LunarisbyAsta
DocsStatusHome
Lunaris
byAsta

Privacy Policy

Last updated August 8, 2026

This policy explains what data Lunaris collects when you add the bot, use the dashboard, or verify through it: why we collect it, and the control you have over it. We collect only what we need to run the features you enable.

01The short version

Lunaris is operated privately from Germany, free of charge. No money changes hands, and your data is never sold, rented or shared with advertisers.

We store your Discord ID, the settings a server configures, moderation records, and activity counts for the features a server switches on: levels, invites, tickets and similar.

Some things exist only if you create them yourself: a birthday (the year is optional), a timezone, to-dos, playlists, highlight keywords, or a linked Last.fm account.

We do not store your messages. The single exception is a backup a server owner runs by hand, which can include recent messages so a restore can replay them.

We do not monitor your DMs. Modmail is the one exception, and you start it.

If a server lets you appeal a ban, what you write and any proof you attach is stored and shown to that server's staff.

Closed tickets and decided appeals become a web page that you and the server's staff are both linked to. Anyone with that link can read it, so do not pass it on. It is deleted automatically after 30 days.

Run /optout and we erase your tracked activity immediately and stop collecting. No reason needed.

When a server removes the bot, everything stored for that server is deleted after 7 days.

You can ask for a copy of your data, a correction, or full deletion at any time: [email protected].

Mail you send there lands on our own server in Germany without passing through Cloudflare. Our replies go out through Mailjet, a French company, because our connection has no fixed address, so they see what we write back to you.

Everything below is the same policy in full detail. If the two ever seem to disagree, tell us, because they should not.

02Who is responsible for your data

The controller for the processing described below, within the meaning of Art. 4(7) GDPR, is:

Jean-Piere Trautmann

Frankfurter Str. 81

35578 Wetzlar, Germany

Email: [email protected]

Lunaris is operated by a private individual and is provided free of charge. No company or other legal entity stands behind it, and no payment is taken for any feature.

03Information we collect

Account data via Discord OAuth: your user ID, username, avatar and the list of servers you can manage. We use this solely to sign you into the dashboard and verify you are allowed to configure a given server.

Server configuration: the settings you create: enabled modules, welcome messages, ticket panels, role rewards, log channels and similar. This is stored against your server ID so your setup persists.

Dashboard action log: administrative actions taken on the dashboard, who performed them, what changed, and when: are logged for accountability and to investigate misuse. This is retained even if you opt out or ask us to erase your data.

Moderation records: cases you create (bans, warns, mutes) with the target ID, moderator ID, reason and timestamp, so you can look them up later.

Activity counts: message totals, voice time, and command usage used for the leveling system and global stats, stored as aggregate numbers: not message content.

Avatar & username history: when you change your Discord avatar or username, the previous value is saved so the /history command works.

Music listening history: your last 30 played tracks (title, author, URL) and any custom playlists you create.

Verification data: if a server enables the verification module, completing it authorizes our Discord application with the identify and guilds scopes. We read your server membership at that moment to check a configured blacklist, then discard the list. We keep a permanent record that you passed verification: your Discord ID, the server, and when, so the server can tell who is verified; this is not removed by /optout.

Profile and fun features you opt into yourself: your birthday, including the birth year, if you choose to give one: your timezone, economy balances and inventory, marriage status inside the bot, and personal to-do entries. None of these exist unless you run the command that creates them.

Highlight keywords: words you ask to be alerted about. To make this work the bot compares messages in servers where the module is enabled against your keywords, in memory. Your keywords are stored; the messages are not.

Server engagement records, who invited you to a server and the resulting invite counts, suggestions you post and votes you cast on them, and entries in giveaways or lotteries.

Staff records: if you apply to or serve on a server's team through the teams portal, we store your application answers, any warnings and points issued to you, absences, complaints, case records, and meeting and event records.

Notes written about you: a server's staff can attach private moderator notes to your account, visible to that server's staff only. Like moderation records, these are not removed by /optout.

API access: if you're granted an API key, we store your Discord ID, a label you choose, the permissions it has, and when it was last used, so keys can be issued, audited and revoked.

Linked accounts: if you connect Last.fm, we store the username you give us and send it to Last.fm's API to retrieve your listening data.

Tickets and modmail: when you open a support ticket or a modmail thread, we store the thread identifiers, its contents, and any staff notes attached to it.

Ban appeals: if a server enables appeals and you choose to appeal a ban, we store your answers to that server's questions, the decision reached, when it was made, who made it, and any note the staff wrote back to you. The staff member who decided your appeal is named to you. If you attach image proof, a copy of that image is embedded into the appeal record. Appealing is entirely voluntary; if you never open an appeal, none of this exists.

Transcripts: when a ticket is closed or a ban appeal is decided, we generate a web page containing it: the messages or answers, the display name, user ID and profile picture of everyone who took part, and any images attached, and both you and the server's staff are sent a link to it. Transcripts are not removed by an erasure request, because they delete themselves 30 days after they are created and we keep them only for the remainder of that period. Anyone holding that link can read the page; there is no login. The link contains a long random value that cannot be guessed or found through search engines, so in practice only the people it was sent to can open it. Every transcript is deleted automatically 30 days after it is created.

04Server backups (premium)

Premium servers with backups enabled get an automatic structural snapshot (channels, roles, permissions: no message content) taken periodically, with only the latest snapshot kept at any time.

A manually-triggered backup additionally stores up to the last 100 messages per text channel: author name, avatar URL, content, embeds and attachment URLs, so a restore can replay them through webhooks. This is the one place Lunaris persists message content, and it only happens when an authorized server owner or extra owner explicitly runs the backup command. Deleting a backup permanently removes that stored data.

05Data we are required to keep

Certain data must be retained for the bot to function correctly, uphold server safety, and comply with Discord's Terms of Service. This data cannot be deleted or opted out of, even if you request data removal or enable data untracking.

This includes: guild configuration (required for the bot to operate), active bans (required to enforce them on rejoin), mutes and timeouts (required to lift them automatically), warnings and moderation cases (required for audit trails), moderator notes attached to your account, your automated-moderation violation history, blacklists (required to prevent access where prohibited), premium status, anti-nuke state and whitelist, active voice sessions, open ticket data, scheduled reminders, verified-member status, the dashboard administrative action log, and the global bot blacklist.

06What we do not store

Outside of explicit, owner-triggered backups described above, message content is processed in memory for AutoMod, command parsing and highlight matching, and is never written to our database. The snipe command keeps the most recent deleted messages briefly in memory only and they are discarded automatically.

We do not monitor your direct messages. The one exception is modmail: if you message the bot to open a thread with a server's staff, that conversation is relayed to them: you start it, and nothing else in your DMs is involved.

We never sell or rent your data to anyone.

07How we use your data

To provide the features you turn on, to keep your configuration between sessions, to authenticate you on the dashboard, and to run verification checks you've configured.

08Our legal basis for processing

Art. 6(1)(b) GDPR: performance of a contract: signing you into the dashboard, storing the server configuration you create, and delivering the features a server has enabled. This is what you ask us to do when you add the bot or log in.

Art. 6(1)(f) GDPR: legitimate interests: moderation records, anti-nuke state, blacklists and the global bot blacklist. Our legitimate interest is keeping servers safe from raids, nuking and ban evasion, and giving moderators an auditable record of actions taken. We consider this proportionate because the data is limited to IDs, reasons and timestamps, and never message content.

Art. 6(1)(f) GDPR: legitimate interests: leveling and activity counts, avatar and username history, and music listening history and playlists. These run by default in servers that enable the relevant module, because the features cannot work without them: a level system with no activity counts does nothing. We keep the data minimal, we do not use it to build a profile of you outside the servers it came from, and we do not share it.

Art. 6(1)(b) GDPR: performance of a contract, again: features you actively ask for by running a command, such as setting a birthday, a timezone, a to-do, a highlight keyword, an economy balance or a Last.fm link. You requested them; we store what is needed to deliver them and nothing more.

Art. 6(1)(f) GDPR: legitimate interests: ban appeals. You submit one yourself, and it exists so a server can reconsider a ban and so you have a route to contest one. The interest is shared between you and the server that banned you. We keep only what you wrote, the attachments you linked, and the outcome.

Art. 6(1)(f) GDPR: legitimate interests: staff records in the teams portal: applications, warnings, absences, complaints and meetings. The interest is the server's, in running its own staff team; we hold this data on that server's behalf.

You have an unconditional right to object to the legitimate-interest processing under Art. 21 GDPR. Run /optout and we stop immediately and permanently delete what was already collected. You do not have to give a reason, and we will not ask for one.

09Data sharing

Your data is stored on infrastructure we control and self-host in Germany (PostgreSQL and Redis). We use no advertisers and no third-party analytics, and we never sell or rent your data.

Discord Inc.: unavoidable, as the bot runs on Discord. Discord is an independent controller and its own privacy policy governs what it does with your data.

Cloudflare, Inc.: our domains are served through Cloudflare, so requests to lnrs.dev and its subdomains pass through Cloudflare's network. They act as our processor under a data processing agreement and do not use the traffic for their own purposes.

Last.fm: only if you link a Last.fm account. We send the username you provided to their API to fetch your listening data. If you never use the feature, nothing is sent.

Mailjet: if you write to us at [email protected], your message arrives on our own mail server in Germany. It does not pass through Cloudflare: the mail record for lnrs.dev points straight at our own machine. Our replies are different, because our connection has no fixed address we cannot send mail directly, so we hand it to Mailjet SAS in Paris, who deliver it for us. They are our processor under Art. 28 GDPR, established in the EU, so no transfer outside the EU/EEA is involved. They see the messages we send you.

10Transfers outside the EU

Some of the recipients listed above are based in the United States, so using Lunaris involves data being transferred outside the EU/EEA.

Discord Inc.: the European Commission has adopted an adequacy decision for the EU–U.S. Data Privacy Framework, and transfers are covered by it to the extent Discord participates. Discord is an independent controller rather than our processor, so its own transfer safeguards and privacy policy govern what happens to your data once it is on Discord.

Cloudflare, Inc.: covered by Cloudflare's data processing addendum, which incorporates the European Commission's standard contractual clauses.

Last.fm: engaged only if you link an account, and limited to the username you gave us.

Mailjet: French, processing in the EU. Email you exchange with us therefore involves no third-country transfer at all.

Our own servers, and every database holding your data, are in Germany.

11Cookies & local storage

We run no analytics, no advertising and no tracking cookies of any kind, and we embed nothing from a third party. There is no cookie consent banner because there is nothing to consent to: everything we store on your device is either strictly necessary to sign you in, or a preference you set yourself. § 25(2) TDDDG exempts both from consent.

The complete list: a session cookie that keeps you signed in to the dashboard, set for one host only and not shared across our subdomains; your chosen interface language; and which announcements you have dismissed. The last two live in your browser's local storage and are never sent to us.

12Automated decisions

The anti-nuke module can ban an account automatically, without a human reviewing it first, when a server has enabled it and the account takes a protected action while not whitelisted. The decision is made by the server's own configuration, not by us, and its effect is limited to that one Discord server.

If you believe an automated ban was wrong, contact the server's staff, or reach us using the details below and we will explain what was recorded and why. Where a server has enabled ban appeals, the bot will message you with a way to contest the ban directly, and a human on that server's staff decides the outcome.

13Your rights & data controls

Access & Export: you can request a full export of your stored data.

Deletion: you may request permanent removal of your data. Because certain data is operationally required (see above), that data will remain: everything else will be erased.

Data collection opt-out: you have the right to opt out of non-essential data collection at any time by running the /optout or l?optout command. When opted out, your previously logged activity is permanently deleted and the bot stops tracking you moving forward. You will not be able to generate API keys or be included in server backups. Moderation history will still be recorded for server safety. You can reverse this at any time using the /optin or l?optin command.

Rectification (Art. 16 GDPR): you can ask us to correct inaccurate data we hold about you.

Restriction (Art. 18 GDPR): you can ask us to stop processing data while a dispute about its accuracy or our legal basis is resolved.

Objection (Art. 21 GDPR): for activity tracking, levels, history and playlists, /optout is the objection: it is honoured immediately and unconditionally. For moderation records, anti-nuke state and blacklists you can also object on grounds relating to your situation, but these are the case where we will usually have compelling grounds to continue, because they exist to keep servers safe.

Portability (Art. 20 GDPR): for data you gave us or that we process on consent or contract, you can ask for a copy in a structured, machine-readable format.

14Complaints

If you think we have handled your data unlawfully, you have the right to complain to a supervisory authority (Art. 77 GDPR): either in the EU country where you live or work, or the one responsible for us:

The Hessian Commissioner for Data Protection and Freedom of Information: official name "Der Hessische Beauftragte für Datenschutz und Informationsfreiheit": Postfach 3163, 65021 Wiesbaden, Germany.

We would rather hear from you first, so please do contact us, but you are not required to.

15Retention & deletion

Configuration and records are kept while Lunaris is in your server. When the bot is removed, everything stored for that server is permanently deleted after a 7-day grace period. The delay exists so that an accidental kick, or removing and re-adding the bot, does not destroy a server's entire moderation history. Re-adding Lunaris within those 7 days cancels the deletion.

Once the grace period passes the purge is complete: configuration, moderation cases, notes, tickets, stats, backups and every other table holding data for that server.

Transcripts of closed tickets and decided ban appeals are deleted automatically 30 days after they are generated, whether or not the bot is still in the server. After that the link stops working permanently and the stored copy is removed from our database.

Your own data is separate from any server's. Run /optout to erase your tracked activity immediately, or contact us to request full erasure. Backups can be deleted at any time from the dashboard or with /backup delete.

16Security

Access to the dashboard is gated by Discord OAuth and authorization is checked per-server on every request. Session cookies are host-only and are not shared across our subdomains. Secrets are never exposed to the browser.

Transcript links are deliberately readable by anyone who holds them, because a banned user cannot log in to a server they are banned from. The link is protected by a 128-bit random value rather than a password, which makes guessing one infeasible, and transcript pages are excluded from search engines and send no referrer information. The trade-off is real: if you forward the link, whoever receives it can read the transcript. Treat it as you would the contents itself.

17Children

Lunaris is intended for Discord users who meet Discord's minimum age requirement (13+, or higher where local law requires). We do not knowingly collect data from anyone below that age.

18Changes

We may update this policy as features change. Material changes will be announced in the support server, and the "last updated" date above will reflect the revision.

19Contact us

To exercise your rights, ask questions about this policy, or request data deletion:

Email: [email protected]

Discord: discord.gg/F7PkFjm4n4

Questions? Reach us in the Lunaris support server.
ImprintPrivacyTerms