Privacy Policy - Noctra

Effective Date: April 3, 2024Last Updated: July 13, 2026Contact: support@noctra.xyz

1. Introduction

This Privacy Policy explains how Noctra (referred to as 'we' and 'us') collects, processes, stores, and protects data when you use the Noctra bot, the website noctra.xyz, the Noctra AI Interface (ai.noctra.xyz), the Noctra API (api.noctra.xyz), game servers operated by Noctra, and any related services, collectively referred to as the 'Service'.

By using any part of the Service, you confirm that you have read and understood this Privacy Policy.

2. Data Controller

The data controller responsible for the processing of personal data under this Policy is:

Leandro Wrede
c/o Impressumservice Dein-Impressum
Stettiner Strasse 41
35410 Hungen
Germany
Email: support@noctra.xyz

3. Data We Process

We process only data that is necessary to operate, secure, and improve the Service.

3.1 Discord Bot - Identifiers

We may process the following identifiers:

  • Discord user IDs
  • Discord server (guild) IDs
  • Discord channel IDs

These identifiers are required to associate actions, settings, and features with the correct context.

3.2 Discord Bot - Message Content

Certain commands, moderation features, or automation systems require temporary processing of message content. Message content:

  • is processed only when required for a specific feature
  • is not permanently stored by default
  • may be temporarily cached for up to 24 hours for security, abuse prevention, or diagnostics where necessary

3.3 Discord Bot - Server Configuration Data

We may store server-specific configuration data, such as enabled features or preferences, to ensure the Service functions correctly.

3.4 Website (noctra.xyz)

When you visit noctra.xyz, our servers may automatically record standard server log data, including your IP address, browser type, pages visited, and timestamps. This data is used solely for security and operational purposes and is not linked to individual Discord identities.

3.5 Noctra API (api.noctra.xyz)

When you access or integrate with the Noctra API, the following data may be processed:

  • API keys or authentication tokens used to identify and authorize requests
  • IP addresses of requesting clients, for rate limiting and abuse prevention
  • Request metadata, including endpoints accessed, timestamps, and response codes
  • Any data explicitly submitted as part of API requests (e.g., Discord IDs, configuration payloads)

Discord Bot Tokens

To enable certain API features, users may voluntarily submit their own Discord bot token to the Noctra API. By submitting a bot token, you acknowledge and agree to the following:

  • Bot tokens are stored in encrypted form and are never stored or logged in plaintext
  • Bot tokens are used exclusively to perform operations you explicitly authorize via the API
  • Tokens are never shared with third parties, disclosed in logs, or used for any purpose outside the scope of your request
  • You may revoke API access and request deletion of your stored token at any time via support@noctra.xyz or through the API itself
  • You are responsible for ensuring your bot token is valid and that you are authorized to submit it
  • In the event of a suspected token compromise, we will notify you immediately and invalidate the stored token on our end
We strongly recommend regenerating your Discord bot token immediately if you believe it has been compromised, via the Discord Developer Portal.

API access logs are retained for up to 90 days. Bot tokens are retained only as long as the associated API integration is active, and are permanently deleted upon revocation or account removal.

3.6 Game Servers - Minecraft

When you connect to a Noctra-operated Minecraft server, the following data may be processed:

  • Minecraft username and UUID (as provided by Mojang/Microsoft)
  • IP address at time of connection
  • Join/leave timestamps and session duration
  • In-game actions relevant to moderation (e.g., chat messages, rule violations)
  • Any data submitted via in-game commands or forms

3.7 Game Servers - Steam

When you connect to a Noctra-operated Steam game server, the following data may be processed:

  • Steam ID (SteamID64)
  • IP address at time of connection
  • Join/leave timestamps and session duration
  • In-game actions relevant to moderation or anti-cheat enforcement
  • Player name as displayed via Steam

Game server data is retained for up to 90 days, or longer if required for active bans or security investigations.

3.8 Noctra AI Interface (ai.noctra.xyz)

The Noctra AI Interface is a standalone pay-per-use AI web application. When you use this service, the following data is processed:

  • Messages and prompts you send to AI models
  • Conversation history within your chat sessions
  • Workspace memories you create or that are automatically extracted
  • Deep research session data (findings, notes, open questions)
  • Files you upload (images) for AI vision analysis
  • Generated files (DOCX, XLSX, PPTX, PDF)
  • Web search queries and results (when using grounded search mode)
  • Account data (email, Discord identity, authentication tokens)

Messages are forwarded to OpenRouter.ai (OpenRouter, Inc.) for processing by large language models. OpenRouter acts as a data processor on our behalf.

Council Feature

The "Council" feature sends your request to multiple AI models simultaneously (e.g., models provided by OpenAI, Anthropic, Google, Meta, or others). Each model processes your request independently, and the results are combined to provide a synthesized response. This means your message content may be transmitted to multiple sub-processors in a single request.

Sub-Processors via OpenRouter

Depending on the model you select or that is used by the Council feature, your data may be routed to different sub-providers, including but not limited to:

  • OpenAI (United States)
  • Anthropic (United States)
  • Google DeepMind (United States / EU)
  • Meta AI (United States)
  • Mistral AI (France / EU)

The specific sub-provider depends on the model chosen. Appropriate safeguards (EU Standard Contractual Clauses or adequacy decisions) are in place for each transfer.

No personal identifiers (such as your Discord user ID or username) are included in the data sent to OpenRouter unless you voluntarily include them in your message. Conversation data is stored in our database for the duration of your account. You may delete individual chats or request full data deletion at any time.

User Data Control

Within the AI Interface, you have direct control over your stored data:

  • Chats: You can view and delete any of your chat sessions at any time. Deleted chats are permanently removed
  • Workspace Memories: You can view, edit, pin, pause, or delete any memory. You can also disable automatic memory extraction entirely
  • Research Sessions: You can view, edit, and delete research entries and full sessions
  • Generated Files: You can view and delete your generated files

These self-service controls fulfill your rights of access, rectification, and erasure (Art. 15–17 GDPR) for data stored within the AI Interface without requiring a separate request to support.

Legal basis: Art. 6(1)(b) GDPR (performance of a service you actively use) and Art. 6(1)(a) GDPR (consent by voluntarily using the feature).

OpenRouter may process data in the United States. Appropriate safeguards (EU Standard Contractual Clauses) are in place. For more information, see OpenRouter's Privacy Policy.

3.9 Noctra Dashboard AI Assistant

The Noctra Dashboard (noctra.xyz) includes a separate AI-powered assistant to help users with dashboard-related questions. When you use this feature, the following data is processed:

  • Messages you send to the assistant
  • Conversation history within the active session
  • Your guild context (guild ID) to provide relevant answers

Messages are forwarded to OpenRouter.ai for processing. No personal identifiers are included unless you voluntarily include them in your message. Conversation data is not stored permanently after the session ends.

Legal basis: Art. 6(1)(b) GDPR (performance of a service you actively use).

3.10 Noctra Discord Bot AI Feature

The Noctra Discord Bot includes an optional, admin-configurable AI feature that operates directly within Discord servers. This feature is separate from the Dashboard AI Assistant (3.9) and the AI Interface (3.8). When enabled by a server administrator, the following functions are available:

  • Reference Document Context: Server admins may upload or configure reference documents (e.g., server rules, FAQs, guidelines) in the bot configuration. These documents are included as context in every AI request made within that server, enabling the AI to provide server-specific answers.
  • Web Search: The AI may perform web searches to answer user questions. Search queries are processed on Noctra's own infrastructure. No search data is shared with external third parties.
  • General Help AI: Users may ask general questions to the AI within configured Discord channels.

Data processing:

  • User messages directed at the AI feature are forwarded to OpenRouter.ai (OpenRouter, Inc.) for processing by large language models, together with admin-configured reference documents as context
  • Web search queries are processed on Noctra's own infrastructure (no external third-party involvement)
  • Conversation contents operate on a fire-and-forget principle: individual messages and AI responses are not permanently stored after the interaction ends
  • Admin-configured reference documents are stored as part of the server configuration data (see 3.3) and are retained while Noctra is active on the server
  • No personal identifiers are included in data sent to OpenRouter or search providers unless voluntarily included in the user's message

Responsibilities: The server administrator who enables and configures this feature is responsible for the content of uploaded reference documents. Noctra processes these documents solely on behalf of the administrator to provide the AI feature functionality. Administrators must ensure that reference documents do not contain special categories of personal data (Art. 9 GDPR) or content that infringes third-party rights.

Legal basis: Art. 6(1)(b) GDPR (performance of a service actively used) and Art. 6(1)(a) GDPR (consent by administrator activation of the feature).

OpenRouter may process data in the United States. Appropriate safeguards (EU Standard Contractual Clauses) are in place.

3.11 Billing and Usage Data

When you use paid features (pay-per-use AI), the following data is processed for billing purposes:

  • Token consumption per request (input and output tokens)
  • Cost per message/request
  • Credit balance and transaction history
  • Timestamps of usage events
  • Model selected for each request

Credit costs vary depending on the AI model selected for each request. More capable models generally consume more credits per message than lighter models. The per-model cost is transparently displayed in the AI Interface before and during usage.

To comply with the age requirements for paid features (TOS §5), we store a one-time age confirmation timestamp per account when a user confirms they are at least 18 years of age or have parental consent. No birthdate or identity documents are collected.

This data is necessary to calculate charges, display your usage history, and fulfill legal accounting obligations. In accordance with German tax law (§ 147 AO), billing records and invoices are retained for a minimum of 10 years. Usage data that is no longer required for billing or legal purposes is deleted or anonymized after the applicable retention period.

Legal basis: Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(c) GDPR (legal obligation for accounting records).

3.12 Cookies and Local Storage

Our services use the following cookies, all of which are technically necessary for authentication and session management. No tracking, analytics, or advertising cookies are used.

Cookie NameServicePurposeDuration
dashboard_sessionnoctra.xyzAuthenticates your dashboard session after Discord OAuth2 loginSession (expires on browser close or after inactivity)
oauth_statenoctra.xyz, ai.noctra.xyzCSRF protection during OAuth2 login flow10 minutes
oauth_returnnoctra.xyzStores the return URL to redirect you after login10 minutes
noctra.sidai.noctra.xyzAuthenticates your AI Interface session24 hours (renewed on activity)

These cookies are strictly necessary for the operation of the Service and do not require consent under § 25(2) TDDDG (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz). No consent banner is required as no non-essential cookies are set.

Legal basis: Art. 6(1)(b) GDPR (necessary for service performance) and § 25(2) Nr. 2 TDDDG (technically necessary).

4. Legal Basis for Processing (GDPR)

Where applicable under the General Data Protection Regulation (GDPR), data is processed under one or more of the following legal bases:

  • Art. 6(1)(b) GDPR - Processing is necessary for the performance of a service you have requested
  • Art. 6(1)(f) GDPR - Processing is necessary for our legitimate interests, such as preventing abuse, fraud, and ensuring service security, where these interests are not overridden by your rights
  • Art. 6(1)(a) GDPR - Consent, where explicitly required by law

5. Purpose of Processing

Noctra follows a user-centric data protection principle: data is processed exclusively to deliver the requested functionality, is never sold, never used for advertising, and never shared with third parties for commercial purposes.

We process data exclusively for the following purposes:

  • Providing and operating all parts of the Service (bot, website, AI Interface, API, game servers)
  • Executing commands, automation logic, and API requests
  • Processing AI chat requests, web search queries, and research sessions
  • Billing and usage tracking for pay-per-use features
  • Preventing abuse, fraud, cheating, and misuse
  • Enforcing bans and moderation decisions across game servers
  • Monitoring, diagnostics, and service optimization
  • Rate limiting and securing API access
  • Responding to support and administrative requests

We do not sell, rent, or use data for advertising, profiling, or marketing purposes.

6. Data Retention

Data TypeRetention Period
Temporary message processingUp to 24 hours
Operational logs and diagnosticsUp to 90 days
API access logsUp to 90 days
Game server session dataUp to 90 days
Bot tokensWhile API integration is active; deleted upon revocation
Server configuration dataWhile Noctra is active on the server
Discord Bot AI conversationsNot stored after session ends (fire-and-forget)
Reference/rule documents (Admin config)While Noctra is active on the server
AI Interface chat historyDuration of active account; deleted on request. Credits and chat data are purged after 6 consecutive months of inactivity (no login or AI usage)
Workspace memoriesUntil deleted by user or account removal
Research sessionsDuration of active account; deleted on request
Generated filesTemporary; auto-deleted after expiry period
Ban and moderation recordsUntil lifted, or permanently if required for security
Legal and security hold dataAs required by applicable law
Billing records and invoices10 years (§ 147 AO)
Usage data (token consumption, costs)Duration of active account; anonymized thereafter
Age confirmation recordDuration of active account

After the applicable retention period, data is securely deleted or anonymized.

7. Data Sharing and Third Parties

We do not sell or share personal data with third parties for commercial purposes. Data may be disclosed:

  • When required by applicable law or court order
  • To protect the integrity and security of the Service
  • With infrastructure and hosting providers necessary to operate Noctra (e.g., database, server, and API hosting providers)
  • With OpenRouter.ai (OpenRouter, Inc.) for AI Interface, Dashboard AI Assistant, and Discord Bot AI Feature functionality — only message content you voluntarily submit is shared. For the Discord Bot AI Feature, admin-configured reference documents are additionally included as context. Depending on the model selected, data may be further processed by sub-providers such as OpenAI, Anthropic, Google, or others
  • With a self-hosted search engine operated by Noctra for web search functionality within the AI Interface and the Discord Bot AI Feature — only search queries are processed on Noctra's own infrastructure. No data is shared with external third parties for this purpose
  • With Paddle.com Market Limited ("Paddle") for payment processing — Paddle acts as the Merchant of Record and processes your payment data (e.g., name, email, payment method, billing address, transaction amounts) to facilitate purchases. Legal basis: Art. 6(1)(b) GDPR (performance of contract). For more information, see Paddle's Privacy Policy
  • With top.gg — we transmit our server count to top.gg for bot listing purposes, and receive vote notifications containing your Discord user ID when you vote for Noctra on top.gg

All third-party providers are contractually required to implement appropriate data protection measures and may only process data on our behalf and in accordance with our instructions.

8. International Data Transfers

Data may be processed or stored outside the European Economic Area (EEA). Where such transfers occur, appropriate safeguards are applied in accordance with GDPR requirements, such as EU Standard Contractual Clauses (SCCs) or adequacy decisions by the European Commission.

9. Security Measures

We apply reasonable technical and organizational measures to protect data against unauthorized access, loss, or misuse, including encrypted storage of API keys and access controls on infrastructure.

Discord bot tokens submitted to the API are encrypted at rest using industry-standard encryption. Access to stored tokens is strictly limited to automated systems performing user-authorized operations. No human operator can retrieve a token in plaintext.

In the event of a data breach affecting your rights, we will notify the relevant supervisory authority and, where required, affected individuals in accordance with applicable law.

10. Automated Decision-Making

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR that produces legal or similarly significant effects on individuals. Automated systems such as spam filters or anti-cheat detection may flag accounts for human review, but final decisions are made by a human moderator.

11. Children's Privacy

The Service is not intended for individuals who are not legally permitted to use the platforms on which Noctra operates. In accordance with Discord's Terms of Service, users must be at least 13 years of age. Minecraft and Steam services are likewise intended only for users meeting the minimum age requirements of those platforms. If we identify that data has been collected from underage users without appropriate consent, it will be deleted without undue delay.

12. Your Rights

Depending on applicable law, in particular the GDPR, you may have the right to:

  • Access your personal data (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure - right to be forgotten (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Object to processing based on legitimate interests (Art. 21 GDPR)
  • Withdraw consent at any time, without affecting the lawfulness of prior processing

To exercise any of these rights, contact us at support@noctra.xyz. We will respond within 30 days in accordance with Art. 12 GDPR.

You may also access, review, and request deletion of certain data directly through the Noctra Dashboard settings. Data export and deletion requests submitted via the Dashboard are processed automatically where technically feasible.

You also have the right to lodge a complaint with a supervisory authority. The competent authority for North Rhine-Westphalia is:

Landesbeauftragte für Datenschutz und Informationsfreiheit NRW (LDI NRW)
Postfach 20 04 44
40102 Düsseldorf
www.ldi.nrw.de

13. Changes to This Policy

This Privacy Policy may be updated from time to time. We will notify users of material changes by updating the 'Last Updated' date and, where feasible, through an announcement via the Service. We recommend reviewing this Policy periodically. Continued use of the Service after changes have been published constitutes acknowledgment of the updated version.

14. Contact

For any privacy-related questions or requests:

Leandro Wrede
c/o Impressumservice Dein-Impressum
Stettiner Strasse 41
35410 Hungen
Germany
Email: support@noctra.xyz