Privacy Policy
This policy explains what data Sodium collects, why, how long we keep it, who we share it with, and the rights you have over it. It covers both the Discord bot and the dashboard, documentation and site at sodi.dev. It is written to meet the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).
Last updated: 22 July 2026
At a glance #
- We collect only what a feature needs. Sodium does nothing until you turn a system on.
- Moderated content is scored in transit and discarded - we do not build a store of your members' messages.
- Our AI moderation runs on our own in-house, self-hosted models. Your content is not sent to any third-party AI company.
- We do not sell or share your personal information, and we do not use it for advertising.
- Removing Sodium from a server deletes that server's settings, cases and logs automatically.
Who we are #
Sodium is operated by Kay David Kalex, the data controller for the purposes described below.
Operator | Kay David Kalex |
Address | c/o Online-Impressum #4165, Europaring 90, 53757 St. Augustin, Germany |
Email | [email protected] |
Community | Discord support server |
Controller & processor #
Which role we play depends on the data:
- We are the controller for your dashboard account - the Discord profile and guild list we use to sign you in and show your servers.
- We are a processor for the data a server produces - its settings, moderation cases, logs, ticket transcripts and analytics. The administrators of that server decide what is collected and why; Sodium processes it on their behalf. If you are a member of a server running Sodium, the server's administrators are your first point of contact for that data, and this policy explains how it is handled.
Dashboard data #
When you sign in to the dashboard with Discord (OAuth2), we receive and use:
| Data | Why |
|---|---|
| Discord user ID, username, avatar | To identify you and show who is signed in. |
| Your list of servers and your permissions on them | To show which servers you can configure or add Sodium to. |
| OAuth access token | Held in memory for your session to read the above from Discord. We never receive your password. |
We request only the identify and guilds OAuth scopes. Your session is kept in a first-party cookie described under Cookies.
Bot & server data #
Once you enable a system on a server, Sodium stores what that system needs. Depending on your configuration this can include:
| System | What is stored |
|---|---|
| Configuration | Server ID and your settings, plus a cached snapshot of channels and roles for the dashboard pickers. |
| Moderation cases | Case number, moderator and target user IDs, action, reason, optional duration and up to two proof images. |
| Logging | The server events you route to log channels - the details of each event depend on the event type and your exemptions. |
| Tickets | An HTML transcript of the conversation (messages, embeds, attachments) when a ticket closes. |
| Welcomer & Messages | Your greeting content, image designs and message templates. |
| Analytics | Aggregate counts only - messages and voice activity per channel per day, joins, leaves and invite attribution. Never message content. |
Content that AI moderation checks is scored as it arrives and then discarded. It is only persisted when it becomes part of something you asked for - a case, a configured log entry or a ticket transcript.
AI moderation #
When you enable AI moderation, message text and images are scored for categories like harassment, hate, NSFW content and scams. This scoring is performed by modapi.xyz, a moderation service we operate ourselves. The models are self-hosted and run in-house - your members' content is not sent to OpenAI, Google, Anthropic or any other third-party AI provider.
Content is processed transiently to produce a score and is not retained by the moderation service after scoring. Where a score crosses a threshold you set, the resulting action is recorded as a moderation case as described above.
Cookies #
We use a single, strictly necessary first-party cookie:
| Cookie | Purpose |
|---|---|
session | Keeps you signed in to the dashboard. Without it, sign-in does not work. |
We do not use advertising, tracking or third-party analytics cookies. Our infrastructure is fronted by Cloudflare for delivery and security; Cloudflare does not set cookies through our site. Because our only cookie is strictly necessary, no consent banner is required for it.
How we use data #
- To provide the systems you enable and keep the dashboard working.
- To carry out the moderation, logging, ticketing, welcomer and analytics you configure.
- To keep the service secure - preventing abuse, debugging faults and enforcing our Terms.
- To respond to your questions and data requests.
- To meet legal obligations.
We do not sell your data, we do not share it for cross-context behavioural advertising, and we do not use it to train models beyond what is needed to operate the moderation you enable.
Legal bases (GDPR) #
Where the GDPR applies, we rely on these bases under Article 6(1):
| Basis | When |
|---|---|
| Contract | Providing the dashboard and bot you have chosen to use. |
| Legitimate interests | Running the moderation, logging and analytics a server configures, and keeping the service secure and functional - balanced against the rights of the people involved. |
| Legal obligation | Complying with laws that apply to us. |
| Consent | Where we ask for it - you may withdraw it at any time. |
For data we process on behalf of a server, the server's administrators are responsible for having a lawful basis to collect and moderate their members' data.
Sharing & service providers #
We keep the number of parties who touch your data small. We share it only with:
| Provider | Role |
|---|---|
| Discord | The platform Sodium runs on and the source of bot and sign-in data. Governed by Discord's own privacy policy. |
| Cloudflare | Network, content delivery and security in front of our site. Processes traffic in transit; sets no cookies for us. |
| modapi.xyz | Our own in-house moderation service that scores content for AI moderation. Operated by us, not a third party. |
Our databases and application servers are self-hosted and operated by us. We may also disclose data where required by law, to protect our rights or the safety of others, or in connection with a business transfer - in which case we will tell you. We do not sell personal information.
International transfers #
We are based in Germany and host our data on self-managed infrastructure in the European Union. Some providers, such as Cloudflare, operate a global network and may process data (for example, routing a request) outside the EEA. Where that happens, transfers are protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
Retention #
We keep data only as long as it is needed:
| Data | Kept for |
|---|---|
| Server settings, cases and logs | Until you delete them, or automatically when Sodium is removed from the server. |
| Ticket transcripts | 14 days after the ticket closes, then deleted automatically. |
| Analytics counts | 180 days, then dropped automatically. |
| Moderated content (in transit) | Not stored - scored and discarded. |
| Dashboard session | Cleared when you sign out or the session expires. |
Re-adding Sodium to a server starts clean.
Your GDPR rights #
If you are in the EEA or UK, you have the right to:
- Access the personal data we hold about you.
- Rectify data that is inaccurate or incomplete.
- Erase your data ("right to be forgotten").
- Restrict or object to certain processing, including processing based on legitimate interests.
- Port your data to another service in a machine-readable form.
- Withdraw consent at any time, where we relied on it.
To exercise any of these, email [email protected]. Where your request concerns data we process on behalf of a server, we may direct you to that server's administrators or act on their instruction. We respond within the timeframes the law requires. You also have the right to complain to a supervisory authority - in Germany, your state Data Protection Authority or the Federal Commissioner (BfDI).
Your California rights #
If you are a California resident, the CCPA/CPRA gives you the right to:
- Know what personal information we collect and how we use it - set out in this policy.
- Access a copy of the personal information we hold about you.
- Delete your personal information, subject to legal exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information.
- Non-discrimination for exercising your rights.
We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding 12 months. To make a request, email [email protected]; we will verify it against the account or server involved and will not discriminate against you for making it. You may use an authorised agent where the law allows.
Children #
Sodium is not directed at children under 13, and you must meet Discord's minimum age - or the higher age set by your local law - to use it. We do not knowingly collect data from children below that age. If you believe a child has provided us data, contact us and we will delete it.
Security #
We protect data with encryption in transit, access controls, and by keeping our infrastructure self-managed and limited to what the service needs. No method of storage or transmission is completely secure, but we work to keep the risk low and to store as little as possible in the first place.
Changes to this policy #
We may update this policy as the service changes or the law requires. We will revise the date at the top of the page and, for material changes, give notice through the dashboard or our community. Continuing to use Sodium after an update means you accept the revised policy.
Contact #
For any privacy question or to exercise your rights, contact us at [email protected], through our Discord support server, or by post at Kay David Kalex, c/o Online-Impressum #4165, Europaring 90, 53757 St. Augustin, Germany.
