Privacy Policy
Last updated: September 4, 2026
What we collect
When you log in to the Varko dashboard with Discord, we store your Discord user ID, username, discriminator, and avatar, along with an encrypted copy of your OAuth access and refresh tokens (AES-256, never stored in plaintext). When Varko is added to a server, we store that server's ID, name, and icon. Using moderation features creates case records (target, moderator, reason, action type, timestamp). Staff actions on the dashboard are recorded in an audit log for accountability.
Message content
Varko reads messages in order to run automod, custom commands, prefix commands and leveling. Almost none of that is kept: those checks happen in memory and are discarded. The exceptions, which are stored, are messages sent inside a ticket (so the transcript survives the channel being deleted), and anything you deliberately submit to Varko — a suggestion, a reminder, a sticky or scheduled message. The logging feature posts edits and deletions to a channel you configure and does not write them to our database; retention of those is your server's own channel history.
Voice
The Call Recording module, if a server turns it on, keeps a short rolling audio buffer of a voice channel in memory so a moderator can save the last few seconds as evidence. It announces itself in the channel every time it starts, and never records silently. Nothing is written to disk unless somebody actively saves a clip — at which point that clip and its per-speaker audio are stored, along with who requested it. Servers with the module off are never joined.
Server verification and restore
If you verify through a server's Varko verification page, we store your encrypted Discord tokens against that server so its owner can re-add you if the server is lost. That token is only ever usable for the specific server you verified in, and for nothing else. You can withdraw at any time from the verification page, which deletes the token rather than flagging it.
Purchases
If you buy something from the Varko store we store the order, what it was for, the email you gave, and the payer name or Cashtag you told us to expect — that last one so a payment can be matched to an order. Payments happen entirely inside Cash App or PayPal. We never see or store card details.
How we use it
Data is used solely to operate Varko's features: authenticating you to the dashboard, running moderation and logging, and displaying your servers and their configuration. We do not sell data, and we do not use it for advertising.
Retention and deletion
Data is retained for as long as Varko remains in your server or your account remains active. To request deletion of your data or a server's data, contact us using the details below.
Third parties
We don't use analytics or advertising trackers, and we don't sell data to anyone. Some features do reach other services to work, and only send what that feature needs: Discord itself for login and the API; YouTube, SoundCloud, Twitch, Kick and TikTok for music and stream announcements; Google Translate for translate; Urban Dictionary for urban; Roblox for account linking; an AI provider for the optional AI ticket and voice features; and an email provider for the emails we send. None of them receive your Discord tokens.
Security
OAuth tokens are encrypted at rest. All traffic between you, the dashboard, and our API is served over HTTPS. Session cookies are marked HttpOnly and Secure.
Children's privacy
Varko is not directed at anyone under 13, consistent with Discord's own Terms of Service.
Changes to this policy
We may update this policy as Varko's features change. Material changes will be reflected by updating the date at the top of this page.
Contact
Questions or data requests: daltonlusiak20@gmail.com