Legal · Discord apps

Nefarious Success Privacy Policy

Effective September 12, 2026 · Last updated September 12, 2026

This Privacy Policy explains how Nefarious Digital, doing business as Nefarious (“Nefarious,” “we,” “us,” “our”), collects, uses, shares, and retains information when you use the Discord application Nefarious Success (application ID 966614821174915092).

Discord Inc. and X Corp. operate their own platforms. Their policies also apply. This document covers what we do with data we receive through Nefarious Success. The website Privacy Policy covers nefarious.trading separately.

Privacy questions or deletion requests: Business@nefarious.trading.

01Who we are (controller)

The controller for Nefarious Success is Nefarious Digital. Contact: Business@nefarious.trading.

02Scope and opt-in

This Policy applies when you:

  • post an image in the designated success channel;
  • run !sp, !scl, !sclm, !sclw, !scly in a channel the bot can see;
  • react with 🗑️ on a Success reply (to request deletion of that tweet); or
  • appear on a leaderboard that other members can view in Discord.

You opt in by posting or using a command. The bot does not scrape the rest of the server. You opt out of further collection by not posting there and not using the commands. That does not by itself delete points or tweets already created — see Retention & deletion.

03Information we collect

A. Discord account data (stored)

For each member who earns a point we store, in an operator-controlled points file: your Discord user ID, the display name shown at the time of the post, and an earned list. Each earned entry is a UTC timestamp and the X post ID. We use the user ID to mention you on the leaderboard and to add or remove points. We do not receive your email, password, phone number, or Discord billing information.

B. Message content (privileged intent — processed, then posted to X)

Nefarious Success uses Discord’s Message Content privileged intent. Discord will not deliver attachments, embeds, or message text to the bot without it. We use that access only to:

  • Success posts. In the designated channel we read image attachments (filename/type/URL) and any caption you typed. We download the image in memory, upload it to X, and include the caption on the tweet. We do not keep a separate local archive of the image bytes or the caption text after the upload finishes (or fails).
  • Commands. We read the text of !sp, !scl, !sclm, !sclw, !scly so we can reply with your points or a leaderboard. Command text is not written to the points file.

We do not read message content in other channels for this bot, do not read DMs as a feature, and do not use message content to train machine-learning or AI models (Discord Developer Policy §21).

C. Message and reaction metadata

  • Channel ID we are configured to watch, and the Discord message IDs we have already processed (deduplication markers on disk).
  • While the process is running, an in-memory map from the bot’s reply message ID to the X post ID, the original author ID, and the original message ID — used so a 🗑️ reaction can delete the right tweet.
  • Reaction emoji and the reacting user’s ID, solely to decide whether that user may delete the post (author, administrator, or designated moderator).

D. What we do not collect

  • Server Members privileged data — we do not subscribe to join/leave/role-update events or build a member roster. A one-off REST fetch may run when someone reacts with 🗑️ so we can check moderator permissions.
  • Presence, online status, devices, or streaming activity.
  • Messages outside the designated channel, except command text you send to the bot.
  • Payment cards, brokerage credentials, or X login credentials of members (X API keys we use belong to our operator account, not to you).

04How and why we use information

Where GDPR or similar law applies, the legal basis is in brackets.

  • Publish the post you just made to X and confirm it in Discord [contract / your request].
  • Award, display, and correct points and leaderboards [contract / legitimate interest in running the community feature].
  • Honour a delete reaction from you or a moderator [contract / legitimate interest].
  • Prevent duplicate tweets if the bot restarts while a message is in flight [legitimate interest].
  • Respond to deletion or access requests and legal process [legal obligation].

We use this data only to operate Nefarious Success as described. We do not use it for advertising, for profiling you off Discord, or to contact you outside Discord except to answer a request you sent us.

05Who we share information with

We do not sell personal information and do not share it for advertising. We share it only:

  • X Corp. (Twitter). The image, caption, and a line naming your Discord display name are sent to X to create a public tweet on @NefariousTrades. Anyone on the internet can see that post until it is deleted. X’s own retention and visibility rules then apply.
  • Other Discord members in channels where the bot replies: your mention, point total, and leaderboard rank.
  • Discord Inc. as the platform that delivers events to the bot.
  • Operators and hosts who run the bot process and store points.json and processed-message markers (access limited to staff who operate the bot).
  • Law enforcement or courts when legally required, or to protect members if we reasonably believe content is unlawful.

Nefarious is not affiliated with X/Twitter beyond this posting/deletion use. See the Terms.

06Retention & deletion

  • Points records (Discord user ID, display name, timestamps, X post IDs) — kept until (i) that point is removed because the tweet was deleted via 🗑️, (ii) you ask us to erase your record, or (iii) we reset or retire the leaderboard. This is typically longer than 30 days.
  • Public X posts — remain on X until you or a moderator delete them through the bot, we delete them from the X account, or X removes them. We do not automatically expire tweets after 30 days.
  • Processed message IDs — kept on disk so the same Discord message is not tweeted twice after a restart. These IDs are not message text.
  • In-memory delete map — discarded when the bot process restarts. After a restart, 🗑️ on an old reply may not find the mapping; email Business@nefarious.trading or ask a moderator.
  • Image bytes and captions — held in memory only during upload. We do not keep a local media library. The lasting copy is the public tweet (and Discord’s own copy of your original message, which Discord retains under its policy).

How to request deletion

Email Business@nefarious.trading from an address we can reply to and include your Discord username and user ID (Discord → Settings → Advanced → Developer Mode → right-click your name → Copy User ID). We will delete your row from the points file within 30 days and, on request, delete tweets we still control that are tied to your IDs. We may ask a moderator to confirm the request in Discord because we do not hold your email as part of the bot. Discord messages in the server are controlled by server admins and Discord, not solely by us.

07Security

  • In transit. Traffic between the bot, Discord, and X uses TLS/HTTPS.
  • At rest. Points and processed-message markers live as files on the operator-controlled host that runs the bot. Access is limited to staff who operate the service. We rely on that host’s access controls and, where enabled, volume/disk encryption. The points file is not end-to-end encrypted — operators can read it to run the leaderboard. Discord’s Developer Policy requires encryption at rest for stored API Data; we apply host-level encryption where the host provides it.
  • Secrets. Discord and X API credentials are stored as environment secrets for the bot process, not in this website.

No system is perfectly secure. A public tweet can be copied by others before it is deleted. If you think data was exposed, contact Business@nefarious.trading promptly so we can notify Discord and affected users as required.

08Your rights

Depending on where you live you may request access, correction, erasure, portability, restriction, or objection, and you may lodge a complaint with a data-protection authority. Email Business@nefarious.trading. We respond within 30 days (45 days for certain U.S. state requests). We do not sell or share personal information for cross-context advertising, so there is no sale opt-out to toggle.

09Children

Nefarious Success is part of an adult trading community and is for users 18 or over. We do not knowingly collect data from children. If a minor has points or a tweet, email Business@nefarious.trading and we will delete what we hold.

10Discord privileged intents

The only privileged Gateway intent this application uses is Message Content. We do not request Server Members or Presence. Why, and the Discord form answers, are published at /legal/nefarious-success/intents.

11International transfers

We operate from the United States. Discord and X process data in the United States and other countries. If you use the bot from the EU, UK, or elsewhere, your data is transferred to those locations. We rely on those platforms’ contractual safeguards and on the fact that you chose to post publicly.

12Changes

We will update this Policy when our practices change and revise the date above. Material changes will be noted in Discord when practical. Continued use after an update means you accept the new Policy.

13Contact

Privacy and deletion: Business@nefarious.trading.

Also see our Nefarious Success Terms of Service, Privileged intents, and Site Privacy Policy.