Last updated: August 2026
identify scope), and the list of servers you belong to with your permission flags (guilds scope). We never receive your password, email or messages through OAuth.Data is used solely to operate PureXit's features: enforcing your server's configuration, displaying dashboards, and keeping accountability logs. OAuth tokens are stored server-side only, encrypted in transit, and are never exposed to the browser or other users.
Server data is retained while PureXit is in your server. Removing the bot stops collection. For full deletion of stored data, request it in the support server — requests are honored within 30 days. Dashboard sessions expire automatically after 7 days.
Credentials and tokens are kept in server-side secret storage, never in frontend code. Dashboard sessions use signed HTTP-only cookies. Every API operation is authorized against your live Discord permissions.
We may update this policy; material changes will be announced in the support server.