Privacy Policy
1. Who we are and how to contact us
Wobby is a Discord security bot operated independently. For any privacy-related enquiries, erasure requests, or data access requests, contact us on Discord: deliv3r. We respond within 30 days.
For data erasure or access requests, message Wobby directly on Discord — the bot will guide you through the process. See Section 10 for your full rights.
2. Who this policy applies to
This policy applies to:
- Members — Discord users who complete a Wobby verification when joining a server, and Discord users who send messages in a server where Wobby is installed. The second group includes people who have never verified: message activity is counted for everyone who speaks (see Section 4).
- Server administrators — Discord users who add Wobby to their server and configure it via the dashboard
Server administrators are data controllers for the verification data collected in their server. Wobby acts as a data processor on their behalf for that data.
3. Legal basis for processing
We process personal data on the following bases:
- Legitimate interests (Art. 6(1)(f) GDPR) — Discord server communities have a legitimate interest in protecting themselves from ban evasion, coordinated abuse, and bot accounts. The security screening Wobby performs serves that interest directly.
- Contractual necessity (Art. 6(1)(b) GDPR) — for data processed as part of the server administrator's agreement to the Terms of Service.
EU/EEA and UK residents have the right to object to processing on the basis of legitimate interests. See Section 10.
4. What data we collect
When a member completes the verification flow, the following data is recorded:
| Data point | Purpose | Stored as |
|---|---|---|
| Discord user ID and username | Identify the account being verified | Plaintext |
| IP address | Detect VPNs, proxies, Tor, and datacenter connections | Encrypted + one-way hash for alt detection |
| Browser and device signals | Confirm the verification is completed by a real, non-automated browser | Encrypted + one-way hash for alt detection |
| Submitted username | Cross-referenced against known risk patterns as part of the security assessment | Plaintext (encrypted at rest in full record) |
| Risk score and verdict | Output of the automated security assessment (clean / mixed / high_risk) | Plaintext |
| Approximate geolocation | Country derived from IP address for staff context | Encrypted |
| Network provider | ASN / ISP name for VPN and hosting provider detection | Encrypted |
Message activity
Separately from verification, Wobby keeps a running count of how many messages each account has sent in a server where Wobby is installed. This is recorded for every member who speaks, whether or not they have ever completed a verification.
| Data point | Purpose | Stored as |
|---|---|---|
| Message count (per member, per server) | Let a server's administrators distinguish participating members from accounts parked in the server | Plaintext number |
| First and most recent message time | Show whether an account is still active without recording every message | Plaintext timestamp |
| Hourly message totals (per server, not per member) | Activity graph and detection of unusual spikes such as raids | Plaintext aggregate |
What is not recorded: the text of any message, the channel it was sent in, who it was addressed to, attachments, embeds, reactions, edits or deletions. The stored data can show that an account sent 400 messages and when it last spoke. It cannot show what was said, or which parts of a server somebody spends time in.
We do not collect passwords, payment card data, message content, voice or video data, or any file you upload. Wobby does not request Discord's Message Content privileged intent, which means Discord does not transmit the text of your messages to Wobby at all. That restriction is enforced by Discord rather than by our own restraint, and anyone can confirm it from Wobby's published application settings without taking our word for it.
5. How we use your data
Data collected during verification is used exclusively for:
- Generating a risk assessment and verdict for the Discord server you are joining
- Allowing the server's administrators to review your verification in the Wobby dashboard
- Detecting whether the same person has previously verified under a different Discord account (alt detection) — see Section 7
- Automated security analysis to improve the accuracy of the risk assessment (see Section 6)
- Showing a server's administrators which accounts are actively participating, and flagging unusual spikes in activity that may indicate a raid
Your data is not used for advertising, profiling for commercial purposes, or any purpose unrelated to moderation of the Discord server you joined.
6. Third-party services
IP intelligence
Your IP address is sent to one or more of the following services to determine whether it is associated with a VPN, proxy, Tor network, or hosting provider. Only the IP address is transmitted — no other personal data is included in these requests:
Security challenge (CAPTCHA)
The verification page may display a security challenge to confirm it is being completed by a real person. The following providers may be used. Each may receive your IP address and interaction behaviour as part of the challenge:
- Intuition Machines, Inc. (hCaptcha) (United States)
- Cloudflare, Inc. (Turnstile) (United States)
Automated security analysis
As part of the security assessment, limited information — such as the submitted username and any publicly available profile text associated with it — may be processed by automated security analysis services. These services help Wobby identify patterns associated with ban evasion, coordinated abuse, and other risks.
This analysis runs entirely in the background and its outputs are used only to inform the risk score and the server administrator's moderation decisions. Individual analysis outputs are not displayed to members.
The following third-party providers may be involved in this analysis. Data sent to them is used solely for moderation risk assessment and is not used to train their models under their standard API terms:
- Google LLC (United States)
- Groq, Inc. (United States)
7. Cross-server signals
If your IP address or browser environment data was previously recorded in connection with another Discord account verified through Wobby — on any server — the server you are joining may receive an automated alert. The specific source server is not disclosed to the alert recipient.
IP addresses and browser environment data used for this matching are stored only as one-way cryptographic hashes. The original values cannot be recovered from what is stored.
8. Data retention
Retention is activity-based, not time-based. Records are kept only for as long as they remain useful for the security purpose they were collected for. When data becomes inactive, it is deleted automatically by a daily background process — no manual action is needed.
| Category | Deleted when |
|---|---|
| Active members | Retained while the member has verified in any Wobby-enabled server within the last 90 days |
| Inactive members (left, removed, or simply stopped joining) | Automatically deleted 90 days after the member's last verification across any server — no re-join means no reason to keep it |
| High-risk members (any flagged verdict on record) | Automatically deleted 180 days after last verification — the longer window supports cross-server alt detection on potential re-joins |
| Erasure tombstones | Non-PII record kept for 30 days after a self-service erasure (fraud-prevention hold), then purged |
| Support ticket records | Deleted 90 days after resolution or closure |
| Message counts (per member) | Deleted 180 days after that account's most recent message — an account that has stopped speaking is no longer activity worth recording |
| Hourly activity totals (per server) | Deleted after 90 days |
You may request deletion of your data at any time — see Section 10. Erasure requests are processed immediately; the activity-based schedule above is the automatic fallback for users who never request it.
9. Data security
All data is stored in cloud infrastructure located within the United States. Access is restricted by server — administrators of one server cannot view verification records from another.
Sensitive fields — including IP addresses, browser and device signals, geolocation, and security analysis outputs — are encrypted at rest using current industry-standard authenticated encryption. The fields used for cross-server alt detection are stored only as one-way hashes; the original values are not recoverable from stored data.
All data is transmitted over encrypted connections at every stage — between your browser and our servers, and between our servers and any third party.
Access to each server dashboard requires authentication via Discord OAuth or a per-server administrator password.
10. Your rights
Depending on your jurisdiction — including the EU/EEA under GDPR, the UK under UK GDPR, and California under CCPA — you may have the following rights:
| Right | Description | How to exercise |
|---|---|---|
| Access (Art. 15) | Request a copy of the personal data held about you | Contact us on Discord: deliv3r |
| Erasure (Art. 17) | Request permanent deletion of all your data | Message Wobby on Discord for guided self-service, or contact us at deliv3r |
| Correction (Art. 16) | Request correction of inaccurate data | Contact us on Discord: deliv3r |
| Objection (Art. 21) | Object to processing based on legitimate interests | Contact us on Discord: deliv3r |
| Restriction (Art. 18) | Request restriction of processing in certain circumstances | Contact us on Discord: deliv3r |
| Portability (Art. 20) | Receive your data in a structured, machine-readable format | Contact us on Discord: deliv3r |
We will respond to all requests within 30 days. For erasure, message Wobby directly on Discord — the bot will verify your identity and guide you through the process step by step. Note that erasure is subject to a 30-day retention hold after a new verification (legitimate interest, fraud prevention).
11. Minimum age policy
Wobby is not available to anyone under 16 years of age. This is our own requirement and it is deliberately higher than Discord's.
Discord permits accounts from age 13, or older where local law requires. Meeting Discord's minimum does not make a person eligible to use Wobby: being in a Discord server and completing a Wobby verification are separate things, and the second one has its own age floor. We set ours at 16 because verification involves device and network signals that we would rather not process for children at all.
We do not knowingly collect or process data from anyone under 16. Where we become aware that a verification was completed by someone below that age, the associated records are deleted and the account may be refused further verification.
If you are a parent or guardian, or you believe someone under 16 has completed a Wobby verification, contact us on Discord (deliv3r) and the data will be deleted. No proof of age is required to make that request.
12. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision. Continued use of the verification service after an update constitutes acknowledgement of the revised policy. For material changes, we will make reasonable efforts to notify affected server administrators.