This Privacy Policy explains what information the Discord bot "Stellarix" and its
companion web dashboard (stellarix.org, together "the Service") collect,
how that information is stored, and how it is used.
1. Operator
The Service is developed and operated by an individual, melty. You can reach us via our Support page.
2. Information We Collect
The Service stores only the information necessary to provide its features, in a SQLite database. We do not store the content of your messages (see "4. Information We Do Not Collect" below).
2.1 Per-server feature settings
| Data | Details | Retention |
|---|---|---|
| X/Steam embed settings | Server ID, on/off state per feature | Until changed (not automatically removed even if the bot is removed from the server) |
| Verification panel settings | Server ID, channel ID, message ID, verification method, granted role ID, panel title/description text entered by an admin, the admin's user ID | Kept as a record even after being deactivated (not physically deleted) |
| Voice hub settings | Server ID, trigger channel ID, target category ID, channel name template, member limit, the admin's user ID | Same as above |
| Log channel setting | Server ID, destination channel ID for moderation logs | Until the setting is removed |
| Member counter settings | Server ID, target channel ID, counter type, the admin's user ID | Kept as a record even after being deactivated |
| Recruitment form settings | Server ID, channel ID, message ID, title/description text, capacity, the admin's user ID | Kept as a record even after being deactivated |
Note: Member counters fetch the current member count from the Discord API each time they refresh. We do not store historical counts or a roster of individual members.
2.2 Information about individual users
| Data | Details | Retention |
|---|---|---|
| Temporary voice channel ownership | Channel ID, owner's user ID | Deleted immediately when the voice channel becomes empty and is removed — the shortest-lived data we store |
| Moderation action log | Target user's ID, the acting admin's user ID, action type (ban/kick/lockdown/unlock), the reason text entered by the admin, timestamp | Currently kept indefinitely, with no automatic deletion or retention limit, since it serves as an audit log for server admins |
| Recruitment form entries | Participant's user ID, the free-text comment the participant entered, join timestamp | Kept until the participant withdraws. This is the only place where the Service stores free text that a user chose to submit |
2.3 Web dashboard login information
When you log in with your Discord account, we store the following in a cryptographically signed cookie in your browser (a session). We do not store this in our server-side database.
- Your Discord user ID, username, and avatar hash
- The list of servers (ID, name, icon) where you had "Manage Server" permission at the time you logged in
This session expires automatically after 12 hours, after which you'll need to log in again. We do not store your Discord access token or refresh token on the web side. They are used once, during login, to fetch your profile and server list, and are discarded immediately afterward.
3. How We Use This Information
We use the information we collect only to:
- Provide the Service's features (embed conversion, verification panels, voice hubs, moderation, member counters, recruitment forms)
- Let you view and change settings on the web dashboard, and verify you're authorized to do so (that you hold "Manage Server" permission on the server in question, and that Stellarix is installed there)
- Investigate the cause of bugs when they occur, using standard server operation logs
We do not use your information for advertising, do not sell it to third parties, and do not track your behavior.
4. Information We Do Not Collect
- Message content: the X/Steam link embedding feature reads messages in order to repost them as rich embeds, but we do not store the message content itself in our database.
- Discord access or refresh tokens (see above)
- Advertising or analytics cookies/trackers: we do not use analytics tools such as Google Analytics.
Our web server (nginx) may, as standard practice, temporarily record access logs (source IP address, request time, requested URL, and so on). This is a routine measure for server operation and troubleshooting — not a form of user analytics specific to the Service.
5. Sharing Information with Third Parties
We do not sell or share the information we collect with third parties. Providing the Service inherently involves communicating with the Discord API operated by Discord Inc., which is governed by Discord's own privacy policy.
6. Deleting Your Data
We do not currently offer a fully self-service way to delete your data (the "deactivate" actions in the dashboard mark a record as inactive rather than deleting it). If you'd like data deleted, please contact us via our Support page.
7. Security
We connect to the database only for as long as each operation takes, rather than holding a persistent connection open, which also lets multiple processes access it safely at the same time. That said, no internet service can be guaranteed to be completely secure.
8. Minors
In line with Discord's own Terms of Service, the Service is not intended for use by anyone who does not meet Discord's eligibility requirements.
9. Changes to This Policy
We may revise this Policy at any time to reflect changes to the Service. Material changes will be reflected in the "Last updated" date above.
10. Contact
Questions about this Policy can be directed to our Support page.