Privacy Policy

Effective date: 23 June 2026 Last updated: 26 June 2026 Version 2.1
Short version: Wobby collects limited technical data when you complete a verification check on a Discord server. That data is used only to help server administrators protect their communities from bots and ban-evaders. It is never sold or shared with advertisers.
Table of Contents
  1. Who we are and how to contact us
  2. Who this policy applies to
  3. Legal basis for processing
  4. What data we collect
  5. How we use your data
  6. Third-party services
  7. Cross-server signals
  8. Data retention
  9. Data security
  10. Your rights
  11. Children
  12. Changes to this policy

1. Who we are and how to contact us

Wobby is a Discord security bot operated independently. For any privacy-related enquiries, erasure requests, or data access requests, contact us on Discord: deliv3r. We respond within 30 days.

For data erasure or access requests, message Wobby directly on Discord — the bot will guide you through the process. See Section 10 for your full rights.

2. Who this policy applies to

This policy applies to:

Server administrators are data controllers for the verification data collected in their server. Wobby acts as a data processor on their behalf for that data.

3. Legal basis for processing

We process personal data on the following bases:

EU/EEA and UK residents have the right to object to processing on the basis of legitimate interests. See Section 10.

4. What data we collect

When a member completes the verification flow, the following data is recorded:

Data point Purpose Stored as
Discord user ID and username Identify the account being verified Plaintext
IP address Detect VPNs, proxies, Tor, and datacenter connections Encrypted + one-way hash for alt detection
Browser and device signals Confirm the verification is completed by a real, non-automated browser Encrypted + one-way hash for alt detection
Submitted username Cross-referenced against known risk patterns as part of the security assessment Plaintext (encrypted at rest in full record)
Risk score and verdict Output of the automated security assessment (clean / mixed / high_risk) Plaintext
Approximate geolocation Country derived from IP address for staff context Encrypted
Network provider ASN / ISP name for VPN and hosting provider detection Encrypted

We do not collect passwords, payment card data, messages, voice or video data, or any content from your Discord account.

5. How we use your data

Data collected during verification is used exclusively for:

Your data is not used for advertising, profiling for commercial purposes, or any purpose unrelated to moderation of the Discord server you joined.

6. Third-party services

IP intelligence

Your IP address is sent to one or more of the following services to determine whether it is associated with a VPN, proxy, Tor network, or hosting provider. Only the IP address is transmitted — no other personal data is included in these requests:

Security challenge (CAPTCHA)

The verification page may display a security challenge to confirm it is being completed by a real person. The following providers may be used. Each may receive your IP address and interaction behaviour as part of the challenge:

Automated security analysis

As part of the security assessment, limited information — such as the submitted username and any publicly available profile text associated with it — may be processed by automated security analysis services. These services help Wobby identify patterns associated with ban evasion, coordinated abuse, and other risks.

This analysis runs entirely in the background and its outputs are used only to inform the risk score and the server administrator's moderation decisions. Individual analysis outputs are not displayed to members.

The following third-party providers may be involved in this analysis. Data sent to them is used solely for moderation risk assessment and is not used to train their models under their standard API terms:

7. Cross-server signals

If your IP address or browser environment data was previously recorded in connection with another Discord account verified through Wobby — on any server — the server you are joining may receive an automated alert. The specific source server is not disclosed to the alert recipient.

IP addresses and browser environment data used for this matching are stored only as one-way cryptographic hashes. The original values cannot be recovered from what is stored.

8. Data retention

Retention is activity-based, not time-based. Records are kept only for as long as they remain useful for the security purpose they were collected for. When data becomes inactive, it is deleted automatically by a daily background process — no manual action is needed.

CategoryDeleted when
Active membersRetained while the member has verified in any Wobby-enabled server within the last 90 days
Inactive members (left, removed, or simply stopped joining)Automatically deleted 90 days after the member's last verification across any server — no re-join means no reason to keep it
High-risk members (any flagged verdict on record)Automatically deleted 180 days after last verification — the longer window supports cross-server alt detection on potential re-joins
Erasure tombstonesNon-PII record kept for 30 days after a self-service erasure (fraud-prevention hold), then purged
Support ticket recordsDeleted 90 days after resolution or closure

You may request deletion of your data at any time — see Section 10. Erasure requests are processed immediately; the activity-based schedule above is the automatic fallback for users who never request it.

9. Data security

All data is stored in cloud infrastructure located within the United States. Access is restricted by server — administrators of one server cannot view verification records from another.

Sensitive fields — including IP addresses, browser and device signals, geolocation, and security analysis outputs — are encrypted at rest using AES-256-GCM. The same fields used for cross-server alt detection are stored only as HMAC-SHA256 hashes; the originals are not recoverable from stored data.

Data is transmitted over encrypted connections (TLS 1.2+) at every stage — between your browser and our servers, and between our servers and any third-party services.

Access to each server dashboard requires authentication via Discord OAuth or a per-server administrator password.

10. Your rights

Depending on your jurisdiction — including the EU/EEA under GDPR, the UK under UK GDPR, and California under CCPA — you may have the following rights:

Right Description How to exercise
Access (Art. 15) Request a copy of the personal data held about you Contact us on Discord: deliv3r
Erasure (Art. 17) Request permanent deletion of all your data Message Wobby on Discord for guided self-service, or contact us at deliv3r
Correction (Art. 16) Request correction of inaccurate data Contact us on Discord: deliv3r
Objection (Art. 21) Object to processing based on legitimate interests Contact us on Discord: deliv3r
Restriction (Art. 18) Request restriction of processing in certain circumstances Contact us on Discord: deliv3r
Portability (Art. 20) Receive your data in a structured, machine-readable format Contact us on Discord: deliv3r

We will respond to all requests within 30 days. For erasure, message Wobby directly on Discord — the bot will verify your identity and guide you through the process step by step. Note that erasure is subject to a 30-day retention hold after a new verification (legitimate interest, fraud prevention).

11. Children

Wobby is not directed at children under 13 (or under 16 in the EU/EEA). We do not knowingly collect data from minors. Discord itself requires users to be at least 13 years old. If you believe a minor's data has been collected, contact us for immediate deletion.

12. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision. Continued use of the verification service after an update constitutes acknowledgement of the revised policy. For material changes, we will make reasonable efforts to notify affected server administrators.