Privacy Policy

Last updated: August 23, 2026

1. Overview

This Privacy Policy explains what information Discal collects through the website (the “Site”) and the Discal Discord bot (the “Bot”), why we collect it, and how it’s used. Discal is an independent, third-party service and is not affiliated with, endorsed by, or operated by Discord Inc. — using Discord itself is separately governed by Discord’s own Privacy Policy.

2. Information collected when you log in

Discal uses “Login with Discord” (OAuth2) instead of its own passwords. When you log in, Discord shares the following with us, based on the permissions you approve on Discord’s own consent screen:

  • Your Discord user ID, username, discriminator/global display name, and avatar;
  • Your email address, if your Discord account has one attached;
  • A list of the Discord servers you belong to, and which of those you can manage — used only to show you which servers you’re allowed to add to Discal.

We never see or store your Discord password — authentication happens entirely on Discord’s side.

3. Information the Bot collects from your server

When you add the Bot to a Discord server, it can read the information needed to run Discal’s permission and role-hierarchy checks: the server’s name, icon, and approximate member/online counts; the server’s roles and their positions; and the Bot’s own permissions and role position within that server. This is fetched directly from Discord using the Bot’s own credentials, only for servers the Bot has actually been added to.

The Bot does not read, log, or store the content of messages sent in your server. It only sends messages itself (setup confirmations and partnership notifications) and reads message history where needed for those replies to thread correctly — it does not monitor or record ordinary conversation.

For the partnership workflow, the Bot also observes specific server events — a member joining, and role updates or deletions — so Discal can grant the Partner Role automatically and keep your permission checklist accurate without you having to manually recheck it.

4. Information you provide directly

When you list a server, you provide its description, category, language, tags, Discord invite link, and your own partnership requirements (minimum members, account age, and similar settings). This information is shown publicly on your server’s Discal profile and in the directory, since that’s the point of listing it.

5. Cookies

Discal uses two cookies, both strictly functional:

  • Session cookie — a signed token that keeps you logged in for up to 30 days. It’s httpOnly (not readable by page scripts) and only sent over HTTPS in production.
  • OAuth state cookie — a short-lived (10-minute) cookie used only during the Discord login round trip, to protect against cross-site request forgery.

We don’t use third-party advertising or tracking cookies.

6. How we use this information

  • Operating your account and session, and letting you manage the servers you own on Discal;
  • Running the setup wizard’s permission and role-hierarchy checks;
  • Matching, verifying, and activating partnerships, and granting the Partner Role automatically once verified;
  • Directory features — search, sorting, the leaderboard, and Discal Bump;
  • Basic analytics for your own server’s dashboard — profile views, join-button clicks, partner requests, and bumps;
  • Sending you notifications and Discord DMs about things that concern your own account or server (e.g. a partnership update);
  • Reviewing reports submitted about a listing, for moderation purposes.

7. How we share information

We don’t sell your information, and we don’t share it with third parties for their own marketing purposes. Information is shared only:

  • With Discord itself, as an unavoidable part of how OAuth login and the Bot work;
  • Publicly, for whatever you’ve chosen to put on a public server listing (name, icon, description, tags, member counts);
  • With another server owner, when needed to run the partnership workflow you both took part in;
  • If required to comply with a legal obligation, or to protect the safety and integrity of the Service.

8. Data retention

We keep account and server data for as long as your account or server listing is active on Discal. Removing the Bot from your server stops it from collecting any further live data from that server, but previously stored listing and analytics data isn’t automatically deleted — see the next section for how to request removal.

9. Your choices and rights

You can update your server’s listing details yourself from the dashboard at any time. To request deletion of your account, a server listing, or other personal data we hold about you, contact support@discal.org. Depending on where you live, you may have additional rights over your personal data (such as access, correction, or portability) under applicable law — reach out to the same address to exercise them.

10. Children’s privacy

Discal is not directed at children, and Discord itself requires account holders to meet Discord’s own minimum age requirement. We don’t knowingly collect information from anyone below that age; if you believe we have, contact us and we’ll remove it.

11. Security

We take reasonable technical measures to protect the information Discal holds — including encrypting session cookies and never storing your Discord password — but no online service can guarantee perfect security. Please let us know right away if you believe your Discal account or a server you manage has been compromised.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we’ll update the “Last updated” date above. Continuing to use Discal after changes take effect means you accept the updated policy.

13. Contact

Questions about this Privacy Policy can be sent to support@discal.org.