Legal
Privacy Policy
What Apera stores about servers and people, why, how long, and how to get it deleted.
Last updated: October 5, 2026
01Who we are
Apera is a Discord bot and the websites that go with it: apera.site (the website and dashboard), docs.apera.site (the documentation and its assistant) and the transcript pages on apera.site. They are run by the Apera team (“we”, “us”). This policy explains what information we handle when you use any of them, why, how long we keep it, and what you can ask us to do with it.
For anything in this policy, contact us in the support server. That is the fastest way to reach the team.
02The short version
- We only use data to run Apera’s features. We never sell it, never show ads, and never use it to build advertising profiles.
- Most of what Apera stores is what a server’s admins switch on: logs, tickets, backups, warnings. Admins choose the features; we store what those features need.
- Message content is only stored when a server turns on message logging or ticket transcripts, and only for a limited time.
- Signing in to the dashboard gives us your Discord ID, name, avatar and server list. Never your password or email.
- No advertising or analytics trackers on our sites. The one cookie keeps you signed in.
- You can ask us to show or delete your data at any time.
03Information from Discord servers
When Apera is in a server, Discord sends it information about that server so it can work. Depending on which features the server’s admins turn on, Apera stores:
- Server settings: everything configured in the dashboard or with commands (channels, roles, limits, messages, designs).
- Server structure: channel, role, emoji and permission IDs and names, used by protection, logging and backups.
- Member details needed by a feature: user IDs, usernames, display names, avatars and roles, for example the member a warning, ticket or welcome is about.
- Messages: Apera reads messages so commands, anti-spam, filters, auto-responders and custom commands work. They are checked as they arrive and are not stored, except: (1) with message logging on, recent messages and their attachments are kept so edits and deletions can be logged, and the content of a deleted or edited message is included in that log entry; and (2) ticket transcripts save the messages of a ticket when it closes.
- Moderation and security records: warnings, timeouts, jails, kicks, bans, strikes, incidents and the actions Apera took (for example removing a nuker’s roles), with who did what and when.
- Recent activity: a short history of logged events per server, shown on the dashboard.
- Tickets: who opened each ticket, who joined it, its status, ratings and staff points, and the transcript if transcripts are on.
- Backups: when a server makes a backup (by command or automatically), a copy of its roles, channels, permissions, emojis, bans, server settings, and members’ roles and nicknames, so the server can be restored.
- Role memory: with “persist roles” on, the roles of members who leave, so they get them back when they return.
- Giveaways, self roles, verification, temp voice, stream alerts: entries, panels, channel owners and the channels being followed.
04Signing in to the dashboard
You sign in with Discord. We ask Discord only for the identify and guilds permissions, which give us your Discord ID, username, display name, avatar, and the list of servers you are in with your permissions there. We use this to show you the servers you can manage and to record who changed a setting. We never receive your password, and we do not ask for your email address.
While you are signed in, a session is kept on our server and a cookie in your browser links you to it. Changes you make in the dashboard are recorded with your user ID so server owners can see who changed what.
05Vanity Guard recovery accounts
Vanity Guard (a beta feature) can reclaim a server’s custom invite link. To do that, a Discord account can be connected (usually by the Apera team, or by a server owner who is asked to) through a separate Discord sign-in that asks for more permissions (identify, guilds, guilds.join, email, connections). We store that account’s ID, name and avatar, and its Discord access and refresh tokens encrypted. The tokens are used only for Vanity Guard. We do not store the account’s email or connections. To disconnect an account, ask us in the support server and we delete its tokens; you can also remove Apera under Discord’s Settings → Authorized Apps at any time, which makes the tokens stop working.
06Our websites, the docs assistant and uploads
- Docs assistant (on apera.site and docs.apera.site): we save the questions you type and the answer shown, for up to 30 days, to see what people need and to improve the docs. We store a one-way hash of your IP address with them, not the address itself. The assistant answers from our documentation. If AI answers are turned on, a question the docs don’t clearly answer is sent to our AI provider, Anthropic, along with related docs pages, and is handled under Anthropic’s API terms.
- “Was this page helpful?”: the page, your vote and any note you write. No account or IP address is stored with it.
- Uploaded images (for example welcome backgrounds or webhook avatars): stored on our server and served from a public link so Discord can show them. Anyone with the link can open the image.
- Transcripts: ticket transcript pages require signing in, and are only shown to people allowed to see that ticket, such as the member who opened it and the server’s staff.
- Technical logs: like most websites, our web server logs each request (IP address, time, page, browser) to keep the service secure and working. These logs are deleted after about two weeks. The bot keeps an internal activity log (commands used, settings changed, servers joined or left) for spotting problems and abuse.
07How we use information
Only to provide and improve Apera:
- running the features a server turns on: protection, logs, moderation, tickets, backups, welcomes, and the rest;
- showing servers and settings in the dashboard, and recording who changed what;
- keeping Apera secure: stopping attacks, spam and abuse, and blacklisting servers or users who misuse it;
- fixing bugs and improving features and documentation;
- answering you when you contact us.
We do not sell or rent data, show ads, use it for advertising, or use your messages to train AI models.
08Legal bases
Where privacy laws such as the GDPR apply, we rely on: providing the service you or your server asked for (running the bot and dashboard); our legitimate interests in keeping Apera secure, preventing abuse and improving it, balanced against your rights; and consent where a feature asks for it, such as connecting a Vanity Guard account, which you can withdraw at any time. Server admins who turn on features like message logging are responsible for having a valid reason to do so in their community.
10How long we keep it
| Data | Kept for |
|---|---|
| Logged messages (message logging on) | Up to 7 days |
| Logged attachments | Up to 48 hours |
| Ticket transcripts | 30 days |
| Recent activity on the dashboard (including logged message content) | The newest 2,000 events per server |
| Backups | Until the server deletes them; automatic backups keep the number of copies the server sets |
| Docs assistant questions | Up to 30 days |
| Web server request logs | About 2 weeks |
| Dashboard sign-in sessions | Until you sign out, or about a day without use |
| Settings, moderation records, tickets, role memory | While Apera serves the server, so they keep working |
Removing Apera from a server stops all new collection, but does not erase what was stored, so the setup comes back if Apera is added again. To have a server’s data erased, ask us in the support server.
12Security
All our sites use HTTPS. Discord tokens we hold are encrypted, dashboard pages check your permissions on every request, transcripts need signing in, and our pages block being embedded in other sites. Only the Apera team can access our servers. No system is perfectly secure, so if you find a security problem, please tell us privately in the support server.
13Your choices and rights
- Server admins control what Apera stores: turn features off in the dashboard, delete backups and warnings with commands, or remove Apera from the server.
- Anyone can ask us to see the data we hold about them, correct it, delete it, get a copy, or object to how we use it. Ask in the support server. We may need to confirm the Discord account is yours, and we answer within 30 days.
- Some records belong to a server’s moderation history (for example a ban for breaking its rules). We may keep those where deleting them would let someone avoid moderation, and will tell you if so.
- If you are in the EU, UK or another region with a data protection authority, you can also complain to it.
14Where data is processed
Our servers may be in a different country from you, and Discord and our providers operate worldwide. Wherever your data is processed, this policy applies to it.
15Children
Apera follows Discord’s minimum age: you must be at least 13, or older where your country requires it. We do not knowingly collect data from children under that age. If you think a child’s data is held by us, tell us and we will delete it.
16Changes to this policy
When Apera changes in a way that affects your data, we update this page and the date at the top. For important changes we also announce them in the support server before they take effect.