Pensira shield logo Pensira
Dashboard My Profile FAQ Feedback Add Bot
My Profile

Privacy Policy

Last updated: July 2026

Pensira is committed to transparency about how your data is handled.

1Local-First Scanning, Two Minimal Online Lookups

The vast majority of scanning happens entirely on Pensira's own server, performed by the Pensira Engine — your file, image, and text content is never sent to a third-party service (no VirusTotal, no OpenAI, no Google, no external API of any kind). All content detection (malware signatures, phishing/adult-site blocklists, PII/secrets scanning, image classification, QR code decoding, etc.) happens locally using signature matching, statistical heuristics, and machine learning models that run directly on the bot's own hardware.

Deep Check (not Quick Scan) additionally sends the bare domain name — never the full URL, message content, or any file — of links you scan to two free, no-account-required threat-reputation services, to check if the domain is already known-malicious: Cloudflare's malware-blocking DNS resolver, and SinkingYachts, a community-maintained database of Discord-specific phishing/scam domains. Both services only ever receive a domain name (e.g. example.com), never your message content, files, or full URLs with query parameters.

2Message Parsing & Zero-Download Architecture

User App Privacy Win: Because Pensira is a User-Installable App, it physically does not have the ability to read or monitor chat messages in the background (no Auto-Mod). It can only read a message when you explicitly right-click it and select Apps → Quick Scan / Deep Check, or when you use a slash command.

Zero-Logging Guarantee: The bot does not log, store, or archive any user conversations. The bot extracts and analyzes URLs, text, and attachments purely in-memory — no files or images are ever written to the server's hard drive, and once a scan completes, all message and attachment data is immediately discarded from memory.

3Data We Store

The table below summarizes the only data Pensira stores in its own database.

DataPurposeStored As
Discord User IDXP, badges, referral trackingPlain integer
Scan timestampsRate limiting, cooldownsUnix timestamps
Cyber XP & BadgesGamificationPlain integers/JSON
Referral linksReferral trackingUser ID pairs

We never store: message content, usernames, server IDs, file content, or link URLs beyond what is briefly needed in-memory to perform the scan.

4Data Deletion

You may delete all your stored data (profile, XP, badges, and referral history) at any time via /settings → Erase My Data. This action is immediate and permanent.

5About This Dashboard

The stats shown on the homepage are aggregate, anonymous totals only (total scans, community-wide XP, threat-category counts) — no individual user data is ever shown there.

If you choose to log in with Discord, we request the identify and email scopes — your Discord user ID, username, avatar, and email address. We never request server memberships or message access through this login. The email address is used only to (a) check whether an account has been blocked from logging in due to abuse of the service, and (b) attach your identity to feedback you submit while logged in (see below) — it is never shown anywhere on the dashboard, never sold or shared with third parties, and never used for marketing. After logging in, you can see your own Cyber XP, scan counts, referrals, and badges (the same data already visible to you via the /profile command in Discord) — you can never see another user's data through this dashboard, and no one else can see yours. Your login session is stored in a signed browser cookie and expires automatically after about a week, or immediately if you click Log out.

Submitting feedback requires being logged in with Discord. Unlike stats, feedback is linked to your account: your username, Discord ID, email, and current stats (Cyber XP, scan counts, badges) are included alongside your message when it's forwarded to the team's private Discord channel. This lets us follow up on reports and identify abuse of the feedback form; it is not used for any other purpose.

A small number of project maintainers can view submitted feedback (with the account details above) and can block a specific email address from logging in if it's associated with abuse of the bot or dashboard. Blocking only prevents dashboard login — it does not affect using the bot on Discord itself.

6Third-Party Data & Attributions

The Pensira Engine's blocklists are built in part from several free, publicly available threat-intelligence sources, refreshed automatically on a regular schedule. None of these are queried live at scan time — every scan is checked against a local snapshot already stored on Pensira's own server, so no message, file, or link content is ever sent to any of these sources (only the snapshot's maintainers ever see their own data being downloaded, on a schedule, with no query tied to your activity).

One of these sources, the Phishing.Database project, is distributed under the MIT License, which requires its notice to be reproduced here:

MIT License Copyright (c) 2018-2025 Mitchell Krog - github.com/mitchellkrogza Copyright (c) 2018-2025 Nissar Chababy - github.com/funilrys Copyright (c) 2018-2025 Phishing.Database Contributors - github.com/Phishing-Database Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, subject to the above copyright notice and this permission notice being included in all copies or substantial portions of the Software.

The Pensira Engine's other data sources and their own terms: The Block List Project (public domain), abuse.ch's URLhaus/MalwareBazaar/Feodo Tracker (free for non-commercial fair use), the Spamhaus Project's DROP list (free to use), and the OpenPhish community feed (free tier). We're grateful to the maintainers of all of these for making them freely available.

7Changes to This Policy

We may revise this Privacy Policy periodically. Material changes will be reflected by an updated date at the top of this page.

8Contact

Privacy questions or data requests can be submitted through the feedback form.

FAQ Terms of Service Privacy Policy Feedback
© 2026 Pensira. All rights reserved.