1. Acceptance of these Terms
These Terms of Service (“Terms”) govern your use of CordVault (“CordVault,” “we,” “us,” or “our”). By installing the bot, authorizing Discord OAuth, opening the dashboard, creating or joining a CordVault workspace, accessing an export, or otherwise using the Service, you agree to these Terms and the Privacy Policy.
If you use CordVault for a Discord community or another group, you represent that you have authority to make that decision for the group. If you do not agree, do not install, access, or use CordVault.
2. Definitions
- Service
- The CordVault bot, website, dashboard, APIs, collectors, workers, databases, alerting, incident tools, exports, restoration tools, documentation, and related services.
- Server
- A Discord guild in which CordVault is installed or whose authorized records are displayed.
- Server Owner
- The Discord account identified by Discord as owning a Server.
- Administrator
- A user authorized by a Server Owner or by applicable Server permissions to configure CordVault or investigate records.
- Discord Data
- Data made available through Discord’s APIs, Gateway, OAuth, audit log, or other developer services.
- Audit Data
- Events, object snapshots, identifiers, timestamps, attribution, correlations, alerts, cases, notes, exports, integrity records, and restoration records processed by CordVault.
- Message Evidence
- Optional message-edit or message-deletion metadata and, only when configured, encrypted message content.
- User Content
- Notes, settings, case descriptions, requests, and other information submitted directly by users.
3. Eligibility and authority
You must be at least 13 years old, meet Discord’s minimum age for your country, and be legally capable of agreeing to these Terms. If local law requires parental or guardian consent, that consent must be obtained before use. CordVault is not directed to children under 13.
You may configure CordVault for a Server only if you are the Server Owner or have genuine authority to manage applications and the relevant data-processing settings. You may not use another person’s Discord account, OAuth session, credentials, or permissions without authorization.
4. Discord is a separate service
CordVault is a third-party application and is not Discord, affiliated with Discord, sponsored by Discord, or endorsed by Discord. Discord controls its platform, APIs, audit logs, permissions, event delivery, rate limits, account enforcement, and availability. Your use of Discord remains subject to Discord’s own terms and policies.
You must comply with the current Discord Terms of Service, Discord Developer Terms, Discord Developer Policy, Community Guidelines, and other applicable Discord rules. If Discord changes or withdraws access, CordVault features may change or stop without liability to you.
5. Discord OAuth, sessions, and access
The dashboard uses Discord OAuth to identify you and retrieve the Servers you can manage. You are responsible for protecting your Discord account, devices, browser sessions, and credentials. Do not share an authenticated dashboard session. Notify us promptly if you believe access has been compromised.
Dashboard roles may include Owner, Admin, Investigator, and Viewer. Server Owners are responsible for granting the minimum access necessary, reviewing access regularly, and promptly removing users who no longer require it. CordVault may rely on current Discord ownership data and stored dashboard grants when deciding access.
6. What CordVault provides
CordVault may collect supported Discord administrative events, store historical object states, match Discord audit-log entries to live events, calculate attribution confidence, detect security risks, organize cases, verify hash chains, generate exports, and restore limited configuration. Feature availability depends on configuration, Discord permissions, API access, subscription level, infrastructure, and law.
CordVault begins observing only after installation and authorization. It cannot reconstruct activity or state it never received. Discord events may arrive late, more than once, out of order, or not at all. Correlation and reconciliation reduce these limitations but cannot eliminate them.
7. Limited right to use the Service
Subject to these Terms, we grant you a limited, revocable, non-exclusive, non-transferable, non-sublicensable right to access and use CordVault for legitimate administration, security, moderation, compliance, and incident-response purposes in Servers you are authorized to manage.
You receive no ownership interest in CordVault software, branding, documentation, detection logic, interfaces, or other operator materials. Any rights not expressly granted are reserved.
8. Acceptable use and prohibited conduct
You must not, and must not help another person to:
- access a Server, dashboard, record, export, session, or account without authorization;
- use CordVault for stalking, harassment, intimidation, unlawful employee monitoring, discrimination, doxxing, or surveillance unrelated to legitimate Server administration;
- collect or use Discord Data beyond CordVault’s disclosed purposes or in violation of law, Discord policy, or another person’s rights;
- use audit or message data for advertising, data brokerage, eligibility decisions involving employment, housing, credit, insurance, or similar high-impact purposes;
- submit protected health information, financial account data, government identifiers, credentials, secrets, or other unnecessary sensitive data;
- misrepresent inferred or unknown attribution as confirmed fact;
- tamper with integrity records, conceal unauthorized activity, fabricate evidence, or remove context to mislead another person;
- reverse engineer, probe, bypass, disable, overload, scrape, or interfere with security, rate limits, tenant isolation, authentication, or operation;
- upload malware or use CordVault to facilitate unlawful conduct;
- resell, sublicense, or expose the Service or Discord Data except under a written agreement with us;
- use message content to train an AI or machine-learning model unless Discord and all required rights holders expressly authorize it; or
- violate export controls, sanctions, applicable law, or Discord rules.
9. Server Owner and administrator responsibilities
Server Owners and Administrators decide why CordVault is installed, what categories are recorded, alert destinations, dashboard access, optional Message Evidence, and whether restoration is requested. Core event history is retained for 180 days; separately configured Message Evidence may use a shorter period. Administrators are responsible for ensuring their choices are lawful, proportionate, documented, and appropriate for their community.
You must configure permissions using least privilege; keep CordVault’s role and alert channels secure; review dashboard members; respond to access, correction, and deletion requests; preserve required notices; avoid entering names or sensitive data into free-text notes; and test settings before relying on them during an incident.
10. Transparency, notice, and lawful monitoring
You are responsible for giving members, staff, contractors, and other affected people clear notice that CordVault is used, what it records, why it is needed, who can access it, how long it is retained, and how rights requests can be made. If consent is legally required, you must obtain valid consent before collection.
Installing CordVault does not by itself satisfy employment, labor, wiretap, electronic-communications, biometric, privacy, or monitoring laws. You must not secretly enable optional content collection where notice or consent is required.
11. Optional Message Evidence
Message Evidence is disabled by default and is not required for CordVault’s core audit functions. Available modes may include disabled, metadata only, moderation incidents only, selected channels, and limited retention. Administrators must choose the narrowest suitable mode.
Message deletion usually does not identify the deleting moderator through the Gateway alone. Actor attribution may depend on a separate Discord audit-log entry and may remain unknown. Content can only be retained when CordVault observed it, required Discord access is available, encryption is configured, and Server settings permit it.
You must not use Message Evidence as a general conversation archive. You are responsible for channel selection, disclosure, retention, access review, and deletion workflows.
12. Data, content, and permissions
As between you and us, you retain rights you lawfully hold in User Content. Discord and Discord users retain their respective rights in Discord Data. You grant us a limited, worldwide, non-exclusive license to host, reproduce, transform, encrypt, index, correlate, display, export, and otherwise process User Content and authorized Discord Data only as needed to operate, secure, support, and improve CordVault; comply with law and Discord requirements; and enforce these Terms.
You represent that you have all permissions and lawful bases necessary for information you direct CordVault to process. Do not place information in CordVault that you are not permitted to process.
13. Security responsibilities
We use safeguards designed to protect the Service, but no system is perfectly secure. You must use strong Discord account security, enable multi-factor authentication where available, secure devices, protect exports, limit dashboard access, keep tokens and credentials confidential, and report suspected unauthorized access.
Exports may contain sensitive audit information. Once downloaded, you—not CordVault—control the copy and are responsible for secure storage, transmission, access, retention, and disposal.
14. Safe Restoration terms and risks
Restoration is a controlled administrative action, not a guaranteed rollback. It requires a saved version, dependency analysis, preview, permission validation, explicit confirmation, execution, verification, and a new audit event. You authorize CordVault to make the displayed Discord changes when you submit the confirmation.
Discord may assign new object IDs; original names are not stored and may be replaced with temporary names; role members may require reassignment; category, role, or channel references may require remapping; integrations and webhooks may not reconnect; role hierarchy can block changes; and Discord may normalize positions or reject settings. You must review the preview and complete any manual cleanup.
Do not request restoration during an active incident unless you understand how it may alter evidence or interfere with containment. CordVault may refuse unsupported, unsafe, or unauthorized restoration.
15. Audit evidence, attribution, integrity, and exports
CordVault distinguishes confirmed, highly likely, inferred, and unknown attribution. Only confirmed attribution is directly matched to a Discord audit-log entry. Other levels are estimates based on available context and must not be treated as certainty.
Hash chains and signed manifests provide tamper evidence by showing whether stored or exported bytes differ from previously hashed values. They do not make records legally immutable, prove Discord delivered every event, establish authenticity beyond the checked data, establish chain of custody outside CordVault, or guarantee admissibility in any proceeding.
You are responsible for reviewing records, preservation procedures, legal holds, evidentiary requirements, and obtaining professional advice before using exports for discipline, litigation, law enforcement, employment, or other consequential decisions.
16. Availability, changes, and beta features
CordVault may be identified as beta. Features may be incomplete, changed, suspended, rate-limited, or discontinued. We do not guarantee uninterrupted operation, any specific retention duration, delivery of alerts, successful correlation, recovery of data, or compatibility with future Discord changes.
Maintenance, infrastructure failure, network interruption, Discord outage, API restriction, database failure, security response, or force majeure may affect service. We may modify safeguards, limits, interfaces, storage, or functionality to protect users or comply with law and platform rules.
17. Fees, plans, taxes, and renewal
If paid plans are introduced, price, billing interval, included usage, retention, limits, renewal, cancellation, refund terms, and taxes will be disclosed before purchase. Unless a separate order states otherwise, fees are non-refundable except where law requires. We will not charge you without an affirmative purchase flow.
18. Intellectual property
CordVault software, design, documentation, logos, trademarks, detection rules, and other operator-created materials are owned by us or our licensors and protected by applicable law. Discord names, marks, platform, and data remain the property of Discord or their respective owners. No trademark license is granted except as necessary to identify the Service accurately.
19. Feedback
If you voluntarily provide suggestions, you grant us a worldwide, perpetual, irrevocable, royalty-free, transferable, sublicensable right to use and commercialize that feedback without restriction or compensation, provided we do not publicly identify you as the source without permission.
20. Suspension, removal, and termination
You may stop using CordVault and remove the bot. Server Owners may revoke dashboard access. We may suspend or terminate access when reasonably necessary to prevent harm, investigate abuse, comply with law or Discord, address nonpayment, protect security, or enforce these Terms.
Termination does not automatically erase all data. Retention, deletion requests, backups, legal obligations, disputes, and Discord requirements are handled under the Privacy Policy. Provisions that logically survive—including ownership, disclaimers, liability, indemnity, disputes, and accrued obligations—continue after termination.
21. Disclaimers
TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE.” WE DISCLAIM ALL EXPRESS, IMPLIED, AND STATUTORY WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, COMPLETENESS, AVAILABILITY, SECURITY, AND QUIET ENJOYMENT.
CordVault is not a substitute for backups, Discord administration, cybersecurity monitoring, emergency response, legal advice, employment advice, or law-enforcement reporting. Alerts are signals, not findings. Attribution is not proof unless independently validated. Restoration and exports are used at your risk.
22. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, CONSEQUENTIAL, OR PUNITIVE DAMAGES; LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS; SERVER DISRUPTION; FAILED ALERTS; INCORRECT ATTRIBUTION; RESTORATION EFFECTS; THIRD-PARTY CONDUCT; OR UNAUTHORIZED ACCESS, EVEN IF ADVISED OF THE POSSIBILITY.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, OUR TOTAL AGGREGATE LIABILITY ARISING FROM THE SERVICE WILL NOT EXCEED THE GREATER OF (A) THE AMOUNT YOU PAID US FOR THE SERVICE DURING THE TWELVE MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY OR (B) USD $100. Some jurisdictions do not allow certain exclusions, so parts of this section may not apply.
23. Indemnification
To the extent permitted by law, you will defend, indemnify, and hold harmless CordVault, its operator, affiliates, personnel, contractors, and service providers from claims, damages, losses, liabilities, costs, and reasonable legal fees arising from your Server configuration, unlawful monitoring, User Content, Message Evidence choices, restoration requests, exports, violation of these Terms, violation of law or Discord policy, or infringement of another person’s rights. We may control the defense of a covered claim, and you will cooperate.
24. Governing law and disputes
These Terms are governed by the laws applicable to the CordVault operator, without regard to conflict-of-law principles, except where mandatory consumer law requires otherwise. Before filing a formal claim, each party agrees to send written notice describing the dispute and attempt good-faith informal resolution for at least 30 days.
The appropriate forum and venue, and any required consumer withdrawal rights, should be configured for the laws that apply before public launch. Nothing here limits rights that cannot legally be waived.
25. General provisions
These Terms and referenced policies are the entire agreement concerning the Service unless a signed order or data-processing agreement says otherwise. If a provision is unenforceable, it will be modified only as necessary and the remainder stays effective. Failure to enforce is not a waiver. You may not assign these Terms without our written consent; we may assign them with the Service or as part of a reorganization, subject to law.
Headings are for convenience. “Including” means “including without limitation.” Electronic notices and acceptance are valid. We may update these Terms; material changes will be posted with a new date and, when appropriate, additional notice. Continued use after the effective date means acceptance where permitted by law.
26. Contact and legal notices
Service: CordVault
Email: Not configured. Set LEGAL_CONTACT_EMAIL before launch.
Notices should identify the requester, relevant Discord user and Server IDs, the request or dispute, and a reliable response method. Do not send passwords, tokens, private keys, or unnecessary message content.