Privacy & Data Protection

Privacy Policy

Last updated: September 2026 / SpyCloud Data Protection & Privacy Principles

1. Information We Collect

SpyCloud processes strictly the minimum Discord data necessary to power leveling, invite telemetry, and dashboard management:

  • Discord Account Identity: User ID, username, global display name, and avatar hash (for rank card rendering and dashboard auth).
  • Progression & XP Metrics: Guild-specific XP totals, current level milestone, message telemetry count, and last daily claim timestamp.
  • Invite Telemetry: Referral attribution counts, join timestamps, leave logs, vanity codes, and anti-fake filter scores.
  • Guild Configurations: Announcement channel ID, invite log channel ID, milestone role IDs, and customized command permission rules.

2. Data We Never Collect

We take your privacy seriously. SpyCloud never collects, accesses, or stores the following data:

  • User passwords, private email addresses, or phone numbers.
  • Chat message text content, uploaded files, or private direct messages (DMs).
  • Credit cards, bank account details, or payment credentials.
  • Real-world personal identity or physical location coordinates.

3. How We Use Your Data

Collected data is utilized exclusively to provide the following bot operations:

  • Calculating XP progression and maintaining live Discord /top leaderboard rankings.
  • Hardware-rendering personalized /rank cards with current level and progression bar.
  • Accurately attributing server joins and leaves to the correct inviter.
  • Auto-granting Discord server roles when users hit configured level milestones.
  • Verifying server administrator permissions and synchronizing web dashboard preferences.

4. Data Storage & Security

All guild settings and progression telemetry are stored in secured, encrypted MongoDB database clusters. All API endpoints are protected with rate limiters, CSRF state verification, and strict Discord OAuth2 authentication.

5. Third-Party Sharing

We do not sell, rent, monetize, or trade any user or guild data to advertising networks, data brokers, or third parties. Data is processed strictly on our hosting infrastructure solely to execute bot functionality.

6. Cookies & Local Storage

Our web application utilizes limited cookies and local storage keys solely for core functionality:

  • spycloud_session: Encrypted HTTP-only Discord OAuth2 session cookie.
  • spycloud-theme: Your preferred Light or Dark interface theme.
  • spycloud_lang: Your preferred interface language (TR / EN).

7. Data Deletion & User Rights

You maintain full rights and control over your stored data:

  • Server-Wide Reset: Server administrators can wipe member progression anytime via /resetlevel or the dashboard.
  • Bot Removal: Kicking SpyCloud from a server deactivates guild telemetry and cached configs.
  • Personal Deletion Request: To request permanent deletion of all records tied to your Discord ID, contact us on Discord or via [email protected].

8. Contact & Privacy Requests

For privacy questions, data audits, or deletion requests, reach our team directly at: