LynxFeaturesDocumentationBuilderAdd to Discord

Privacy Policy

Last updated: August 20, 2026

This Privacy Policy explains what data the Lynx Discord bot and the websites and dashboards provided under lynxbot.org (together, the "Service") process, for what purposes, for how long, and what choices you have.

The Service is operated by its individual operator (the "Operator") on self-managed infrastructure. The Service is independent of Discord Inc.; your use of Discord itself is governed by Discord's own privacy policy.

The Service is designed around a simple principle: it only processes the data needed to provide the features that a server's administrators have enabled, it keeps short-lived data short-lived, and it does not sell data to anyone.

1. Scope

This Policy applies to the Lynx bot on Discord and to the lynxbot.org websites, including the configuration dashboard. It applies to server administrators who configure the bot, to members of servers where the bot is installed, and to visitors who sign in to the dashboard.

Server administrators decide which features are enabled in their server. Data described below is only processed where the corresponding feature is active. Administrators are responsible for informing their members that the bot is in use and for any consent required from their members in their jurisdiction.

2. Data We Process

Discord account data: your Discord user ID, username, display name, and avatar, and — for servers — server (guild) IDs, names, icons, roles, channels, and permission information. When you sign in to the dashboard via Discord OAuth2, we receive the account and server list information you authorize through Discord's consent screen.

Server configuration: settings chosen by server administrators (enabled features, thresholds, channels, roles, custom texts, and similar).

Messages and activity: where moderation-related features are enabled, message content is analyzed in real time (for example by the auto-moderation, anti-phishing, or leveling features). Most of this analysis is transient. Some features keep message data for a limited time or purpose:

  • deleted and edited messages can be held in a short-lived cache for up to 2 hours so that moderation commands can display them, after which they expire automatically;
  • media attached to deleted messages can be retained for up to 12 hours for moderation review, after which it is deleted automatically;
  • ticket and modmail conversations are stored as transcripts for the server's records until deleted;
  • moderation logs and case records (warnings, timeouts, kicks, bans, and similar events, including relevant message excerpts) are stored for the server's moderation history.

Feature data you provide voluntarily: information you actively submit to specific features, such as birthdays, reminders, AFK notes, suggestions, appeals, or highlight keywords.

Engagement data: where enabled, activity counters such as experience points, levels, message counts, voice activity time, and invite attribution (who invited whom) for the servers you are in.

Verification and security data: where a server uses member verification or the Service's protection features, we process signals needed to distinguish humans from bots and to detect raids, such as account age, join patterns, challenge results (for example a captcha or Cloudflare Turnstile check), and network identifiers. IP addresses used during verification are processed for the security checks; a limited number of recent addresses is kept with the verification record, and for abuse-correlation purposes addresses are stored in a salted, hashed form that does not reveal the original address.

Dashboard sign-in and security data: when you sign in to the dashboard, we record login events with your IP address, browser and device information (user agent), approximate location derived from the IP address, and time, in order to show you your login history and warn you about suspicious sign-ins. If you enable two-factor authentication, the secret needed to verify your codes is stored encrypted.

Technical logs: server logs needed to run and debug the Service (timestamps, event types, error information), which can include IDs of the affected users, servers, or channels.

3. What We Use Data For

We process data exclusively to:

  • provide the features that a server has enabled (moderation, protection, verification, tickets, leveling, notifications, music, and so on);
  • protect servers and the Service itself against abuse, raids, spam, and security threats;
  • protect your dashboard account (login history, sign-in alerts, optional two-factor authentication);
  • operate, maintain, debug, and improve the Service, including through aggregate, non-identifying statistics;
  • comply with legal obligations where they apply.

We do not use your data for advertising, we do not build profiles for purposes unrelated to the Service, and we do not sell or rent data to anyone.

4. Sharing of Data

Data is shared only in the following cases:

  • Discord: the Service runs on the Discord platform, so providing any feature necessarily involves exchanging data with Discord's API (for example sending a moderation action or reading a message event). Discord's handling of data is governed by Discord's own policies.
  • Infrastructure and delivery: the lynxbot.org websites are delivered and protected through Cloudflare, which processes visitor connection data as a network provider, and may present anti-bot challenges (Turnstile) where enabled.
  • Login location lookup: when a dashboard login is recorded, the IP address is sent to a geolocation service (ip-api.com) to derive the approximate location shown in your login history and used for sign-in alerts.
  • Feature-dependent platforms: when you use features that connect to external platforms — for example music playback, or notifications for streaming and social platforms — the queries needed for that feature are sent to the relevant platform. Anti-phishing link checks are performed locally against known scam patterns; links are not sent to external checking services.
  • Legal reasons: where disclosure is required by applicable law, or strictly necessary to protect the rights, safety, or property of Users, third parties, or the Service.

There is no sale, rental, or trading of personal data, and no sharing with advertisers or data brokers.

5. Cookies and Local Storage

The dashboard uses only functional cookies and local storage: a session cookie to keep you signed in, security-related tokens (for example CSRF protection), and stored preferences such as language and theme. No advertising or cross-site tracking cookies are used.

6. Storage and Security

Data is stored on self-managed infrastructure using PostgreSQL for persistent data and Redis for short-lived caches. Connections to the websites are encrypted (HTTPS). Access to production systems is restricted to the Operator and protected by network-level access controls.

Security measures applied to sensitive values include, among others, storing verification-related IP addresses only as salted hashes and storing authentication secrets in protected form.

No system can be guaranteed to be absolutely secure. In the event of a data incident affecting you, the Operator will act in accordance with applicable law, including notifying affected users where required.

7. Retention

Data is kept no longer than needed for its feature:

  • deleted/edited message cache: at most 2 hours, then expires automatically;
  • media from deleted messages: at most 12 hours, then deleted automatically;
  • dashboard login history: retained for approximately 90 days for account-security purposes, then deleted automatically;
  • moderation logs, cases, transcripts, configuration, levels, and similar server records: retained while the bot is used in the server and the feature is active, and removable at the server's request;
  • operational backups: rotated automatically on a short cycle (approximately 14 days), after which old backups are deleted;
  • technical logs: kept for a limited operational period.

When the bot is removed from a server, that server's data is no longer collected and its stored data becomes eligible for deletion; a complete deletion can be requested at any time (see "Your Rights and Choices").

8. Your Rights and Choices

Regardless of where you live, the Service honors the following requests:

  • access: you can ask what data the Service holds about you;
  • correction: you can ask for inaccurate data to be corrected;
  • deletion: you can ask for your data, or your server's data, to be deleted;
  • objection and opt-out: you can leave a server using the bot, ask your server's administrators to disable a feature, or stop using the dashboard at any time.

To make a request, contact us on the support Discord server (see "Contact"). Requests are answered within a reasonable time. Where a request concerns data controlled by a specific server (for example its moderation logs), we may refer you to, or coordinate with, that server's administrators.

9. Automated Features

Moderation and protection features can act automatically according to the configuration chosen by each server's administrators (for example removing a message or applying a timeout). These automated actions are taken on behalf of the server's staff, and every server has staff able to review and reverse them. If you believe an automated action affected you wrongly, contact the staff of the server where it happened; for questions about how the feature itself works, you can contact the support server.

10. Children

The Service is not directed to children below the minimum age required to use Discord in their country or region, and we do not knowingly process data of users below that age outside of what Discord itself transmits. If you believe a child is using the Service in violation of this rule, contact us and we will act accordingly.

11. Where Data Is Processed

The Service is operated from Japan and its data is stored on infrastructure located in Japan. If you use the Service from another country, you understand that your data is transferred to and processed in Japan as described in this Policy.

12. Changes to this Policy

This Policy may be updated as the Service evolves. The current version, with its "last updated" date, is always available on this page, and material changes will be announced in an appropriate manner. Continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.

13. Language

This Policy is published in multiple languages for convenience. If there is any inconsistency between the Japanese version and a version in another language, the Japanese version prevails to the extent permitted by applicable law.

14. Contact

For any question or request regarding privacy or this Policy, contact us on the official support Discord server: https://discord.gg/pG2rn8SZdD

Lynx

Wick-class anti-nuke and raid protection, IP-scored member verification and full moderation — plus Lavalink music, VOICEVOX voice reading (TTS), tickets, leveling and 15+ community tools. All configured from a polished web dashboard in 11 languages. 100% free.

Product
FeaturesDocumentationBuilder

© 2025 Lynx Bot. All rights reserved.