HTTPS protects network traffic.
The public website and dashboard use HTTPS through Cloudflare. Traffic between Cloudflare Workers and D1 is also protected with TLS.
●Reply messages are currently disabled while we improve and restore this feature.
This page explains what linker stores, where it is kept, what is encrypted, and which checks control access. It describes the current implementation rather than making broad promises.
Encryption is only one part. linker also limits permissions, avoids exposing secrets to browser code, and checks every sensitive change on the server.
The public website and dashboard use HTTPS through Cloudflare. Traffic between Cloudflare Workers and D1 is also protected with TLS.
Cloudflare documents automatic AES-256-GCM encryption at rest for D1. linker additionally encrypts Discord OAuth tokens with AES-GCM before saving them.
The bot currently stores operational data as ordinary JSON files on its Termux host. The linker code does not add file-level encryption to those files, so device and Termux account security matter.
The exact fields depend on the features a person or server uses.
Technical operators can still require access for maintenance. Encryption does not remove that operational reality.
A logged-in person can see the account, bot profile, and moderation information associated with their own Discord user ID.
Server owners and members with Administrator or Manage Server permission can access supported server settings. Servers without linker are shown but cannot be configured.
The bot sends snapshots and receives queued changes through internal endpoints protected by a separate bearer secret.
The linker operator can technically access the Termux host and Cloudflare account for support and maintenance. Cloudflare processes the hosted dashboard database and Discord processes account, server, and bot activity under their own service terms.
API routes for personal data and server settings require authentication. Sensitive write operations also require same-origin and CSRF checks.
These measures reduce common risks around stolen sessions, forged requests, unsafe redirects, and unauthorized server changes.
The enforcement exception prevents someone from escaping an active global-chat restriction by deleting their profile.
A deletion request removes personal settings, statistics, profile fields, and rule-acceptance data from the bot once the queued request is processed. The synchronized user snapshot is then removed from the dashboard database.
Active enforcement status and expiry information remain. A ban or mute is not lifted by deleting profile data.
This is a technical explanation, not a replacement for the formal Privacy Policy or GDPR notice. Retention periods and legal rights should be read in those documents.