Privacy policy
Last updated: 7 October 2026
1. Who processes your data
The data controllers are the people running the project — Pand0r and Nexoniarz (the “Pandor Systems” project, with no company or registered business). For anything about your data, message us on our Discord support server or send a direct message to one of the founders.
2. What we collect and why
| Data | Why |
|---|---|
Your Discord account when you sign in: ID, name, avatar, list of your servers (identify guilds scope) | signing in and showing the servers you can manage |
| Server module settings | so the bot works the way it was configured |
| User IDs, counters and history used by modules (levels, economy, moderation cases, tickets, giveaways, suggestions, votes) | running those modules on the server |
| Message content | only when a module needs it: AutoMod, edit/delete logs, ticket transcripts, auto replies, AI, scripts. We don’t build profiles from it and never sell it. |
| Direct messages sent to the bot | visible to the founders in their panel so they can reply (e.g. support) |
| Dashboard change log (who changed a module and when, max 30 entries per server) | transparency for the server staff |
| PexoBot+ and payment data: plan, amount, status, e-mail entered in Paddle | linking the subscription to your account and handling payments |
| API keys (AI, Paddle) | stored encrypted (AES-256-GCM), never shown in full |
3. Who we share data with
- Discord — the bot runs on the Discord platform.
- Paddle — merchant of record for PexoBot+ and paid addons: payments, taxes and invoices (card details go only to Paddle).
- The AI provider chosen by the server staff (Anthropic, OpenAI, Google or another) — only when the AI module is on; we send the conversation needed to generate a reply.
- Google AdSense — ads on the website (Free plan) may use Google cookies.
- SoundCloud, Spotify, Apple Music — only for track search in the music module (YouTube is not used).
We don’t sell data and don’t share it with anyone beyond the services above.
4. Cookies
We use a necessary session cookie (sign-in) and a cookie that remembers your language. Google ads may set their own cookies — with PexoBot+ there are no ads.
5. How long we keep data
- Server data — as long as the bot is on the server, or until the server owner deletes it (the dashboard lets you clear history, leaderboards and other data).
- Script run history — 3 days. Dashboard change log — the last 30 entries.
- Payment data — as long as the law requires and as needed to handle any complaints.
6. Your rights
You can ask to access, correct or delete your data, restrict or object to processing, and to receive your data in a portable form. Message us and we’ll reply as soon as we can. You can also lodge a complaint with your data protection authority (in Poland: the President of the Personal Data Protection Office, UODO).
7. Security
Only the project owners (Pand0r and Nexoniarz) can access the panel that manages the whole bot. Secrets are encrypted, the website is served over HTTPS, and user scripts run in an isolated sandbox with no network or file access.