Privacy Policy
Last updated: August 20, 2026
This Privacy Policy describes how NOTALIVEX collects, uses, stores, shares, and protects your personal data, and explains your rights under applicable data protection laws including the EU General Data Protection Regulation (GDPR) and equivalent legislation.
1. Introduction and Scope
NOTALIVEX ("we", "our", "us") is committed to protecting your privacy and handling your data in a transparent, lawful, and secure manner. This Privacy Policy applies to:
- The NOTALIVEX website and web dashboard
- The official NOTALIVEX API
- The NOTALIVEX Discord bot
- All communications with our support channels
This policy does not govern the data you query through the Service. As explained in Section 6, when you perform searches about third parties (data subjects), you act as an independent data controller for that processing, and you are responsible for complying with applicable law.
2. Data Controller and Contact
The data controller for the personal data described in this policy is NOTALIVEX. You can reach us for any privacy matter through our Discord community or Telegram. Always use official channels only.
3. Information We Collect
3.1 Account Information
When you register for an account, we collect:
- Username
- Email address (Gmail, Hotmail, or Outlook only)
3.2 Billing Information
For paid plans we store basic order records: plan, amount, currency, and payment status. We do not receive or store card numbers or bank credentials; payments are processed by external providers.
3.3 Usage Information
We only collect the time it takes to complete your searches (search latency), which we use solely to measure and improve the performance of the Service. We do not store the content of your searches.
4. Legal Basis for Processing
Under GDPR and similar frameworks, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)): providing the Service, authenticating you, managing credits, subscriptions, and orders
- Legitimate interests (Art. 6(1)(f)): securing the platform, preventing fraud and abuse, rate limiting, maintaining audit logs, and protecting the rights and safety of our users and third parties
- Legal obligation (Art. 6(1)(c)): retaining billing records and responding to valid requests from competent authorities
- Consent (Art. 6(1)(a)): optional features such as linking your Discord account, which you may revoke at any time by unlinking
5. How We Use Your Information
We use the collected information for:
- Service Provision: to provide, maintain, personalize, and improve the Service
- Authentication: to verify your identity and manage your account and sessions
- Billing: to process purchases, grant credits and subscriptions, and keep accounting records
- Security: to detect, prevent, and address fraud, abuse, scraping, credential sharing, automated attacks, and security incidents
- Analytics: to understand aggregate usage patterns and improve performance
- Communication: to send service updates, security notices, and important administrative messages
- Compliance: to comply with legal obligations and enforce our Terms of Service
We do not use your data for behavioral advertising profiling, and we do not make legally significant decisions about you solely through automated means.
6. Search Queries and Third-Party Data (Important)
NOTALIVEX is an OSINT/CSINT platform: it returns information that is already publicly available from open sources. Regarding searches:
- Your searches are private. We do not store or share what you search for. We only record the time it takes to perform a search, and only to keep the Service fast.
- You are the controller of third-party data you obtain. When you search for information about another person, you determine the purpose and means of that processing. You must have a lawful basis, respect data minimization, and comply with all applicable laws. See our Terms of Service, Sections 8 and 9, for mandatory rules.
- We do not enrich or profile data subjects. We return references to public sources; we do not build dossiers, score individuals, or combine results across users into new profiles.
- Data subject requests. Individuals who find references to themselves in sources indexed by the Service should first contact the original source. We assist competent authorities and rights holders within the limits of the law.
7. Data Storage and Security
7.1 Security Measures
We implement industry-standard technical and organizational measures, including:
- Bcrypt password hashing with salt
- HTTPS/TLS encryption for all communications, with HSTS enabled
- Strict Content Security Policy with per-request nonces
- CSRF protection on state-changing endpoints
- Rate limiting, L7 protection, bot fingerprinting, and automatic blacklisting
- Account lockout after repeated failed login attempts
- HMAC signature verification for payment postbacks
- Access controls and least-privilege principles for administrative functions
- Regular security audits, dependency updates, and monitoring
7.2 Incident Response
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify affected users and, where required, the competent supervisory authority without undue delay and within the timeframes established by applicable law (72 hours under GDPR where applicable).
7.3 Data Retention
We retain personal data only as long as necessary for the purposes described:
- Account data: while your account is active, and as needed after deletion requests where legally required
- Billing records: for the retention period mandated by accounting and tax law
You may request deletion of your account at any time; some information may be retained where required by law or for legitimate purposes such as fraud prevention or dispute resolution.
8. Cookies and Tracking
We use cookies and similar technologies strictly for:
- Session management and authentication (login sessions, refresh tokens, CSRF cookies)
- Security and fraud prevention
- Essential preferences and settings
We do not use cookies to build advertising profiles. You can control cookies through your browser settings, but blocking essential cookies may prevent login and core functionality.
9. Information Sharing and Disclosure
9.1 We Do Not Sell Your Data
We do not sell, trade, rent, or monetize your personal information to third parties. Ever.
9.2 Limited Disclosure
We may disclose your information only in the following circumstances:
- Legal Requirements: when required by law, court order, subpoena, or valid request from a competent authority. Where legally permitted, we will attempt to notify you before disclosure.
- Safety and Abuse Prevention: to protect the rights, property, or safety of NOTALIVEX, its users, data subjects, or the public — including reporting evidence of serious crimes such as stalking, threats, or fraud.
- Service Providers: with trusted processors who assist in operating the Service (hosting, email delivery, payment processing), bound by data processing agreements and strict confidentiality obligations.
- Payment Networks: transaction data shared with payment providers to process your orders and prevent payment fraud.
- Business Transfers: in connection with a merger, acquisition, reorganization, or sale of assets, with notice via email or dashboard notification.
10. Your Rights and Choices
10.1 Data Protection Rights
Depending on your location, you may have the following rights under data protection laws:
- Right to be informed about how your data is processed (this document)
- Right to access your personal data
- Right to rectification of inaccurate or incomplete data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing based on legitimate interests
- Rights related to automated decision-making and profiling
- Right to withdraw consent at any time (for consent-based processing)
- Right to lodge a complaint with your local supervisory authority
To exercise these rights, contact us through our official channels. We may need to verify your identity before fulfilling certain requests, and we will respond within the timeframes established by applicable law.
10.2 Account Self-Service
You can access and update your account information through the dashboard, regenerate your API token at any time, unlink your Discord account, and request full account deletion.
11. API Token and Credential Security
Your API token is the key to your account's quota and is treated as confidential data:
- Tokens are stored hashed/secured server-side and can be regenerated by you at any time
- Never share your token — see the Terms of Service, Section 5
- We monitor unusual access patterns to detect leaked or shared tokens and may automatically suspend tokens showing compromise indicators until you regenerate them
12. Third-Party Links and Services
Our Service may contain links to third-party websites or services (payment gateways, Discord, Telegram). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing them with any personal data.
13. Children's Privacy
Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that a minor has created an account or provided us with personal information, we will take steps to delete the account and such information.
14. International Data Transfers
Your information may be transferred to, processed, and maintained on servers located outside your country or jurisdiction, where data protection laws may differ. When we transfer personal data internationally, we apply appropriate safeguards such as adequacy decisions, standard contractual clauses, or equivalent mechanisms, and we handle it securely in accordance with this policy regardless of where it is processed.
15. Automated Decision-Making
We use automated systems for security purposes only: rate limiting, bot detection, proxy/VPN screening, blacklist enforcement, and anomaly detection. These systems operate on traffic and usage metadata, not on the content of your identity as a person, and they do not produce legal effects concerning you or similarly significantly affect you. If an automated system blocks your traffic in error, contact us through official channels to review the decision.
16. Discord Bot Data
NOTALIVEX operates a Discord bot focused on anti-raid protection, moderation, and server security. This section describes how the bot handles data within Discord servers.
16.1 Data Collected by the Bot
The bot may access and process the following data solely for security and moderation purposes:
- User IDs and usernames: to identify users involved in moderation actions such as kicks, bans, warns, or role assignments.
- Message content: read in real-time to detect spam, prohibited links, flood attacks, repeated raid messages, and other violations of server rules. Message content is not stored outside of Discord.
- Role changes and server events: monitored to detect unauthorized role assignments, mass joins, bot additions, and other suspicious activity that may indicate a raid.
- Server and channel IDs: used to apply moderation actions in the correct server context.
- Account metadata: such as account creation date, used to identify potentially suspicious or newly created accounts during raid detection.
16.2 How We Use Bot Data
All data processed by the NOTALIVEX bot is used exclusively for:
- Detecting and preventing raid attacks on Discord servers
- Automating moderation actions such as deleting messages, applying timeouts, or banning users
- Generating security logs and alerts for server administrators
- Providing OSINT tools to help administrators identify threats
16.3 Data Storage
Message content read by the bot is processed in real-time and is not stored outside of Discord. Moderation logs (such as user IDs, action types, and timestamps) may be temporarily stored to provide audit trails for server administrators. This data is not shared with third parties.
16.4 User Rights Regarding Bot Data
Users who wish to inquire about data collected by the bot, or request deletion of any stored moderation records, may contact us through our Discord community or Telegram.
16.5 No AI or Machine Learning Use
Data collected through the Discord bot, including message content, is never used to train machine learning or artificial intelligence models.
17. Changes to Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the Service, technology, or legal requirements. We will notify you of material changes via email, dashboard notification, or website banner before they take effect. Continued use of the Service constitutes acceptance of the updated policy. Previous versions are available upon request.
18. Contact Us
If you have questions about this Privacy Policy, our data practices, or wish to exercise your rights, please contact us through our Discord community or Telegram. Always use official channels only — we will never ask for your password or API token.