SYNIXEN
Contact support

Legal center

Policies and account controls.

Use these direct paths for privacy requests, terms questions, cookie controls, and account information. These notices describe current product behavior and request paths; deployment operators should still complete their own legal and platform-policy review.

Last updated August 31, 2026.

PrivacyTermsCookies

Privacy

Review account, session, connection, billing, and licensed-device controls in the SYNIXEN Portal. For an access, correction, deletion, export, or other privacy request, open a privacy support request or email support@synixen.com.

SYNXGuard Discord account-protection verification

A Discord server may optionally use SYNXGuard to ask a newly joined member to confirm the same Discord account through an identify-only Discord OAuth screen. SYNXGuard never asks for or receives a Discord password, MFA code, session cookie, or user token. The short-lived OAuth access token is used to read the Discord account ID. Revocation is attempted immediately, and the token is never stored.

  • The verification record contains the Discord user and server IDs, attempt status, and security timestamps.
  • Network address, coarse network, browser user-agent, and an authenticated first-party device value are converted into server-scoped keyed hashes. Raw values are processed in memory for the check and are not written to the SYNXGuard database.
  • The device value is held in a Secure, HttpOnly, SameSite=Lax cookie. Its configured lifetime is 1–365 days and defaults to 90 days.
  • Verification signals and lifecycle events use the Discord server's configured 1–365 day retention period, which defaults to 30 days, and are removed by bounded retention jobs after they expire.

A delivered link has a three-minute verification window. When a server has explicitly enabled enforcement, missing that window can result in a guarded kick. Only an authenticated persistent device match to an account that remains banned in that same Discord server can support a guarded automatic ban. IP, network, and browser matches are staff-review signals and do not independently authorize a ban. Developer OAuth tests are logging-only and cannot moderate anyone.

For access or deletion help, open a privacy support request or email support@synixen.com. Include the affected Discord user ID and server ID so the correct server-scoped records can be located. Security or legal retention obligations may limit immediate deletion of a record.

SYNXGuard server dashboard

The server dashboard uses a separate Discord authorization with the identify and guilds scopes. No SYNIXEN account registration is required. It reads your Discord identity and server list; current membership and permissions are checked before protected server data or actions are made available.

Dashboard access tokens are encrypted in server-side storage. Refresh tokens are not retained. The browser receives an opaque Secure, HttpOnly, SameSite session cookie. Sessions expire after 30 minutes of inactivity or 12 hours, whichever comes first, and never outlive the Discord access token. Signing out invalidates that browser session without revoking another browser's Discord authorization. Expired sessions and their encrypted tokens are removed by bounded cleanup jobs.

The dashboard shows retained server reports, evidence, moderation history, and configuration to authorized staff only. Dashboard action receipts record the actor, server, requested action, and outcome for up to 30 days. Evidence remains subject to its original expiry. Protected dashboard records are not saved in browser local storage. The site's theme preference may be saved separately. Privacy requests use the support contact above.

SquishyBOT Dashboard

SquishyBOT's settings dashboard uses a separate Discord application with identify and guilds scopes. No SYNIXEN account is required. Current server membership and Administrator permission, or server ownership, are checked before settings or audit history are read or changed. Host credentials and private bot logs are not exposed.

Access tokens are encrypted server-side and refresh tokens are not retained. An opaque Secure, HttpOnly, SameSite session cookie expires after 30 minutes of inactivity or 12 hours, capped by Discord token expiry. Signing out invalidates only that browser's session. Authentication sessions are independent of SYNXGuard and SYNIXEN login.

Dashboard request receipts are retained for up to 30 days and its settings audit history for up to 90 days. The bot's existing configuration audit also records accepted changes under its existing retention policy. Settings, channel and role references, actor IDs, and change outcomes are visible only to authorized server administrators. Protected data is not persisted in browser storage; the website theme preference is stored separately. Privacy requests use the support contact listed above.

Terms of Service

Product, trial, billing, renewal, license, and service conditions should be presented before the related purchase or activation. For the current terms applicable to an order or service, open a terms support request before proceeding.

Cookies and browser storage

Browser settings can clear or block cookies and local site data. Blocking required session or security storage may prevent sign-in, checkout, account, licensing, or support features from working. For a storage-specific question, open a cookie support request.

© 2026 SYNIXEN, Inc.Return to synixen.com