Back to Quixly

Privacy Policy

Last updated 2026-08-28

This page describes what Quixly (the Discord bot, its dashboard, and its AI features) actually collects and stores, based on the software as built — not a generic template. For how to delete any of it, see the Data Deletion page.

1. Who this policy covers

Quixly is operated by Quixly Development, based in the Netherlands, which is the data controller for the processing described here. This policy applies to the Quixly Discord bot, the Quixly web dashboard at this domain, and the AI features built into both.

For anything about Quixly itself — privacy requests, deletion, or support — write to [email protected]. The company behind it can be reached at [email protected].

2. What we collect

Quixly is a bot that operates inside servers you or your admins add it to. It collects the data it needs to run the features you turn on:

Discord account data

  • Your Discord user ID, username, and avatar — Discord provides this whenever the bot sees you send a message, join/leave a server, or interact with a command.
  • If you log in to the dashboard: an OAuth access token and refresh token (used to read your servers and act on your behalf), stored server-side and never exposed to the browser.

Server configuration

  • Per-server settings your admins configure — channel IDs, moderation and automod rules, welcome/farewell messages, ticket categories, AI persona and content-filter choices, and similar.

Moderation & activity logs

  • Moderation actions (bans, kicks, warnings, timeouts) with the target user, the acting moderator, and a reason, so servers have an accountability trail.
  • Automated moderation (auto-mod) actions taken against messages.
  • Leveling/XP, economy balances, and similar gameplay state tied to your Discord user ID within a server.

AI conversation data

  • When you talk to Quixly's AI (by mentioning it, in a channel it's active in, or via a slash command), the message content and the AI's reply are processed to generate that reply and are kept briefly as conversation context.
  • The AI extracts short, specific facts from conversations into a long-term memory store — not full transcripts. Each memory has a visibility level you or your server controls (private to you, public, or shared with that server) and can be viewed, edited, or deleted at any time. See Data Deletion for how.
  • Technical metadata about each AI call — which model handled it, token counts, latency, and cost — is logged separately from the conversation content itself, for reliability and abuse monitoring.

Uploaded media

  • Images your admins upload as welcome/farewell or rank-card backgrounds, stored with a server-hosted CDN.

3. How the AI features work

To generate a reply, message content is sent to OpenRouter, the gateway Quixly uses to reach language models. OpenRouter forwards the request to whichever model answers it — currently models operated by Google, xAI, DeepSeek and Anthropic, selected per request based on what is being asked. Quixly does not use your server's messages to train its own models. What those providers may do with a request is governed by OpenRouter's terms and the terms of the provider that answers it, not by this policy. We send only what is needed to produce the reply, we do not sell message content, and we do not use it to train any model of our own. If you would rather nothing was sent at all, the AI is off until a server admin turns it on, can be limited to specific channels, and you can opt out of being remembered entirely — see section 7.

The AI's behavior — its persona, tone, and how much profanity or edge it's allowed — is configured per server by that server's admins. Content sent to and generated by the AI is subject to whatever content filter level that server has chosen.

4. How long we keep it

Quixly runs an automatic retention sweep that deletes old rows on a fixed schedule:

DataKept for
AI call metadata (model, tokens, cost)90 days
AI conversation turns (raw chat content)30 days
AI proactive-message activity90 days
Aggregated AI usage stats (hourly, no message content)180 days
Auto-moderation action logs90 days
Reaction-translation logs30 days
Dashboard login tokens, after expiry30 days

Two categories are not on an automatic timer:

  • AI long-term memories persist until they're explicitly deleted, decayed for low relevance, or trimmed once your server's plan-tier cap is reached — not on a fixed clock, because a memory that's still useful shouldn't expire on a schedule.
  • Moderation logs persist indefinitely by default, so a server keeps an accountability record. If you're the subject of one, see Data Deletion for what can and can't be removed.

5. How we share data

We share message content with the AI model provider(s) described above, strictly to generate a reply. We do not sell personal data. We may disclose data if required by law, or to Discord itself when required for platform compliance.

6. Your rights & controls

  • View, edit, or delete any AI memory tied to your Discord account at /dashboard/profile/memories, or wipe all of it at once — see Data Deletion for exact steps.
  • Ask your server's admins about server-level settings (channels, logs, moderation history) — they control that configuration, not us.
  • For anything without a self-service control today (e.g. a full account-data export, or removing your user reference from historical moderation logs), contact [email protected]. We aim to respond within 30 days.

7. Children's privacy

Discord requires users to be at least 13 (or the age of digital consent in their country). Quixly does not knowingly collect data from anyone below that age beyond what Discord itself already requires to hold an account.

8. International transfers & legal basis

Quixly Development is established in the Netherlands, so this processing falls under the GDPR. We rely on these legal bases:

  • Contract — running the bot and the dashboard for the server that invited it, including your settings and your dashboard session.
  • Legitimate interest — moderation logs, automod records and audit trails, which exist so a server can account for what its staff did, and abuse prevention such as rate limiting and the blacklist.
  • Consent — the AI features. A server admin turns them on per server and per channel, and any member can opt out of being remembered or erase what is stored about them at any time.

Message content sent to the AI leaves the EU: OpenRouter routes it to model providers that operate outside the European Economic Area. For those transfers we rely on the data-processing terms we have agreed with OpenRouter and, through it, with the provider that answers the request. If you want the specifics for a particular provider, ask us at [email protected] and we will tell you which safeguard applies. Everything else — your settings, levels, moderation logs and dashboard session — stays in our own database and is not sent to the model providers.

9. Changes to this policy

We'll update the date at the top of this page when this policy changes. Material changes will be announced in our support server.

10. Contact

Questions about this policy: [email protected]. Use the same address for data-protection requests — access, correction, deletion, objection or portability. Quixly Development has not appointed a separate data protection officer.