// Discord Application / Privacy
Privacy Policy_
This policy explains how the AVRXT Discord application and its authentication service collect, use, store, and protect Discord-related data. It applies when you authorize the application, use its bot features, or access protected AVRXT services with Discord.
01. Data We Collect
Depending on the feature you use, we may receive your Discord user ID, username, display name, avatar, email address, OAuth authorization data, server membership, and assigned role IDs. When you interact with bot commands, we may also process the command, server ID, channel ID, interaction ID, and the response required to provide that command.
We do not ask for or collect your Discord password. Discord credentials are entered only on Discord's authorization pages.
02. How We Use Data
- Authenticate you and maintain a secure session.
- Confirm server membership or required roles before granting protected admin access.
- Operate requested bot commands and application features.
- Prevent abuse, investigate errors, and protect the application and its users.
- Comply with law, Discord's rules, and valid security requests.
03. OAuth, Cookies & Storage
Discord authentication is handled by our self-hosted OpenAuth service. It uses essential, HTTP-only cookies and short-lived authorization records to complete OAuth and maintain your session. Authentication records are stored in Cloudflare Workers KV. The public website runs on Vercel.
We request only the Discord scopes needed for identity and authentication. Bot-based role verification is performed server-side and does not expose the bot token to your browser.
04. Sharing & Third Parties
We do not sell Discord API data, use it for targeted advertising, provide it to data brokers, or use message content to train AI models. Data is shared only with service providers necessary to operate the application, including Discord, Cloudflare, and Vercel, or when required by law.
Those services process information under their own terms and privacy policies. Discord's privacy policy is available at discord.com/privacy.
05. Retention & Deletion
OAuth state is retained only long enough to complete authorization. Website authentication cookies normally expire within 30 days. Security logs may be retained for up to 30 days unless a longer period is required to investigate abuse or comply with law. Bot interaction data is retained only when necessary for the requested feature.
You may revoke access through Discord's Authorized Apps settings at any time. To request access, correction, or deletion, email [email protected] with your Discord user ID. After identity verification, we will act promptly and ordinarily complete deletion within 30 days, except where retention is legally required.
06. Security
We use encrypted transport, restricted server-side secrets, HTTP-only cookies, role-based access checks, and limited-access infrastructure. No online service can guarantee absolute security; please report suspected vulnerabilities to [email protected].
07. Children & International Processing
The application is not directed to anyone under 13 or below the minimum digital-consent age in their jurisdiction. Data may be processed in countries where Discord, Cloudflare, Vercel, or our other infrastructure providers operate, subject to applicable safeguards.
08. Changes & Contact
We may update this policy when the application, law, or Discord requirements change. The effective date above identifies the current version. Questions, privacy requests, and application-related reports can be sent to [email protected].