Last updated: August 20, 2026
This Privacy Policy explains what data the Lynx Discord bot and the websites and dashboards provided under lynxbot.org (together, the "Service") process, for what purposes, for how long, and what choices you have.
The Service is operated by its individual operator (the "Operator") on self-managed infrastructure. The Service is independent of Discord Inc.; your use of Discord itself is governed by Discord's own privacy policy.
The Service is designed around a simple principle: it only processes the data needed to provide the features that a server's administrators have enabled, it keeps short-lived data short-lived, and it does not sell data to anyone.
This Policy applies to the Lynx bot on Discord and to the lynxbot.org websites, including the configuration dashboard. It applies to server administrators who configure the bot, to members of servers where the bot is installed, and to visitors who sign in to the dashboard.
Server administrators decide which features are enabled in their server. Data described below is only processed where the corresponding feature is active. Administrators are responsible for informing their members that the bot is in use and for any consent required from their members in their jurisdiction.
Discord account data: your Discord user ID, username, display name, and avatar, and — for servers — server (guild) IDs, names, icons, roles, channels, and permission information. When you sign in to the dashboard via Discord OAuth2, we receive the account and server list information you authorize through Discord's consent screen.
Server configuration: settings chosen by server administrators (enabled features, thresholds, channels, roles, custom texts, and similar).
Messages and activity: where moderation-related features are enabled, message content is analyzed in real time (for example by the auto-moderation, anti-phishing, or leveling features). Most of this analysis is transient. Some features keep message data for a limited time or purpose:
Feature data you provide voluntarily: information you actively submit to specific features, such as birthdays, reminders, AFK notes, suggestions, appeals, or highlight keywords.
Engagement data: where enabled, activity counters such as experience points, levels, message counts, voice activity time, and invite attribution (who invited whom) for the servers you are in.
Verification and security data: where a server uses member verification or the Service's protection features, we process signals needed to distinguish humans from bots and to detect raids, such as account age, join patterns, challenge results (for example a captcha or Cloudflare Turnstile check), and network identifiers. IP addresses used during verification are processed for the security checks; a limited number of recent addresses is kept with the verification record, and for abuse-correlation purposes addresses are stored in a salted, hashed form that does not reveal the original address.
Dashboard sign-in and security data: when you sign in to the dashboard, we record login events with your IP address, browser and device information (user agent), approximate location derived from the IP address, and time, in order to show you your login history and warn you about suspicious sign-ins. If you enable two-factor authentication, the secret needed to verify your codes is stored encrypted.
Technical logs: server logs needed to run and debug the Service (timestamps, event types, error information), which can include IDs of the affected users, servers, or channels.
We process data exclusively to:
We do not use your data for advertising, we do not build profiles for purposes unrelated to the Service, and we do not sell or rent data to anyone.
Data is shared only in the following cases:
There is no sale, rental, or trading of personal data, and no sharing with advertisers or data brokers.
The dashboard uses only functional cookies and local storage: a session cookie to keep you signed in, security-related tokens (for example CSRF protection), and stored preferences such as language and theme. No advertising or cross-site tracking cookies are used.
Data is stored on self-managed infrastructure using PostgreSQL for persistent data and Redis for short-lived caches. Connections to the websites are encrypted (HTTPS). Access to production systems is restricted to the Operator and protected by network-level access controls.
Security measures applied to sensitive values include, among others, storing verification-related IP addresses only as salted hashes and storing authentication secrets in protected form.
No system can be guaranteed to be absolutely secure. In the event of a data incident affecting you, the Operator will act in accordance with applicable law, including notifying affected users where required.
Data is kept no longer than needed for its feature:
When the bot is removed from a server, that server's data is no longer collected and its stored data becomes eligible for deletion; a complete deletion can be requested at any time (see "Your Rights and Choices").
Regardless of where you live, the Service honors the following requests:
To make a request, contact us on the support Discord server (see "Contact"). Requests are answered within a reasonable time. Where a request concerns data controlled by a specific server (for example its moderation logs), we may refer you to, or coordinate with, that server's administrators.
Moderation and protection features can act automatically according to the configuration chosen by each server's administrators (for example removing a message or applying a timeout). These automated actions are taken on behalf of the server's staff, and every server has staff able to review and reverse them. If you believe an automated action affected you wrongly, contact the staff of the server where it happened; for questions about how the feature itself works, you can contact the support server.
The Service is not directed to children below the minimum age required to use Discord in their country or region, and we do not knowingly process data of users below that age outside of what Discord itself transmits. If you believe a child is using the Service in violation of this rule, contact us and we will act accordingly.
The Service is operated from Japan and its data is stored on infrastructure located in Japan. If you use the Service from another country, you understand that your data is transferred to and processed in Japan as described in this Policy.
This Policy may be updated as the Service evolves. The current version, with its "last updated" date, is always available on this page, and material changes will be announced in an appropriate manner. Continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.
This Policy is published in multiple languages for convenience. If there is any inconsistency between the Japanese version and a version in another language, the Japanese version prevails to the extent permitted by applicable law.
For any question or request regarding privacy or this Policy, contact us on the official support Discord server: https://discord.gg/pG2rn8SZdD
Wick-class anti-nuke and raid protection, IP-scored member verification and full moderation — plus Lavalink music, VOICEVOX voice reading (TTS), tickets, leveling and 15+ community tools. All configured from a polished web dashboard in 11 languages. 100% free.
© 2025 Lynx Bot. All rights reserved.