Skip to content

Privacy Policy

Last updated: August 17, 2026

This policy covers the Nighthawk bot and this dashboard. It describes every category of data we hold, why we hold it, how long we keep it, who else can see it, and the rights you have over it.

Who Controls Your Data

Nighthawk is installed by the people who run a community. That split matters for your rights:

  • Community data. For moderation records inside a given server (cases, appeals, notes, activity, message copies), the operators of that server decide what is collected and why. We process it on their behalf and on their instructions.
  • Service-wide data. For dashboard accounts, the Shared Watchlist and anti-raid detection, Nighthawk itself decides the purpose and means.

If a request concerns data inside one community, we may need to refer you to that community's operators, or consult them before acting. We will tell you when that happens.

What Data We Collect & Store

Nighthawk collects only what its configured features require. Depending on which features a server enables, that can include:

  • Identifiers: Fluxer user, server, channel, message and role IDs, along with usernames and server nicknames.
  • Name history: previous usernames and nicknames, with the time they changed.
  • Message copies: where moderation features require it, a short-lived copy of message content, attachment metadata and author details. This backs spam cleanup, deleted-message logging and incident replay, and is deleted after 7 days.
  • Moderation records: warns, mutes, kicks, bans, timeouts and notes, with the reason given and the moderator responsible.
  • Automod events: which rule fired, and the fragment of content that matched it.
  • Activity events: joins, leaves, message edits and deletions, used for raid detection and incident reports.
  • Appeals: the text you submit, your identifiers, and the staff decision and notes attached to it.
  • Verification records: a hashed challenge code or a one-time link token, its status and expiry, and failed attempt counts.
  • Persisted state: roles and nicknames stored so they can be restored if you rejoin.
  • Server configuration: settings, rules, role groups, channel bindings and reaction-role panels, plus an audit log of staff changes.
  • Dashboard accounts: for staff who sign in, the Fluxer account ID, username, avatar, assigned role and sign-in timestamps. We request only theidentify andguilds scopes, so we do not receive your email address.
  • Connection data: if a server turns on the VPN check, your IP address is examined when you open a verification link. See the Verification section.

We do not collect payment details, government identifiers, or any special category data (health, biometrics, beliefs, and similar). Please do not put such information into an appeal or a moderation note.

Why We Need This Data

We process this information to run the moderation and utility systems a server has configured, specifically:

Appeals

Processing and logging ban appeal forms submitted by users.

Cases

Logging moderation actions (warns, mutes, bans) into a searchable audit history.

Nickname Moderation

Detecting and restoring modified nicknames to enforce server guidelines.

Role Persistence

Automatically restoring roles and nicknames when members rejoin a community.

Automod

Matching messages against the rules a server configured, and recording what fired.

Anti-Raid

Spotting coordinated join floods and automated account behaviour.

Verification

Confirming that a joining member is a person rather than an automated account.

Incident Replay

Reconstructing what happened during an incident so staff can review it.

Our legal basis. For moderation, safety and abuse prevention we rely on legitimate interests: keeping communities safe and enforcing their rules, balanced against your interests, which is why retention is short and content copies are minimised. For dashboard accounts we rely on performance of a contract with the staff member. Where a server operator turns on an optional feature that goes beyond this, they are responsible for having a basis for it. You can object to processing based on legitimate interests at any time.

How Long We Keep It

Short-lived data is deleted automatically by a sweep that runs every hour. Records that exist to be a moderation history are kept until they are deleted by staff or on request.

DataKept forNotes
Message copies (saved_messages)7 daysDeleted automatically by an hourly sweep.
Deleted-message content inside incident reports7 daysStripped from the report; the report itself remains.
Activity events (joins, leaves, edits, deletions)14 daysMessage content within them is stripped at 7 days.
Bot status history (latency, server counts)30 daysOperational metrics only, no user data.
Automod events (rule hits)90 daysIncludes the matched fragment that triggered the rule.
Moderation cases, name history, persisted roles and nicknamesUntil deletedKept while the bot is in the server, as a moderation record. Removable on request.
Appeals and appeal decisionsUntil deletedKept as a record of the decision. Removable on request.
Shared Watchlist entries and reportsUntil removed or disputedSee the Shared Watchlist section below.
Anti-raid observationsUntil deletedPseudonymised. Used to measure and improve detection accuracy.
Dashboard account recordsUntil you ask us to remove itDeleted on request, or when access is revoked.
AI moderation usage counters13 monthsPer-server totals only (a server ID and a count). No message content, and nothing that identifies a member.
Subscription recordsUntil the subscription ends, then on requestWho pays, which server it applies to, and its status. Erasable once ended.
Invoices and payment records10 yearsHeld by Stripe, not by us. German tax and commercial law requires this, and it overrides a deletion request (Art. 17(3)(b) GDPR).

When Nighthawk is removed from a server, that server's stored data can be wiped on request from its operators.

The Shared Watchlist

This is the one feature where information about a user travels beyond the server it came from, so it deserves to be spelled out plainly.

Servers that opt in can report an account for raiding, scams and phishing, child safety, harassment, or malware. A report records the reported account ID, the reporting server, the reporting staff member, a category and a written reason. Other servers that have opted in can then see that an account has been reported, in which category, and with what confidence. Confidence rises when several independent servers report the same account, and a server's reports only start counting after it has taken part for 7 days.

  • Participation is off unless a server enables it. Servers that do not take part neither contribute nor receive.
  • A listing is information, not a sentence. Each server decides for itself what to do with it.
  • Reports are rate limited, and every report is attributable to the server that filed it.
  • You can dispute a listing. Use the dispute form. Disputes are reviewed by hand, and the message and contact details you provide are end-to-end encrypted so that only the reviewer can read them.

Automated Detection & Decisions

Nighthawk includes a machine-learning anti-raid system. It scores joining accounts on behavioural signals such as join timing relative to others, account age and profile characteristics. It does not read your messages to do this.

  • The default response is an alert to staff, not a removal. A human decides what happens.
  • A server may configure a stricter automatic response, up to requiring verification, a timeout, a kick or a ban. Where that is enabled, a decision that removes or silences you can be made without a person reviewing it first.
  • You have the right to contest it. Ask for a human to review the decision through that server's appeal form, or contact us. Any moderation action taken this way is recorded as a case with its reason, so it can be examined and reversed.
  • Scored observations are stored under a salted, irreversible hash of the account ID rather than the ID itself, and are used to measure and improve accuracy.

AI Moderation

A server may switch on AI Moderation. When it is on, the text of messages posted in that server, and image attachments if the server also enables that, are sent to OpenAI's moderation service to be scored for categories such as harassment, threats and sexual content. It is off by default and no server sends anything until an administrator turns it on.

  • Not everything is sent. Very short messages, bot commands and messages that are only emoji or mentions are filtered out before any request leaves the server. Repeated identical text, such as raid spam, is answered from a short-lived local cache rather than being sent again.
  • Nothing is stored at OpenAI for training.Content sent to the moderation endpoint is not used to train models. We keep only a per-server count of how many checks were made, never the content or who wrote it.
  • This is a transfer outside the EEA. OpenAI processes in the United States under Standard Contractual Clauses.
  • Legal basis. Legitimate interests (Art. 6(1)(f)): keeping a community free of abusive content. The server operator decides whether to enable it and is the controller for that choice. You can object, see Your Rights below.
  • A score crossing a threshold triggers the same automod pipeline as any other rule, so the automated-decision protections described above apply to it in full, including your right to have a person review the outcome.

Payments & Subscriptions

Nighthawk DeepIntel is an optional paid plan that raises one server's AI Moderation allowance. This section only concerns people who buy it. Nothing here applies to members of a server.

  • We never see your card. Payment details are entered directly into a form served by Stripe and are transmitted to Stripe, not to us. We do not store, log or have any means of retrieving a card number.
  • Checkout asks for an address. Stripe collects it and Stripe keeps it; it is never sent to us and we have no copy of it. Nothing is shipped to you. It is there because Stripe will not offer Google Pay on a checkout that calculates VAT automatically unless the address field is present, and Stripe uses the same address to work out which country's VAT rate applies.
  • What we store: your Fluxer account ID, the Stripe customer and subscription IDs, which server the plan applies to, the plan status and renewal date, and the billing email address you gave Stripe at checkout. That email is the only one we hold, and we use it solely to tell you about your subscription when a direct message cannot reach you.
  • What we never send to Stripe: message content, member lists, moderation records, or anything about the people in your server. The only identifiers we attach to a payment are your account ID and the server ID.
  • Legal basis. Performance of a contract (Art. 6(1)(b)) for the subscription itself, and a legal obligation (Art. 6(1)(c)) for the invoice records.
  • Retention. Subscription records are erasable once the subscription has ended. Invoices are not: German tax and commercial law requires them to be kept for up to ten years, and Art. 17(3)(b) GDPR makes that obligation override a deletion request. Those records are held by Stripe.
  • You can cancel at any time from your profile page, without contacting us. Access runs to the end of the period you have already paid for.

Verification & IP Checks

Servers can require new members to pass a verification gate. Depending on the method, this stores a hashed code or a one-time link token, its status and expiry, and how many attempts failed.

If a server enables the VPN check, then when you open a verification link your IP address is sent to IPHub, which reports whether the address belongs to a VPN, proxy or hosting provider. We use that answer, plus the network operator and country it returns, to decide whether to let you through, and the server's staff may be notified that a flagged connection was seen.

  • No lookup happens at all when a server has both the block and alert options switched off.
  • We do not store your IP address in our database. It is held briefly in memory (up to 30 minutes) to avoid repeat lookups, and may appear in short-lived server logs.
  • The check fails open: if the lookup is unavailable, you are let through rather than refused.

Who Else Processes It

We do not sell your data, and we do not share it for advertising or profiling. We do rely on a small number of service providers to run Nighthawk, each bound to process data only on our instructions:

ProviderPurposeLocation
SupabaseManaged PostgreSQL database hosting.European Union (eu-west-1, Ireland)
VercelHosting for this dashboard, plus aggregate traffic and performance analytics.European Union, with global edge routing
SentryError and crash reporting, including sampled session replays of dashboard use.European Union / United States
IPHubVPN and proxy reputation lookups, only when a server enables the verification gate check.United States
FluxerThe platform Nighthawk runs on. All identifiers originate there.Per Fluxer’s own policy
OpenAIScores message text, and image attachments where a server enables it, for the AI Moderation feature. Only servers that switch it on send anything. Content is not used to train models.United States (Standard Contractual Clauses)
StripePayments and subscription billing for Nighthawk DeepIntel. Receives your billing details, email and checkout address directly; none of it reaches our servers, and card numbers never do.European Union / United States (Standard Contractual Clauses)
ResendSends subscription emails, and only when a direct message could not be delivered.European Union

International transfers. Your data is stored in the European Union. Where a provider processes data outside the EU or UK, that transfer relies on the European Commission's Standard Contractual Clauses or an adequacy decision.

Session replay. To diagnose faults, Sentry records a sample of dashboard sessions, and records the session around an error when one occurs. Text content is masked and media is blocked in these recordings, so they capture layout and interaction rather than what is written on screen. This applies to the staff dashboard, not to the bot.

We may also disclose data where the law requires it, or where it is necessary to investigate abuse or protect someone's safety.

Cookies & Local Storage

  • Strictly necessary. Signing in to the dashboard sets a session cookie. Without it, staff cannot stay logged in.
  • Analytics. Our traffic and performance analytics are cookieless and produce aggregate counts, not profiles of individuals.
  • Diagnostics. Error reporting and session replay use browser storage to tie events within one visit together.

We do not use advertising or cross-site tracking cookies.

How We Protect It

  • End-to-end encryption. Appeal text, staff notes and watchlist disputes can be encrypted so that only the intended holder of the private key can read them. We cannot read those fields.
  • Encryption at rest. Sensitive columns, including message copies, case reasons, matched automod content, nicknames and incident data, are encrypted per server with keys that are themselves wrapped by a master key held outside the database.
  • Access control. Every database table enforces row-level security, dashboard access is restricted to approved staff accounts, and staff changes are recorded in an audit log.
  • Data minimisation. Message content is kept for the shortest window the features allow, and exports deliberately exclude stored message content.

No system is perfectly secure. If a breach affects your personal data, we will notify the relevant supervisory authority within 72 hours where required, and inform affected users without undue delay when the risk to them is high.

Your Rights

If you are in the European Economic Area or the United Kingdom, you have the following rights. We extend them to everyone who uses Nighthawk.

  • Access: a copy of the data we hold about you.
  • Rectification: correction of anything inaccurate.
  • Erasure: deletion of your data, subject to a server's need to keep a moderation record, and to invoices we are required by tax law to retain.
  • Restriction: pausing our use of your data while a dispute is resolved.
  • Objection: objecting to processing we base on legitimate interests.
  • Portability: your data in a machine-readable format.
  • Human review: contesting an automated moderation decision, as described above.
  • Objection to AI Moderation: you can object to your messages being scored. Raise it with the server's operators, who choose whether the feature runs, or contact us.

To exercise any of these, contact us using the details below. We will respond within one month. There is no charge. If we cannot act, for example because a request concerns a moderation record a server operator must retain, we will explain why.

You also have the right to complain to your local data protection supervisory authority.

Children

Nighthawk is not directed at children. It is used on Fluxer and is intended for people who meet Fluxer's minimum age requirement. We do not knowingly collect data from anyone below it. If you believe a child's data has been collected, contact us and we will delete it.

Changes to This Policy

When this policy changes we update the date at the top of this page. For changes that materially affect what we collect or how we use it, we will announce it in our support community before the change takes effect.

Contact & Data Requests

To exercise any of the rights above, request deletion, or ask how Nighthawk handles your data, email us at contact@nighthawk.bot. This is the address to use for anything formal, because it gives both of us a written record and starts the one-month response clock.

Please include the account ID and the server involved so we can find the right records. For general questions and setup help, our support community is usually faster.