PRIVACY NOTICE · EFFECTIVE AUGUST 8, 2026

Privacy boundaries should be as clear as audit boundaries.

This notice describes the current DisplayState for Discord beta. It explains the data required to authenticate users, connect Discord, create reports and plans, and run scheduled configuration audits.

Audit excludes messagesPrivate reportsNo data sale

PLAIN-LANGUAGE SUMMARY

Oracle processes configuration—not conversations

ACCOUNT

Identity and session data

The shared Identity service supplies the authenticated user and tenant context needed to operate a standalone Oracle account session.

DISCORD

Linked account and configuration

Oracle processes Discord OAuth identifiers and tokens, manageable guild metadata, supported server configuration, and sanitized integration or webhook inventory.

PRODUCT

Plans, reports, and monitoring

Oracle stores interviews, operations, checkpoints, snapshots, audit reports, report history, schedules, run status, and security-relevant product events.

Data Oracle collects

Account and authentication

Identity user identifiers, tenant identifiers, session identifiers, and the account attributes provided to Oracle by the configured Identity service. Authentication cookies are used to maintain the signed-in session.

Discord connection data

Discord account identifiers, OAuth authorization state, manageable guild lists, bot installation state, and encrypted Discord OAuth tokens. The shared bot token is a deployment secret, not user data.

Guild configuration evidence

Supported guild settings, roles and permission values, channel and overwrite configuration, native AutoMod rules, credential-free webhook and integration inventory, welcome or onboarding configuration, capacity metrics, evidence hashes, and availability limitations.

Oracle workflow data

Setup interview choices, generated plans, selected findings and operations, execution checkpoints, pre-change snapshots, normalized audit reports, consultant summaries, monitoring cadence, scheduled-run history, failure codes, and timestamps.

Data Oracle intentionally does not collect for the audit

The current configuration audit does not read message content, inventory guild members, or assess member activity. Discord may return webhook credentials to the server-side inventory request, but Oracle strips them at that boundary and does not retain, persist, or expose them. It does not infer spam, toxicity, raids, scams, engagement, or moderator performance from missing behavioral data.

New-server setup has one narrow message-access exception. During starter-message execution—including the first attempt and any retry or recovery—Oracle may request up to 50 recent messages from the approved destination channel and inspect their content only to locate the exact marker message authored by the Oracle bot. The matched message ID is kept as an execution receipt; unrelated message content is not persisted in Oracle’s plan or audit records.

Why the data is used

  • Authenticate the user and maintain the product session.
  • Connect the user’s Discord account and identify servers they may manage.
  • Inspect supported configuration and generate private findings, coverage, and recommendations.
  • Create, approve, execute, retry, and verify supported plans.
  • Run enabled daily or weekly configuration audits and preserve report history.
  • Protect account boundaries, diagnose failures, and operate the service.

Storage and service providers

The standalone beta uses a shared Identity service for authentication, Discord’s APIs for account and guild access, Railway for application and worker hosting, and Railway PostgreSQL for Oracle records. These providers process data needed to deliver their part of the service.

Retention and deletion

Oracle currently retains linked-account records, plans, snapshots, reports, monitoring history, and related product records until the operator deletes them or a future retention policy is implemented. Disabling monitoring does not delete previous reports. This is a beta limitation, not a promise of indefinite retention.

Self-service export and account-data deletion are not yet implemented. A normalized audit JSON export is available from a loaded private report, but it is not a complete account export.

Sharing and sale

Oracle uses service providers to operate the product and may disclose data when required to comply with law, protect users, or secure the service. Oracle does not sell personal information and does not publish private audit reports. If an owner exports and shares a report, that recipient receives the included information outside Oracle’s control.

Security

Discord OAuth tokens are encrypted before database storage. Product sessions, server authority, state drift, selected operations, and post-apply results are checked at different stages. No internet service is risk-free; see the security page for current safeguards and limitations.

Your choices and requests

You can disconnect or stop using Oracle and disable future monitoring in the product. These actions do not currently delete saved Oracle records. Depending on applicable law, you may have rights to request access, correction, deletion, restriction, or a copy of personal data.

Deployment notice: a privacy contact has not been configured. The operator must set SITE_SUPPORT_EMAIL and establish a verified request process before broad promotion.

Children and changes

Oracle is intended for people authorized to administer Discord servers and is not directed to children. This notice may change as deletion, billing, notifications, analytics, or additional processors are introduced. Material changes should be reflected by a new effective date.