Astra.

Astra · Effective October 2, 2026

Privacy Policy

This policy describes the information handled by the Astra website and Discord bot, why it is used, and how to contact the operator about a privacy request.

01Who operates Astra

The Astra project operator is responsible for information processed by the Astra bot. For privacy questions or requests, contact the operator through the Astra support server.

Discord independently processes information when you use Discord. Its handling of that information is described in Discord’s Privacy Policy.

02Information the bot processes

When Astra is in a server or you use a command, Discord makes information available to the bot so it can work. Depending on the feature, this can include Discord user, server, channel, role, and message identifiers; display names and avatars; command names and arguments; and server settings or moderation events needed to respond to the command.

The bot’s persistent settings database stores configuration used by its features, such as server prefixes, moderation and antinuke settings, whitelist entries, logging and welcome settings, role and voice settings, and premium or owner configuration. The current bot code uses a local SQLite database file named json.sqlite. Information in it is used to provide the feature that created the setting.

Some commands need to handle message text or other content to work. If the bot operator enables the optional command logging webhook, the bot sends the command text, command name, user tag and ID, server name and ID, and channel name and ID to the configured Discord webhook. Optional error, rate-limit, and memory webhooks can send technical error details, API route information, or system usage reports. These webhooks are disabled unless configured by the operator.

03Why information is used

Information is used to execute requested commands, apply server configuration, provide moderation and safety features, troubleshoot errors, protect the bot from abuse, and keep the bot operating reliably. The bot does not sell Discord data or use message content to train AI models.

Where the GDPR applies, the operator generally relies on legitimate interests in operating, securing, and supporting the bot and providing features configured by server administrators. Consent is used where applicable law requires it. You may object to processing based on legitimate interests by contacting the operator.

04Website and third-party services

The current website does not provide user accounts, sign-up forms, or contact forms, and it does not include an analytics tool. The site loads typefaces from Google Fonts, which means your browser connects to Google to retrieve those font files. See Google’s Privacy Policy for information about Google’s handling of those requests.

The website is hosted by Vercel. Like other hosting providers, Vercel may process technical request information such as IP address, date and time, requested page, and browser or device details for delivery, reliability, and security. The bot runs on the host selected by its operator; that host stores the SQLite database and may keep infrastructure logs.

05When information is shared

Information is shared with Discord as needed to receive commands and perform requested actions within Discord. Hosting providers process technical information needed to run the website or bot. If the bot operator enables optional webhooks, the information described above is sent to the configured Discord webhook and may be visible to people who can access its destination channel.

Astra does not sell personal information or share it with advertising networks. Information may also be disclosed where required by law or when reasonably necessary to protect users, servers, or the Services.

06Storage and retention

Persistent bot settings are stored in the operator’s SQLite database on the machine running that bot instance. The operator keeps those settings while they are needed to provide the configured features. The code does not set one general automatic expiry period for all saved settings; server administrators can reset or change many settings with the bot’s commands, and you can contact the operator to request deletion of information they control.

Information held temporarily in the bot’s runtime memory is not the same as the persistent settings database. Optional webhook messages and host logs are retained by their respective operators under their own retention practices.

07Security and international processing

The bot operator should limit access to the bot host, database, credentials, and webhook destinations to people who need them. No internet service or storage system can be guaranteed completely secure.

Discord, Google, Vercel, and the bot host may process information in countries other than yours. Their own policies and safeguards apply to those services. Contact the Astra operator if you need more information about a particular bot deployment.

08Your choices and privacy rights

You can stop using Astra, ask a server administrator to remove the bot, and contact the operator to ask for access to, correction of, or deletion of information held by that operator. Where data protection law applies, you may also have rights to restrict or object to processing, request portability, withdraw consent, or complain to your local data protection authority.

To make a request, contact the operator through the Astra support server. The operator may need enough information to verify that the request relates to you. Discord separately handles requests about data in your Discord account.

09Children and policy updates

Astra is not intended for anyone below Discord’s minimum age or the higher minimum age required in their location. The operator does not knowingly seek personal information from children below that age.

This policy may be updated when the Services or their data practices change. The effective date above identifies the current version. Material updates will be published on this page.