Trust Center

You are trusting us with roles and bans.

CloudMod changes real permissions on real servers. That only works if you can see exactly what it stores, what it never touches, and which Discord permissions it needs and why. This page is that answer — no marketing, just the mechanics.

Hosted in the EU

All servers run in Germany (Hetzner, Gunzenhausen) under a GDPR data-processing agreement. Your network data never leaves the EU for our own processing.

Encrypted where it matters

Discord OAuth tokens are encrypted at rest with AES-GCM. The dashboard is HTTPS-only and mutating requests are origin-checked against CSRF.

Least privilege by default

CloudMod does not ask for Administrator. It requests the specific permissions the features need — and features you never enable simply stay inert.

Everything is auditable

Every role change, ban propagation and drift correction is written to an audit log with the reason behind it, and can be exported as CSV.

What we store

The short version: identifiers and events, never conversations.

Discord server, role and channel IDsstored

Needed to know what to sync where.

Sync events and moderation casesstored

The audit trail: what changed, when, and why.

Your Discord OAuth tokenstored

Encrypted at rest with AES-GCM, used only to show your servers in the dashboard.

Message contentsnot stored

Edit/delete logging holds them briefly in memory and posts them to your log channel — never to our database.

Member profile datanot stored

No emails, no DMs, no member profiles beyond the IDs needed for sync.

Tracking or advertising datanot stored

No tracking cookies, no ad networks, no third-party analytics.

Which permissions, and why

Every permission CloudMod asks for maps to a feature you can point at. Skip a feature and the permission simply goes unused.

CloudMod permission matrix
FeatureDiscord permissionWithout it
Role syncManage RolesRoles cannot be granted or removed — sync is inert.
Nickname syncManage NicknamesNicknames stay whatever each server set.
Ban syncBan MembersBans stop at the server they were issued on.
Moderator attribution in logsView Audit LogLog entries cannot name who performed an action.
Word filter, purge, Scam Guard cleanupManage MessagesOffending messages are detected but not deleted.
Posting logs, panels and alertsSend Messages · Embed LinksNothing can be posted to your channels.
Tickets and temp voice channelsManage ChannelsTicket and temp-voice channels cannot be created.
Ticket transcriptsAttach FilesTranscripts cannot be uploaded.
Reaction roles, starboard, suggestionsAdd ReactionsReactions are not seeded, so members cannot self-assign.
Button roles and channel mirrorManage WebhooksWebhook-based posting falls back to plain bot messages.
Temp voice move / lockMove Members · ConnectMembers are not pulled into their created channel.
Network panel auto-invitesCreate Instant InviteInvite links in the server panel go stale.

CloudMod never requests Administrator. Roles above the bot in your server's role list can never be assigned or removed — Discord enforces that, and so do we.

Every change answers “who, what and why”

This is what one synced role looks like in your audit log.

13:42:11   ROLE SYNC
  member    @Max
  source    Main Server  ·  @Booster granted
  action    added @VIP
  targets   Server A ✓   Server B ✓   Server C ✓
  reason    role mapping #12
  result    3 of 3 servers updated

Drift corrections, ban propagation and nickname changes are logged the same way, per category and to the channels you choose — plus a CSV export when you need it outside Discord.