Legal
Privacy Policy
Effective 2026-09-13
Novaris Enterprises LLC ("Lunaris", "we", "us") operates the Lunaris Discord bot, the dashboard at lunaris.bot, and this website. This policy explains what we collect, why, and for how long, in the same plain language the rest of the product uses. Lunaris is not affiliated with Discord Inc.
For the full technical detail behind every line here, including every permission Lunaris requests and what breaks without it, see /transparency. That page and this one describe the same product and must never disagree; if you find somewhere they do, tell us.
Information we collect
What Lunaris collects depends on how you use it: as a server owner or admin signing in to the dashboard, as a member going through verification, or as a member opting into a specific feature like Reunite.
- Dashboard sign-in (Discord OAuth, identify and guilds scopes): your Discord user id, username, avatar, and the list of servers you can manage, so the dashboard knows what to show you. No password. Discord does not hand over your email with these scopes, and we do not ask for it.
- Verification: your account creation date and a trust score computed from it at join, kept per server so staff can look it up (the score and its parts, not a copied profile); a verification-session row tracking which step you are on, removed within a day of finishing or expiring; and a CAPTCHA attempt count, kept only until you pass or a moderator clears it.
- Security events: an append-only record of what Lunaris did in a server, tied to the Discord ids of who triggered it and who it targeted, kept 30 days on the Free plan or 90 days on Pro, then deleted by a scheduled job that runs twice a day.
- Guild configuration: the channel and role ids, thresholds and feature switches an admin sets, kept while the bot is installed so a re-invite restores your settings, deleted on request.
- Message log excerpts, only if an admin switches message logging on: a deleted or edited message's author, channel, and text before and after, on the same retention clock as security events above. Beyond these excerpts, the only member-typed text Lunaris keeps is what a member types into a Lunaris form on purpose: a ticket subject, or a moderator's warning reason.
- Backups, a Pro feature and only if you use it: a JSON snapshot of channel structure, roles and permissions, up to 7 kept per server. Never messages, never a member list.
- Threat network reports, only if an admin switches the network on: an account id, one category from a fixed list, a timestamp, and the id of the reporting server. No free-text field exists in a report. A report is withdrawn automatically if the ban it accompanied did not go through, and on request through the appeal path below.
- Reunite authorizations: if you personally opt in as a member (a separate consent screen, the guilds.join scope, granted by you and not by the server), an encrypted token letting the person who owned that server when you opted in re-add you to its official replacement if the original is lost. Expires after 365 days and is then deleted, and you can revoke it at any time from your account, which deletes it outright rather than marking it inactive.
- Billing information: handled entirely by Stripe. No card number reaches our database; there is no column for one.
What we never collect
- Your full member list. Lunaris sees members as they arrive and acts on them there; it does not copy, export, or sell a roster.
- Message content beyond the logged excerpts above. No channel is archived, and nothing scanned for threats is written down unless it matched and was acted on.
- Direct message content. The DM-privacy probe sends one message and deletes it; Lunaris is never in a member's DMs and receives nothing from them.
- Payment card details, which Stripe holds on our behalf.
- Anything in a threat-network report beyond an account id and a category.
How we use this information
- To operate the features you or your server's admins turned on: verification, security detection, moderation tools, the dashboard.
- To compute a trust score at join time, used only to inform verification decisions in that server.
- To send security alerts and the weekly digest to the channels an admin configured.
- To enforce the limits of your plan (Free or Pro) and to bill for Pro, through Stripe.
- To respond to support requests and enforce these terms.
Retention, in full
This is the complete list, not the categories a privacy policy usually collapses it into:
- Security events and message log excerpts: 30 days Free, 90 days Pro.
- Guild configuration: while the bot is installed, deleted on request.
- Verification state: removed within a day of finishing or expiring.
- Attempt ledger: until you pass verification or a moderator clears it.
- Trust score: while you are a member of that server and the bot is installed.
- Warnings: while the bot is installed, or until a moderator clears them.
- Tickets: the ticket record, including its subject, while the bot is installed.
- Backups: the newest 7 kept, older ones dropped automatically.
- Threat network reports: until withdrawn by the reporting server, a failed ban, or an appeal.
- Reunite authorizations: 365 days, then deleted, or immediately on revocation.
- Dashboard job records (a backup or Reunite run you started from the website): who started it and how it ended, while the bot is installed.
Your rights and how to exercise them
- Remove the bot from your server at any time. Verification stops immediately; your channels, roles and permissions are untouched; your configuration sits dormant in case you reinstall.
- Ask for a full erase. One request to privacy@lunaris.bot deletes your server's configuration row and every event attached to it, no waiting period and no retention hold for analytics.
- If you are a member, not an admin: revoke a Reunite authorization yourself, at any time, from your account or with /reunite revoke in Discord. It is deleted immediately.
- If your account was flagged by the threat network, you have a documented removal and appeal path that does not run through the server that reported you. Contact privacy@lunaris.bot to start it.
Children's privacy
Discord requires every account to meet Discord's own minimum age (13, or higher where local law requires it). Lunaris relies on that requirement and does not knowingly collect information from anyone below it. We do not ask for or store a birthdate.
Where your information is processed
Lunaris is a hosted service, and the servers that run it and store this data may be located outside the country you or your Discord server's members are in. By using Lunaris you consent to that processing.
Changes to this policy
We will post updates to this page. A change that materially affects what we collect or how long we keep it will also be announced in the dashboard or the bot's own security log. Continuing to use Lunaris after a change takes effect means you accept it.
Contact
Questions about this policy, or a request under it: privacy@lunaris.bot.