Privacy Policy
Last updated September 2026
This policy explains what data Nyra collects, why, and how it's used across the bots and this dashboard. It describes what the code actually does — where something is only read and never kept, or kept only for a short while, that's said plainly below rather than left to the broadest possible reading.
1. What we store
Your account
- Your Discord user ID, username and avatar
- Your email address, if you granted it at sign-in or used it at checkout
- License keys, premium status and subscription records
- A salted hash of your IP address, used only to confirm a sign-in code came from the same place the login started, and to remember a trusted device. The raw address is hashed before it ever reaches our API — we never store it
Server features you or your admins turn on
- Moderation records: the action, reason, moderator and target for each case
- Ticket transcripts, if the server has transcripts enabled — the full text of the ticket
- Appeal submissions, including the answers you give on the form
- Levels and XP totals, per server
- Birthdays (day and month only — never a year), reminders, AFK status, highlights and tags
- Confessions are posted anonymously. If a server has configured a staff log channel, the real author is recorded there for that server's staff — the public post stays anonymous either way
Optional integrations
- Your Last.fm username, if you link one with
/fmlogin - A record that you voted, if you vote for Nyra on Top.gg
- For Nyra Custom, your bot token — encrypted at rest with AES-256-GCM, used only to run your bot, and never shown back to you or anyone else
2. What we read but don't keep
- Message content. AutoMod inspects messages as they arrive to apply the filters a server enabled, and audit logging quotes deleted and edited messages into that server's own log channel. Neither writes message content to our database. The one exception is
/snipe, which holds the single most recent deletion per channel in memory for two hours and then discards it — nothing is written to disk - Your Discord presence.
/fmreads what you have playing on Spotify at the moment you run it, straight from Discord. It isn't stored, logged or shared - Voice activity. Join and leave events are logged to a server's own log channel if it enabled voice logging. We never record, listen to or store audio
- Your server list. Fetched live from Discord each time you open the dashboard, to show which servers you can manage. It isn't stored
3. How we use it
Strictly to operate the Service: authenticating your dashboard session, showing your servers and premium status, and running the moderation and utility features you or your server admins configured. Aggregate counts — how many servers Nyra is in, how many commands exist — are used publicly on this site. Nothing about an individual is.
4. Who else sees it
We don't sell your data, and we don't share it for advertising. Data reaches a third party only where that party is what makes the feature work:
- Discord — everything the bot does happens on their platform
- Whop — payment processing. They handle card details; we never see them
- Last.fm — only if you link an account. Your Last.fm username is sent with each request so they can return your listening data
- Top.gg — only if you vote, and they tell us that you did
- Brevo (and fallback mail providers) — sign-in codes and receipts
- Vercel and Amazon Web Services — hosting
Server data is also visible to that server's own staff, which is the point of it — moderation cases, ticket transcripts and appeal answers are there for the moderators of the server they belong to.
5. Data retention
We keep data for as long as your account or your server uses the Service. Removing Nyra from a server doesn't immediately erase that server's records — ask and we will delete them. Sign-in codes expire in minutes, snipe entries in two hours, and both are discarded automatically.
6. Your rights
Both of these are self-service, on your settings page — no need to ask anyone.
- Download a copy. Everything we hold about you as a JSON file, including the records that deletion would leave behind
- Delete it. Removes everything in section 1 immediately and signs you out. It ends any remaining premium on the account and can't be undone
Deletion doesn't remove everything, and the exact list is shown before you confirm. Moderation cases stay with the server that issued them — yours to request from that server or from us, but not something you can erase unilaterally, because otherwise this would be a way to wipe your own ban history. Punishments that haven't expired stay in force, as does a ban from Nyra itself. Purchase records are kept for refunds, chargebacks and accounting, with the email address removed.
If you have a subscription that's still running, cancel it first — deleting your account here wouldn't stop the billing. You can still reach us through the support server for anything the buttons don't cover.
7. Children
Discord requires users to be at least 13, or older where local law sets a higher age. Nyra is not intended for anyone below that age, and we don't knowingly collect their data.
8. Changes
We'll update this policy when what we collect changes. The date at the top of this page is when it was last revised.
9. Contact
Questions about this policy can be directed to our support server.