Axis
— LEGAL

Privacy Policy

Axis · Updated October 2026

Passkeys are optional and scoped to this site and one account per server. We store the public key, credential identifier and counter, never your private key or biometric data. You can remove them from the verification completion screen or through a deletion request. They avoid repeating Discord sign-in but do not link accounts or bypass sanctions. Staff decisions about distinct people and evidence corrections retain their history. Inherited sanctions apply only to confirmed identities; sharing a network or device does not confirm identity.

Account relationships confirmed by staff are stored per server with their reason and can be corrected. StromBot receives only confirmed relationships, without IPs or sanctions. New network blocks expire after 30 days by default (configurable from 1 to 365 days); existing blocks receive a transition period when checked. Account bans remain in effect.

Axis is a security and moderation bot that operates inside a Discord server. This policy explains what data it processes, for what purpose and for how long. By using the server or the bot's web portal, you accept what is described here.

1. What data we process

  • Discord identifiers: user, role, channel and server IDs, along with usernames and tags. They are needed to moderate and to display readable logs.
  • Moderation records: warnings, sanctions (kicks, bans, mutes), staff notes and the history of actions taken by moderators.
  • Message content — in a limited way: the automod system analyses messages in the moment to filter spam, scams, malicious links and abuse, and does not store them. Content is stored when: (a) a message is edited or deleted and is logged for auditing —including a copy of any attached images, videos, audio and stickers, so that deleting something does not hide the evidence—; (b) a moderator saves a transcript of a channel, or one is generated automatically when a ticket is closed; or (c) the server enables enhanced monitoring on a specific account (see section 6).
  • Public server activity: joins and leaves, which invite was used to join and who created it, nickname and username changes, server boosts, and joining/leaving voice channels (including muting your microphone or sharing your screen, only if the server enables voice logging). It is used for security auditing.
  • IP address — only in the web verification portal: if the server uses web verification, your IP is processed on entry to detect anonymous connections (VPN, proxy or the TOR network) and alternate accounts of sanctioned users. The IP is stored converted into an irreversible hash (scrypt with a key that is not stored alongside the data: a stolen copy of the database cannot recover it); it is never stored in plain text and the record is deleted automatically 90 days after you leave the server, and at most one year after your last verification. On IPv6 connections only the network prefix of your connection is processed, not your device's specific address.
  • Browser fingerprint and a security cookie — only in the web verification portal: to stop a sanctioned person from coming back simply by changing connection, the portal measures technical characteristics of your browser and stores a cookie with a random number. All of this is detailed in section 3.
  • Verification captcha: if the server enables it, the challenge is generated and validated on our own server; no external provider is involved and no additional data is collected for solving it.
  • Timestamps of the events above.

2. What we use the data for, and our legal basis

Exclusively for the security and moderation of the server: applying and auditing sanctions, detecting raids and alternate accounts, preventing attacks (anti-nuke/anti-raid) and giving staff investigation tools.

Our legal basis is the legitimate interest in protecting the community against abuse, attacks and sanction evasion (Art. 6(1)(f) GDPR), and the enforcement of the server rules you accept by taking part. Processing is limited to what is strictly necessary for that security purpose.

We never sell or share your data with third parties for commercial purposes, we do not run advertising or commercial profiling, and we do not use it to train artificial intelligence models.

3. Browser fingerprint and cookie (web verification)

Authenticated portal visits record whether the same account and cookie change connection. Only hashes and timestamps are kept: up to eight recent changes per account and server, for at most 90 days. This is informational and does not cause a ban; it cannot observe your connection while you use Discord. An approved deletion request removes this history.

Changing your IP address is trivial and free (restarting the router, using mobile data, another wifi network). That is why a sanctioned person can come back again and again by creating new accounts. To prevent this, the verification portal measures technical characteristics of your browser: browser and system model, language, time zone, screen size and density, number of cores and approximate memory, whether the device is touch-enabled, and the result of two standard graphics tests (a canvas drawing and your graphics card model).

  • That data is not stored item by item: it is combined and turned into a hashed, irreversible identifier (HMAC-SHA256). Neither your browser nor your computer can be reconstructed from it.
  • We do not read your files, your history, your passwords, your GPS location, your camera or your microphone. Only data that any website routinely sees is consulted.
  • It is used only for two things: detecting that a sanctioned account is coming back from the same device, and detecting several accounts used from a single device.
  • It is deleted on the same schedule as the IP (90 days), and disappears if staff lift the block.
  • The server administrator can disable this feature; in that case no fingerprint is collected at all.

Security cookie. The portal stores a single cookie (argos_id) containing a random number that identifies your browser, for the same purpose: detecting that a sanctioned account is coming back. It is a strictly necessary cookie for the security of the service: it is not advertising, it does not track you outside this portal and it is not shared with anyone. It is HttpOnly, meaning no script on the page can read it, and it expires after 400 days (the maximum browsers accept). It is one of several independent checks, so on its own it decides nothing, and removing it from your browser does not erase any record of a sanction that already exists.

Virtual machine detection. From your graphics card model we infer whether the session appears to run inside a virtual machine, which is common in automated attacks. By default this only raises an internal notice for staff and does not block anyone, precisely because an old computer or a browser with hardware acceleration turned off produce the same signal.

Global attacker list

If Axis’s anti-nuke stops an attack and that server’s owner confirms it was one, the attacking account’s Discord ID joins a list seen by the other servers running Axis, together with the incident identifier, the rule that fired and the date. Which server it happened in is not stored (only a hash), nor anything of its content. It is used to warn when that account is staff in another server and to let each server decide what to do if it joins. If you are on the list, /mis-datos ver tells you and lets you appeal; confirmed entries are reviewed after a year.

4. Third-party services

To classify an IP as a VPN or proxy we use a network reputation service (proxycheck.io, always over an encrypted connection). That service receives only your IP address for analysis; it does not receive your Discord identity, your browser fingerprint or any other data. It handles that query under its own privacy policy.

To detect the TOR network we periodically download the public exit-node list from the Tor Project and compare it on our own server: that check sends no data about you to anyone.

Authentication is done through Discord's official login (OAuth2), which only gives us your basic identifier.

If a server subscribes to Sentinel (the paid plan), the payment is processed by Lemon Squeezy, which acts as the seller (merchant of record) and handles the payer’s billing data under its own policy. Axis does not receive or store the card, the email or the name: only the subscription ID, its status and its dates, linked to the server.

Sentinel AI. Only on servers with Sentinel whose owner has turned the AI on, and only for an image that has already raised suspicion (for example, from a brand-new account with a link), Axis sends that image — downscaled and without metadata — and its text to Anthropic (Claude) to tell whether it is a scam. Who posted it is not sent, Axis does not keep the image (only the verdict and a numeric fingerprint of the image), and Anthropic does not use this data to train its models.

5. Where data is stored and for how long

Data is stored on our own, access-restricted server, not on third-party devices. Retention:

  • IP, browser fingerprint and security cookie (hashed): deleted automatically 90 days after you leave the server, and at most one year after your last verification. They are kept longer only while a sanction is in force.
  • Audit log (deleted/edited messages, joins, configuration changes…): a limited number of events is kept, and the administrator can additionally set a maximum age in days, after which they delete themselves.
  • Moderation and sanction records: kept for as long as they are needed to administer the server, since they document a decision that is still in force.
  • Block list of sanctioned accounts: kept for the duration of the sanction and contains only hashes, never readable IPs or fingerprints.
Every server is isolated. Connection or device blocks only take effect on the server where you were sanctioned. One server blocking you does not block you on any other server that uses Axis, and moderation teams cannot see other servers' data or sanctions.

6. Enhanced monitoring (exceptional staff use)

The moderation team can enable closer monitoring of one specific account when there is a well-founded suspicion of abuse. Depending on the option chosen, this may log their reactions or copy their public messages to a private staff channel in real time.

This is an exceptional, targeted measure visible only to staff. It reaches public server content only: never private messages, nor conversations outside the server, nor the content of voice calls.

7. Your rights and how to exercise them

You have the right to access your data, to rectify it, to request its deletion, to object to the processing and to request the portability of what you provided. You do not need to write a formal request: you can exercise these rights from Discord itself.

  • /mis-datos — access. We send you by direct message the detail of everything stored and linked to your account in that server. It is never posted in a channel. For security the report does not include the hash of your connection or the accounts linked to it: those are third-party data and would allow probing how evasion detection works.
  • /borrar-mis-datos — deletion. This records your request. It is not executed automatically: an authorised person reviews it, and you are told the outcome by direct message, whether it is accepted or rejected (with the reason).
  • Rectification, objection and portability: contact the administration team of the server, or us through the channels in section 10.

We resolve requests within a maximum of 30 calendar days from the moment they are recorded.

7.1. What is deleted and what is not

If your request is approved, your ordinary activity is deleted: your messages logged when edited or deleted —including the re-hosted attachments, which are removed from disk—, your joins, your name and nickname changes, your reactions, your voice activity and the record of which invite you used.

There are two things that are not deleted on request, and we want to be transparent about why:

  • The hash of your connection and device. If it could be erased at will, any sanctioned person would dodge their removal by requesting deletion and rejoining, and alt-account protection would stop working for everyone. It is pseudonymised data (it does not reveal your IP) and kept for a limited time: it is deleted automatically after 90 days, whether or not you request deletion.
  • Sanctions in force and security records (warnings, kicks, bans and their reason, moderation history). They document an active decision and are the evidence with which that decision can be defended or reviewed if you challenge it.
These two exceptions rely on the limits that data protection law itself places on the right to erasure: the legitimate interest in community security and fraud prevention, and the defence of legal claims. They are not a blanket refusal: everything else is deleted.

If you believe a connection or device block has affected you by mistake, tell the staff: an appeal system exists and the block can be lifted, which erases both the connection and the device associated with it.

7.2. Who decides on your request

Deletion requests are resolved by the bot operator or by a person they have authorised expressly and by name. Deliberately, holding a role as administrator or moderator in a server is not enough: if it were, someone with access to a role could erase the evidence of a sanction by presenting it as an exercise of the right to be forgotten. Every approval or rejection is logged with the identity of whoever resolved it.

You may also lodge a complaint with the data protection supervisory authority of your country if you consider that we have not handled your request properly.

8. Minors

As with Discord, the service is intended for people who meet the minimum age required by Discord's Terms (13 years, or higher where your country requires it).

9. Changes

We may update this policy. The date of the last update appears at the top of the document.

10. Who is accountable for your data, and contact

Two roles are worth distinguishing, because they determine who to approach:

  • The Discord server where Axis is used —that is, its administration team— decides to install the bot, which features to enable and for what purpose. In data protection terms it acts as the controller.
  • Whoever operates Axis provides the tool and the infrastructure where the data is stored, and processes it on that server's instructions: acting as the processor. We do not sell, share or use that data for any purpose of our own, nor for advertising or commercial profiling.

To exercise any of the rights in section 7, the fastest route is /mis-datos and /borrar-mis-datos, or contacting the administration team of the server. If you get no response, you can reach whoever operates Axis through the support server linked on the bot's website.