the future. To exercise these rights, contact us at support@swisser.dev.

You can opt out of activity tracking (XP/leveling and your activity profile) at any time directly in Discord using the /privacy opt-out command. The opt-out applies to your account on every server using NoxBot and can be reversed with /privacy opt-in. Moderation and security features are not affected by this opt-out.

You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA).

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes through the platform or via Discord. Continued use of the service after changes constitutes acceptance of the updated policy.

Contact

If you have questions about this Privacy Policy or your data, contact us at support@swisser.dev.