Service and scope
This policy applies to the Nitwit Community Discord verification service hosted at store.nww.lol. It supplements the website's general Privacy Policy.
Discord data we process
- Discord user ID, username, display name, avatar, and verified email.
- OAuth scopes and encrypted access/refresh tokens granted through
identify,email, andguilds.join. - Verification status, Member-role delivery status, guild membership status, and verification timestamps.
- First/last IP address and Cloudflare country code used for security, abuse prevention, and audit records.
How we use Discord data
- Verify that a user controls a valid Discord account and verified email.
- Assign the Member role after successful verification.
- Show authorized administrators whether verified members remain in the community and identify members who joined without completing verification.
- At an administrator's manual request, restore a previously verified member to the same community after they leave, using the user's prior
guilds.joinconsent, then restore the Member role.
Guild Members intent
The Server Members Intent is used only when an authorized super administrator opens the verification dashboard. The service compares Discord user IDs in the current guild roster with verified records to calculate: verified members still present, verified members who left, and present members who have not verified. The on-demand unverified roster is not written to our database. We do not request Presence or Message Content intents.
Storage and security
Verified account records are stored off-platform in our access-controlled PostgreSQL database. OAuth tokens are encrypted at rest with AES-256-GCM using a server-only key. Bot and OAuth client secrets are stored outside the application repository. Tokens and ciphertext are never returned to the admin interface. We do not sell Discord data, use it for advertising, or read users' messages.
Retention, deletion, and user controls
We keep verified membership data while it is needed to provide verification, role restoration, security, and account support. Users may revoke the application in Discord's Authorized Apps settings and may request access, correction, or deletion using the contact below. Expired OAuth intents are removed after 24 hours, IP addresses in attempt logs are removed after 90 days, identifying names and emails in historical attempt logs are removed after 180 days, and IP addresses on inactive verification records are removed after 180 days. Other records are removed when no longer necessary, subject to limited security, fraud-prevention, backup-rotation, and legal obligations.
Sharing and Discord compliance
Data is available only to authorized Nitwit Community administrators and infrastructure providers needed to operate the service. We follow the Discord Terms of Service, Discord Developer Policy, and applicable privacy requirements.
Contact and data deletion requests
Open a support ticket or contact Nitwit Community staff in the official Discord server. Include your Discord user ID so we can locate the correct record.