●Reply messages are currently disabled while we improve and restore this feature.

Safety & data

Clear answers about your information.

This page explains what linker stores, where it is kept, what is encrypted, and which checks control access. It describes the current implementation rather than making broad promises.

QUICK ANSWER

How protection is layered.

Encryption is only one part. linker also limits permissions, avoids exposing secrets to browser code, and checks every sensitive change on the server.

↔IN TRANSIT

HTTPS protects network traffic.

The public website and dashboard use HTTPS through Cloudflare. Traffic between Cloudflare Workers and D1 is also protected with TLS.

◇AT REST

Cloudflare D1 encrypts stored data.

Cloudflare documents automatic AES-256-GCM encryption at rest for D1. linker additionally encrypts Discord OAuth tokens with AES-GCM before saving them.

!LOCAL BOT FILES

JSON files are not app-encrypted.

The bot currently stores operational data as ordinary JSON files on its Termux host. The linker code does not add file-level encryption to those files, so device and Termux account security matter.

WHAT IS STORED

Data by category.

The exact fields depend on the features a person or server uses.

Category
Examples
Protection
Discord account
User ID, username, display name, avatar reference, and manageable server list.
D1 encryption at rest; access limited to an authenticated session.
Discord OAuth tokens
Access and refresh token used to refresh the server list.
Additional linker encryption: AES-GCM with a server-side secret.
Session
Random session and CSRF values with timestamps.
Browser cookie is Secure, HttpOnly, SameSite=Lax; D1 stores a hash of the session token.
Profile & statistics
Privacy choices, global-chat statistics, profile fields, room settings, and related bot data.
No extra field encryption in linker code. Protected by D1 at rest and authorization checks.
Moderation
Active ban or mute type, expiry, reason, and creation time.
No extra field encryption in linker code. Kept when personal profile data is deleted to prevent bypass.
Server settings
Server and channel IDs, names, selected global-chat channel, mode, and permission state.
D1 at-rest protection; settings are shown only after server permission checks.
Bot JSON files
Operational files for users, servers, roles, rooms, rules, moderation, statistics, and codes.
Local copies are plain JSON; synchronized dashboard copies are in encrypted-at-rest D1 storage.
WHO CAN ACCESS WHAT

Access follows the job being done.

Technical operators can still require access for maintenance. Encryption does not remove that operational reality.

◌MEMBERS

Their own dashboard data.

A logged-in person can see the account, bot profile, and moderation information associated with their own Discord user ID.

⌘SERVER MANAGERS

Supported settings for permitted servers.

Server owners and members with Administrator or Manage Server permission can access supported server settings. Servers without linker are shown but cannot be configured.

◇BOT CONNECTION

Internal sync routes require a secret.

The bot sends snapshots and receives queued changes through internal endpoints protected by a separate bearer secret.

◎OPERATORS & PROVIDERS

Administrative access exists.

The linker operator can technically access the Termux host and Cloudflare account for support and maintenance. Cloudflare processes the hosted dashboard database and Discord processes account, server, and bot activity under their own service terms.

×PUBLIC VISITORS

No public dashboard records.

API routes for personal data and server settings require authentication. Sensitive write operations also require same-origin and CSRF checks.

SECURITY MEASURES

Checks currently in place.

These measures reduce common risks around stolen sessions, forged requests, unsafe redirects, and unauthorized server changes.

01
OAuth state validationLogin uses a short-lived random state and compares it before accepting Discord's callback.
02
Protected cookies and hashed sessionsSession cookies are Secure and HttpOnly; database lookup uses a SHA-256 hash instead of the raw session value.
03
Same-origin and CSRF checksLogout, deletion, and settings changes require the expected origin plus a session-specific security token.
04
Permission checks on the serverThe backend verifies ownership, Administrator, or Manage Server before returning or changing server settings.
05
Restrictive response headersAPI responses disable caching and framing, block content-type guessing, and use a restrictive content security policy.
DELETION

What deletion removes and keeps.

The enforcement exception prevents someone from escaping an active global-chat restriction by deleting their profile.

✓REMOVED

Personal profile data and settings.

A deletion request removes personal settings, statistics, profile fields, and rule-acceptance data from the bot once the queued request is processed. The synchronized user snapshot is then removed from the dashboard database.

!RETAINED

Active bans and mutes.

Active enforcement status and expiry information remain. A ban or mute is not lifted by deleting profile data.

Scope of this page

This is a technical explanation, not a replacement for the formal Privacy Policy or GDPR notice. Retention periods and legal rights should be read in those documents.