The audit database is designed around stable Discord identifiers. Live names shown in the dashboard are retrieved when needed rather than preserved as historical identity records.
Privacy
Privacy Policy
This Policy explains what CordVault collects, why it is needed, how it is protected, who can access it, how long it is kept, and the choices available to Server Owners, administrators, and Discord users.
This is a product-specific privacy draft, not legal advice. It should be reviewed for the laws that apply before CordVault is made publicly available.
Set LEGAL_CONTACT_EMAIL before launch. A working contact method is required for privacy questions and rights requests.
Core audit features do not require conversation archiving. Content collection is separately controlled, encrypted when enabled, and subject to a shorter retention period.
CordVault does not sell Discord Data, provide it to data brokers, or use it for targeted advertising.
1. Scope of this Policy
This Privacy Policy applies to the CordVault Discord bot, website, dashboard, event collectors, databases, queues, security alerts, incident-management tools, exports, restoration tools, support interactions, and related services (“CordVault,” “we,” “us,” or “our”). It applies when you sign in, manage a Server, appear in an authorized Server’s audit records, contact CordVault, or otherwise interact with the Service.
This Policy does not govern Discord itself, a Server Owner’s separate practices, third-party integrations, or copies of exports after an authorized user downloads them. Those parties may have their own duties and policies.
2. Who decides how information is used
CordVault determines how information required to run, secure, and improve the Service is processed. Depending on applicable law and the deployment, CordVault may be treated as a data controller, service provider, processor, or covered business for account, security, support, and product-operation data.
A Server Owner generally decides whether to install CordVault, which event categories to record, who may use the dashboard, retention periods, whether optional Message Evidence is enabled, and how records are used for that Server. For those choices, the Server Owner or the group running the Server may have separate privacy responsibilities, and CordVault may process information on its behalf. This Policy does not replace a Server Owner’s required notices, lawful basis, consent, employment policies, or data-processing agreement.
3. Information CordVault collects
3.1 Discord OAuth and dashboard account data
- Your Discord user ID, current username or display name, avatar reference, and OAuth authorization data needed to sign you in.
- Discord Server IDs, current Server names and icons, ownership or management status, and permissions returned by Discord so CordVault can show Servers you are allowed to manage.
- Dashboard role and access grants, such as Owner, Admin, Investigator, or Viewer.
Current names and images may be held temporarily in a server-side authenticated session or retrieved from Discord for display. They are not intended to become historical names in the CordVault audit database.
3.2 Core audit and snapshot data
- Discord IDs for Servers, users, members, actors, subjects, bots, roles, channels, categories, webhooks, invitations, emojis, stickers, and other supported objects.
- Event type, source, timestamps, before and after state, object settings, permission values, hierarchy and position, deleted-object state, schema version, and technical source metadata.
- Audit-log entry IDs, action types, reason fields when Discord supplies them, attribution level, confidence score, correlation keys, deduplication keys, and related-event groups.
- Current and historical snapshots, reconciliation results, detected drift, duplicate detection, and missed-event indicators.
3.3 Security, case, and restoration data
- Alerts, risk levels, affected object IDs, recommended responses, acknowledgements, and linked events.
- Incident titles, descriptions, statuses, severity, assigned Discord user IDs, investigator notes, affected entity IDs, attached evidence, and case activity.
- Restoration requests, selected snapshot, proposed changes, validation results, confirmation, execution output, object-ID mappings, verification, and resulting audit event.
- Administrative activity records, including the acting Discord user ID, action, target, timestamp, outcome, request identifier, and a one-way hash of the source IP address where configured.
3.4 Technical and operational data
- Server-side session identifiers, OAuth state, CSRF protection values, request IDs, application logs, error reports, worker and queue status, rate-limit state, database health, and performance metrics.
- Approximate network and device information that web servers ordinarily receive, such as IP address, browser type, operating system, referring page, and request time. CordVault does not need precise location data.
- Support messages and any information you choose to provide. Do not send passwords, bot tokens, encryption keys, or unnecessary personal information.
3.5 Evidence and export data
CordVault records canonical event hashes, chain positions, previous hashes, export timestamps, manifest details, signature-verification information, format selections, and the Discord ID of the authorized requester. An export can contain the audit and case information selected by that authorized user.
4. Where information comes from
- Discord: OAuth, API responses, Gateway events, guild audit-log entries, bot permissions, and objects available to the installed application.
- Server Owners and authorized users: settings, access grants, incident notes, evidence selections, restoration confirmations, support requests, and other submitted content.
- CordVault systems: normalized events, correlations, confidence scores, alerts, snapshots, hashes, queue records, security logs, and operational telemetry generated while providing the Service.
- Service providers: delivery, hosting, database, cache, backup, monitoring, and security information needed to operate their services.
CordVault cannot collect historical Server activity that Discord does not provide and that CordVault did not observe after installation.
5. How information is used
We process information to:
- authenticate users and determine which Servers and features they may access;
- collect, normalize, deduplicate, preserve, search, and display authorized audit events and snapshots;
- match Gateway activity with audit-log entries and communicate whether attribution is confirmed, highly likely, inferred, or unknown;
- detect risky changes, generate alerts, group related activity, and support incident investigation;
- honor Server logging, retention, alert, message-evidence, and dashboard-access settings;
- produce requested JSON, CSV, PDF, timeline, and configuration-evidence exports;
- perform previewed and confirmed restoration operations and verify results;
- provide integrity checks, signed manifests, and tamper-evidence verification;
- secure tenant boundaries, sessions, credentials, infrastructure, and records; prevent fraud, misuse, and unauthorized access;
- diagnose errors, reconcile missed events, operate queues and backups, measure reliability, and improve usability;
- respond to support, privacy, legal, and security requests;
- enforce the Terms of Service, comply with law, and protect users, Discord, CordVault, and others.
We do not use Discord message content to train general-purpose artificial-intelligence or machine-learning models.
6. Legal bases where required
Where a law such as the GDPR or UK GDPR requires a legal basis, processing may rely on:
- Contract: to provide requested sign-in, dashboard, recording, investigation, export, and restoration functions.
- Legitimate interests: to secure Discord communities and the Service, maintain reliable records, prevent abuse, troubleshoot, improve operations, and establish or defend legal claims, balanced against affected rights.
- Consent: where a feature, jurisdiction, or communication requires it. Consent can be withdrawn for future processing, but withdrawal does not make earlier lawful processing unlawful.
- Legal obligation: to respond to valid legal process, retain legally required records, or satisfy regulatory duties.
- Vital interests or public interest: only in exceptional circumstances recognized by law.
The Server Owner is responsible for identifying and documenting the appropriate basis for monitoring and optional content choices made for its Server.
7. IDs-only audit-database design
CordVault’s persistent audit schema is designed to store Discord IDs instead of usernames, display names, member nicknames, Server names, role names, channel names, webhook names, emoji names, or invitation creator names. Stable IDs improve accuracy and reduce unnecessary identity history. The dashboard may resolve an ID to current information from Discord at display time when authorization and API access permit.
Names can still appear if an authorized user types them into an incident title, description, note, reason, or other free-text field, or if Discord includes text inside raw data that a feature is configured to preserve. Administrators should use IDs and avoid personal or sensitive information in free text. CordVault may redact or remove unnecessary text.
8. Optional Message Evidence
Core administrative auditing works without storing ordinary conversations. Message Evidence is separately configurable and may be disabled, metadata only, limited to moderation incidents, limited to configured channels, or limited by a short retention window.
Depending on settings and Discord access, Message Evidence may include message ID, Server ID, channel ID, author ID, timestamps, edit or deletion status, attachment count and non-content metadata, and actor attribution where Discord provides a matching moderation audit entry. If content retention is explicitly enabled, observed message text may be encrypted and stored only for the configured purpose and period.
A deletion event does not always identify who deleted the message. The author is not necessarily the deleting actor. CordVault labels uncertain attribution rather than assuming. Content that the bot never observed cannot be reconstructed.
Server Owners must provide clear disclosure, select only necessary channels, restrict dashboard access, use the shortest practical retention period, and honor deletion requests. Message Evidence must not be enabled as undisclosed general surveillance.
10. When information is disclosed
We may disclose information only as reasonably necessary to:
- Authorized Server users: Server Owners and dashboard members whose role permits viewing the relevant events, alerts, cases, messages, settings, exports, or restorations.
- Infrastructure providers: hosting, database, queue or cache, object storage, backup, monitoring, security, and communication providers bound to protect information and use it only to provide contracted services.
- Discord: when using Discord APIs, carrying out a requested restoration, responding to platform enforcement, or protecting the Discord ecosystem.
- Professional advisers: attorneys, auditors, insurers, and security specialists under confidentiality obligations.
- Legal and safety recipients: courts, regulators, law enforcement, or affected parties when reasonably believed necessary to comply with valid process, protect rights or safety, investigate abuse, or defend claims.
- Business successors: a buyer, investor, lender, or successor during a merger, financing, reorganization, sale, or insolvency, subject to appropriate confidentiality and applicable law.
- At your direction: when an authorized user creates, downloads, or transmits an export or configures an alert destination.
We do not make Server records public. A downloaded export is controlled by the person or organization that receives it.
11. No sale, data brokerage, or targeted advertising
CordVault does not sell personal information or Discord Data for money, share it for cross-context behavioral advertising, provide it to data brokers, use it to build advertising profiles, or place third-party ads in audit records. We do not use Discord Data to determine eligibility for credit, employment, housing, insurance, or similar services.
If our practices materially change, we will update this Policy and provide legally required notice and opt-out mechanisms before the new practice begins.
12. Tenant isolation and dashboard permissions
Each Server is treated as a separate tenant. Requests are checked against the authenticated Discord user, current Server ownership where available, and stored dashboard access. Roles are intended to limit capabilities: viewers can inspect permitted records, investigators can work with cases, administrators can manage operational settings, and Server Owners retain primary control.
Server Owners are responsible for reviewing dashboard membership, promptly removing former staff, protecting Discord accounts with multi-factor authentication, and granting the least access required. We may suspend a session or access grant when ownership changes, the bot is removed, authorization is revoked, or misuse is suspected.
13. How long information is kept
Retention depends on the kind of information, legal requirements, security needs, and active disputes:
| Category | Retention period |
|---|---|
| Core events and historical snapshot versions | 180 days. Expired records are removed automatically in bounded maintenance batches. |
| Current object snapshots | Kept while needed to show the current or last-known state, including supported deleted-object recovery. |
| Message content | Only when enabled; generally 1 to 90 days according to Server settings. |
| Message metadata | Generally 1 to 3,650 days according to Server settings and necessity. |
| Browser session | Normally 1 to 24 hours, or earlier on sign-out, expiry, revocation, or security action. |
| Cases, alerts, restorations, and integrity anchors | While reasonably needed for investigation, security, dispute, or compliance purposes. Event attachments expire with core event history. |
| Operational and security logs | For a limited period appropriate to troubleshooting, abuse prevention, security, and legal obligations. |
| Backups | Until rotated under the backup schedule; deletion from active systems may take additional time to age out of protected backups. |
A valid legal hold, security investigation, or a requirement to delete Discord Data sooner may change normal handling. We periodically review stored data and aim to delete or de-identify it when no longer necessary for the disclosed function.
14. Bot removal, account closure, and deletion
Removing the bot stops new collection after Discord communicates the removal, but does not necessarily delete existing records immediately. A Server Owner may request deletion or use available dashboard workflows. We may retain limited records where necessary for security, fraud prevention, legal compliance, disputes, integrity of other parties’ records, or proof that a deletion request was completed.
Deletion from active databases may not instantly remove encrypted backups. Backup copies are isolated from ordinary use and expire under the backup schedule unless restoration is required. If restored, applicable deletion records should be re-applied.
Discord may direct us to delete API data, and we will act on valid platform instructions. Downloaded exports, Discord’s own copies, alert messages already sent to a Discord channel, and copies held separately by a Server Owner are outside CordVault’s deletion control.
15. Security safeguards
CordVault uses measures designed for the sensitivity of its records, which may include encrypted transport in production, database transport security, encryption for retained message content, server-side sessions, secret separation, least-privilege service accounts, tenant authorization checks, dashboard roles, administrative action logs, one-way hashing of source IPs, queue isolation, rate-limit handling, tamper-evident event chains, encrypted backups, monitoring, and restoration testing.
No security measure eliminates all risk. Users must protect Discord accounts, devices, browser sessions, exports, credentials, and alert channels. Do not send bot tokens, passwords, encryption keys, or session cookies to support. Report suspected unauthorized access promptly.
16. Tamper evidence, exports, and accuracy
Canonical serialization, per-Server hash chains, and signed export manifests can indicate whether checked stored records or exported bytes differ from what was previously hashed. They do not make data legally immutable, prove that Discord delivered every event, guarantee the truth of user-submitted notes, or preserve chain of custody after download.
Discord events may be delayed, duplicated, incomplete, or missing. Correlation and reconciliation are designed to improve the record, and the dashboard distinguishes original source data from later enrichment. Authorized investigators should review context and confidence before making consequential decisions.
17. International data transfers
CordVault, Discord, and service providers may process information in countries other than where an affected person lives. Those countries may have different privacy laws. Where required, we use an approved transfer mechanism, contractual safeguards, adequacy decision, or other lawful basis and apply technical and organizational protections.
The operator should identify production hosting locations and subprocessors before launch and provide any jurisdiction-specific transfer disclosures or data-processing addendum required by customers.
18. Privacy rights
Depending on location and applicable law, you may have rights to:
- know whether and how personal information is processed;
- access or receive a copy of personal information;
- correct inaccurate information;
- delete information, subject to lawful exceptions;
- restrict or object to certain processing;
- receive portable information in a structured format;
- withdraw consent for future processing;
- appeal a refusal where local law provides an appeal;
- avoid unlawful discrimination for exercising privacy rights; and
- complain to a data-protection authority or regulator.
These rights are not absolute. For example, an audit event may also document the actions or rights of a Server, victim, or other user; security and legal obligations may require limited preservation; and CordVault cannot correct source data controlled by Discord. We will explain applicable limitations when responding.
19. California and similar U.S. state disclosures
Subject to applicability and exceptions, residents may have rights to know categories and specific pieces of personal information, learn sources and purposes, access, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive equal service when exercising rights.
During the preceding 12 months, the categories CordVault may collect are identifiers; Internet or electronic network activity; commercial or account relationship information if a paid plan exists; user-submitted content; and inferences such as security risk or attribution confidence. Sources, purposes, recipients, and retention are described in Sections 3 through 13.
CordVault does not sell personal information or share it for cross-context behavioral advertising and therefore does not currently provide a “Do Not Sell or Share” link. We also do not use or disclose sensitive personal information to infer characteristics for advertising. If those practices change, we will add required controls and recognize legally required opt-out preference signals.
20. How to exercise a privacy right
The operator must configure LEGAL_CONTACT_EMAIL before launch. Until then, this draft does not provide a valid public request channel.
Include the relevant Discord user ID, Server ID, the right you wish to exercise, your relationship to the Server, jurisdiction, and a reliable response method. Do not send passwords, tokens, or unnecessary message content. We may request reasonable verification through Discord OAuth, Server ownership, or another secure method. We will use verification information only to handle the request.
Server members may also contact the applicable Server Owner because that owner controls many Server-specific settings and uses. If a request concerns data we process for a Server Owner, we may refer the request to that owner and assist as required. Authorized agents must provide proof of authority. We aim to respond within the period required by applicable law.
21. Children
CordVault is not directed to children under 13 and must not be used below Discord’s minimum age for the person’s country. We do not knowingly seek personal information directly from a child who cannot lawfully use the Service. If you believe such information has been processed, contact us with the relevant IDs so it can be investigated and handled appropriately.
22. Sensitive information and data minimization
Do not enter passwords, authentication tokens, private keys, payment-card details, bank details, government identifiers, health information, precise location, biometric data, or other unnecessary sensitive information into CordVault notes, cases, settings, or support requests. Server Owners should disable content retention or exclude channels likely to contain sensitive conversations unless collection is demonstrably necessary, lawful, disclosed, and tightly restricted.
If sensitive information appears unexpectedly, access should be restricted and deletion or redaction requested promptly. CordVault may remove information that is unsafe, unlawful, or unnecessary for the Service.
23. Correlation, alerts, and automated analysis
CordVault automatically matches events, calculates confidence, detects duplicates and drift, evaluates security rules, groups related activity, and may create an incident from a critical alert. These tools support human investigation. A risk label or inferred actor is not a final factual, legal, employment, or disciplinary determination.
CordVault does not make solely automated decisions that produce legal or similarly significant effects on individuals. Server Owners and investigators are responsible for reviewing source evidence, uncertainty, context, and applicable policy before acting.
24. Discord platform data and permissions
Discord controls the data and permissions its platform makes available. CordVault requests only permissions and privileged intents needed for configured functions. Message content and member access may require Discord review or approval at applicable scale. If access is denied, revoked, or changed, affected features may stop.
Use of Discord Data is also governed by Discord’s Terms of Service, Developer Terms, and Developer Policy. Discord has its own privacy policy and is responsible for its platform practices.
25. Security incidents and notification
We investigate suspected unauthorized access, loss, alteration, or disclosure and take reasonable containment and recovery steps. Where law or contract requires, we will notify affected customers, individuals, Discord, or regulators within the applicable period. Notices may be delivered through the dashboard, registered contact, Discord, email, or another appropriate channel.
Server Owners should provide a monitored security contact and promptly report incidents involving CordVault sessions, exports, dashboard users, alert channels, or credentials.
26. Changes to this Policy
We may update this Policy as CordVault changes or legal and Discord requirements evolve. The page will show the effective and last-updated dates. Material changes may also be announced in the dashboard or through another reasonable channel. Where consent is legally required for a new use, we will request it before that use begins.
Earlier versions should be retained for reference when CordVault enters public operation. Continued use after an effective date does not waive rights that applicable law does not permit users to waive.
27. Contact
Service
CordVault
Privacy and legal email
Not configured—set LEGAL_CONTACT_EMAIL.
For the quickest response, include Discord IDs rather than names and clearly identify whether the question concerns dashboard access, a specific Server, Message Evidence, deletion, security, or another privacy right.