Privacy
What Axaro stores, why, and for how long. Written from the code, not from a template.
Last updated: September 27, 2026
This is a translation. The French version is the reference: Axaro is published in France, and the French text prevails if the two ever differ.
Who handles this data
Axaro is an independent project, published in France by two people. For any question or request, write to us on the support server.
What we store
- Discord IDs. Those of the servers, channels, roles and accounts involved in an action. They are numbers; they contain no email address, no password and no payment method.
- Your server’s settings. What your team chose in the dashboard: modules turned on, channels, thresholds, messages.
- What moderation produces. Sanctions with their reason, tickets and their subject, security events, and the logs your team turned on.
- What you hand to the bot yourself. The text of a reminder, a suggestion or an away status.
Message content
The bot reads messages to do its job — AutoMod to decide whether to act, levels to count activity — and in most cases keeps nothing of them. It keeps an excerpt in three cases only, all tied to a feature the server’s team turned on:
- The message log, when it is on: the text of a deleted message (up to 1,000 characters), and that of an edited message, before and after (500 characters each).
- An AutoMod sanction: an excerpt of the sanctioned message (up to 500 characters), as evidence in the case.
- A message wave caught by the anti-raid: an excerpt of the repeated content (up to 200 characters).
When you log in to the dashboard
Login goes through Discord, with two permissions only: identify to know who you are, and guilds to list the servers you manage. Axaro can neither read your direct messages, nor write on your behalf, nor see your email address.
A session cookie is set. It only keeps you logged in, it is signed, only the server can read it, and it expires by itself. A second cookie remembers the language you picked on the site. No advertising cookie, no tracker, no third-party analytics tool.
Site statistics
We count visits to the site ourselves, without any third-party tool and without cookies. For each page view we store the page (without server IDs), the site you came from, the device type and the browser language.
To count a day’s visitors without counting anyone twice, we compute a fingerprint from your IP address, your browser and a random value that changes every day. Your IP address is never stored, and neither is the fingerprint: only the number of distinct visitors is kept. The next day, nothing links your new visit to the previous one.
These figures are kept for 100 days. If your browser sends “Do Not Track”, you are not counted at all.
How long
- Activity logs, message excerpts included — 365 days, then deleted automatically.
- Security events — 180 days once handled. An alert nobody has handled yet is kept until it is.
- Reminders — until they are sent, then 30 days.
- Away status — until you are back.
- Automation run history — 30 days.
- Settings, moderation cases and suggestions — as long as the bot is on the server.
These cleanups run by themselves, once a day. They depend on no manual step.
If you remove the bot
Nothing is deleted right away, on purpose: a mistaken removal followed by a reinstall should find the configuration intact. The data stays available and simply stops being used.
For permanent deletion, ask for it — see below. It is done within 30 days.
Where the data lives
The bot and the site run on a server located in France. The database is hosted by Neon in Frankfurt, Germany (region eu-central-1). The data stays in the European Union.
Neon is an American company. Our agreement with them includes the European Commission’s standard contractual clauses, which govern any access from outside the Union. We mention it because it is information you should be able to find.
Who it is shared with
Nobody. Nothing is sold, rented or passed to third parties for commercial purposes. The only intermediaries are technical: the server host and the database host, who do not use this data for themselves. Discord, of course, sees what the bot posts there.
Your rights
The GDPR gives you the right to access your data, correct it, have it deleted, and object to its processing. To exercise one, write to us on the support server with the ID of the server concerned.
We answer within 30 days. If the answer does not satisfy you, you can refer the matter to the CNIL, the French data protection authority.
Minors
Discord requires a minimum age of 13, and more in some countries. Axaro does not knowingly collect data from younger people. If it has happened, tell us: we delete it.
If this text changes
The date at the top of the page prevails. A change that truly affects what we do with your data will be announced on the support server, not slipped in quietly.