MortisBot
TermsPrivacyPanel

What we hold, and what we do not

Privacy

Two things share this policy because they share an account: MortisBot, the Discord bot, and Mortis Cloud, the notes app. They are described separately wherever they differ.

The short version

  • Your notes are encrypted before they leave your device. The server stores ciphertext it cannot open, and nobody operating this service can read them.
  • Nothing is sold, and there is no advertising, profiling or third-party analytics anywhere in either product.
  • Card details never reach these servers. Stripe handles payment and we keep only a subscription reference.
  • You can export everything and delete everything yourself, without asking.

Mortis Cloud — what the server holds

An account is an email address and a password hash (bcrypt — the password itself is never stored). Alongside it:

  • Your notes, folders and attachments. With vault encryption switched on these are stored encrypted end to end: the key is derived from your passphrase on your device and never sent. Without it they are stored as written.
  • API tokens, stored as hashes. The token itself is shown once and cannot be recovered from the server.
  • Shared spaces: which accounts are members, and the space key wrapped to each member’s public key. The server holds the wrapped keys and cannot open them.
  • Anything you deliberately publish — a shared page or a digital garden — which is public by definition, to anyone with the link.
  • Your email address if you subscribed to the newsletter, until you unsubscribe.

Server logs record request times, paths and IP addresses, as any web server does. They are operational and are not used to build a profile of anybody.

MortisBot — what the bot holds

The bot stores per-server configuration and the data the features it is given need to work. Concretely:

  • Discord identifiers — server, channel, role and user ids. Never passwords, and never your Discord email.
  • Levels and experience, if levels are enabled on that server.
  • Moderation records: the action, who performed it, who received it, the reason and the time. That is a log the server’s own moderators keep, and it is visible to them.
  • Feature data you create: reminders, notes, birthdays, invite counts, economy balances, tickets.
  • Message content only where a feature is explicitly switched on for it — audit logging of edits and deletions, automod filtering, and the snipe command. Anti-spam and filtering read messages as they pass and keep nothing.
  • If you link a Mortis Cloud account, its API token, encrypted at rest with a key the bot holds separately.

A server’s administrators decide which of those are switched on. Data belonging to a server is removed when the bot is removed from it.

Payment

Payment is handled entirely by Stripe. No card number, expiry or security code ever reaches these servers — this software holds no Stripe API key at all, only the secret used to verify that a webhook genuinely came from Stripe. What is stored here is a reference linking a subscription to the account that bought it, so the plan can be applied and so cancelling it takes effect.

Stripe is the data controller for the payment itself, under its own privacy policy.

How long

  • Account data: until you delete the account. Deletion removes notes, folders, attachments, tokens and space memberships along with it.
  • Bot data for a server: until the bot is removed from that server.
  • Newsletter address: until you unsubscribe, which is a link in every message.
  • Server logs: rotated by the host and kept only as long as they are operationally useful.
  • Payment records: kept as long as accounting obligations require, which in France is ten years for invoices.

Your rights

Under the GDPR you may ask for a copy of your data, its correction, its deletion, or that processing stop. Most of it you can do yourself and immediately: Mortis Cloud exports the whole vault as a zip from Settings, and deletes the account from the same screen.

For anything else, write to support@mortis.cloud. If you are unhappy with the answer you may complain to the CNIL, the French supervisory authority.

Where it runs

Servers are hosted by Infomaniak, in Switzerland. Switzerland is recognised by the European Commission as providing an adequate level of data protection, so no additional transfer safeguards are required.

Sub-processors

  • Infomaniak — hosting and email delivery (Switzerland).
  • Stripe — payment processing (Ireland and the United States, under its own safeguards).
  • Discord — the platform the bot runs on, under its own privacy policy.

There are no others: no analytics, no tag managers, no advertising networks.

Children

Discord requires its users to be at least 13, or older where local law says so. These services are not directed at anybody younger.

Changes

If this policy changes in a way that affects what is collected or why, the change is announced before it takes effect — through the bot for anyone who has asked for product news, and by email for Mortis Cloud accounts.

Last updated 2026-08-29. Written by the people who wrote the software, from the software.

MortisBot
HomeTermsPrivacyContact