Legal · Discord bot

Nefarious Alerts Privacy Policy

Effective September 12, 2026 · Last updated September 12, 2026

This Policy explains what Nefarious Digital doing business as Nefarious stores when we run Nefarious Alerts (application id 1511878442571006103). It is written from NefariousAlerts.py, not from a generic “we store nothing” template.

Operator Discord bot for the Nefarious server. It role-pings when a watched alert bot posts, keeps staff stickies at the bottom of a channel, runs slime/unslime (role strip, message purge, decision tree), extracts $cashtags into a 24-hour ticker digest, deletes Zoom and Apex links in two configured channels, logs which invite a joiner used, posts a public Trump-remarks schedule, and DMs Early Supporters a personal promo code.

Discord Inc. operates Discord. Whop operates checkout for Early Supporter codes. Their privacy policies apply to those platforms. This page covers what we keep on our hosts (the nefarious-alerts stack).

Questions or deletion requests: Business@nefarious.trading.

01Who we are

Controller: Nefarious Digital (Nefarious). Email: Business@nefarious.trading.

The wider site and Discord community are described in the site Privacy Policy. This Policy is only about the Alerts bot.

02What is stored

Operator configuration (config.json / secrets)

  • Discord bot token (secret). Configured channel ids include monitor 1504278715125993512, Zoom/alert 1511418965249888377, Apex 1483674425684529188, slime decisions 1519909922417021019, join log 909379483641987093, remarks schedule 1523132948524564590, plus role ids for pings, slime, and staff gates.
  • Optional site-sync URL and secret so the remarks calendar can update nefarious.trading.

Stickies and message ids (alerts_state.json)

Per channel: sticky text, active flag, current Discord message id, a counter, and optional paused text. We also keep lists of processed ticker message ids and already-pinged alert message ids (ids only, capped).

Slime role snapshots

For each open decision we store the Discord message id of the decision post plus target user id, moderator id, guild id, previous_role_ids (the role snapshot used to unslime), optional latest message link, and status (pending / reverted / banned). We do not write the purged message bodies to disk.

Ticker rows

Rolling 24-hour entries of cashtag, source message id, and seen_at. These come from tweet-bot posts in the monitor channel, not from a general member-chat archive.

Join tracking (memory, then a Discord embed)

While the process runs we cache invite code, use count, inviter name/id, and channel id. On join we post a “Member Joined” embed (mention, username, user id, invite, inviter, account age, member count) to the join-log channel. That cache is not the on-disk state file.

Early Supporter file (es_codes.json)

Operator-supplied mapping used by Nefarious Alerts only to look up Discord user id → promo code. The file may also contain Discord username, Whop user id/username, email, and promo id from the export that created it. The bot DMs the code; it does not add new emails itself.

Remarks schedule files

Per-day Discord message ids, event lines, and a content hash so we can edit one schedule message instead of spamming. Speak-alert keys record that we already pinged a role. The payload pushed to the website is the public calendar, not member profiles.

03What we do not collect

  • A server-wide archive of ordinary member chat — we are not a backup bot.
  • DMs you send the bot, except the !ThankYouES command that triggers an outbound promo DM.
  • Presence, online status, devices, or streaming activity.
  • Payment cards or brokerage credentials. Whop handles VIP checkout.
  • Advertising cookies or cross-site tracking tied to this bot.

Privileged intents: Message Content: used; Server Members: used; Presence: not used. Details: Terms, intents and /legal/nefarious-alerts/intents.

04How we use this information

Where GDPR or similar law applies, the legal basis is in brackets.

  • Keep stickies at the bottom of a channel and avoid double-pinging the same alert [legitimate interest / operating the server].
  • Apply, revert, or record slime decisions [legitimate interest in moderation].
  • Build the 24-hour cashtag digest [legitimate interest].
  • Attribute joins to an invite for staff [legitimate interest].
  • Send an Early Supporter code you requested with !ThankYouES [contract / your request].
  • Respond to deletion or access requests and legal process [legal obligation].

We do not sell this data, do not use it to train public AI models, and do not use it to advertise to you off Discord.

05Retention

  • Ticker rows: pruned after 24 hours.
  • Processed / pinged message ids: capped (thousands of ids) so the file does not grow forever — not a 30-day timer.
  • Stickies and slime decisions: until staff remove the sticky, the decision is finished and later deleted, we retire the bot, or you ask us to erase that row. Typically longer than 30 days.
  • Early Supporter mapping: until the list is regenerated or we remove your id after a request.
  • Schedule / speak state: recent days only (schedule days older than about a week are dropped; speak keys older than 14 days are dropped).
  • Invite cache: in memory; refresh loop about every 10 minutes.
  • Discord copies (pings, join embeds, stickies, slime posts): until a moderator deletes them or Discord expires them.

06Sharing and no sale

We do not sell sticky text, slime snapshots, cashtags, join-log fields, or Early Supporter records, and we do not share them with data brokers or advertisers.

We disclose information only:

  • To Discord as needed to send the messages you already see in the server (and a promo DM).
  • To other members in those channels (role pings, slime lines, join embeds, leaderboards of tickers).
  • To operators and hosting providers that run the nefarious-alerts process.
  • To Whop when you use a promo code at checkout (their checkout, their policy).
  • If required by law, or to defend a legal claim, or to stop abuse of the bot.

07Third parties

  • Discord. Discord Privacy Policy.
  • Whop (Early Supporter checkout only). Their terms and privacy policy apply when you redeem a code.
  • Public remarks calendar source used for the Trump schedule. They see our server’s fetch, not your Discord identity.

08Your rights and how to request deletion

Email Business@nefarious.trading from an address we can reply to and include your Discord username and user id (Discord → Settings → Advanced → Developer Mode → right-click your name → Copy User ID). Say what you want removed, for example:

  • A slime decision row (user id + previous role ids) or a join-log embed we can still delete.
  • Sticky text you authored, or a ticker/ping message id tied to you.
  • Your Early Supporter mapping (Discord id, and any email/username sitting in that export).

We will delete what we control within 30 days unless we must keep a record of the request or of unlawful content. We cannot erase Discord’s own copies other members already screenshotted, or roles/messages staff already changed. Server admins also control channel history.

If you are in the EEA, UK, or a U.S. state with a comprehensive privacy law, you may also ask for access, correction, or a portable copy of personal data we hold about you in these files. We will not discriminate against you for asking. You may complain to your local supervisory authority.

09Security

  • In transit. Traffic between the bot and Discord uses TLS.
  • At rest. State and code files live on the operator-controlled host for nefarious-alerts. Operators can read them to run the bot. Discord’s Developer Policy requires encryption at rest for stored API Data; we apply host-level encryption where the host provides it.
  • Secrets. The Discord token is in an environment file on that host, not in this website.

No system is perfectly secure. If you think data was exposed, contact Business@nefarious.trading promptly.

10Children

Nefarious Alerts is part of an adult trading community and is for users 18 or over. Discord’s own minimum age still applies. If a minor appears in our state files, contact Business@nefarious.trading and we will delete what we have.

11Discord privileged intents

This application uses Message Content and Server Members. It does not use Presence. Why, and the Discord form answers, are at /legal/nefarious-alerts/intents.

12International transfers

We operate from the United States. Discord (and Whop, if you redeem a code) process data in the United States and other countries. If you use the bot from the EU, UK, or elsewhere, your data is transferred to those locations.

13Changes

We will post updates at this URL and change the “Last updated” date. If the code starts storing full member chat or Presence, this Policy will say so — we will not leave it describing a smaller store than the bot actually keeps.

14Contact

Privacy and deletion: Business@nefarious.trading.

Also see our Nefarious Alerts Terms, Nefarious Alerts intents, Discord intents matrix, Site Privacy Policy, and Site Terms of Service.