← Back to home
Legal

Privacy Policy

Last updated: July 15, 2026

Your privacy is important to us. It is InviteForge's policy to respect your privacy and comply with any applicable law and regulation regarding any personal information we may collect about you, including through our bot InviteForge operating on discord.com and our website invite-forge.com.


Information We Collect

We collect the minimum amount of information necessary to operate the service. This includes:

  • Discord Guild ID — to identify and configure your server
  • Discord User ID — to attribute invites and manage leaderboard entries
  • Dashboard Email address — collected via Discord OAuth when you sign in to the dashboard (email scope); used for account-related and optional marketing communications
  • Invite data Invite codes, usage counts, and join/leave events
  • Message count Per-user message count per server — only the count is stored, never the content of messages
  • Billing Stripe customer and subscription IDs for premium plan management (no card data is stored by us)
  • Config Server settings such as channel IDs, message templates, and reward configurations
  • Verification When enabled by a server admin: verification session tokens, verification status, and optional hashed device fingerprint (only if the member consents on the verify page)

We do not collect message content, voice data, or passwords. Personally identifiable information is limited to what Discord exposes through its API or OAuth, plus optional verification data you explicitly consent to (fingerprint).


Dashboard Login & Discord OAuth

InviteForge uses Discord OAuth2 for two distinct purposes. Each flow requests only the scopes it needs:

  • Dashboard login — scopes: identify email guilds guilds.join. Used to authenticate server administrators, display the guild picker for servers they manage, sync their email address, and (once per account, on first dashboard login) add them to the official InviteForge support Discord server via Discord's guilds.join API.
  • Member verification — scope: identify only. Used solely to confirm that the person completing verification is the same Discord user who joined the server. No email, guild list, or guilds.join is requested during verification.

The guilds scope lets us show which Discord servers you can configure in the dashboard. The guilds.join scope is used only to add you to our official support server on your first dashboard login so we can share product updates and provide help. You are not added again on later logins, and leaving that server does not affect dashboard access.


Email Addresses & Marketing Communications

When you sign in to the InviteForge dashboard, Discord may share the email address linked to your Discord account (via the email OAuth scope). We store this email alongside your Discord user ID to manage your dashboard account and, if you are opted in, send product updates, feature announcements, and other marketing emails about InviteForge.

  • Opt-in — new dashboard users are enrolled in marketing emails by default on first login
  • Unsubscribe — to opt out of marketing emails, sign in to the dashboard and visit invite-forge.com/dashboard/email. Toggle marketing off to stop future promotional emails
  • After opt-out — your email remains stored for account purposes unless you request deletion
  • Delivery — marketing emails are sent through Brevo (see Third-Party Services). We do not sell your email address
  • Verification — members completing server verification are never asked for their email address

Member Verification

Servers may enable InviteForge's optional verification gate. When a member opens their personal link at invite-forge.com/verify/[token], they are asked to sign in with Discord via OAuth2 using the identify scope only. This confirms their Discord user ID matches the join event — it is not a bot invite, does not request email or guilds.join, and does not install InviteForge on their account.

  • Stored data — Discord user ID, verification status, expiry, and failure reason per session; linked invite event when counting is enabled
  • Fingerprint (PRO, optional) — if enabled by the server and accepted by the member, a browser fingerprint payload is hashed with a server-specific salt. We store only the hash to detect duplicate devices on the same guild — never raw fingerprint data
  • Captcha (PRO, optional) — if enabled, members may be asked to complete a captcha challenge before verification completes
  • Retention — verification identity hashes are purged after 90 days by default

Server administrators control whether verification is enabled and which roles are assigned. InviteForge processes verification on their behalf according to their configuration.


Legitimate Reasons for Processing Your Information

We only collect and use your personal information when we have a legitimate reason for doing so. Data is collected solely to provide, maintain, and improve the InviteForge service — including invite tracking, leaderboard ranking, reward automation, and premium subscription management.


How We Use Your Information

  • To track and attribute Discord server invites in real time
  • To generate leaderboards, analytics, and statistics for server administrators
  • To trigger auto-role rewards when invite milestones are reached
  • To send join/leave messages and join DM messages based on your server's configuration
  • To manage premium subscriptions via Stripe
  • To run optional member verification and role assignment when enabled by a server administrator
  • To send optional marketing emails to dashboard users who remain opted in
  • To display your server's data on the InviteForge dashboard

Data Retention

We retain your data for as long as your server has InviteForge installed or as long as necessary to provide the service. When you remove the bot from your server or request deletion, your data will be deleted or anonymised within a reasonable period.

Dashboard account data (Discord user ID, email, marketing preference) is retained while you use the dashboard or until you request deletion. Billing records may be retained longer where required by applicable accounting or legal obligations.


Third-Party Services

We use the following third-party services to operate InviteForge:

  • Discord — the underlying platform. Subject to Discord's own Privacy Policy.
  • Stripe — payment processing for premium subscriptions. Stripe does not share card details with us.
  • Brevo — email delivery and contact list management for opted-in dashboard users. Subject to Brevo's Privacy Policy.

We do not sell, rent, or trade your personal information to any third party.


Discord Gateway Intents

The InviteForge Discord bot requests the following privileged Gateway Intents. Each is used for a specific, limited purpose directly related to the bot's invite-tracking and server-management features. We do not use these intents for surveillance, advertising, or any purpose unrelated to the service described on this page and in our documentation.

  • GUILD_MEMBERS Used to detect when members join or leave a server, attribute invites to the correct inviter, update leaderboard counts, assign verification roles, deliver reward roles, and send join/leave messages configured by the server administrator. Without this intent, invite tracking and verification cannot function. This is a privileged intent.
  • GUILD_MESSAGES Used to count messages per user per server (message events only — author and channel IDs). This count enforces the optional minimum message requirement for giveaway eligibility. Message text, embeds, and attachments are never read, stored, or logged. This is not a privileged intent; InviteForge does not request Message Content.

Security

We protect your information within commercially acceptable means to prevent unauthorised access, disclosure, copying, use, or modification. No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.


Your Rights

You have the right to:

  • Request access to the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data (right to erasure)
  • Object to or restrict processing of your data
  • Unsubscribe from marketing emails at any time by signing in and visiting invite-forge.com/dashboard/email
  • Lodge a complaint with a data protection supervisory authority

To exercise any of these rights, contact us at the address below.


Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to our practices or for legal and regulatory reasons. Updates will be posted on this page with a revised "Last updated" date. Continued use of the service after changes are posted constitutes your acceptance of the updated policy.


Contact

For any questions or requests regarding this Privacy Policy, please contact us at our Discord server.

HomeTerms of ServiceDocumentation