Security and privacy

Specific permissions instead of blanket Administrator access

Byterider checks sensitive actions server-side, encrypts OAuth tokens and keeps public data separate from internal operations.

01

No Administrator permission

The bot invite requests explicit Discord access for channels, messages, roles and voice.

02

Server-side authorization

Dashboard session, server access, module delegation and Discord permissions are checked again before changes.

03

Encrypted OAuth tokens

Discord access tokens are stored encrypted while session tokens are stored only as hashes.

04

Controlled retention

Product metrics, error occurrences and audit logs follow documented retention windows.

05

Auditable owner actions

Sensitive operational actions require confirmation and idempotency and are logged.

06

No advertising networks

Public pages use no marketing trackers and do not disclose data to advertising networks.

Public data

What may become public

  • Aggregated server and usage figures only when available
  • Technical service health without hostnames or internal URLs
  • Public leaderboards only after explicit server opt-in
  • No guild or user IDs for marketing analytics