AltScan
Features How it works FAQ
Verify Now
← Back to AltScan

Privacy Policy

Effective: September 19, 2026 Version: 2.1 Applies to: altscan.lol and all associated services

1. Our Data Philosophy

AltScan is a verification service, not a data business. This policy explains exactly what we collect when you verify, why each element is necessary, how it's protected, how long it's retained, and every option available to you. Our operating principles:

  • Minimum collection — we collect only what verification, alt detection, and giveaway integrity require;
  • No selling, ever — we do not sell, rent, trade, or share personal data for commercial gain;
  • No third-party trackers — our pages load no analytics, advertising, or fingerprinting scripts;
  • Encryption by default — sensitive credentials are encrypted before storage;
  • Deletion on request — you can have your data removed promptly at any time by emailing [email protected], with no community membership required.

2. Data We Collect

2.0 How We Obtain Your Data

All account-level Discord data described in this policy (identity, email where authorized, server membership, tokens) is received exclusively through OAuth2 authorization scopes that you explicitly grant at verification time. Beyond these scopes, our Discord bots enable Discord's Message Content privileged gateway intent for one purpose: detecting text commands that begin with the bot's command prefix (e.g. "v!"). Here is exactly how that works and what it does and does not expose:

  • What data it gives access to: the text content of messages sent in servers where one of our bots is present;
  • The specific feature that requires it: prefix-based bot commands (e.g. "v!link", "a!status") — Discord's API only delivers message text to bots that declare this intent, and without it prefix commands cannot function;
  • Stored or in-memory only: processed in memory only. Each incoming message is checked against the command prefix; messages not starting with the prefix are discarded immediately and no part of any message's content is ever written to our database, logs, or any other storage;
  • Retention period: zero — nothing is stored;
  • Opt-out: message text is only ever received from servers our bots are in. Server administrators can remove the bot (or restrict the channels it can read) to stop this processing entirely, and individual users can message in channels the bot cannot view.

We do not enable Discord's Server Members or Presence privileged intents. Direct messages are never processed: our bots do not read or respond to DMs, and the command-prefix check described above applies only to messages in servers where an administrator has added the bot.

2.1 Account Identity Data

Provided by Discord's OAuth2 API when you authorize:

  • Discord user ID — the permanent numeric identifier for your account. This is the core of verification; without it we cannot distinguish unique members;
  • Username and display name — for profile display and administrator search;
  • Avatar hash — to render your profile image;
  • Locale — your Discord language/region preference, used for community geographic analytics.

2.2 Email Address (Optional)

If you complete a full-scope verification (as opposed to our basic scope), Discord may include your email address in the authorization response. Email is used for: duplicate-account detection across verifications, account records, and service communications where necessary. Our basic verification scope excludes email entirely — the choice is presented to you before authorizing.

2.3 Security and Anti-Abuse Data

Collected on every verification to maintain integrity of the system:

  • IP address — used to detect bulk verification from single sources (alt farms), enforce rate limits, and investigate abuse. Historical IPs associated with your verifications are retained;
  • Browser user-agent string — parsed for browser, operating system, and device type. Used to flag suspicious patterns (e.g., identical fingerprints across "different" accounts) and detect automated abuse;
  • Timestamps — every verification is time-stamped for audit trails and live counters;
  • HTTP metadata — language preferences and referring page, used for abuse correlation.

This data is used exclusively for security operations: alt detection, duplicate prevention, rate limiting, and incident investigation. It is not used to build advertising profiles, behavioral models, or for any commercial purpose.

2.4 Authorization Tokens

The OAuth2 access and refresh tokens issued during your authorization. Required to: maintain your verified session, refresh access without re-prompting you, and add you to servers where you opted into auto-join. Tokens are encrypted at rest using AES symmetric encryption, with keys stored separately from the encrypted data (see Section 5).

2.5 Server Membership Snapshot

The list of participating servers visible to your account at verification time. Used to: place you in the correct communities if auto-join is enabled, maintain accurate membership records, and provide administrators with guild-level analytics.

2.6 Extended Profile Data (where available)

Depending on your Discord privacy settings and the verification scope, Discord's API may return: banner hash, accent color, account flags, premium status indicator, and multi-factor authentication status. Where available, these enrich alt-detection models (e.g., freshly-created accounts with default avatars and no MFA are statistically more likely to be alts). This data is stored with your verification record.

2.7 Administrative Records

If you are a community administrator using AltScan's management tooling, we record: your admin status, the actions you perform (joins initiated, giveaways created, configuration changes), and the timestamps of those actions. This creates an audit trail for abuse investigation and accountability.

3. Data We Never Collect

  • Your Discord password — technically impossible. Authorization happens entirely on Discord's infrastructure. We never see, process, proxy, or store credentials;
  • Message content storage — no message text is ever stored (see Section 2.0 for how the Message Content intent is used transiently for command detection);
  • Voice data — no access, no collection;
  • Friends list or connections — not requested, not received;
  • Payment or financial data — the Service is free and processes no transactions;
  • Cross-site browsing data — no third-party trackers, advertising identifiers, or fingerprinting scripts run on our pages;
  • Data from accounts that have not verified — we only hold records for accounts that completed authorization.

4. How We Use Data

  • Verification — confirming you are a real Discord user and maintaining your verified status;
  • Alt detection — analyzing IP overlaps, device fingerprints, account age signals, and verification patterns to identify users operating multiple accounts to abuse giveaways. This is the Service's core security function;
  • Server placement — automatically adding you to participating servers when and only when you have opted in;
  • Giveaway integrity — counting entries, preventing duplicates, and confirming winner eligibility;
  • Abuse prevention — rate limiting, blocking bulk automated verification, and investigating incidents;
  • Aggregate analytics — community-level statistics (member counts, geographic distribution) that contain no individual identity;
  • Legal compliance — where applicable.

We do not use your data for: automated decision-making with legal effect, profiling for advertising, sale to data brokers, training machine learning models for external use, or any purpose not described in this policy.

5. Storage and Security

  • Encryption at rest — OAuth tokens are sealed with AES symmetric encryption before writing to storage. Encryption keys are held separately from the database;
  • Encryption in transit — all connections use TLS. Certificates are auto-renewed via Let's Encrypt;
  • Access control — production data is accessible only to a small, fixed set of service administrators (currently fewer than five named Discord accounts). Access to the administrative dashboard is gated by Discord-account allowlisting, and administrative actions (joins, giveaway changes, configuration edits) are recorded with the acting administrator's identity and a timestamp;
  • Infrastructure — data is hosted with reputable infrastructure providers under appropriate data processing agreements;
  • Minimization — where a verification scope excludes email or server data, that data is never requested or stored;
  • Incident response — if we discover a breach affecting your data, we will notify affected users by email (where we hold one) and through participating communities within 72 hours of confirmation, revoke exposed credentials, and take corrective action.

No system is perfectly secure. The measures above are the ones actually in place; we do not claim certifications or third-party audits we do not have.

6. Retention

  • Active verifications — retained while your verification is active and used for its stated purposes;
  • After revocation — authorization tokens are immediately invalidated and purged. A last-known profile snapshot (absent tokens) is retained for 12 months after revocation for audit integrity and alt-detection continuity, then deleted — this is necessary because deleted accounts frequently re-verify as new alts;
  • Security events — verification events with IP and device data are retained for 90 days from the event date for fraud prevention, then automatically deleted;;
  • Aggregate statistics — anonymous counts (total verifications, locale distributions) may be retained indefinitely as they contain no personal data;
  • Deletion requests — verified deletion requests are processed within 7 days of receipt, with the exception of data we must retain for legitimate security or legal purposes, which will be minimized and access-restricted. You will receive confirmation at the email address you contacted us from.

7. Third Parties

We do not sell, rent, trade, or share your personal data with advertisers, data brokers, or any party for commercial gain. A limited set of processors handle data solely to operate the Service:

  • Discord Inc. — operates the OAuth2 authorization API and the platform delivering bot functionality. Your authorization interaction is governed by Discord's own privacy policy;
  • Hosting provider — operates the servers running the Service;
  • Database provider — stores encrypted records;
  • DNS/CDN provider — routes traffic to the Service.

Giveaway partner servers receive only aggregate entry counts — never individual-level data. Where data protection law applies, transfers to processors are covered by appropriate safeguards.

8. Your Rights

  • Revoke access — disconnect AltScan instantly in Discord Settings → Authorized Apps. This halts all ongoing access and invalidates tokens;
  • Request deletion — email [email protected] from any email address and we will remove your records. You do not need to be a member of any participating community to make this request. We process verified requests within 7 days and confirm completion by reply. As a secondary convenience, you may also ask any staff member in a participating community;
  • Access and correct — where applicable law grants access or correction rights over your data, email [email protected] and we will facilitate reasonable requests;
  • Object to processing — if you believe our processing of your data is unlawful, email [email protected] and we will review;
  • Complain — you may lodge a complaint with your local data protection authority.

9. Children

The Service is not directed to children under 13 (or the higher minimum digital-consent age in your jurisdiction). We do not knowingly collect data from children below these thresholds. If you believe a child has provided data, email [email protected] and we will delete it promptly.

10. International Transfers

The Service operates globally. Your data may be processed in jurisdictions other than your own, including the United States and European Union. Where required, transfers are safeguarded through standard contractual mechanisms or equivalent protections.

11. Changes

We may update this policy as the Service evolves. Material changes will be reflected in the "Effective date" above and, where practicable, announced through participating communities. Continued use after changes take effect constitutes acceptance, but we encourage periodic review. The version history of this policy is retained internally.

12. Contact

Privacy questions, data requests, or concerns may be directed to [email protected] — this is the primary contact channel and works whether or not you are in any participating community. You may also reach AltScan staff in a participating community as a secondary route. We treat privacy inquiries seriously and respond within 7 days.

AltScan

Secure Discord account verification for communities. One authorization, instant access, live giveaways.

Product

FeaturesHow it worksFAQVerify

Resources

Live stats

Legal

Terms of ServicePrivacy Policy
© 2026 AltScan. All rights reserved.
Terms · Privacy