This policy explains, in plain language, exactly what data AltScan ("we", "us") collects when you verify your Discord account, precisely why each item is needed, how it is protected, how long it is retained, and every option available to you. We designed the Service to collect the absolute minimum required to operate verification, giveaways, and community tooling — and nothing more. We do not run an advertising business, we do not sell data, and we do not embed third-party trackers on our pages.
2.1 Account identifiers. Your Discord user ID (a numeric identifier assigned by Discord) and your username. This is the core record that makes verification possible — without it, we cannot distinguish verified members.
2.2 Profile information. Your avatar hash and locale (Discord's name for your language/region preference), as returned by Discord's standard identify endpoint during authorization.
2.3 Email address. If Discord includes your email in the authorization response (depending on your Discord privacy settings), it is stored with your verification record for account-management purposes such as duplicate detection and, where needed, service communications.
2.4 Technical and security data. When you complete a verification, we log your IP address, browser user-agent string, and a timestamp. This data is used exclusively for security operations: detecting duplicate verifications from the same source, identifying fraudulent patterns, rate-limiting abuse, and investigating incidents. It is not used to build behavioral profiles.
2.5 Authorization tokens. The OAuth2 access and refresh tokens issued during your authorization. These are required to maintain your verified session, refresh access without re-prompting you, and add you to servers you opted into. Tokens are encrypted at rest (see Section 5).
2.6 Server membership snapshot. The list of participating servers visible to your account at verification time. This is used solely to place you in the correct communities and maintain accurate membership records.
Data is processed exclusively to: (a) operate and maintain your verification and its associated member status; (b) automatically add you to participating servers when and as you elect; (c) count giveaway entries and render live, aggregate community statistics; (d) prevent, detect, and investigate fraud, duplicate accounts, and platform abuse; (e) maintain the security and integrity of the Service; and (f) comply with legal obligations where applicable. We do not use your data for automated decision-making that produces legal effects, and we do not profile you for advertising or any commercial purpose.
Data resides in an access-controlled database hosted with a reputable infrastructure provider. OAuth tokens are encrypted at rest using industry-standard symmetric encryption (AES) before being written to storage, with keys held separately from the ciphertext. Administrative access to production data is restricted to a minimal set of service administrators, and all administrative actions are logged. Transport security is enforced via TLS for all connections. While no system is perfectly secure, we apply layered controls appropriate to the sensitivity of the data involved and respond to security incidents with diligence.
Verification records, including the associated technical data described in Section 2.4, are retained while your verification is active and for a reasonable period thereafter for community-management and fraud-prevention purposes. If you unverify, a last-known profile snapshot (absent active tokens, which are revoked and purged) may be retained for audit integrity. Aggregate statistics (counts, not identities) may be retained indefinitely as they contain no personal data. Deletion requests are honored as described in Section 8.
We do not sell, rent, trade, or share your personal data with advertisers, data brokers, or any party for commercial gain. A strictly limited set of processors handle data solely to operate the Service: (a) Discord, whose OAuth2 API initiates your authorization and whose platform delivers bot functionality; (b) our hosting provider, which runs the Service's infrastructure; and (c) our database provider, which stores encrypted records. Participating giveaway servers receive only aggregate entry counts — never individual-level data. Where data protection law applies, these processors operate under appropriate safeguards.
The Service operates globally, and your data may be processed in jurisdictions other than your own. Where required, transfers are safeguarded through standard contractual mechanisms or equivalent protections. By using the Service, you consent to such transfers for the limited purposes described in this policy.
The Service is not directed to children under 13 (or the higher minimum digital-consent age in your jurisdiction). We do not knowingly collect data from children below these thresholds. If you believe a child has provided data, contact staff and we will delete it promptly.
We may update this policy as the Service evolves. Material changes will be reflected by revising the "Effective date" above, and where practicable, announced through participating communities. Continued use after changes take effect constitutes acceptance, but we encourage periodic review.
Privacy questions, data requests, or concerns may be raised with AltScan staff in any participating community. We treat privacy inquiries seriously and respond within a reasonable timeframe.