1. What We Collect
Stardust stores the minimum data required to operate its features:
- Server configuration — server ID, welcome channel ID, level-up channel ID, reward channel ID, ticket configuration
- Per-user economy — Discord user ID, coin balance, last daily claim time, owned shop items
- Per-user leveling — Discord user ID, XP, level
- OAuth session — Discord user ID, username, avatar hash, and access token (server-side only, never exposed to the browser)
Stardust does not permanently store the content of your messages.
2. How We Use It
All data is used exclusively to operate Stardust's features — for example, to determine your coin balance for /wallet or to route welcome messages to the correct channel.
We do not sell, rent, or share your data with third parties.
3. Authentication
When you log into the dashboard, we authenticate via Discord's official OAuth2 flow. Your access token is stored server-side in an encrypted session and never sent to the browser. Session cookies are HttpOnly and use the strictest available SameSite policy.
4. Data Retention
Server configuration is retained while Stardust remains on your server. Per-user economy and XP data is retained while you remain in a server that uses Stardust. Removing Stardust from a server deletes server-specific configuration within 30 days.
5. Your Rights
You may request deletion of your data by removing Stardust from your server or contacting us through the support server. We respond to all data requests within 30 days.
6. Security
We take reasonable measures to protect your data, including HTTPS-only traffic, HTTP-only session cookies with SameSite protection, and role-based access verification on every API request.
7. Changes
We may update this policy from time to time. Significant changes will be announced in the support server.
8. Contact
For privacy questions, join our support server.