NexGuild Privacy Policy
Effective date: July 20, 2026
Publisher: Neural Nexus Studios ("NexGuild," "we," "us," "our")
Contact: neural.nex.studios@gmail.com
Address: Kolkata, West Bengal, India
1. What NexGuild is
NexGuild is a desktop application that runs on your own Windows PC. It is not a hosted web
service: there is no NexGuild-operated server that your Discord bots, messages, or configurations
pass through as a matter of course. The app connects directly, from your device, to the third
parties described below (Discord, Microsoft, and any optional integrations you choose to
configure). This shapes almost everything below — most of what NexGuild touches never leaves your
computer at all.
2. Information we — and the services we rely on — collect
2.1 Account sign-in (Microsoft identity platform)
NexGuild requires sign-in with a Microsoft account (personal or work/school) via Microsoft's own
MSAL/Entra identity platform. We receive your account's email address and a Microsoft account
identifier (object id), used only to identify your NexGuild account and look up your subscription
entitlement. We never see or store your Microsoft account password — authentication happens
entirely inside Microsoft's sign-in flow, not in NexGuild.
2.2 Discord bot tokens and Discord data
When you add a bot, its Discord bot token is encrypted at rest using Windows' built-in DPAPI
(Data Protection API), tied to your Windows user account on your specific device, and stored only
in a local secrets vault — never in plain text, never transmitted anywhere but to Discord's own
API using the standard Discord bot authentication scheme.
Messages, member lists, server (guild) data, reactions, and other Discord content your bots
observe are processed locally, on your device, transiently, to run the automations you've
configured (a "trigger → condition → action" graph). NexGuild does not operate a server that
stores a copy of your Discord message content; what a graph doesn't explicitly persist (e.g. as a
counter, a saved message, or statistics you've configured a module to keep) is not retained at
all. Anything a module does persist (leveling scores, saved sticky messages, transcripts you've
enabled, etc.) is stored locally in the encrypted database described in §2.3.
Discord itself, as the platform your bot connects to, separately collects and processes data under
its own Privacy Policy and Developer
Terms —
using NexGuild to operate a Discord bot does not change your (or your bot's) relationship with
Discord, and you remain responsible for your bot's compliance with Discord's rules.
2.3 Local application data
Your bot configurations, module settings, per-server overrides, and any module-persisted data
(counters, leveling scores, saved messages, statistics, etc.) are stored in a SQLCipher-encrypted
SQLite database on your device, at %LOCALAPPDATA%\NexGuild\. This file is encrypted; we do not
have a copy of it, and nothing in it is synced to any NexGuild-operated server (there isn't one).
2.4 Subscription and billing data
NexGuild offers optional paid tiers (Plus, Pro, Enterprise; monthly or yearly) sold as Microsoft
Store in-app products. All billing — payment method, card details, purchase history, refunds — is
handled entirely by Microsoft Store under Microsoft's own privacy
practices. NexGuild never receives or stores your
payment card details; we only receive the resulting entitlement state (which tier you hold)
from the Microsoft Store APIs on your device.
2.5 Optional integrations you choose to configure
These only apply if you turn on the relevant module and supply your own credentials — nothing here
activates by default:
- AI providers (AI modules): you supply your own API key for a provider of your choice (OpenAI,
Anthropic, Google, or a custom OpenAI-compatible endpoint). Prompts you configure are sent
directly from your device to that provider using your own key and are governed by that
provider's own privacy policy and terms, not ours — NexGuild is a pass-through here, not a
party to what that provider does with the request. - Twitch notifications: if configured, a Twitch application client id and a user OAuth token
you supply are used to subscribe to that streamer's "went live" events via Twitch's EventSub;
governed by Twitch's Privacy Policy. - YouTube notifications: reads a channel's public upload RSS feed — no account, no API key, no
data you provide beyond the channel id you choose to watch. - Weather / location lookups: uses the free, key-less Open-Meteo API
(open-meteo.com) — no account, no key, and only the place name/coordinates you look up are sent
to it. - Music (Lavalink): audio playback is served through a Lavalink server you run or point the
bot at (locally or on infrastructure you control) — NexGuild does not operate a Lavalink service. - top.gg (Free Premium): if you use the "vote for free premium" feature, top.gg records your
vote per top.gg's own privacy policy; NexGuild checks vote status via
top.gg's API to grant a temporary entitlement.
2.6 Marketplace, Gifting, and Collaboration (Discord-channel-backed features)
The Marketplace (browse/share bot-configuration listings), Gifting (subscription gift codes), and
Collaboration (multi-user editing) features use a Discord channel — rather than a NexGuild-run
database — as their storage and delivery mechanism:
- Marketplace: content you submit as a listing is a redacted copy of a bot-configuration graph
(secrets are stripped before it ever leaves your device) posted as a message to a shared Discord
channel that Neural Nexus Studios operates. Anyone able to read that channel can see listing
content; do not submit anything you don't want shared. - Gifting: a gift code and the subscription tier it grants are likewise posted to a Discord
channel Neural Nexus Studios operates, and redemption is recorded the same way. - Collaboration: each bot's collaboration channel is one you configure and control — not a
shared NexGuild channel — so this data flow stays inside infrastructure you already own.
2.7 What we do not collect
NexGuild does not include any telemetry, analytics, or crash-reporting SDK. We do not track your
usage of the app, and we do not automatically transmit diagnostic data anywhere. Error logs the app
shows you (Error Logs page) stay local to your device; nothing is sent to us unless you choose to
copy and send it to us yourself (e.g. for support).
3. How we use this information
- To authenticate you and identify your account.
- To determine your subscription tier/entitlement (including any Free-Premium or gifted grant) and
gate features accordingly. - To run the Discord bot automations you configure, entirely on your device.
- To operate the Marketplace/Gifting/Collaboration features described above.
- We do not sell your information, and we do not use it for advertising.
4. Data retention and deletion
- The Settings page's Delete Bot action removes that bot's local configuration, secrets
vault entry, and persisted module data. - The Settings page's Delete Account action removes your local account state.
- Because your Discord bot tokens are DPAPI-sealed to your specific Windows user account, they
cannot be decrypted by anyone else, on any other device — reinstalling Windows or moving to a new
PC requires re-adding your bot tokens, which is a consequence of how the encryption works, not a
retention choice. - Marketplace/Gifting content already posted to the shared Discord channel before you delete a bot
or account is not automatically retracted, since it lives in Discord's own message history, not
in your local database; contact us at neural.nex.studios@gmail.com if you need a specific listing
removed.
5. Children's privacy
NexGuild is not directed at children. You must be at least 13 years old, or the higher minimum age
required by Discord's own Terms of Service or your country's law (whichever is greater), and you
must already hold a Discord account and a Microsoft account in good standing — both of which are
independently age-gated by Discord and Microsoft respectively.
6. International data
Because almost everything NexGuild touches stays on your own device, there is generally no
NexGuild-side cross-border transfer to describe. Where data does leave your device (sign-in via
Microsoft, Discord's API, Microsoft Store billing, top.gg, or any optional integration you
configure), it is subject to that provider's own privacy policy and data-location practices, not
ours.
7. Security
Bot tokens and other secrets are sealed with Windows DPAPI; the local application database is
SQLCipher-encrypted; the owner "super-user" identity is protected by a salted Argon2id hash and an
ECDSA-signed record rather than a plaintext credential anywhere in the software. No method of
storage or transmission is 100% secure, and we cannot guarantee absolute security — DPAPI's
protection is tied to your own Windows user account on your own device, so the security of your data
also depends on the security of your device and your Windows account, which are outside our control.
See the Terms of Service's disclaimer of warranties and limitation of liability.
8. Changes to this policy
We may update this policy as the app changes. We'll update the effective date above; if a change
is material, we'll make reasonable efforts to flag it in the app (e.g. a Settings-page notice) or
via the Support Server.
9. Contact
Questions about this policy, or a request relating to your data (access, correction, deletion
beyond what the in-app Delete Bot/Delete Account actions already do): neural.nex.studios@gmail.com,
or via our Support Server: https://discord.gg/MezTB9FtEH.