What Lunar collects, why it needs it, and the things it will never do with it.
Lunar only stores what it needs to run the features a server turns on: your Discord identity when you sign in, the servers you can manage, and the per-server data the bot is asked to keep, such as levels, moderation cases, and logs. It does not collect your email, it does not sell or rent your data, it shows no ads, and it never uses your data to train AI or machine-learning models.
If you only ever talk to Lunar inside a Discord server, the most it keeps about you is set by what that server's admins enable.
Lunar ("Lunar", "we", "us") is a Discord bot and web dashboard operated by Krislyz. This policy covers the bot, the dashboard at thelunarbot.com, and the related services we run. Lunar may also operate on other community platforms in the future; where it does, this policy applies there too.
Krislyz is an independent developer who builds and runs Lunar. You can find Krislyz on the web at krislyz.com, on GitHub at github.com/krislyz, and on Discord as @krislyz.
Lunar runs on Discord, and your use of Discord is also governed by Discord's own privacy policy and terms. We are not affiliated with or endorsed by Discord.
Signing in uses Discord's standard OAuth flow. We ask Discord for two things: your identity (the identify scope) and your list of servers (the guilds scope). From that we store your Discord user ID, your username, your display name, your avatar reference, and your locale, plus the servers you belong to with your roles and whether you own or administrate each one. We use the server list to show you only the servers you are allowed to manage.
We do not request or store your email address.
When you sign in we create a session and set a cookie so you stay signed in. Alongside the session we keep, on a best-effort basis, your IP address and browser user-agent for security and audit purposes. Sessions last up to 30 days and are refreshed as you use the dashboard.
Where a server's admins add Lunar and turn features on, the bot keeps the data those features need, scoped to that server:
So the operator can keep the closed-alpha service healthy, certain events generate a notice to the operator and are recorded in the dashboard: when an approved user signs in, when someone who is not approved tries to, when Lunar is added to or removed from a server, and when permission grants are made. A sign-in notice includes the username and user ID involved.
We use the data above only to provide and operate Lunar: to run the features a server enables, to keep you signed in, to show the right information in the dashboard, to secure the service against abuse, and to let the operator respond to operational events during closed alpha. We rely on our legitimate interest in running the service you asked for, and on Discord's authorization that you grant at sign-in.
Lunar is intentionally light on third parties:
Some features still on the roadmap, such as music or an AI you can talk to, would involve sending limited data to a provider to work. We will update this policy and disclose any such provider before a feature that needs it ships.
Sessions expire after up to 30 days. The message cache used for edit and delete logging is short-lived and pruned on a schedule. Other per-server data is kept while Lunar is active in that server so the features keep working.
During closed alpha, removing Lunar from a server does not yet automatically erase that server's stored data. If you want a server's data, or your own data, removed, contact us and we will delete it. An automatic cleanup when Lunar leaves a server, and a self-serve opt-out, are planned.
Providing your data to Lunar is your choice: you choose whether to sign in, and a server's admins choose whether to add Lunar and which features to turn on. The trade-off is simply that without the relevant data a given feature, or the dashboard itself, cannot work for you. You can ask us what personal data we hold about you and to review it, ask us to correct it if it is wrong, incomplete, unclear, or out of date, and ask us to delete it, by emailing the address below; on request we can provide the information we hold about you in Hebrew, Arabic, or English. Server admins can already remove much of the per-server data directly from the dashboard, and can remove Lunar from a server at any time. Depending on where you live, you may have additional rights over your personal data, and we will honor valid requests to the extent the law requires.
We take reasonable measures to protect your data. The dashboard is served over HTTPS, session cookies are HttpOnly, signed, and marked Secure in production, sign-in is gated, and database queries are written to avoid injection. No system can be guaranteed perfectly secure, but we aim to collect little, keep it scoped, and guard it sensibly.
If a security breach affects your data, we will take appropriate steps to address it and provide any notifications required by the law that applies to you. If you think you have found a security problem, please report it through our Security page rather than disclosing it publicly.
Lunar is used through Discord, and you must meet Discord's minimum age for your country to use Discord at all (13 in many places, higher in some). Lunar is not directed to children under that age, and we do not knowingly collect their data. If you believe a child has provided data to Lunar, contact us and we will remove it.
Lunar is operated from Israel, and your data may be processed there and wherever the underlying platforms (such as Discord) operate. By using Lunar you understand your data may be handled in locations outside your own country.
While Lunar is in closed alpha, we may update this policy at any time without prior notice, and the updated version applies from the date it is posted. Once Lunar leaves closed alpha, we will give notice of material changes in advance. The "last updated" date at the top always reflects the current version.
Questions, or a request about your data? Email [email protected], or reach Krislyz on Discord at @krislyz. See also our Terms of Service.