Nodariq Core โบ Security & data
Security & your data
Adding a bot to your server is a big decision. Here's exactly what Nodariq can do, what it stores, and how you stay in control.
Nodariq asks only for the permissions its features use. Discord shows the full list before you add it.
Every channel, role, kick or ban Nodariq makes appears under "Nodariq Core" in Server Settings โ Audit Log.
You log in with Discord itself, and payments go through Stripe. We never see either.
One button in the dashboard, and it's deleted automatically 30 days after you remove the bot.
The permissions Nodariq asks for, and why
Nodariq never asks for Administrator, which would let a bot do anything. It also can't do more than its role allows: Discord only lets it manage roles below its own, and you can remove any permission at any time in Server Settings โ Roles.
| Permission | What it's used for |
|---|---|
| View Channels, Send Messages, Embed Links, Attach Files, Read Message History | Posting panels, welcome cards, alerts and logs, and editing its own messages |
| Manage Channels | Ticket channels, join-to-create voice channels, counter channels, and locking a channel when you ask |
| Manage Roles | Autoroles, verification, role menus, level rewards and ticket access (only roles below Nodariq's own) |
| Manage Messages | Removing spam and scam links (AutoMod and Guardian) and !purge |
| Timeout, Kick and Ban Members | Moderation commands your staff run, AutoMod timeouts and anti-raid (both off until you turn them on) |
| View Audit Log | Showing who made a change in your mod log |
| Manage Server | Reading which invite each new member used (invite tracking). It doesn't change your server settings |
| Create Invite | The Join button on your community website |
| Connect, Move Members | Moving members into their own join-to-create voice channel |
| Mention Everyone, Create and Send in Threads | Pinging staff roles when a ticket opens, and suggestion discussion threads |
What we store
- Your settings, like welcome messages, ticket panels and AutoMod rules.
- Content from features you use: tickets and transcripts, moderation cases, applications, suggestions, staff notes, levels and achievements, and activity counts for your charts.
- Discord IDs of servers, channels, roles and members, so features know who is who.
- Billing: your email and subscription status. Card details stay with Stripe.
What we don't store
- Your Discord password or login token. The dashboard uses Discord's official login, and we only see your username, avatar and the servers you manage.
- Card numbers. Stripe handles every payment.
- A copy of all your messages. Nodariq reads messages to run features like AutoMod and levels, but only keeps what a feature needs (for example the text of a deleted message in your mod log).
What other servers can see
Your server's moderation history, tickets, notes and settings are only visible to your server's staff. If members turn on their public Nodariq Profile, it shows only public stats like levels and achievements, and your server's name only if both you and the member allow it.
Deleting your data
- Any time: go to nodariq.net/dashboard, pick your server, and use Delete this server's data at the bottom of the Overview. You can also remove Nodariq at the same time.
- Automatically: when Nodariq is removed from a server, that server's data is deleted 30 days later. If you add it back within 30 days, nothing is lost.
- Your own account: email support@nodariq.net and we'll delete data linked to your Discord account.
Billing and purchase records are kept, as the law requires for tax and accounting, and so you don't lose a plan or Blueprint you paid for.
How it's built
- The website and dashboard only work over HTTPS.
- The dashboard talks to the bot over requests that are encrypted and signed, and expire within a minute, so they can't be read, faked or replayed.
- The dashboard only shows servers where you have Manage Server, and the bot checks that again on every save.
- Every setting saved in the dashboard is re-checked by the bot, so it can never do more than the matching slash command.
- Secrets like our Discord and Stripe keys are never put in the website's code.
Anti-nuke
If someone with admin access (or a hacked admin account, or a malicious bot) starts deleting channels and roles or banning people in bulk, anti-nuke removes that person's roles with dangerous permissions mid-attack and alerts your staff. Deleted channels and roles can then be restored with Time Machine. The server owner and anyone the owner trusts are never touched, and it only works on roles below Nodariq's own role.
The Nodariq blacklist
Servers can turn on warnings about accounts confirmed as scammers, phishers or raiders. It's built to be fair:
- Nothing is added without review. Servers can only report an account, with evidence. The Nodariq team checks every report before anything is listed.
- It never kicks or bans anyone. Servers that turn it on get a warning when a listed account joins, and their staff decide what to do.
- Hacked accounts get a second chance. Entries for accounts that were hacked and used for spam expire after 30 days.
- You can appeal. If your account is listed by mistake, ask in our Discord or email support@nodariq.net, and we'll review it.
The Nodariq team's access
We'd rather you hear it from us. To give support, the Nodariq team has tools that can:
- see your server's name, member count, plan and which features are set up;
- give or remove a plan, for example a free trial;
- send a message to your server's owner from the bot;
- create an invite to your server, which always shows in your audit log as made by Nodariq.
These are only used for support and billing, never to read your members' conversations.
Found a problem?
If you think you've found a security issue, please email support@nodariq.net before sharing it publicly, and we'll reply as soon as we can. For anything else, ask in our Discord.
More detail is in our Privacy Policy and Terms. No system is perfectly secure, so we can't promise that, but we can promise to be upfront about how Nodariq works.