Privacy Policy

Last updated: August 2026. This is a plain-language summary, not a substitute for legal advice — if you need a fully vetted policy, have it reviewed by a lawyer before relying on it.

What we collect

Who can see it

Your server's admins can see verification status, moderation history, and which of their server's Discord accounts share a device fingerprint (as a match, not the underlying data) — but never your IP address or the fingerprint hash itself. We, as the operators of the bot, can see everything stored, including IP addresses, fingerprint hashes, and OAuth tokens, solely to operate and maintain the service.

How long we keep it

We don't currently auto-delete data after a fixed period — it's retained for as long as your account is used with the bot. If you want your data removed, contact us (below) and we'll delete it.

Third parties

We use Discord's and VRChat's own OAuth login systems to verify your identity — we never see your password. The bot runs on Railway's hosting infrastructure. We don't sell your data, and we don't use it for advertising.

Your choices

You can unlink your VRChat account, log out, or ask us to delete your data entirely at any time. Removing the bot from a server doesn't automatically delete existing records for that server — contact us if you want that data removed too.

Contact

Questions about this policy or a data removal request: [add a support contact here before this page goes live].