Privacy Policy
Last updated: July 21, 2026
What we collect
When you log in to the Varko dashboard with Discord, we store your Discord user ID, username, discriminator, and avatar, along with an encrypted copy of your OAuth access and refresh tokens (AES-256, never stored in plaintext). When Varko is added to a server, we store that server's ID, name, and icon. Using moderation features creates case records (target, moderator, reason, action type, timestamp). Staff actions on the dashboard are recorded in an audit log for accountability.
What we don't store
Varko's logging feature posts message edits and deletions to a channel you configure — it does not write message content into our database. Once posted, retention of that content is entirely up to your server's own channel history and permissions.
How we use it
Data is used solely to operate Varko's features: authenticating you to the dashboard, running moderation and logging, and displaying your servers and their configuration. We do not sell data, and we do not use it for advertising.
Retention and deletion
Data is retained for as long as Varko remains in your server or your account remains active. To request deletion of your data or a server's data, contact us using the details below.
Third parties
The only third party involved is Discord itself, via OAuth login and its API. We don't use third-party analytics or advertising trackers.
Security
OAuth tokens are encrypted at rest. All traffic between you, the dashboard, and our API is served over HTTPS. Session cookies are marked HttpOnly and Secure.
Children's privacy
Varko is not directed at anyone under 13, consistent with Discord's own Terms of Service.
Changes to this policy
We may update this policy as Varko's features change. Material changes will be reflected by updating the date at the top of this page.
Contact
Questions or data requests: daltonlusiak20@gmail.com