Who this policy covers
This Privacy Policy applies when you interact with the LevelPay Discord application, participate in a LevelPay event or quest, use a LevelPay command, visit the LevelPay public website, or sign in to the connected administrator portal. “LevelPay,” “we,” and “us” refer to the operator of the LevelPay application.
Data we collect
Depending on the features you use, LevelPay may process:
- Discord user, server, channel, role, event, and message identifiers.
- Public Discord profile information made available to the bot, such as username and avatar.
- Server membership status, server join time, and participant-role eligibility.
- Quest, event, referral, streak, leaderboard, point, reward, entitlement, and claim records.
- Aggregate activity signals such as message counts, active-user counts, voice time, reactions, and polls.
- Proofs or other information you intentionally submit through commands, buttons, or modals.
- Administrative, moderation, fraud-prevention, transaction, payout, and audit records needed to operate and protect the service.
- Basic website request information processed by our hosting provider, such as IP address, device information, and request logs.
- When the connected portal is enabled: your basic Discord identity, avatar, and the server list and permission bitfields returned through the
identifyandguildsOAuth scopes. - Short-lived portal security records, including hashed OAuth state, opaque session identifiers, anti-replay nonces, and rate-limit counters.
- For a Community Spotlight application: your Discord identifier, server identifier and name, invitation, theme description, language, consent time and review status. The application is private to its contact and authorised LevelPay management. Approved live programmes and previously featured servers appear publicly on the website; pending applications and future selections do not.
- For website purchases: Stripe Customer, Checkout, subscription, invoice, payment, refund, and dispute references linked to your Discord user identifier, plus the billing status needed to grant, suspend, or revoke a plan or item.
LevelPay is seeking Discord Message Content access for its conversation quest. This access is not yet enabled in production. LevelPay does not request Presence Intent.
Message text is used by features that need to inspect it, including conversation validation and existing prefix commands. The conversation tracker checks the configured server channel, excludes bots, webhooks and system messages, and checks the account-deletion opt-out before reading text. It does not run in Event mode. Active members are not required to repeat onboarding to remain eligible.
The tracker normalizes text to reject commands, repeated text, very short messages, and simple low-context or spam patterns. Message counts alone cannot perform these checks. After the conversation reward has been credited, it stops accepting further conversation events for that member in the same daily period.
For accepted messages, the tracker stores Discord user, server, channel and message identifiers, the daily period, processing and expiration times, and a SHA-256 fingerprint of normalized text. These fingerprints are linked data, not anonymous data. The tracker does not save the original or normalized text, attachments or embeds in its activity table. Information deliberately submitted as quest proof is handled separately.
Discord may deliver messages from other channels the bot can access. The bot client keeps up to 200 message objects per channel in memory, including available message text, without a configured time-based expiration. Event handlers and explicit message requests can also hold message objects. This cache is separate from the conversation activity table. There is no promise of immediate physical erasure from memory.
How we use data
We use data only as needed to:
- Provide commands, quests, events, rewards, reminders, profiles, and leaderboards.
- Verify current server or support-community membership and retention requirements.
- Grant participant roles and cancel provisional rewards when eligibility ends.
- Process claims, entitlements, transactions, and payment-related workflows.
- Prevent abuse, duplicate participation, fraud, and unauthorized administrative actions.
- Maintain security, diagnose failures, respond to support requests, and comply with legal obligations.
- Improve LevelPay using aggregated or de-identified operational information.
- Confirm on every requested server that the signed-in user is the owner or currently has Administrator or Manage Server permission before returning a safe server-status view.
- Review voluntary Spotlight applications, verify server-management permission and invitations, maintain the candidate pool, and contact the designated responsible person for approval of each proposed programme.
We do not sell Discord API data. We do not use it for targeted advertising, data-broker services, or to train machine-learning models.
Discord Server Members Intent
LevelPay uses Discord's Server Members privileged intent for server-only leaderboards, membership and joined-time checks, participant-role eligibility, and join or leave retention events. Member information is fetched only when a LevelPay feature requires it. We do not store complete server member lists or presence data.
Data retention
Conversation activity records are assigned an expiration time 14 days after processing. The running bot checks for expired records about once per minute in both Normal and Event modes and removes them from the active database. Downtime or cleanup failures can delay removal. Backups are separate copies, so this is not a guarantee that every copy disappears exactly after 14 days.
When LevelPay receives a single or bulk Discord message deletion before the conversation reward has been credited, it removes the corresponding activity record. Uncredited progress can therefore decrease. Once credited, the reward and completion remain unchanged, and the same quest period cannot be credited again. Supporting activity records can remain until their scheduled expiration or account deletion. Deletion events missed while the bot is offline do not trigger this immediate cleanup; the expiration process still applies.
Normal quest completions, reward ledgers and audit records have no automatic expiration in the current implementation. They support accounting, reward verification and prevention of duplicate credits. Account deletion replaces the member identifier in certain other records, including transaction history, with a stable pseudonym. Normal quest completions, reward ledgers and Normal audit records keep their member identifiers under the current deletion implementation. This is not full anonymization.
Database backups may contain earlier copies and are not modified by account deletion. Managed automatic backups use a rolling 14-day retention window for operational recovery. Older managed copies are removed only after a new backup is successfully created and verified, with at least two recent valid copies retained. Failed checks or uncertainty stop deletion. Manual, historical, held or otherwise unverified copies remain for operator review and can outlast this window. This is not a guarantee that every copy of deleted account data disappears after 14 days.
Short-lived activity aggregates are routinely cleaned up after they are no longer needed. Account, quest, event, reward, entitlement, transaction, fraud-prevention, and audit records may be kept for more than 30 days while needed to provide the service, resolve disputes, prevent abuse, maintain accurate balances, or meet legal obligations.
Portal OAuth transactions expire after at most 10 minutes and can be used only once. Portal sessions expire after at most 8 hours. Logout revokes the local session immediately and asks Discord to revoke the associated OAuth grant. Expired session, nonce, and rate-limit records are routinely deleted.
We delete or anonymize data when it is no longer necessary for these purposes, when Discord requires deletion, when the service stops operating, or when a valid deletion request applies.
Your choices and deletion
You can run /deleteaccount in Discord to permanently delete your LevelPay account. You may also request access, correction, or deletion by opening a ticket in the LevelPay support server.
Deletion removes account balances, presentation preferences, reminders, saved payment methods and onboarding profiles. Some server-level settings and non-conversation activity records are separate and may remain as described below. It also removes temporary Normal conversation events, voice sessions, voice progress and sandbox activity for the account. Quest proof submissions use the existing redaction process; this does not erase every retained review record.
Normal quest completions and reward ledgers retain their member identifiers, reward, period, timestamps, source links and transaction references. Their existing reward keys and Normal audit metadata are not changed by account deletion. Completion history continues to prevent duplicate credits for the same quest period after account recreation.
Account deletion creates a persistent conversation opt-out. The tracker checks this choice before reading message text. Speaking in a configured channel, or having an account recreated by another feature, does not resume conversation tracking. The opt-out is removed only when you explicitly complete the existing Normal /start flow and its final confirmation. Opening the flow, cancelling it, or completing an Event profile does not remove the opt-out.
To remember this choice, LevelPay stores one 64-character SHA-256 key derived from your Discord identifier and a fixed feature-specific prefix. This marker contains no raw Discord identifier, message text or timestamp. It is a stable pseudonym that can still be linked to a known identifier, not anonymous data. It has no automatic expiration because it must preserve your choice until explicit reactivation. The opt-out applies to conversation tracking; it does not disable the client cache or the separate processing described in this policy.
This command does not erase backups or every payment, dispute, security or fraud-prevention record. Other content-free server activity statistics and membership records are separate from conversation tracking and can continue to process identifiers and activity dates after account deletion. Account deletion is therefore not a global opt-out from all server metadata processing. Contact support using the route above for questions about retained records.
Removing LevelPay from a server stops new server activity from being processed there. A server administrator may contact support about server-level records.
Spotlight applications and pool contacts are server-level records retained while needed for review or participation. To withdraw a server or request deletion of its application and contact information, contact support. Deleting a member rewards account does not automatically withdraw a server.
Security
We use access controls and technical and operational safeguards designed to protect LevelPay data. No method of storage or transmission is completely secure, and we cannot guarantee absolute security. We review safeguards as the service changes and will address suspected data incidents in accordance with applicable requirements.
Discord OAuth access and refresh tokens are encrypted at rest on the backend and are never stored in browser local storage or exposed in portal URLs. The browser receives only secure,HttpOnly, SameSite cookies containing opaque session material. Requests between the website and the backend use short-lived signed assertions with replay protection.
Age requirements
LevelPay is not intended for anyone below the minimum age required to use Discord in their jurisdiction. If you believe that a person below that age provided data to LevelPay, please contact support so we can review and delete it where required.
Changes and contact
We may update this policy as LevelPay changes. The effective date at the top identifies the latest version. Material changes will be communicated through the service or support community when appropriate.
Questions or privacy requests can be submitted by opening a ticket in the LevelPay support server.
