Detailed Privacy Policy - NexusBot & TOMPA Ecosystem
Effective Date: July 22, 2026
This Privacy Policy outlines how TOMPA, operated by Meir Haim Zano ("TOMPA", "we", "us"), collects, processes, and secures data through NexusBot, its associated web dashboard, and the Command Store (collectively, the "Service").
1. Information We Collect
We collect only the data necessary to operate the Service. Depending on how you use NexusBot, this includes:
- Discord Account Data: When you log in with Discord, we receive your Discord User ID, username, avatar hash, and the list of servers (guilds) you belong to or administer, via Discord's identify and guilds OAuth2 scopes. We never request or receive your Discord password, and we do not request your Discord email address through this login flow.
- Guild (Server) Configuration: We store Guild IDs, Role IDs, and Channel IDs required to safely execute automation, custom management rules, and moderation commands you configure on the dashboard.
- Message Monitoring: To provide active Anti-Spam and chat moderation, the bot processes incoming message content in real-time. Non-violating messages are never written to permanent storage.
- Ticket Transcripts: If your server uses the support-ticket feature, the full content of ticket channels (messages, usernames, attachments, and embeds) is retained so administrators can review closed tickets.
- Profile Settings: Optional profile information you choose to add, such as a bio, display language, profile color, and badges, some of which may be shown on a public profile page if you enable that visibility setting.
- Command Store Content: If you create or import custom commands through the Command Store, we store the command content, its author/origin, and your favorites/import history so the feature can function.
- Payment & Billing Data: If you purchase Premium, the email address you enter and a customer identifier from our payment processor are stored to manage your subscription. We never see or store your card details (see Section 4).
- AI Assistant Prompts: If you use the in-dashboard "NEXUS" assistant to help build custom commands, the text you type is sent to our AI processing endpoint to generate a suggested response. Do not paste sensitive personal information into the assistant.
- Usage & Analytics Data: If you consent to analytics cookies, we collect anonymized/aggregated usage data such as pages visited, approximate location derived from IP, device and browser type, via Google Analytics (see Section 2).
2. Cookies & Tracking Technologies
The dashboard uses two categories of cookies/local storage:
- Essential Cookies (always active): A session cookie ("connect.sid") keeps you securely logged in and remembers your language preference. These are strictly necessary - disabling them will prevent the dashboard from loading correctly, so they are not subject to the consent banner.
- Analytics Cookies (optional, consent-based): We use Google Analytics to understand how visitors use the site. These cookies are only loaded after you accept them in the cookie banner shown on your first visit. You can change your choice at any time using the "Manage Cookie Preferences" link in the footer, which lets you re-open the banner and accept or reject analytics cookies again.
- We do not use third-party advertising cookies or sell any data collected through cookies.
3. Web Dashboard & OAuth2 Authentication
When authenticating through the TOMPA dashboard via Discord's secure OAuth2 protocol:
- Secure Tokens: Discord access and refresh tokens are encrypted before being stored and are used strictly to verify your administrative permissions across connected guilds.
- Session Management: A short-lived cache of your session is also kept in our Redis infrastructure to speed up authentication checks, and expires automatically.
4. Financial, Verification & Transaction Records
To comply with global digital business standards, prevent fraud, and manage customer subscriptions:
- Email Management: We collect the email address you provide at checkout to distribute transaction receipts and verify subscription status.
- Payment Logs: We retain structural tracking logs, including transaction IDs, receipt identifiers, and timestamps. TOMPA never views, handles, or stores your raw card details - all international checkouts are processed by our Merchant of Record, Dodo Payments, whose own privacy policy also applies to the checkout process.
5. Data Retention
We keep different categories of data for different lengths of time, based on operational need:
- Ticket Transcripts & Archives: Retained on our Supabase/PostgreSQL infrastructure to maintain operational history for server administrators, until the server owner or an authorized admin requests deletion, or the bot is removed from the server.
- Dashboard Audit Logs: Structural changes made through the web control interface are logged with an associated User ID and timestamp, subject to a standard 7-day auto-deletion policy. Servers with an active Premium subscription are retained for an extended 30-day period instead.
- Account & Profile Data: Kept for as long as your account exists, and deleted upon a verified deletion request (Section 9) or prolonged inactivity, whichever is applicable.
- Billing Records: Transaction metadata is retained as required for accounting, tax, and fraud-prevention obligations, even after a subscription ends.
6. Data Security & Third-Party Service Providers
Our backend systems run inside secured cloud environments. We never sell, rent, lease, or trade your personal data. Information is shared strictly with the following providers, solely to operate core functionality:
- Discord: Authentication and delivery of bot functionality inside your servers.
- Supabase (PostgreSQL): Our primary database for account, configuration, ticket, and billing records.
- Redis: Short-lived caching of session data to keep the dashboard fast and responsive.
- Cloudinary: Hosting for images you upload, such as welcome-message backgrounds or custom assets.
- Dodo Payments: Our global Merchant of Record, for processing secure checkout sessions and recurring subscription billing.
- Google Analytics: Aggregated site-usage analytics, loaded only if you consent to analytics cookies (Section 2).
- AI Processing Provider: The "NEXUS" in-dashboard assistant sends your prompt text to an AI model provider to generate suggested custom-command configurations.
- Cloudflare: Global edge routing, network caching, and DDoS prevention.
- Oracle Cloud Infrastructure: The hosting provider for our application servers.
7. International Data Transfers
Because our service providers operate global infrastructure, your data may be processed on servers located outside of your own country. Where this occurs, we rely on the security and contractual safeguards each provider listed in Section 6 maintains for cross-border processing.
8. Children's Privacy
NexusBot is not directed at children and is not knowingly used to collect data from anyone under 13 years old (or the minimum age required by Discord and your local law, if higher). If you believe a child has provided us with personal data, contact us using the details below so we can remove it.
9. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights over your personal data. To exercise any of them, contact us using the details at the bottom of this page:
- Access: Request a copy of the personal data we hold about you.
- Correction: Ask us to correct inaccurate or incomplete data.
- Deletion: Request permanent deletion of your personal data, subject to legal/accounting retention obligations described in Section 5.
- Objection & Restriction: Object to, or ask us to restrict, certain processing of your data.
- Withdraw Consent: Withdraw analytics-cookie consent at any time via the "Manage Cookie Preferences" footer link, with no effect on essential functionality.
- We aim to respond to verified privacy requests within a reasonable time frame.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the Service or applicable law. The "Effective Date" at the top of this page will always reflect the latest revision, and continued use of the Service after a change becomes effective constitutes acceptance of the revised policy.
11. Global Deletion Rights & Contact Details
Under comprehensive global data privacy regulations (such as GDPR), users retain full rights to request the manual extraction or permanent destruction of all personal information hosted on our systems. To initiate a deletion request or file an inquiry, contact the lead infrastructure developer:
- Developer / Founder: Meir Haim Zano
- Official Business Email: [email protected]
- Discord Contact: meir_zano
- Support Server: Join Official Support Discord