Privacy Policy
Last updated: September 2026
What the dashboard receives
When you sign in, Discord provides your Discord account ID, display name and avatar and the servers you have permitted us to see via the identify and guilds scopes. The dashboard checks your current server-management permission before showing server controls.
Each Sonivyr bot sends authenticated operational data: its instance identity, health counters, server IDs and names, voice-channel information, song titles/artists and basic playback state, queue counts, selected settings, and timing information. The dashboard stores a limited song-start history to show analytics.
Authentication and cookies
The dashboard uses an HTTP-only, signed session cookie. Your Discord OAuth access token is stored on the private dashboard server with a session expiration, rather than embedded into public pages. It is used to confirm identity and check server permissions. Do not upload the private dashboard database, bot secrets or OAuth credentials to public_html.
How data is used
Data supports logging in, selecting authorized Discord servers, showing live status, processing explicitly requested controls, remembering server configuration, diagnosing errors, and producing limited analytics. Administrative actions are logged with the acting Discord account ID and server ID. This release does not accept or process credit-card details.
Retention
Sign-in sessions expire after no more than eight hours; song-start history is pruned after 90 days. Current bot status, installation records, action results, and audit records remain in the operator's private database unless removed by administration or a future data-retention update. Hosting and third-party providers may have their own logs and policies.
Third parties
Discord provides sign-in and bot infrastructure. Audio sources, hosting providers, and CDNs may separately process service-related network requests under their own privacy policies.
Data access and deletion
Before public launch, Sonivyr will publish a verified contact method for data access and deletion requests. Discord account-level data remains subject to Discord's separate controls and policies.
sonivyr.Dashboard ↗