Skip to main content

Privacy Policy

Last updated:

How we handle information across accounts, hosting, and moderation.

1. Scope and contact

This policy explains how NexusHost handles information when you use its website, dashboard, hosting, and moderation features. NexusHost is responsible for the account and service administration described here. Send privacy questions and data requests to jairvianen@icloud.com. General support is available through https://discord.gg/nexushosts, and restricted users can submit moderation appeals through https://appeal.gg/HMAKgkmwkY.

Discord, PayPal, GitHub, appeal.gg, and other external services also process information under their own policies when you use them.

2. Information processed

Account information: Discord ID, username, avatar, and email address provided through Discord authorization, plus profile preferences, friends and requests, referrals, account limits, and subscription or entitlement status.

Hosted information: uploaded code and files, environment/configuration values, bot ownership and settings, deployment information, console output, and resource measurements. Information your bot handles may also be processed on the hosting infrastructure.

Operational and moderation information: requests and service logs, staff actions and access reasons, suspension and review records, and limited bot snapshots used for enforcement review. Support and appeal messages include information you choose to provide.

Payments: we store subscription identifiers and status needed to connect a purchase to your account. PayPal processes payment details; do not send card details to NexusHost staff.

3. Purposes and legal grounds

We use account and hosted information to authenticate users, run services, enforce resource entitlements, and provide requested account features. We use operational and moderation information to investigate abuse, protect users and infrastructure, and review decisions.

Where data-protection law requires a legal ground, processing to provide the requested service is based on the service relationship; security, abuse prevention, and service administration rely on legitimate interests, subject to your applicable rights. Records may also be processed to meet legal obligations. Features requiring consent use that consent where applicable; using this policy does not replace a separate consent choice.

4. Discord sign-in and server membership

Discord authorization supplies account details and may include permission to join the NexusHost Discord server. With that permission, NexusHost attempts to add your Discord account to the server and, where configured, assign a member role.

You can leave the server or revoke the application's authorization through Discord. Revoking authorization can affect future sign-in. NexusHost does not receive your Discord password.

5. Possible linked accounts

The account-integrity detector compares keyed hashes of recent sign-in network addresses and verified Discord email addresses, when available. A keyed hash is a protected matching value, not anonymous information. The detector does not store or display raw network addresses and does not use a persistent device-tracking cookie.

Network observations and alerts expire after 7 days without a matching sign-in; verified-email observations and alerts expire after 30 days. Expired records are excluded from results and deleted by scheduled cleanup.

Moderator-level roles and above can view possible account links. Sharing a network does not prove that two accounts belong to one person. Alerts support a human investigation and do not automatically suspend an account.

6. Network restrictions and reviews

Team members may request a network ban with a documented reason. Only the owner can apply, approve, or lift one. The feature stores a keyed network hash, target account ID, reason, creation details, and related audit or review information. Raw IP addresses are not stored or shown by this feature.

An active ban is retained until lifted and is checked for access enforcement. It can affect another person using the same network. Matching is automatic after the owner's decision; the decision to impose the restriction is made by a person. You can dispute an incorrect restriction through the appeal route.

Hosting and infrastructure providers may separately process network addresses in their own access, security, or service logs. The detector's no-raw-IP rule does not describe every provider's logging.

7. Staff access and hosted content

Role permissions limit administrative access. Authorized staff may inspect relevant bot files and console output for support, security, or moderation, and access reasons and actions may be recorded. Bot snapshots used for review may contain limited file content; they are not complete backups.

Protect secrets in your code, files, and logs. NexusHost does not use your uploaded code or hosted data to train an AI model. You remain responsible for the notices, permissions, and lawful handling of information your bot collects from other people.

8. Providers and external services

NexusHost uses hosting, database, and bot-server infrastructure to deliver the service, including Vercel, database storage such as Neon, and configured hosting nodes. Discord supplies sign-in; PayPal handles payments. GitHub is involved when you connect or deploy repositories, and appeal.gg handles appeals submitted there.

Relevant data is shared with a provider when necessary for the feature or service you use. Authorized team members receive information needed for their duties. We do not sell personal information. We may disclose relevant information when required by law or necessary to address security incidents or legal claims.

Providers may operate outside your country. Where applicable law requires protection for international transfers, those transfers must use an appropriate legal mechanism. External links and provider policies should be reviewed before submitting information.

9. Cookies and browser storage

The dashboard uses a signed session cookie, normally lasting up to 7 days after issue, with secure and HTTP-only settings in production. Signing protects its integrity; it does not mean its contents are encrypted. Short-lived Discord authorization cookies help verify the sign-in request and may carry a referral reference.

Browser storage also keeps settings such as theme, language, and dismissed notices. The account-integrity feature does not set a separate device identifier. External embeds, links, or advertising features, when enabled, may involve provider technology and must be considered under that feature's disclosures and applicable consent requirements.

When Google AdSense advertising is enabled on public pages, Google and its advertising partners may process network addresses, browser and device information, page activity, and advertising identifiers, and use cookies or similar storage to deliver, measure, and protect advertisements. Advertising is not enabled merely by publishing site-ownership verification. Where required, advertising uses a Google-certified consent platform to present choices before applicable advertising processing. Use the advertising consent controls to manage or withdraw your choices. Google's information about partner-site processing is available at https://policies.google.com/technologies/partner-sites.

10. Retention and deletion

Account records and hosted information are kept to operate active services. Account deletion removes the account record and associated account-link observations; it does not automatically erase all bot storage, payment records, support messages, or moderation evidence. Request removal of remaining personal data through the team.

Bot files and logs may be removed when a bot is deleted, logs rotate, or hosting storage is cleared. Recovery is not guaranteed. Enforcement history may include limited snapshots; audit, review, payment, and support records can remain where needed to investigate abuse, provide support, meet legal duties, or handle disputes. We do not promise a fixed 30-day backup window or a fixed support-message retention period.

Account-link signals have the 7-day and 30-day limits above. Active network-ban records remain until lifted; related audit or review history can remain separately. Data that is no longer needed should be removed, subject to applicable retention requirements.

11. Your choices and rights

Use available dashboard controls to view or update profile information, export bot files, or request account deletion. Email jairvianen@icloud.com for information or deletion requests that those controls cannot complete, including requests from suspended users.

Depending on applicable law, you may have rights to access, correct, erase, restrict, or object to processing, receive portable data, and withdraw consent where processing relies on it. Exceptions can apply, including for legal obligations and necessary security records. We may need to verify account ownership before responding.

You may complain to the data-protection authority or regulator available to you. A restriction on hosting does not remove your data-protection rights. Never send your password or bot token as identity verification.

12. Security, age requirements, and updates

We use authenticated access, role permissions, signed sessions, and protected connections to reduce security risks. No system can guarantee perfect security. Report suspected compromise promptly through support.

Use the service only if you meet Discord's minimum age requirement for your country and applicable requirements for using NexusHost. Contact the team if an account appears to belong to someone below that age.

We publish policy changes with a revision date and communicate material changes where required. This policy describes processing; it does not waive your legal rights or create consent for unrelated processing.