Legal
Privacy policy
Draft. Review with counsel before publishing.
This policy explains what DisAuth collects, why, how long it is kept and what choices you have. It applies to the website, the search product and the verification bot.
What we collect
From moderators who sign in
- Your Discord user ID, username and avatar, received through Discord OAuth.
- Your email address, only if you opt in to email alerts.
- Search history and watchlist entries you create.
- Billing details handled by our payment processor. We never see full card numbers.
From people who verify in a server using the bot
- Discord user ID and the ID of the server where verification happened.
- IP address and derived network information such as ASN and whether the address belongs to a VPN, proxy or datacenter.
- Browser and device characteristics used to build an anonymised fingerprint.
- A verification cookie so repeat verifications from the same browser can be recognised.
- Timestamps of verification attempts.
We do not read messages, voice, friend lists or any content posted on Discord.
Why we collect it
- To detect alternate accounts used to evade bans and to flag VPN or proxy verification attempts.
- To deliver watchlist alerts that moderators have asked for.
- To operate, secure and bill for the service.
We do not use this data for advertising, profiling outside of server security, or any purpose unrelated to moderation.
Retention
Verification signals are deleted automatically after a fixed retention period. Placeholder: 24 months from the last verification. Account data is deleted within 30 days of account closure.
Sharing
We never sell personal data and never share it with advertisers or data brokers. We use processors for hosting, email delivery and payments, each bound by a data processing agreement.
Your rights
- Request a copy of the data we hold about your Discord account.
- Request deletion of your data.
- Request exclusion from search results. Excluded records are masked, not shown to moderators.
Send requests to support@disauth.app from an address linked to your Discord account, or through the Discord server.
Children
DisAuth is not directed at anyone under 13 or under the minimum age required in their country.
Changes
We will announce material changes on the website and in the Discord server before they take effect.