Privacy Policy

Last updated: 12 September 2026

This Privacy Policy explains how Vidar (“Vidar”, “we”, “us”) processes personal data when a server uses our verification and alt-detection service. Vidar is a moderation tool enabled by a server's administrators (the “Operator”). The Operator of a server is the data controller for that community's data; Vidar processes it on their behalf.

1. Data we process

  • Discord identifiers — your user ID and username, obtained through Discord OAuth and Discord's bot API when you join a participating server.
  • Account metadata — account age, whether you use a default avatar, public badges, and (only where a server requires it) whether your Discord email is verified.
  • Network signals — derived from the connection you use at the verification checkpoint: a reputation assessment (VPN/proxy/Tor/hosting), country, and network operator (ASN). Your IP address is converted to non-reversible salted hashes on receipt and the raw address is not stored.
  • Device signals — a privacy-respecting device fingerprint composed of coarse, hashed browser/device facets. Raw values are not stored.
  • Decision records — the resulting risk score, decision, and human-readable reasoning, retained for moderator audit.

Vidar does not read your messages, direct messages, or browsing history.

2. Why we process it

  • To verify that an account belongs to a real, distinct person before granting access.
  • To detect alternate accounts, ban evasion, and automated/raid activity.
  • To let moderators review and act on borderline cases.
  • To keep the service secure and prevent abuse.

Where the GDPR or similar laws apply, our lawful basis is the legitimate interests of the Operator and its community in keeping the server safe, and/or your consent given at the checkpoint. Operators are responsible for surfacing an appropriate lawful basis to their members.

3. Retention

  • Exact-IP hashes are purged on a short schedule (default 14 days).
  • Coarse network hashes and the global sighting index are pruned on a longer schedule (default 90 days).
  • Decision records are retained for audit until deleted by the Operator or on removal of the bot.

4. Sharing & subprocessors

We do not sell personal data. Data is processed by infrastructure providers strictly to run the service, which may include: Discord (identity and role management), a database host (e.g. Supabase), a web host (e.g. Vercel), and an IP intelligence provider used to assess the connection at the checkpoint. Each processes only what is necessary for its function.

5. Cross-server checks

If a server enables cross-server checks, Vidar may compare anonymized hashes against a network-wide index to identify accounts already flagged elsewhere. This comparison uses hashes only — no server can view another server's members, messages, or raw identifiers.

6. Security

We apply hashing and salting to sensitive values, restrict database access to trusted server components, enforce a strict Content Security Policy and transport security on the web application, and follow the principle of least privilege for Discord permissions.

7. Your rights

Depending on your jurisdiction you may have the right to access, correct, delete, or restrict processing of your personal data, and to object to processing. Because the Operator of your server is the controller, please direct requests to that server's moderators; Vidar will assist Operators in fulfilling valid requests.

8. Children

Vidar is not directed to children under the minimum age required to use Discord in their country. Operators must not use Vidar to process data of users below that age.

9. Changes

We may update this policy; material changes will be reflected by the “last updated” date above. Continued use after an update constitutes acceptance of the revised policy.

10. Contact

Questions about this policy can be directed to the Operator of your server, or to the Vidar maintainer at support@vidars.online. See also our Terms of Use and technical privacy documentation.