Global Privacy Policy
Last Updated: May 09, 2026
Community Partnership & Data Responsibility
This document honors and governs all users residing outside the European Union (EU) and the United States (US). Throughout this agreement, the community leader integrating the bot is warmly referred to as the "Guild Owner".
Aegitox is proud to operate as your B2B Infrastructure Provider (Data Processor). By uniting our bot with your server via Discord OAuth2, you step into the vital role of the Primary Data Controller. Together, we ensure your server operates in perfect harmony with your local digital and privacy laws, with you guiding your community's compliance and assuming the responsibility for the platform's local deployment.
Jurisdiction Notice:
If you are a resident of the United States, please proceed to our strictly optimized US Privacy Policy
If you are a resident of the European Union, EEA, or UK, please proceed to our fully compliant EU Privacy Policy
1. Global Infrastructure & Cross-Border Transit
To provide lightning-fast, highly resilient moderation, Aegitox is hosted on enterprise-grade infrastructure physically located within the United States. We focus our global resources here to ensure maximum stability for your server.
Authorizing Data Transit: By seamlessly integrating Aegitox, you authorize the transit of your community's contextual data to the United States to utilize our API. As the community leader and Data Controller, you smoothly manage the lawful basis for this international transfer under your local telecommunications and privacy regulations, ensuring your members enjoy a safe and uninterrupted experience.
2. Discord Ecosystem Harmony & AI Transparency
- Zero-Retention & Inference-Only: We possess a profound respect for the Discord Developer Policy. Aegitox utilizes third-party Large Language Models (LLMs) strictly for real-time inference to uphold community guidelines. We unequivocally DO NOT use Discord API data to train or fine-tune machine learning models.
- Empowering Your Governance: Aegitox acts as a deterministic, supportive conduit. Because generative AI is probabilistic and may occasionally misinterpret nuance, we provide the service "AS IS". Final administrative authority always resides with you. To keep innovation thriving, you kindly agree to assume the liability for any automated actions, timeouts, or AI-rewritten text occurring on your server, shielding Aegitox from external disputes.
- Building Trust Through Transparency: To foster a healthy environment and comply with global transparency mandates (such as anti-impersonation standards), text gracefully paraphrased by our AI is conspicuously labeled by default (e.g., "✨ Upgraded by Aegitox AI"). This builds trust with your users and perfectly aligns your server with international synthetic media guidelines.
3. Data Minimization, Analytics & RLS Isolation
Data Minimization in Action: To empower you with beautiful, real-time analytics on the Aegitox Dashboard, we dynamically cache only the most essential, minimized metrics required for functionality.
- Display Data:
GlobalNameandServerName. To respect platform limits and prevent abuse, these are safely restricted to 256 characters. - Behavioral Insights:
KarmaScore(a fluid metric of community positivity) andViolationsCountto help you guide server culture. - Essential Identifiers:
GuildIdandUserId(Int64), necessary for platform routing.
Protecting Your Community's Ecosystem (Row-Level Security): Your community is your private sanctuary. Our PostgreSQL architecture enforces strict Row-Level Security (RLS). A user's Karma and behavioral profile are mathematically sealed within your specific Discord Server. We absolutely do not aggregate global profiles, track users across different communities, or act as a data broker. What happens in your server, stays in your server.
Gamification Only: Aegitox Karma is a fun, internal moderation tool. You agree to never utilize these metrics for real-world consequential decisions (like employment or credit evaluations), keeping the tool enjoyable and legally compliant.
4. Upholding Discord's Safety Standards for Youth
Privacy by Design (Volatile Processing): We stand firmly alongside Discord's commitment to user safety. Intercepted chat messages exist fleetingly in Volatile RAM. They are evaluated instantaneously by our AI and permanently destroyed by the Garbage Collector—never written to a persistent database.
The "Teen-by-Default" Framework: Aegitox is enterprise B2B software and respects Discord's native age-gating mechanisms. By partnering with us, you confidently guarantee that your community complies with local digital age of consent laws and is not improperly directed at children, shielding both our platform and your server from regulatory scrutiny.
5. Our Trusted Global Supply Chain
To deliver a world-class experience, we partner with industry-leading sub-processors:
- Hetzner Cloud: US-based, high-performance bare-metal infrastructure.
- Cloudflare: Global Edge CDN and rigorous Web Application Firewall.
- Supabase: US-based, highly secure PostgreSQL database management.
- Groq, Inc. (Enterprise Inference Cluster): Our strategic AI partner, featuring Global Zero Data Retention to ensure prompt privacy.
- Discord: Our esteemed host platform and Event Gateway, whose ecosystem we are privileged to support.
- PayPro Global: Independent Merchant of Record (Financial Data Controller). We entrust all global transaction processing to our highly respected partner to ensure maximum tax compliance and data security.
6. Global Compliance & Trade Regulations
To maintain our highly secure infrastructure and trusted banking relationships, Aegitox operates gracefully under United States Export Administration Regulations (EAR) and OFAC sanctions programs.
Honoring Global Embargoes: We kindly require that by accessing Aegitox, you confirm you are not located in, or a resident of, a comprehensively embargoed territory (such as Russia, Belarus, Cuba, Iran, North Korea, Syria, and the comprehensively sanctioned regions of Ukraine including Crimea, Donetsk, and Luhansk).
We value integrity. Attempting to bypass these essential global compliance measures via VPNs forces us to immediately terminate access to protect the network.
7. Protecting Our Partnership & Dispute Resolution
We view our relationship with Guild Owners as a collaborative partnership. To provide this powerful infrastructure globally, we rely on a clear understanding of mutual support and shared boundaries.
- Mutual Support (Indemnification): As you control the deployment of Aegitox within your unique community, you agree to indemnify and hold Aegitox harmless from local regulatory fines, legal claims, or lawsuits arising directly from your server's use of our moderation tools.
- Amicable Resolution (Arbitration): We aim to resolve any issues quickly and fairly. Any formal dispute will be resolved by binding, confidential remote arbitration via JAMS.
- Class-Action Waiver: You and Aegitox agree that claims may only be brought in your individual capacity, and absolutely NOT as a plaintiff or class member in any purported class, consolidated, or representative proceeding.
- Predictable Boundaries: To sustain B2B software at an enterprise scale, our total cumulative financial liability for any claims is respectfully capped at the amount you paid to our Merchant of Record in the twelve (12) months preceding the claim, or $100.00 USD, whichever is greater.
- Timely Resolution: Any claims must be brought forward within one (1) year of the incident, ensuring we address concerns while they are fresh.
8. Empowering Privacy & Secure Data Requests
We deeply respect your community's right to privacy. As the Data Controller, you guide your users' requests, and we provide the secure tools to execute them.
Cryptographic Security Mandate: To protect your server from social engineering and malicious data wiping, we enforce a zero-trust verification protocol. Data deletion requests (DSARs) must be executed seamlessly via our authenticated Angular dashboard or accompanied by a cryptographically signed JWT payload matching the Discord User ID. We safely ignore unverified direct emails to ensure your community's data remains uncompromised.
Strength in Structure (Severability): If any provision of this Global MSA is found unenforceable by a court of competent jurisdiction, that specific provision shall be limited to the minimum extent necessary, ensuring the absolute liability shield and remainder of the agreement remains in full force and effect.
For verified administrative inquiries: privacy@aegitox.com
9. Security, Authentication & Local Storage
To deliver a seamless, high-performance, and secure experience, the Aegitox platform utilizes the browser's Web Storage API (LocalStorage) rather than legacy HTTP cookies. In strict alignment with the European ePrivacy Directive, the General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA), we are committed to absolute transparency regarding the operational data residing on your device.
Strictly Necessary Data Inventory
We do not deploy LocalStorage for cross-site tracking, third-party marketing, or behavioral profiling. The localized data is legally classified as "Strictly Necessary" to provide the explicitly requested administrative dashboard. We strictly limit client-side storage to the following functional artifacts:
- discord_token: A cryptographically secure JSON Web Token (JWT) generated directly by our server immediately after successful Discord OAuth2 authorization. This token is used to maintain your stateless, authenticated session with our backend microservices.
- discord_user: A localized cache of your Discord profile metadata (such as your username and avatar) alongside an embedded
adminGuildsarray detailing your specific server permissions. Caching this payload client-side is an architectural best practice designed to minimize redundant network requests. By actively reducing unnecessary load on the Discord API, we support the health and stability of their ecosystem while simultaneously guaranteeing instantaneous user interface hydration.
Zero-Trust Security Architecture
While user profile data and server lists are cached locally in your browser for UI performance, the Aegitox platform operates on a strict Zero-Trust security model. Our servers never trust the localized user interface payload for access control. Every administrative action and data request is independently and cryptographically re-validated server-side utilizing your secure JWT. This guarantees that even if local browser payloads are manually altered, unauthorized access or privilege escalation remains cryptographically impossible.
Data Retention and User Control
Because this localized storage is strictly necessary for core application functionality, session security, and rate-limit prevention, it operates under the functional exemptions of global privacy laws and does not require an active consent banner. This functional data remains on your device only for the duration of your active session. You maintain absolute, overriding control and can instantly purge all stored information by clicking "Logout" within the dashboard, which clears all Local Storage data. Furthermore, as a proactive architectural security measure, our platform requires all users to automatically re-login every 12 hours. This guarantees that stale sessions are forcefully terminated and local storage artifacts are routinely wiped.
10. Data Deletion Exemptions & Security Architecture
We respect your right to data erasure and adhere to strict data minimization principles. However, to fulfill our existential security commitments to the community and remain in strict compliance with official Discord Developer Standards, specific retention exemptions apply to accounts that demonstrably violate platform integrity.[1, 2]
High-Risk Security Bans (IsBannedForSecurity)
Accounts involved in verified cyberattacks, malicious exploits, or severe platform abuse are flagged as critical security threats. We maintain the right to deny complete erasure requests for these entities to protect the network. Retaining this limited cryptographic telemetry is strictly necessary to prevent fraud, protect against malicious activity, and ensure the ongoing security of our infrastructure, as mandated by Discord's User Privacy and Security policies.[1, 3]
Financial Disputes & Chargebacks (IsBannedForFinance)
Accounts that initiate hostile chargebacks or violate our financial terms are subject to permanent suspension. To balance your privacy rights with our operational integrity, we utilize a cryptographic pseudonymization strategy when handling deletion requests for these accounts.
Erasure Policy for Financial Suspensions: Your user profile and identifiable data have been successfully deleted. A cryptographic hash of your account identifier is securely stored on a suppression list solely to ensure compliance with our Terms of Service regarding previous financial disputes and chargebacks. Please note that separated financial transaction logs are preserved independently as mandated by international tax, accounting, and anti-money laundering laws.