Privacy Policy
This policy explains what data is processed when you use the TORVIX Discord bot and web dashboard, why it is processed, who it may be shared with, and what rights you have.
1. Scope and data roles
TORVIX is a bot and web dashboard that helps Discord servers manage support, moderation, automation, logging, analytics, and Premium access workflows.
The server administrator decides which features are enabled, which channels are monitored, and how long records are retained. For those activities, the server administrator may act as the data controller and TORVIX as a processor acting on instructions. TORVIX may act as an independent controller for account security, service operations, billing, and abuse prevention.
2. Categories of data processed
Depending on the features used and the server administrator's configuration, the following data may be processed:
- Discord user and server information: user ID, username, display name, avatar, email address, server ID, server name, roles, and permission information.
- Channel and role structure: channel/category IDs, names, types, ordering, and permission settings.
- Ticket and form data: messages, form answers, participants, timestamps, attachment metadata, closure records, and transcripts.
- Message and moderation logs: deleted or edited messages, action type, moderator, and target user information, but only for events enabled by the server administrator.
- Automation data: auto replies, custom commands, reminders, role panels, forum mappings, leveling settings, and server-specific configuration.
- Optional structural backups: roles, categories, channels, and role-based channel permissions. Messages, members, bans, invites, and user-specific permissions are not included in these backups.
- Dashboard security data: session cookies, Discord OAuth state values, IP address, browser information, access logs, and error logs.
- Payment data: provider, order and checkout identifiers, billing period, amount, currency, payment/subscription status, Discord user ID, and server ID. TORVIX does not receive or store card details, including card numbers, CVV values, or card expiry dates.
3. Discord sign-in and authorization
Dashboard sign-in uses Discord OAuth. TORVIX may use the identify and guilds scopes to verify your identity and the servers you manage, and the email scope to match payments.
The Discord access token is used for sign-in and server-list verification and is not stored as persistent application data. Dashboard sessions are protected with HttpOnly, Secure, and SameSite cookies.
4. Purposes of processing
- To operate ticket, transcript, moderation, logging, leveling, automation, and backup features.
- To show an authorized user only the Discord servers they can manage and the related settings.
- To match a Premium order to the relevant Discord server and activate, renew, cancel, or revoke access.
- To detect fraud, unauthorized access, abuse, security incidents, and technical errors.
- To comply with legal obligations, answer requests, and improve the service.
5. Retention periods
By default, message and moderator activity records are retained for 180 days, while trade and moderation records are retained for 365 days. Ticket transcripts have no automatic expiry by default. Server administrators can change these periods in the dashboard from 0 to 3650 days; 0 means that automatic deletion is not applied.
Last-message timestamps used for bulk-DM targeting are retained for no more than 30 days. Payment and accounting records may be retained for as long as required by legal retention duties, fraud prevention, and dispute resolution.
When the bot is removed from a server, new processing stops. Existing records may remain for the configured retention period or longer where required by an active dispute, security incident, or legal obligation.
6. Service providers and data sharing
Data is not sold. Discord, hosting/VPS, security/CDN, backup, and email infrastructure providers may process limited data where necessary to operate the service.
For PayNow.gg payments, users enter payment information directly on the PayNow checkout page. TORVIX receives only order, payment, and subscription status through webhooks or the API. When PayTR or Shopier is used, payment information is likewise processed by the relevant provider and card data does not reach TORVIX servers.
PayNow transactions are also governed by the PayNow Terms of Use, Buyer Agreement, and Privacy Policy: https://paynow.gg/legal/terms-of-use, https://paynow.gg/legal/buyer-agreement, https://paynow.gg/legal/privacy-policy.
Limited information may be shared with competent authorities where required by law or necessary to address a security threat, investigate fraud, or protect rights.
7. Legal bases
For users in the EEA/EU, processing may rely on performance of a contract, legitimate interests, compliance with legal obligations, and consent where required. Each server administrator is responsible for establishing an appropriate legal basis, providing required notices, and obtaining any necessary permissions for processing within their Discord community.
8. Security
TORVIX applies technical and organizational measures such as HTTPS/TLS, secure session cookies, server-scoped authorization, encrypted storage of sensitive data, access restrictions, audit logs, rate limiting, and backups.
No online system can guarantee absolute security. Vulnerability reports should follow the responsible disclosure process described in the Security Policy.
9. Rights and requests
Depending on applicable law, you may have rights of access, correction, deletion, data portability, restriction, and objection. For records created inside a Discord server, you may first need to contact that server's administrator.
For requests directed to TORVIX, email destek@torvixbot.xyz with your Discord user ID, the relevant server ID, and a description of your request. Additional information may be requested to verify identity and protect the rights of others.
10. Children, changes, and contact
TORVIX is not intended for people below Discord's applicable minimum age. Server administrators are responsible for ensuring that their communities comply with Discord rules and local age requirements.
This policy may be updated when the service or applicable law changes. Privacy questions may be sent to destek@torvixbot.xyz.