Legal · Discord bot

Nefarious Congress Tracker Privacy Policy

Effective September 12, 2026 · Last updated September 12, 2026

This Policy explains what Nefarious Digital doing business as Nefarious stores when we run Nefarious Congress Tracker (Nefarious Congress Tracker#7462, application id 1517785951022350507). It is written from the running congress scraper, not from a generic “we store nothing” template.

Operator Discord bot that publishes publicly disclosed U.S. congressional securities transactions into one configured channel, and pushes the same public dataset to the Nefarious Congress Trading pages. It does not read member messages, DMs, or commands.

Discord Inc. operates Discord. Their privacy policy applies to that platform. This page covers what we keep on our hosts (including the nefarious-congress stack) and what we push to the Nefarious website.

Questions or deletion requests: Business@nefarious.trading.

01Who we are

Controller: Nefarious Digital (Nefarious). Email: Business@nefarious.trading.

The wider site and Discord community are described in the site Privacy Policy. This Policy is only about the congress tracker bot and the public-filing dataset it maintains.

02What is stored

Operator configuration

  • Discord bot token (secret), destination guild id 909011353342181426, and channel id 1517787034574655518.
  • A site-ingest secret used only to authenticate pushes to /api/congress-trading/sync. That secret is not Discord member data.

Public filing database (congress.db)

SQLite tables of public congressional trading records, not Discord user profiles:

  • Politicians — name, party, state, chamber, yearly-return figure, leaderboard rank, and the source row used to compute them.
  • Trades — a fingerprint or source trade id, politician name, ticker, buy/sell, trade date, filing date, disclosed size range, the source row, when we first saw it, and whether it has already been posted to Discord.

Scrape state (congress_state.json)

Operator flags and timestamps: whether the historical import finished, last leaderboard sync, last trade sync, backlog-flush markers. This is process state so we do not flood the channel. It is not a member roster.

Website copy

The same public politician and trade records are pushed to the Nefarious site database so /congress-trading can render a leaderboard and filing list for approved members. Site sign-in (Discord OAuth) is described in the site Privacy Policy and is separate from this bot — the bot itself does not run that OAuth flow.

Discord also keeps a copy of each embed we send, under Discord’s retention rules and your server’s channel history.

03What we do not collect

  • Member message content, command text, or DMs — the bot has no message reader and does not open private channels.
  • Discord user ids, usernames, avatars, or role membership for congress-tracker purposes.
  • Presence, voice state, or who is online.
  • Payment cards, government ids of Discord members, or health data.
  • Advertising cookies or cross-site tracking tied to this bot.

Privileged intents are off. Message Content: not used; Server Members: not used; Presence: not used. Details: Terms, intents and /legal/intents.

04How we use this information

  • Post each new public filing once to the configured Discord channel.
  • Update the Nefarious Congress Trading pages with the same public dataset.
  • Avoid duplicate embeds after restarts (posted flag + trade fingerprint).
  • Debug missed sends, rate limits, and source outages.
  • Respond to deletion or takedown requests.

We do not use this dataset to profile Discord members, to train a public recommendation engine, or to give personalized investment advice.

05Retention

  • Filing database: kept for as long as the tracker runs so we can de-duplicate posts and show history on the site. There is no automatic 30-day expiry in the process today.
  • Scrape state, channel ids, and tokens: for as long as the bot is operated, then removed from the host when the stack is retired.
  • Discord copies: until a moderator deletes the message or the platform expires it. We do not control every client cache.
  • Operational logs: stdout from the container may record scrape counts and errors. Those lines are not member message content.

06Sharing and no sale

We do not sell filing records, channel ids, or scrape state, and we do not share them with data brokers or advertisers.

We disclose information only:

  • To Discord, as needed to deliver the public-filing embeds you already see in the channel.
  • To the Nefarious website host and database, so approved members can view the same public tracker.
  • To the public-data sources as ordinary HTTPS clients fetching filings and legislator metadata.
  • To operators and hosting providers (including our NAS Docker stack) that run the process.
  • If required by law, or to defend a legal claim, or to stop abuse of the bot.

07Third parties

  • Discord. Discord Privacy Policy.
  • Public filing aggregators (currently the congress-trading feeds the scraper calls) and public legislator datasets. They see our server’s requests, not your Discord identity.
  • Nefarious website host (Vercel / our database provider) for the VIP-gated Congress Trading pages.

08Your rights and how to request deletion

This bot does not keep a Discord profile of you. If a posted embed or a stored filing still concerns you (for example you are the filer named in a public report, or a post should come down), email Business@nefarious.trading with:

  • The Discord channel and approximate time, or a message link.
  • The politician name and ticker if you have them.
  • Whether you want the Discord message deleted, the stored filing dropped, or both.

We will delete what we control (our database row and messages we can still reach) unless we must keep a record of the request or of unlawful content. We cannot erase the original government filing or copies other members already screenshotted. Official disclosures remain public at the source.

If you are in the EEA, UK, or a U.S. state with a comprehensive privacy law, you may also ask for access, correction, or a portable copy of any personal data we hold about you in this dataset. For most Discord members that is none. Public official names in STOCK Act filings are not treated as secret Discord-user data. We will not discriminate against you for asking. You may complain to your local supervisory authority.

09Children

Discord requires users to meet its minimum age (generally 13+). Nefarious Congress Tracker is a trading-community tool and is not directed at children under 13. If you believe we logged data about a child, contact Business@nefarious.trading and we will delete what we have.

10Changes

We will post updates at this URL and change the “Last updated” date. Material changes to what we store (for example if we later added commands that read message content) will be described here honestly — we will not leave this Policy saying we do not read messages if the code starts doing that.

Also see our Nefarious Congress Tracker Terms, Nefarious Congress Tracker intents, Discord intents matrix, Site Privacy Policy, and Site Terms of Service.