Rexomat
Commands Status Log in with Discord
Terms of Service Privacy Policy Licenses Legal Notice

Privacy Policy

Last updated: 11 October 2026

1. Who is responsible

The operator of Rexomat
Email: BigKawaiiCat@gmail.com

“We” in this policy means the person above, who runs the Discord bot Rexomat and the website rexomat.duckdns.org.

2. What the bot handles on Discord

When the bot is in a server, Discord sends it what it needs to work there: your user ID, username, display name, avatar and roles, the server's channels and roles, and the messages in channels the bot can see. It can't see your private messages with other people.

What the bot stores depends on which modules a server turned on. Every module starts switched off.

ModuleWhat it stores or does
LevelingYour user ID, your XP in that server and whether you want a ping when you level up. Messages and voice time are counted to give XP; their content isn't stored.
ModerationIf staff warn, mute, time out, kick or ban you: your user ID and name, what was done, the reason, who did it and when. Warnings and this log are shown to the server's managers on the dashboard and, if the server turned it on, posted in its moderation log channel. They're deleted after the time the server chose (180 days unless it changed that), or earlier by a manager. A running mute is also stored until it ends. When staff lock a channel, the bot remembers who locked it and why until it's unlocked.
TeamsTeam names, who owns a team, its members and when they joined, and a log of team actions (created, joined, left, deleted).
EventsWho signed up for an event and, if the server asks for it, what you type into the sign-up form (for example a username).
GiveawaysIf you enter a giveaway: your user ID and when you entered, and whether you won. It's deleted 30 days after the giveaway ends. Winners get a direct message if the server turned that on.

Reaction Roles, Welcome (and goodbye), Verification, Anti-Nuke, Role Pings and Owner Tools store nothing about you. They give or take roles, post messages and can note what they did in the server's log channel. Verification can look at when your Discord account was created, if the server only lets older accounts in. Anti-Nuke reads the audit log to spot mass deletions, bans and kicks; it and Role Pings (for its cooldown) only keep short-lived counts in memory.

Server settings chosen on the dashboard (channels, roles, texts) are stored per server. If a server turns on its public leaderboard, the names, avatars, levels and XP of its members can be seen by anyone on a web page.

3. The website and dashboard

  • Log in with Discord. When you log in, Discord gives us your user ID, username, avatar and a list of your servers with your permissions there, so we can show which servers you may manage. Your login (your user ID and the Discord login token, so we can refresh that list) is kept on our server for up to 7 days or until you log out; your browser only gets a cookie with a random login ID, your name and avatar.
  • Cookies. There's only one cookie: your login session, which also protects forms from misuse. The website needs it to work. There's no analytics, no advertising and no tracking. The fonts are served from our own server.
  • Images from Discord. Avatars and server icons load straight from Discord (cdn.discordapp.com), so your browser connects to Discord to show them.
  • Change history. When you change something on the dashboard, we note who did it (Discord ID, name, avatar), when, and what changed, so the other managers of that server can see it and undo mistakes. These entries are deleted after 90 days.
  • Server logs. The web server notes each visit (IP address, time, page, browser) so we can keep the site secure and fix errors. These logs are deleted after 14 days.
  • Verifying on the website. If a server lets you verify on this website, you log in with Discord and we get your user ID, name and avatar, check that you're in that server (and, if the server asks for it, how old your account is), and give you its role. We don't keep any of it; the server can note it in its log channel.
  • Support server. When you log in to the dashboard or verify on the website, Discord also asks you for “Join servers for you”. If you allow it, we store your user ID, name, avatar, when you agreed, and the Discord token for it, so we can add you to our support server. We use it for nothing else. You can take it back at any time in Discord under Settings → Authorized Apps (the token then stops working), or ask us to delete it.

4. Why we're allowed to do this

Under the GDPR (Art. 6(1)):

  • (b) providing the service: running the bot and the dashboard that you or your server use;
  • (f) legitimate interests: running the bot for server communities, keeping it secure and preventing abuse (for example anti-nuke and server logs);
  • (a) your consent: for the support server. You can withdraw it at any time; that doesn't affect what happened before.

5. Who else gets data

  • Discord Inc. (USA), certified under the EU-U.S. Data Privacy Framework. The bot and the login work through Discord. Discord's own Privacy Policy applies to what you do on Discord.
  • Hosting. Zap Hosting runs the server the bot and website are on, and only processes the data on our behalf.
  • Nobody else. We don't sell data or use it for advertising.

6. How long it's kept

  • Bot data stays as long as the module is used in the server, or until a server manager deletes it on the dashboard (for example by resetting XP or deleting a team or event). Mutes are deleted when they end; warnings and the moderation log after the time the server chose (180 days unless it changed that).
  • If the bot is removed from a server, that server's data stays until someone asks us to delete it. Just send us an email.
  • Daily backups are kept for 14 days. Web server and bot logs are kept for 14 days. The dashboard's change history is kept for 90 days. The status page only stores times when the bot was online (no personal data).

7. Your rights

You can ask us for a copy of your data, and to correct, delete or limit it, to get it in a portable format, and you can object to processing based on legitimate interests. Email BigKawaiiCat@gmail.com and include your Discord user ID, so we can find your data.

You can also complain to a data protection authority, for example: Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Wien, Austria (www.dsb.gv.at).

Rexomat Online now Not affiliated with Discord Inc.

Bot

Commands Add to Discord Dashboard Status

Legal

Terms of Service Privacy Policy Licenses Legal Notice