What Nekonomy collects, why, how long it keeps it and how you request deletion — described from how the bot and the dashboard actually work.
Nekonomy is an economy bot for Discord. To work, it needs to know who played and where — and that is very nearly all it keeps.
We store numeric Discord identifiers (user, server, channel, role and message IDs) linked to game progress: balances, items, crops, profession, missions and roleplay records.
We do not store usernames, nicknames, avatars, e-mail addresses, phone numbers, or the content of your messages. We do not sell data and we do not run advertising.
This policy covers the bot on Discord and the dashboard at nekonomy.xyz. It
complements the Terms of Service.
To be clear up front, Nekonomy does not collect or store:
When you sign in to the web dashboard with your Discord account, your username and avatar identifier are held in your own browser session so the page can show who is signed in. That lives in a signed cookie, not in our database, and disappears when you sign out. See Dashboard and sign-in.
Public numbers assigned by Discord that the bot receives when processing a command:
Created by your own actions inside the bot, spread across roughly a hundred tables. In summary:
| Category | What is stored |
|---|---|
| Economy | Wallet and bank balance per server, global diamonds, currency audit history, command cooldowns |
| Shop and inventory | Server and global items, quantities, a snapshot of the item at delivery, purchases and per-player caps, discard deadlines |
| Progression | XP, level, badges, class, daily and weekly mission counters, claims |
| Professions | Current job, work shifts, energy, role syncing |
| Farm | Land shape, plots, planting and harvests, fences and paths, house and rooms, chickens and character appearance |
| Police roleplay | Cases, reports, warrants, arrests, bail, evidence, weapon custody, internal affairs and wrongful-arrest repairs |
| Health and status | Illness, immunity, hospital stays, active jail time and other temporary states |
| Minigames | Bingo, blackjack and mines rounds, bets and outcomes |
| Server configuration | Prefix, language, shop items, per-command permissions, management roles, log channels and role rewards |
Operational logs holding identifiers, command name and timestamp, used to diagnose failures and investigate abuse. Administrative audit records (for example, who granted or removed currency) are kept so the server itself can hold its moderators accountable.
Every piece of data exists for a reason, and lives as long as that reason does.
| Data | Why | For how long |
|---|---|---|
| User ID + progress | Keeping your game between sessions | While you use the bot, or until you request deletion |
| Server configuration | Making the bot behave as the server defined | While the bot is in the server |
| Mission counters | Measuring task progress | Per cycle (daily/weekly); replaced in the next cycle |
| Roleplay and audit records | Game consistency and the server's internal accountability | While the case or the server exists |
| Technical logs | Diagnostics and security | Short term, rotated automatically |
| Website sign-in session (browser cookie) | Keeping you signed in to nekonomy.xyz | Up to 7 days, or until you sign out |
| Subscription (where applicable) | Granting and maintaining benefits | For the life of the subscription, plus any applicable tax period |
Basis for processing: performing the service you requested by using a command, and the legitimate interest in keeping the service secure and free of fraud.
Discord classifies some access as privileged and reviews it individually. This section describes exactly what Nekonomy does with it.
Required for two purposes:
s!profile.
Without reading the text there is no way to know a message is a command.In the counter, the message is used only to check whether it meets a minimum length (a guard against empty-message spam) and, if it does, to increment a number tied to your ID. The text is not written to the database, is not sent to any third party, and never leaves the process memory. There is no messages table anywhere in the system.
The bot neither requests nor uses the members intent. It keeps no member list and receives no join or leave events.
The bot does not read anyone's status, activity or presence.
For the “react to messages” mission, the bot receives reaction events and keeps the user + message pair in memory only so the same reaction is not counted twice. That pair lives in process memory, is capped in size, and disappears when the bot restarts. Only a numeric counter reaches the database.
The dashboard at nekonomy.xyz uses Discord OAuth2 with the
identify and guilds scopes — the minimum needed to know who you
are and which servers you can administer. The bot is invited with bot and
applications.commands.
SameSite=Lax and,
in production, restricted to HTTPS. Valid for up to 7 days./farm or /coop stay clickable in the conversation and depend on no
session: each button carries what it needs in its own identifier, and the state is read from
the database at the moment of the click. That is why they keep working even after the bot
restarts.Administrators and holders of the configured management roles can view and change that server's entire configuration, including activity logs. Grant those roles only to people you trust.
A server's administrators can create forms in the dashboard (reports, support, applications and others) and share links to them. Each form belongs to the server that created it, and whoever configures it decides what to ask.
drive.file scope).Where premium features are enabled, payment is processed by Stripe, entirely within its environment.
We do not sell, rent or share data for marketing. Data passes only through the services the bot needs in order to exist:
| Service | Role | What it receives |
|---|---|---|
| Discord | The platform the bot runs on | Interactions, commands and responses |
| Discloud | Application hosting | Running the bot and the website |
| PostgreSQL (managed database) | Storage | All game and configuration data |
| Stripe | Payments, where enabled | Payment data you provide directly to it |
| Google Fonts | Fonts for these legal pages | A browser request when the page loads |
| Google Drive | Form media, in the account each server connects | Images and videos sent through that server's forms |
We may disclose data where required by law, by court order, or to protect the rights, safety and integrity of the service and its users.
No system is immune. We take measures that are reasonable and proportionate to the nature of the data handled — essentially public Discord identifiers and game progress. In the event of a material incident, we will communicate through the official channels.
At any time you may:
We confirm ownership before deleting — otherwise anyone could erase someone else's progress. Requests are handled within 30 days.
Removal is permanent: balances, items, farm, profession, badges and progress are lost and cannot be restored. Records required for fraud prevention or legal obligations may be retained for strictly the necessary period.
That server's data stops being used. An administrator may request deletion of the server's data through the same channel, providing the server ID.
The service is not intended for people below the minimum age required by Discord's Terms (13 years in most countries, and higher where local law requires it).
We do not knowingly collect data from anyone below that age. If we learn that this has happened, the data will be removed. Guardians may request removal at the contact address.
The bot, the dashboard and the database run on servers that may be located in countries other than yours. By using the service, you acknowledge that the data described here may be processed outside your country of residence, with security measures equivalent to those described in this policy.
This policy may be updated when the service changes, when new Discord requirements arise, or where the law requires it. The last updated date appears at the top of the page, and material changes will be announced through the official channels.
If a change significantly broadens the data collected, it will be highlighted before it takes effect.
Questions about privacy, access requests or deletion requests:
Data controller: the Nekonomy maintainers. Response time: within 30 days.