Privacy
Go backLast updated 24 July 2026
This notice describes how Modfolio ("we", "the Service") processes personal data when you use the website, APIs, Discord bot, and related features.
Questions about privacy: Support. Related rules: Terms of Service.
1. What we process
Depending on how you use Modfolio, we may process:
- Account identity — Discord user id, username / global name, avatar URL, email (when Discord provides it), and Modfolio user/profile ids
- Profile content — handle, display name, bio, pronouns, locale/timezone, skills, availability, open-to-work preferences, avatar/banner media you upload
- Experience and trust data — claimed or verified moderation roles, tenure, community associations, references, endorsements, application answers, and verification status
- Community / team data — claimed servers, team membership, invites, role mappings, listing content, and Discord guild metadata needed to operate claims and the bot
- Support — tickets, messages, optional contact email (logged-out), and attachments you upload
- Billing — subscription/entitlement state and payment-provider references (Paddle processes card data; we do not store full payment card numbers)
- Technical and anti-abuse metadata — hashed IP addresses, coarse client signals (for example user-agent / Accept-Language heuristics), rate-limit counters, session-bound handles, and audit events
- Product analytics — event data in PostHog (EU) when you allow analytics cookies
2. Why we process it
- Provide accounts, profiles, communities, recruiting, and support
- Verify moderation experience and keep current-staff signals honest
- Prevent scraping, spam, impersonation, and other abuse
- Send transactional email (security, tickets, exports, billing)
- Operate paid features and fulfill purchases
- Understand product usage (analytics only with consent; see Cookies)
- Comply with law and enforce our Terms
3. Discord and other connections
Sign-in uses Discord OAuth. We store encrypted Discord tokens where needed to refresh guild membership and power features you use. On account erasure we attempt to revoke Discord tokens.
If you install the Modfolio bot on a Discord server, we process guild and member/role information required for claims, staff rosters, member counts, and related community features, under the authority of the server's administrators who install it.
Optional connections (for example Steam) store provider account ids and public profile fields you authorize so they can appear on your Modfolio profile.
4. Security and anti-abuse
To protect users and the Service we process short-lived access metadata: HMAC-hashed IP addresses (not raw IPs in long-term audit logs), request volume, and coarse client signals. Rate-limit counters are ephemeral (on the order of ~30 days). Related anti-scrape audit entries are retention-limited and anonymised on account erasure where applicable.
We may use challenges (Cloudflare Turnstile), view quotas, canary records, and automated content checks (including optional OpenAI moderation for some text) to reduce abuse. We do not sell this data.
7. Retention
We keep data only as long as needed for the purposes above. In practice:
- Account data — until you erase the account, plus limited records we must keep for safety or law (for example ban / abuse signals)
- Export packages — signed download about 72 hours, or sooner after download + a short grace period; request metadata may be kept longer for audit
- Anti-scrape rate / audit signals — short TTL (~30 days for many counters / related audits)
- Anonymised audit after erasure — retained for a limited period (product target: years-scale, then delete/aggregate)
- Email outbox — delivery logs needed to operate mail and webhooks; anonymised or detached on erasure where designed
8. Your rights
Depending on where you live, you may have rights to access, export, correct, delete, or object to certain processing. In Modfolio you can:
- Request export or erasure in Settings → Your data
- Dispute a CLAIMED experience that names you via Dispute a claim (Discord sign-in required)
- Manage email preferences in Settings → Email (transactional / legal messages may still send)
- Contact us via Support if something looks wrong
Community owners can run community-scoped data requests where the product exposes them; last-owner account erasure may require transferring ownership first.
9. Children
10. Contact and changes
Privacy questions: Support. We may update this notice as the product evolves; the "Last updated" date will change, and material changes may get additional notice when practical.