Return to Shards
Legal

Privacy Policy

This policy explains how the Shards service team processes information when people use the Shards Discord bot, dashboard, hosted forms, community features, games, integrations, custom bot tools, and related websites.

Effective September 2, 2026 Last updated September 2, 2026 Read Terms of Service

Policy contents

  • Scope and roles
  • Information we process
  • Forms Studio
  • Community and companion features
  • Purposes and legal bases
  • Sharing and public visibility
  • Retention and deletion
  • Choices and privacy rights
  • Contact and requests

1. Scope and who controls information

This Privacy Policy applies to services operated under the Shards name by the Shards service team ("Shards," "we," "us," or "our"). It does not replace Discord's privacy policy or the policies of a Discord server, server administrator, linked website, custom AI endpoint, or other third party.

Shards decides how information is processed to authenticate users, provide and secure the platform, run shared infrastructure, administer premium access, prevent abuse, and support users. Discord server owners and administrators independently choose many server-specific purposes and settings, including which modules to enable, which form questions to ask, who can review responses, where notifications are posted, and which community records are exported. Contact the relevant server administrator about those choices and contact Shards about platform-level processing.

2. Sources of information

We receive information from you when you sign in, submit a form, use a command, send content, configure a feature, upload media, request support, or otherwise use Shards. We also receive information from server administrators, Discord and its APIs, selected integrations, custom bot applications, and configured AI providers. Some technical information is generated automatically by browsers, servers, databases, and security systems.

3. Information we process

The information processed depends on the features used and may include:

  • Accounts and authentication: Discord user ID, username, global or display name, avatar, OAuth scopes, encrypted OAuth access and refresh tokens, token expiration, login time, session identifiers, and selected server.
  • Servers, members, and permissions: server ID, name, icon or banner, owner and installation state, role and channel IDs, membership, nicknames, join time, account creation time derived from a Discord ID, boosting state and time, permission snapshots, and dashboard access roles.
  • Configuration and administration: feature settings, command and module choices, dashboards, presets, backups, bot-sync actions, access policies, workflows, form drafts and published versions, collaborators, themes, moderation rules, logs, audit history, premium gates, and administrator-provided names, descriptions, images, URLs, or messages.
  • Economy, games, and activity: virtual balances, resources, inventories, progression, items, trades, listings, rewards, cooldowns, transactions, game submissions and results, giveaways, activity counters, qualifying-message counts, voice activity summaries, and related timestamps.
  • Messages, interactions, and moderation: commands, button or menu interactions, relevant message or attachment content, recent context used by enabled AI or moderation tools, moderation decisions, reports, warnings, restrictions, appeals, and configured channel logs. Many features use content transiently and retain derived counters, decisions, or summaries, but features described below intentionally store content.
  • Premium and integrations: Discord SKU and entitlement identifiers, entitled account or server, subscription or purchase state, gifts or promotions, sync results, Top.gg vote results, and limited responses from other enabled content or validation services.
  • Custom bots and companion access: custom bot application ID, bot identity, validation and update times, encrypted custom bot token, hashed Vencord Companion access token, token last-use metadata, and the account, profile, economy, or inventory data returned to an authorized companion session.
  • Device, security, and diagnostics: cookies and local storage, IP address, user agent, request metadata, rate-limit or HMAC-derived keys, performance diagnostics, error logs, security events, sync health, and audit records.

To remember and evidence dashboard legal acceptance, Shards stores the Discord account ID, accepted document and bundle versions and hashes, Terms and Privacy step timestamps, the final acceptance time, and limited browser metadata. These records may be retained for the life of the account and longer where reasonably needed to establish the agreement, resolve disputes, meet legal obligations, or protect legal rights.

Shards must not be used to collect passwords, authentication secrets, payment card or bank information, government identifiers, protected health information, biometric identifiers, precise location, or other sensitive information protected by law. Do not place that information in forms, messages, uploads, presets, AI prompts, support requests, or configuration fields.

4. Discord messages, interactions, and DMs

Shards processes Discord message content only where needed for stated bot functionality, such as commands, configured rewards and drops, games, moderation, chat activity, workflow submissions, dashboard messages, and enabled AI features. Depending on the feature, content may be used transiently, stored as a submission or conversation, summarized in a log, or converted into activity, safety, game, or economy records.

Some features send service-related Discord DMs, such as a requested game flow, an enabled alert, a Forms Studio receipt, request for information, review decision, or server-directory result. Where a form presents a permission control for response-related DMs, Shards records and applies that choice to the configured workflow. Administrators must enable and use DMs only with any notice, direction, or consent required by law and Discord's rules. Delivery depends on Discord settings and is not guaranteed.

5. Forms Studio

Forms Studio lets authorized server administrators and collaborators create, version, publish, and manage forms. Shards may store form drafts; published-version snapshots; titles, descriptions, content blocks, media references, themes, questions and options; validation, calculations, quiz answers and scoring, conditional logic, access rules, schedules and submission limits; collaboration permissions; Discord publication and notification settings; automation definitions; and associated audit events. A public form's noindex instruction asks search engines not to index it; it is not a password or access control. Anyone with the URL may be able to open a form published for unrestricted link access.

Forms may be completed on a Shards web page, through a native Discord interaction, or through a hybrid flow that moves between Discord and the web. Shards may maintain a server-side draft or response session so a person can continue a multi-step form, resume where enabled, move backward, or complete web-only questions. Discord separately processes interactions, messages, attachments, and account information on its service under Discord's policies.

For a response, Shards may process the exact published form version used; answers and uploaded files; signatures or typed-name acknowledgements; timestamps, progress and completion time; web, Discord, hybrid, or import source; validation and logic results; calculated values; quiz score and grading history; tags; approval status; reviewer decisions, reasons and internal notes; notification delivery state; and automation results. The questions an administrator chooses can request names, contact details, addresses, dates, Discord users, roles or channels, consent records, and other information. A field marked "sensitive" is excluded from ordinary Discord notifications and some analytics by default, but that setting is an access and redaction control—not permission to collect prohibited data and not a promise that the answer can never be viewed by an authorized person or included in an authorized export.

Depending on form settings, Shards may associate a response or draft with a Shards account, Discord user ID, username, display name, server nickname, selected roles, manually entered email, invitation, or a pseudonymous identity key. Even for a form presented as anonymous, Shards may process IP address and other security metadata and retain HMAC-derived identity, deduplication, cooldown, or abuse-prevention keys. It may also send a Discord ID transiently to the selected main or custom bot to perform requested server checks. "Anonymous" therefore describes what ordinary reviewers receive under the form's settings; it does not guarantee that a response cannot be inferred from its content or technical context.

Configured access, eligibility, and frequency rules may check server membership and join time, Discord account age, recent qualifying-message count over the selected period, roles, boosting or screening state, prior submissions, invitation state, and cooldown or quota history. Shards stores the resulting status, relevant facts or rule violations, exceptions and administrative overrides, and evaluation time. Those checks are intended only for legitimate Discord-community administration and anti-abuse purposes. They must not be used to profile or discriminate, determine access to real-world benefits, or make decisions in employment, housing, insurance, credit, education, health care, or another high-impact domain.

Authorized owners, editors, analysts, reviewers, and viewers may receive different form-level permissions. Depending on those permissions and field settings, they may view, search, filter, summarize, score, tag, review, export, delete, restore, or act on responses. Review and audit records may include the actor or reviewer, action, prior and new status, reason, note, time, form version, response reference, and the success or failure of configured actions. Forms audit logs are designed to record safe event metadata rather than answer content, while separate response and review records contain the information needed for the workflow.

If configured, a response or selected non-sensitive fields may be posted to a Discord channel or thread, mentioned to a reviewer role, or sent to a responder by DM. Discord approval controls may update a response message, notify a person, or ask the selected bot to add or remove a server role after a permission-checked decision. Channel members, bot operators, and other people with Discord access to the destination may see those copies. A failed optional Discord action does not erase the underlying response, and delivery status or retry information may be retained.

Forms Studio automations can send Discord messages or DMs, change a response status or tag, notify collaborators, create a review task, change a Discord role where permitted, or send a webhook to a public HTTPS endpoint selected by an administrator. A webhook recipient is an independent third party chosen by that administrator. Information included in its configured payload leaves Shards' direct control and is subject to the recipient's security, retention, and privacy practices. Automation definitions, runs, errors, retry state, and results may be stored for operation and accountability.

Authorized administrators can export permitted responses in Excel, CSV, or JSON formats. Exports may include answers, identity, eligibility, scoring, and review information allowed by the field and export settings. Once downloaded, that copy is controlled by its recipient rather than Shards. Server administrators are responsible for limiting collaborator, reviewer, channel, webhook, and export access; giving an appropriate form-specific notice; asking only necessary questions; securing exports and endpoints; honoring applicable access, correction, export, or deletion requests; and deleting copies when no longer needed. Review decisions and administrator-configured actions are made by the server's administrators, not Shards.

6. Exovail, forums, discovery, and community features

  • Exovail communications: public, global, server, or squad chat and two-party private messages may store content, sender identity and profile snapshots, timestamps, preferences, read state, blocks or ignores, reports, and moderation state. Private messages are not end-to-end encrypted. Reported content and preserved evidence may be reviewed by authorized safety personnel.
  • Forums: Discord author identity, titles, post and reply bodies, tags, reactions, moderation state, and logs may be stored. Forum pages are public and may be indexed, quoted, archived, or cached by others. Removing a public post may hide it while retaining a limited internal moderation or audit copy.
  • Server Discovery: an administrator may submit an opt-in directory profile with server identity, images, description, invite, metrics, category, requester identity, reviewer decision and reason, notification preference, and moderation history. Invite codes are encrypted at rest.
  • Exovail multiplayer: Shards may store presence, squads and invitations, operations, loadout or profile snapshots, game events, achievements, ownership or reward acceptances, and safety or moderation events needed for persistent multiplayer play.
  • Uploads and external media: administrator-uploaded images or audio intended for public features may be served from publicly reachable asset locations. If an administrator embeds an external image, audio file, or other URL, a visitor's browser may contact that external host and disclose ordinary request information such as IP address and user agent.

7. How and why we use information

We use information to provide requested bot, dashboard, form, game, community, custom-bot, companion, and premium functionality; authenticate people and enforce permissions; synchronize selected bots; calculate game or activity state; deliver requested messages; prevent fraud, spam, abuse, and security incidents; investigate reports; preserve integrity and audit history; diagnose and improve reliability; provide support; and comply with legal and platform obligations.

Where applicable law requires a legal basis, processing may be necessary to perform a contract or provide a requested service; based on legitimate interests in operating, securing, troubleshooting, and improving Shards; required to meet legal obligations; or based on consent where a feature asks for it. You may withdraw consent for future consent-based processing, but that does not make earlier lawful processing invalid.

8. Cookies and local storage

The website uses cookies and comparable browser storage for login sessions, CSRF protection, selected server context, account and dashboard preferences, language and theme, navigation state, dismissed notices, media settings, warnings, and diagnostics. Essential storage is needed for login and security; preference storage remembers choices. Shards does not currently use this storage for cross-context behavioral advertising.

Clearing browser storage may sign you out, reset preferences, show notices again, or require you to reselect a server.

9. AI features

If a server enables sentience, genie, AI chat, or AI-assisted moderation, Shards may send the minimum relevant prompts, recent visible conversation context, identifiers, display names, channel labels, links, attachment metadata, configured rules, and server or game state to the configured provider, such as OpenAI or an administrator-configured Ollama endpoint. A self-hosted endpoint is controlled by the administrator or endpoint operator, not Shards.

Shards does not use Discord message content obtained through Discord's APIs to train machine-learning or AI models. Supported AI opt-out controls omit or hide a member from AI prompt context where technically available; they do not erase ordinary game, moderation, security, or server records.

10. Premium purchases

Discord and its payment providers handle supported Shards purchases, subscriptions, renewals, cancellations, refunds, disputes, and payment credentials. Shards receives limited entitlement and transaction metadata needed to grant, restore, synchronize, support, or revoke premium access. Shards does not directly receive full payment-card or bank-account credentials for Discord-handled purchases.

11. Sharing, processors, and public visibility

We do not sell personal information, license Discord API data, or share personal information for cross-context behavioral advertising. We disclose information only as needed for the purposes described here, including to:

  • Discord, because Shards uses Discord OAuth, APIs, bots, messages, entitlements, billing surfaces, and DMs;
  • authorized server owners, administrators, collaborators, reviewers, moderators, configured notification-channel audiences, and export recipients for the server features they control;
  • OpenAI or an administrator-selected AI endpoint for an enabled AI feature;
  • Top.gg and limited content or validation services when the corresponding integration is used;
  • hosting, database, storage, logging, delivery, and security providers that process data for Shards under appropriate instructions;
  • an administrator-selected webhook or integration endpoint when the administrator configures a Forms Studio automation to send information there;
  • other users or the public when a feature is designed to publish information, such as forums, server listings, public presets, profiles, leaderboards, trades, game results, public drops, giveaways, directory listings, or channel notifications; and
  • courts, regulators, law enforcement, Discord Trust & Safety, or another party when reasonably necessary to comply with law, protect people or rights, investigate abuse, secure the service, or complete a business reorganization subject to appropriate safeguards.

Third parties have their own policies. Discord server permissions determine who can see information sent to a Discord channel. Public content may be copied, cached, or redistributed by others after publication.

12. Retention and deletion

We keep information only while it is reasonably necessary for the stated feature, security, support, audit, dispute, or legal purpose. The period depends on the record and the choices made by a server administrator. Active configuration, economy, progression, forum, multiplayer, form, and premium records may remain while the associated service or server feature is active. Short-lived sessions, caches, rate limits, and game rounds expire sooner. Security, report, moderation, entitlement, and audit records may remain longer when necessary to protect users, prove actions, prevent repeat abuse, or meet legal obligations.

Unreported Exovail chat and private-message history is ordinarily bounded by service cleanup limits, currently up to approximately 30 days and 5,000 messages per conversation or scope. Reported messages or immutable evidence may be held longer for investigation and enforcement. Terminal Server Discovery request history is ordinarily eligible for cleanup after approximately 90 days. These periods may be shortened, extended where law or safety requires, or changed as the feature evolves.

Forms Studio retention can differ among drafts and active sessions, published versions, responses, uploaded files, review history, cooldown records, audit events, and automation runs. Where a form owner enables deletion after a response-retention period, scheduled maintenance uses the policy saved with the exact published form version to move each eligible response into deletion and then permanently purges its primary response, answer, and Shards-hosted upload records after a safety window. A response deleted manually remains restorable for a longer limited window before purge. Expired form sessions, unclaimed uploads, and files past an upload-specific retention date are also cleaned up after applicable safety delays. Cleanup runs in bounded background cycles, so it is not instantaneous. Limited audit, security, cooldown, scrubbed delivery, backup, abuse-prevention, or dispute records may remain where needed. Downloaded exports, webhook deliveries, Discord messages, public caches, and copies held by administrators or other recipients are outside Shards' direct control.

Removing the bot, leaving a server, disabling a feature, deleting custom-bot configuration, or canceling premium stops some future processing but does not automatically erase every record. Backups are isolated from ordinary use and age out according to backup operations unless a longer hold is required. When verified deletion is required, we delete or de-identify covered records unless retention is permitted or required for security, legal claims, fraud prevention, platform compliance, or another lawful reason.

13. Security

Shards uses safeguards appropriate to the type of data, including encryption at rest for Discord OAuth and custom-bot tokens, encrypted server invite codes, hashed companion bearer tokens, HMAC-derived form identity and rate-limit keys, signed or opaque workflow references, access and guild scoping, server-side authorization and validation, private form-upload storage and authorized download paths, CSRF protections, session controls, rate limits, audit logs, private/no-store response headers, and spreadsheet formula-injection protection.

No system is perfectly secure. A file's acceptance does not guarantee that it is harmless, and content copied to Discord, a webhook, or an export is no longer confined to Forms Studio. Administrators should collect the minimum information needed, grant the least access needed, secure exports and integration endpoints, keep Discord, companion, and custom-bot credentials secret, and rotate credentials that may have been exposed. If we confirm an incident requiring notice, we will notify affected people and authorities as required by law and Discord's developer rules.

14. Your choices and privacy rights

  • You can avoid optional features, leave a server, disable supported DMs or AI context, revoke a companion token, and manage Discord-handled subscriptions through Discord.
  • Server administrators can disable features, change permissions, remove public listings or custom-bot configuration, close or delete forms, and manage server-controlled records. Where enabled, a responder may use Forms Studio controls to export a response, delete it, or submit a deletion request. Otherwise, ask the relevant administrator to address a specific form response, upload, Discord or webhook copy, forum post, or export they control.
  • Depending on your location and the record, you may have rights to know or access personal information; correct inaccurate information; delete information; receive a portable copy; restrict or object to processing; withdraw consent; appeal a declined request; use an authorized agent; and receive equal service without unlawful discrimination for exercising a right.
  • Because Shards does not sell personal information or share it for cross-context behavioral advertising, there is no sale/share opt-out needed for those practices. If that changes, this policy and required controls will be updated before the practice begins.

Submit a request through the support server below and clearly identify it as a privacy request. Include the Discord account and server or feature involved, but never send a password, login token, payment credential, or other secret. We may verify identity and authority, narrow an overbroad request, or deny a request where permitted by law. Where applicable, you may appeal through the same contact and complain to your local data-protection or privacy authority.

15. Children's privacy

Shards is not directed to anyone under 13 or below the minimum age required to use Discord in their country. Do not use Shards if you are not permitted to use Discord. Server administrators must not use Forms Studio or another Shards feature to solicit information from children who cannot lawfully use Discord. If we learn that covered information was collected from such a child, we will take appropriate steps to delete or disable it as required by law.

16. International processing

Shards and its providers may process information in the United States and other countries where they operate. Those countries may have different privacy laws. Where applicable law requires a transfer mechanism or other safeguard, Shards will use an appropriate mechanism and provide related information on request.

17. Changes to this policy

We may update this policy as Shards, the law, or platform requirements change. We will post the revised policy and update the date above. When a change is material, we will provide additional notice through a reasonable service surface when required or practicable. A change applies prospectively from its stated effective date; we will request consent if law requires consent for a new use.

18. Discord and platform policies

Shards is built on Discord and is operated subject to Discord's Terms of Service, Privacy Policy, Community Guidelines, Developer Terms, and Developer Policy. Discord's policies govern Discord separately from this policy.

19. Contact, privacy requests, and reports

For a privacy request, security report, policy question, or report about misuse of Shards, contact the Shards service team through the official Shards support server. Label the request clearly so it can be routed to the appropriate operator. For a record controlled by a Discord server, you may also need to contact that server's owner or administrators. Discord billing and Discord-account requests must be directed to Discord through its own support channels.

Shards

OAuth2 login, encrypted tokens, and CSRF-protected admin forms.

Terms of Service Privacy Policy Support Server