Privacy Policy
Last updated: August 2026. This is a plain-language summary, not a substitute for legal advice — if you need a fully vetted policy, have it reviewed by a lawyer before relying on it.
What we collect
- Discord identity — your Discord ID, username, and any server-specific info needed to verify you and apply roles.
- IP address — recorded at verification and login, used only to detect duplicate or alt accounts. It is never shown to your server's admins — only to us, the operators of the bot.
- Device/browser fingerprint — while completing web verification, a script briefly checks a few standard browser signals (canvas rendering, WebGL info, screen size, timezone, language) and combines them into a single one-way hash on your own device before sending it to us. We never receive or store the raw signals themselves, only that hash — it's used to flag when the same device appears to be behind multiple Discord accounts. This runs automatically as part of verifying (declining it, e.g. by blocking JavaScript, doesn't stop you from verifying — it just means that check is skipped for your account). Unlike your IP address, a match on this (which Discord accounts share a device) is visible to your server's admins, since it's meant to help them catch alts directly.
- VRChat account (optional) — if a server requires it, we store your VRChat user ID and profile URL when you link it, so duplicate/alt accounts across VRChat can be flagged.
- OAuth tokens — when you log in with Discord (or link VRChat), we store the access/refresh tokens issued to us so the bot can continue acting on your behalf (e.g. checking your VRChat status). Access to these is restricted to us as the bot's operators.
- Moderation history — if a moderator takes action on your account (kick, ban, timeout, warning) in a server using this bot, that action and its reason are logged and visible to that server's admins.
- Discord server list — when you log in, we also ask which Discord servers you have admin permission in, so the panel can show you where you could add or manage the bot. This list is fetched live from Discord each time you visit that page — we don't store a permanent copy of it.
- Session cookies — used to keep you logged in to the web panel. Session tokens are stored hashed, not in plain text.
Who can see it
Your server's admins can see verification status, moderation history, and which of their server's Discord accounts share a device fingerprint (as a match, not the underlying data) — but never your IP address or the fingerprint hash itself. We, as the operators of the bot, can see everything stored, including IP addresses, fingerprint hashes, and OAuth tokens, solely to operate and maintain the service.
How long we keep it
We don't currently auto-delete data after a fixed period — it's retained for as long as your account is used with the bot. If you want your data removed, contact us (below) and we'll delete it.
Third parties
We use Discord's and VRChat's own OAuth login systems to verify your identity — we never see your password. The bot runs on Railway's hosting infrastructure. We don't sell your data, and we don't use it for advertising.
Your choices
You can unlink your VRChat account, log out, or ask us to delete your data entirely at any time. Removing the bot from a server doesn't automatically delete existing records for that server — contact us if you want that data removed too.
Contact
Questions about this policy or a data removal request: [add a support contact here before this page goes live].