Skip to content
Lunara
Menu

Legal

Privacy policy

What Lunara stores about you, why, for how long, and how to see or delete it — written from what the bot and this website actually do.

The short version: your Discord ID and your game, never your messages, never your voice, never your payment details. /data export and /data delete work instantly. See also the terms.

1. Who we are

Lunara is a Discord bot and this website, run by [operator’s legal name] (“we”). We decide what Lunara stores and why, which makes us responsible for it. You can reach us at [contact email address].

Lunara is not Discord. Discord’s own privacy policy covers what Discord does with your account; this one covers what Lunara does.

2. What Lunara stores when you play

Only what the game needs to work. Your account is keyed to your Discord user ID, and everything else hangs off it:

  • Progress: level and experience, daily, weekly and monthly claim times and streaks, quest, season and puzzle progress, and your chosen titles, frame and background.
  • What you own: balances of each currency, cards and their levels, items, pets, upgrades, custom-character slots.
  • A ledger: every currency movement (amount, balance after, reason, time) and every game result (game, bet, payout, time, and the server it was played in).
  • What you did with others: trades, gifts, payments, auctions and bids, duels and battles, friendships, marriages and family links, referrals (who invited whom), raid damage.
  • Activity counters: how many messages you have sent and how many seconds you have spent in voice — counts, never contents (see the next two sections).
  • Votes: when you last voted, your vote streak and your vote total.
  • Settings you chose: your privacy switches, which reminders you turned on, and any gambling pause you set.
  • Things you made: custom characters — the name, series, bio and other text you wrote, the stats you chose, the Discord link to any image you attached, and for one you publish, which server you published it from — plus likes, and reports you file (with your reason).
  • Moderation: whether the account is banned, and why.
  • Value sent by new accounts: a record of each payment, gift or trade made from an account that is still new — see Keeping rewards for real players.
  • Days of Lunara Plus you were given, for example from a chest: the tier, how many days, when they start and end, and where they came from.
  • Purchases: see Purchases.

We do not store your email address, your real name, your IP address in the game’s database, or any payment details. Lunara does not ask Discord for your email at all.

3. What Lunara reads but does not keep

Messages. Lunara can read messages in channels it can see, for two reasons: to recognise commands typed with its prefix (servers can turn text commands off), and to count that you spoke, for chat rewards. The text of your messages is not stored. Answers typed during trivia and guessing games are compared with the answer and then discarded. The daily name puzzle is the exception: your guesses for the day are kept with your attempt, because the puzzle shows them back to you.

Server members. Lunara sees members joining a server so it can post a welcome message where a server has asked for one, and it can see members’ roles so it can hand out role rewards.

A server’s member list, for the invite chest. The chest on this website for adding Lunara to a server pays only for a server with real people in it. To check, Lunara reads that server’s member list from Discord, using the bot’s own access to the server, and counts the members who are not bots and whose Discord accounts are at least 30 days old (an account’s age is read from its ID; see below). It stops counting at 10. This happens for servers you manage that have Lunara in them, while you have not yet claimed that chest, each time your tasks are checked. Only the number is kept: in the site’s memory for up to ten minutes, and in the record of a claim that succeeds. The list itself, and every member’s ID, name and account age, is discarded as soon as it has been counted — including for members who have never used Lunara.

4. Keeping rewards for real players

A spare Discord account costs nothing to make, so some rewards wait until an account looks like a person rather than a prop. Lunara judges that only from what it already has:

  • How old your Discord account is. Every Discord ID has the moment the account was created written into it, so Lunara works out an account’s age from the ID alone. It does not ask Discord for it and does not store it anywhere.
  • Your level and your play, from your progress and ledger described above — for example, whether you pulled, battled, gathered or quested in the last few days.

What depends on it:

  • Chests on this website are earned only by Discord accounts at least 14 days old. Linking your account and the daily check-in also need level 3, and the check-in needs play in the last 7 days.
  • A vote from a Discord account less than 7 days old is counted but pays nothing.
  • A referral pays only once the invited Discord account is 14 days old and has played on 3 separate days.
  • Until your account is established — a Discord account 30 days old, 7 days with Lunara, and level 10 — what you can send other players is capped per receiving player, so one player cannot collect from a crowd of fresh accounts: at most 3 new accounts may send the same player anything in 24 hours. To count against that cap, each payment, gift or trade from a new account is recorded in Lunara’s audit log: who sent it, who received it, what moved, by which feature, in which server, and when. A transfer the cap turns away is recorded the same way. Once an account is established, what it sends is neither capped nor recorded there.

5. Voice activity

Where a server has voice rewards switched on, Lunara checks once a minute who is sitting in a voice channel — from the voice state Discord shares with every bot (which channel, and whether you are muted or deafened). If at least two people are in the channel and able to hear, each of them earns that minute’s reward.

Lunara never joins a voice channel and never receives, records or stores audio. What it keeps is the total number of seconds you have been rewarded for and the experience it paid, plus a counter of today’s minutes (kept in a short-lived cache and discarded after a day) so nobody earns past the daily cap.

6. Votes on bot lists

When you vote for Lunara on a bot list such as top.gg or Discord Bot List, that site tells Lunara your Discord user ID and whether the vote fell on a weekend. Lunara uses that to pay the vote reward and to keep your vote streak and total. It trusts nothing else in the message: the amounts come from Lunara’s own settings. The bot lists’ own privacy policies cover what they collect when you vote on their sites.

7. Purchases

Subscriptions (Lunara Plus and Pro) and gem packs are bought through Discord. Discord runs the checkout and billing and handles your payment details; Lunara never sees a card number or a billing address.

For a gem pack, Lunara records the purchase Discord reports: its ID, which pack and SKU, how many gems it delivered, its price in US cents, and when it was delivered or refunded. The running total of those prices is your VIP progress. For subscriptions, Discord tells Lunara which tier you have each time you use a command; Lunara may cache that answer for a few minutes and does not otherwise store it.

Days of Lunara Plus won from a chest are not a purchase and do not go through Discord. They are stored with your account (see Chests), and your tier is whichever is higher: what Discord says you subscribe to, or days you were given that are running now.

8. This website

Signing in

You sign in with Discord, which asks you to allow two things: identify (your user ID, username and avatar) and guilds (the list of servers you are in, and your permissions in each). Nothing more — not your email, and nothing that lets us act as you.

Your sign-in is kept in an encrypted cookie on your own device, not in our database. It holds your Discord ID, name and avatar link, and the access token Discord issued, which the site reads only on its server to check which servers you manage. The cookie lasts until you sign out or it expires (30 days). The list of your servers is held in the server’s memory for up to two minutes so the dashboard does not ask Discord on every click.

That cookie is the only one the site sets, and it is needed for signing in; there are no advertising or analytics cookies. [Confirm, and update if analytics are ever added]

The dashboard

If you manage a server, changes you save are written to that server’s settings in Lunara’s database. The site checks your permissions with Discord before letting you edit, using an answer never more than two minutes old.

When you add or change a role reward, the site asks Discord, as the bot and at that moment, for the server’s owner, its roles and what each can do, the channel settings for the role you picked, and which roles you hold in that server. That is how it checks the role carries no moderation or server permissions, is not one of the server’s bot-admin roles (the ones allowed to run /admin), and sits below your own highest role, as Discord would require if you handed it out yourself. None of those answers is stored; only the reward you saved is.

Chests

Signing in to open chests creates or finds your Lunara account, exactly as your first command in Discord would. Before a task pays, the site checks your account as described in Keeping rewards for real players, and then the task itself: the short-lived record the bot keeps of your latest vote on each bot list, your level, your daily streak, or how many of your referrals have qualified. For the invite chest it also looks at the servers you manage (from the server list you allowed at sign-in), how long Lunara has been in each — counted from when the bot first joined, a date it keeps even if it is removed and added back — and a count of each server’s members (see What Lunara reads but does not keep).

For each task you claim we record which task, when, and what the check saw (for example the time of the vote, your level, or for the invite chest the server’s ID, how many days Lunara had been there and the member count), so a disputed claim can be looked into. The vote or server a chest was paid for is recorded too, so it cannot pay twice. We record every chest you earn, when you opened it and what was inside.

Days of Lunara Plus. When a chest gives days of Lunara Plus, a record is added to your account: the tier, how many days, when they start and end, and the chest they came from. The bot reads it whenever it decides what your tier is, and keeps a copy in a short-lived cache for up to five minutes so it does not read the database on every command. The record stays with your account after the days run out, as history, until you delete your account. It is included in /data export, and /data delete erases it along with any days not yet used.

Your gambling pause. What comes out of a chest is chance, so opening one first checks whether you have paused gambling with /gamble pause. That reads the end date already stored with your account (see How long we keep it) and records nothing new. While the pause runs, your chests stay closed and the chests page shows the date it ends; tasks still count, and the chests they earn wait for you.

The public leaderboard

The leaderboard on this site shows the top players across every server with their Discord display name, avatar and the number they are ranked by. Names and avatars are fetched from Discord and cached for up to six hours. If you have turned leaderboards off with /privacy, you are not shown at all.

Abuse protection and logs

To stop anyone hammering the site, requests are counted per signed-in user, or per IP address for pages that need no sign-in. Those counters live for about a minute in a short-lived cache and are then gone. The site’s error logs can include your Discord user ID. [How long server logs are kept, and by which host]

9. Who can see what

Lunara is a social game, so some of your numbers are visible to other players by default — somebody can look up your balance or collection with a command. Every such lookup can be switched off, account-wide, with /privacy:

  • Wallet and balances (on by default: yes). Turning this off hides your money from /balance user: and /profile.
  • Cards and collection (on by default: yes). Hides your cards and dex from /collection, /flex and the website, and your name on pulls.
  • Level, XP and prestige (on by default: yes). Hides your level, XP, titles and score (website too), and stops level-ups being announced.
  • Casino history (on by default: no). Off by default — your casino record is already private to you.
  • Appear on leaderboards (on by default: yes). Off takes you off every board — the weekly winner and its prizes too.
  • Trades, gifts and duels from anyone (on by default: yes). Turning this off means only friends can trade, pay, gift, duel or battle you.

Server administrators can see activity inside their own server through Lunara’s admin tools (for example, currency they created and handed out). Lunara’s operators can see everything described on this page, and use it only to run and protect the game.

Publishing a custom character. A character you publish with /character publish is looked at first by Lunara’s own moderators — Lunara’s operators, and the moderators of Lunara’s own Discord server — whichever server you published it from. They see what the gallery would show (its text, stats and picture), a mention of your Discord account, and the name and ID of the server you published it from, and they approve or reject it. The moderators of the server you published from take no part in it. If you change a published character, or enough players report it, it goes back to the same moderators, and they can also take a published character back out of the gallery at any time. When they look at a character they see the reasons given in any open reports on it, but not who filed them. If they reject your character or take it down, the reason they give is shown to you on it.

10. Server settings

For each server Lunara is added to, it stores the server’s ID and name, when Lunara first joined it, and the settings its administrators chose — which features are on, which channels and roles it uses, limits, currencies, role rewards and welcome messages — and a log of administrative actions that records who took them. When an administrator has Lunara make a role, post a role menu, or give or take a member’s role, the administrator’s Discord ID is kept with it, and the log names the member by Discord ID. The dashboard makes those changes in Discord with the bot’s own token, as the bot does. If Lunara is removed from a server, those settings are kept so that adding it back restores them. [How a server owner asks for their server’s settings to be deleted]

11. How long we keep it

Until you delete it. /data delete erases your account and everything attached to it immediately — balances, cards, history, custom characters, chests and any days of Lunara Plus you won included. It cannot be undone, and there is nothing to restore it from on your side.

Backups. Every night we make an encrypted copy of the database, so that a failure on our side cannot wipe out everyone’s collection, and each copy is deleted after 30 days. What /data delete erases leaves the live database at once, and leaves the copies made before you deleted it as they are deleted in turn: within 35 days at the latest. The copies are there to recover from a failure, never to bring back one account, and they are opened only by the automatic check that proves they can still be restored.

One exception, on purpose. If you have an active gambling pause from /gamble pause, its end date, and how many pauses you have set, outlive /data delete: they are kept against a keyed hash of your Discord ID, not the ID itself (see below), and are erased by themselves once the pause runs out. You were told the pause could not be lifted early by anyone, and deleting your account would otherwise be a way to lift it.

And a note that you deleted, also on purpose. When you run /data delete, Lunara keeps a note that the account behind your Discord ID was deleted: a keyed hash of the ID, not the ID itself, and the date it was deleted. Nothing else — no name, no balances, no history. It is there so the welcome rewards for new players (the starter card and the first steps in /start) are given once per person: without it, deleting your account and coming back would look exactly like arriving for the first time. Deleting again keeps the one note and its first date.

What “keyed hash” means here. Both are worked out from your Discord ID with a secret key that is kept apart from the database and never stored in it, so neither can be turned back into your ID from the database alone — not even by someone who holds a copy of it and tries every Discord ID they can find. The pause and the note are worked out differently, so one cannot be matched to the other by its hash either. Their dates are kept to the day, not the time, so neither can be lined up with a new account by the moment it was made, though on a quiet day the date alone can still narrow down whose it might be. This is not anonymity, and we do not claim it is: Lunara holds the key, and recognising your ID when it comes back is the whole purpose of both.

Coming back after deleting. Neither note names you, but the account you make if you use Lunara again is treated as yours, and that shows in the database. It is not given the welcome rewards again, and if a gambling pause was still running, it starts paused, with exactly the end date the pause note holds, a pause that began before the account existed. So someone holding a copy of the database can tell that such an account belonged to someone who had deleted before, and, if it came back paused, which pause note is its own.

Pauses from before the key. A gambling pause set before [the date the keyed hash went live] was first kept against a plain, unkeyed hash of the Discord ID, which someone holding a copy of the database could match against a Discord ID they already had. Each is moved under the key the next time Lunara sees its owner’s Discord ID: when they next use Lunara, pause again, delete their account, or come back after deleting it. Until then, for someone who still has an account, the old entry adds nothing to what their account already shows but the day the pause was first recorded. For someone who deleted their account before the key existed and has not come back, there is no such next time: it stays as it is until the pause runs out, and is then erased with it.

12. Your choices and rights

Everything here works straight away, in Discord, without asking anyone:

  • /data export sends you a file of everything Lunara holds about you.
  • /data delete erases it.
  • /data privacy summarises this page inside Discord.
  • /privacy controls who can look you up, and whether you appear on leaderboards.
  • /remind turns reminder messages on or off. They are all off until you turn them on.

Depending on where you live, you may have further rights — for example under the GDPR in the EU and UK, or the CCPA in California — to access, correct, delete or object to how your data is used, and to complain to a data protection authority. Contact us to use any of them. [The legal bases relied on for each use (for the GDPR), and the relevant authority]

13. Share pages

The Share buttons under /card, /flex and /summon link to a page on this website. A card page exists only while your collection switch in /privacy is open, and a profile page only while both your collection and progress switches are. A pull page shows what was pulled to anybody who has its link, which carries a random secret, and names you only while your collection switch is open. Share pages ask search engines not to index them.

After you close a switch, the site can take up to a minute to stop showing the page, and a link preview image up to twenty minutes. A preview that Discord, X or Reddit has already copied stays on their servers.

14. Who we share it with

We do not sell your data and do not share it for advertising. It passes through the services Lunara runs on:

  • Discord — the platform itself, and the seller of subscriptions and gem packs.
  • Bot lists you choose to vote on, which tell us about your vote.
  • Hosting: [where the bot and this site run, and in which country].
  • Database and cache: [who hosts the database and the Redis cache, and where].

We may disclose data where the law requires it.

15. Children

Lunara is for people old enough to use Discord under Discord’s terms in their country (at least 13). We do not knowingly keep data about anyone younger; if you believe we are, contact us and it will be deleted. [Minimum age for the casino games, if higher]

16. Security

Data is held in a database that only Lunara’s servers can reach, website sessions are encrypted, and the site never exposes your Discord access token to the browser. No system is perfectly secure; if a breach affects your data we will tell you as the law requires.

17. Changes to this policy

If this policy changes in a way that matters, we will say so on this page and in Lunara’s support server before the change applies. Last updated: [date].