Privacy & Data Protection
Privacy Policy
Last updated: September 2026 / SpyCloud Data Protection & Privacy Principles
1. Information We Collect
SpyCloud processes strictly the minimum Discord data necessary to power leveling, invite telemetry, and dashboard management:
- Discord Account Identity: User ID, username, global display name, and avatar hash (for rank card rendering and dashboard auth).
- Progression & XP Metrics: Guild-specific XP totals, current level milestone, message telemetry count, and last daily claim timestamp.
- Invite Telemetry: Referral attribution counts, join timestamps, leave logs, vanity codes, and anti-fake filter scores.
- Guild Configurations: Announcement channel ID, invite log channel ID, milestone role IDs, and customized command permission rules.
2. Data We Never Collect
We take your privacy seriously. SpyCloud never collects, accesses, or stores the following data:
- User passwords, private email addresses, or phone numbers.
- Chat message text content, uploaded files, or private direct messages (DMs).
- Credit cards, bank account details, or payment credentials.
- Real-world personal identity or physical location coordinates.
3. How We Use Your Data
Collected data is utilized exclusively to provide the following bot operations:
- Calculating XP progression and maintaining live Discord /top leaderboard rankings.
- Hardware-rendering personalized /rank cards with current level and progression bar.
- Accurately attributing server joins and leaves to the correct inviter.
- Auto-granting Discord server roles when users hit configured level milestones.
- Verifying server administrator permissions and synchronizing web dashboard preferences.
4. Data Storage & Security
All guild settings and progression telemetry are stored in secured, encrypted MongoDB database clusters. All API endpoints are protected with rate limiters, CSRF state verification, and strict Discord OAuth2 authentication.
7. Data Deletion & User Rights
You maintain full rights and control over your stored data:
- Server-Wide Reset: Server administrators can wipe member progression anytime via /resetlevel or the dashboard.
- Bot Removal: Kicking SpyCloud from a server deactivates guild telemetry and cached configs.
- Personal Deletion Request: To request permanent deletion of all records tied to your Discord ID, contact us on Discord or via [email protected].
8. Contact & Privacy Requests
For privacy questions, data audits, or deletion requests, reach our team directly at: