LEGAL
Lunar only stores what it needs to run the features a server turns on: your Discord identity when you sign in, the servers you can manage, and the per-server data the bot is asked to keep, such as levels, moderation cases, and logs. It does not collect your email, it does not sell or rent your data, it shows no ads, and it never uses your data to train AI or machine-learning models.
If you only ever talk to Lunar inside a Discord server, the most it keeps about you is set by what that server's admins enable.
Lunar ("Lunar", "we", "us") is a Discord bot and web dashboard owned and operated by Moonthia (moonthia.com), the data controller for the purposes of this policy. This policy covers the bot, the dashboard at thelunarbot.com, and the related services we run. Lunar may also operate on other community platforms in the future; where it does, this policy applies there too.
Lunar runs on Discord, and your use of Discord is also governed by Discord's own privacy policy and terms. We are not affiliated with or endorsed by Discord.
Signing in uses Discord's standard OAuth flow. We ask Discord for two things: your identity (the identify scope) and your list of servers (the guilds scope). From that we store your Discord user ID, your username, your display name, your avatar reference, and your locale, plus the servers you belong to with your roles and whether you own or administrate each one. We use the server list to show you only the servers you are allowed to manage.
We do not request or store your email address.
When you sign in we create a session and set a cookie so you stay signed in. Alongside the session we keep, on a best-effort basis, your IP address and browser user-agent for security and audit purposes. Sessions last up to 30 days and are refreshed as you use the dashboard.
Signing in with Discord gives us your user ID and nothing that can reach you anywhere else, which is a problem only when the thing we have to tell you about is a change to these policies. You can leave an email address in your account settings for that purpose. It is optional, we never ask for it anywhere else, and giving one is the only way we come to hold an email address for you.
The option is offered in one place, your account settings, and only to people who are using Lunar, meaning it is in a server you are in. Nobody browsing the site is asked for an address, and there is no form anywhere else that takes one. If you are not using Lunar there is nothing for us to notify you about, so we do not ask.
It is used for one thing: notices about changes to the terms, this policy, or the security model, written and sent by hand from [email protected]. Never for marketing, never for anything a server does, and never shared, including with Discord: when you opt in we are told that somebody did, without the address. You can remove it at any time in your account settings, which deletes it rather than marking it inactive, and it is included in any erasure request.
Where a server's admins add Lunar and turn features on, the bot keeps what those features need to work, and nothing is shared between servers. Broadly, that falls into:
A server's leaderboard and a member's profile card can be viewed without signing in, by anyone who has the link. What they show comes from leveling: rank, level, experience, and the name and avatar Discord already shows publicly. They do not show message content, moderation history, or anything from tickets. A server can also set its leaderboard to members only, in which case you have to sign in and Lunar checks you are in that server before showing you anything, or turn leveling off entirely.
So the operator can keep the closed-beta service healthy, certain events generate a notice to the operator and are recorded in the dashboard: when an approved user signs in, when someone who is not approved tries to, when Lunar is added to or removed from a server, and when permission grants are made. A sign-in notice includes the username and user ID involved.
We use the data above only to provide and operate Lunar: to run the features a server enables, to keep you signed in, to show the right information in the dashboard, to secure the service against abuse, and to let the operator respond to operational events during closed beta. We rely on our legitimate interest in running the service you asked for, and on Discord's authorization that you grant at sign-in.
Spam checks are the one place Lunar looks at recent message timing and repetition in memory to decide whether a burst breaks a server's rules. Nothing from that check is written to the database, and it is discarded as the window moves on.
Lunar is intentionally light on third parties:
Some features still on the roadmap, such as an AI you can talk to, would involve sending limited data to a provider to work. We will update this policy and disclose any such provider before a feature that needs it ships.
Sessions expire after up to 30 days. The message cache that makes edit and delete logging work is deleted after 30 days. Diagnostic records are deleted after 30 days. Other per-server data is kept while Lunar is in that server, so the features keep working.
When Lunar is removed from a server we record the date. Thirty days later that server's data is deleted automatically. Moderation records are kept longer, because a server may need to answer for them, and are deleted once they are both over twelve months old and the server has been gone for thirty days. Adding Lunar back within that window stops the clock and keeps the data.
Deletion means the rows are gone, not flagged. We keep a count of how many rows each run removed, and never a copy of what was in them. Case numbers are never reused, so a purge does not make an old case number point at a new case.
You do not have to wait for that clock. A server owner can erase a server from the dashboard, and anyone can erase their own records with the /lunar data delete command in Discord. Both run immediately rather than being queued, so they are done well inside the 30 days the law allows us.
Providing your data to Lunar is your choice: you choose whether to sign in, and a server's admins choose whether to add Lunar and which features to turn on. The trade-off is simply that without the relevant data a given feature, or the dashboard itself, cannot work for you. You can ask us what personal data we hold about you and to review it, ask us to correct it if it is wrong, incomplete, unclear, or out of date, and ask us to delete it, by emailing the address below; on request we can provide the information we hold about you in Hebrew, Arabic, or English. Server admins can already remove much of the per-server data directly from the dashboard, and can remove Lunar from a server at any time. Depending on where you live, you may have additional rights over your personal data, and we will honor valid requests to the extent the law requires.
We take reasonable measures to protect your data. The dashboard is served over HTTPS, session cookies are HttpOnly, signed, and marked Secure in production, sign-in is gated, and database queries are written to avoid injection. No system can be guaranteed perfectly secure, but we aim to collect little, keep it scoped, and guard it sensibly.
If a security breach affects your data, we will take appropriate steps to address it and provide any notifications required by the law that applies to you. If you think you have found a security problem, please report it through our Security page rather than disclosing it publicly.
Our terms require you to be at least 16 years old to use Lunar. You must also meet Discord's own minimum age for your country, and where that age is higher than 16 the higher age applies. Lunar is not directed to anyone below that age, and we do not knowingly collect their data. If you believe someone below it has provided data to Lunar, contact us and we will remove it.
Lunar is operated from Israel, and your data may be processed there and wherever the underlying platforms (such as Discord) operate. By using Lunar you understand your data may be handled in locations outside your own country.
Notices about changes to this policy are sent from [email protected]. Mail from any other domain is not from us.
While Lunar is in closed beta, we may update this policy at any time without prior notice, and the updated version applies from the date it is posted. Once Lunar leaves closed beta, we will give notice of material changes in advance. The "last updated" date at the top always reflects the current version.
Questions, or a request about your data? Email [email protected]. We answer data requests within 30 days, and usually the same week.
Moonthia is the data controller and can be written to directly at [email protected] for formal or regulatory correspondence. For anything else, [email protected]. See also our Terms of Service.