Legal
How we collect, use, and protect your information.
Last updated: July 2026
When you use Technified, we collect basic information from Discord (user ID, username, avatar) and Roblox (user ID, username) through OAuth 2.0.
To power role bindings, we query Roblox data including group ranks, game passes, badges, and asset ownership on your behalf.
For servers using our Staff Activity Tracker, we collect in-game session times, session durations, and custom action logs for monitored games.
Form field responses submitted through our application and appeal system are stored and associated with your account.
We store server configurations, role bindings, verification settings, AutoMod rules, and command permissions that you configure through our dashboard.
We collect logs of verification attempts, API calls, and system interactions to improve our service and prevent abuse.
Your session token is stored in an HttpOnly cookie, which is inaccessible to browser scripts. For compatibility with the dashboard, an encrypted copy of the token is also kept in your browser's local storage and is removed when you sign out.
CSRF tokens are issued per session and validated on all data-modifying requests to protect against cross-site request forgery.
We do not use advertising or cross-site tracking cookies. Our cookies are strictly necessary for service functionality. Our error monitoring tool may store technical identifiers in your browser's session storage (see Error Monitoring below).
We use Sentry (Functional Software, Inc.) to detect crashes, errors, and performance problems in the dashboard and our backend. When an error occurs, Sentry receives technical data such as the error message, stack trace, the page or endpoint involved, your browser and operating system, and your IP address.
To help us reproduce bugs, Sentry records a replay of a small sample of dashboard sessions and of sessions in which an error occurs. Replays capture page structure and interactions such as clicks and scrolling. Text content and media are masked by default and are not transmitted.
Our Sentry data is ingested and stored in Sentry's EU (Germany) region. Sentry is a US company; see International Data Transfers below for the safeguards that apply. Error data is used solely to fix problems and is not used for advertising or profiling.
Reads your Discord user ID, username, and avatar so we can sign you in to the dashboard. We do not see your email address through this scope.
Reads the list of Discord servers you are a member of so we can show you which servers you can manage with Technified.
Granted by a server administrator when adding the bot. It defines which permissions the bot has inside that server. It is not requested when individual users sign in.
We never request the email, connections, or messages.read scopes. You can revoke OAuth access at any time from your Discord account settings.
Server API keys are stored only as a one-way SHA-256 hash; the full key is never stored in plaintext. Only a short non-secret prefix is kept in plaintext to identify a key in logs and the dashboard.
We log timestamp, requested endpoint, response code, IP address, and last-used time for every API call. These logs are used for security, abuse prevention, and rate-limit enforcement.
You can revoke any API key at any time from the dashboard. Once revoked the key stops working immediately and the hash is deleted shortly after.
Shield is a list of Roblox user IDs that have been observed participating in condo servers (Roblox experiences that violate Roblox's Community Standards). Each entry stores the Roblox user ID, a short reason, and a timestamp. Shield does not contain Discord users or Technified account holders.
Entries are added by automated scrapers that detect condo participation, and by trusted partners who report confirmed cases. We do not add an entry simply because a user joined Technified.
Game owners can query Shield through the API to decide whether to allow a player into their game. Technified itself does not take action on Shield entries; the decision belongs to the game owner.
We process Shield entries on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in protecting Roblox communities from experiences that violate Roblox's Community Standards. Entries created by automated detection can be reviewed by a human on request or through an appeal, and Technified itself takes no automated action against listed users.
If you believe your Roblox user ID is on Shield in error, contact privacy@technified.xyz. We will tell you whether you are listed, share the recorded reason, and remove the entry if it cannot be substantiated.
The Technified Shield browser extension runs on roblox.com and shows which Roblox users and groups are flagged in the Shield safety list, directly on friends lists, group members, profiles and in-game player lists. It also lets you vote on flags and report users or groups for review.
To use the extension you sign in with Discord (identify scope only). We receive your Discord user ID, username and avatar. A login token and that basic profile are stored locally in the browser via chrome.storage so you stay signed in. We do not request your email.
As you view Roblox pages, the extension sends the Roblox user IDs and group IDs visible on that page to api.technified.xyz to look up their flag status. It also reads public profile, avatar and group information from Roblox's own APIs to display in the panel. It does not read your browsing history or pages outside roblox.com.
When you vote on a flag or submit a report, we store your vote or report linked to your Discord user ID, together with the target Roblox ID, the reason category, your written details and any screenshot you choose to upload. This is used to review reports and to prevent abuse of the system.
identity (Discord sign-in), storage (keep you signed in locally), and host access to roblox.com (to show flag status on the page), api.technified.xyz (to query Shield and submit votes/reports) and Roblox public APIs (users, thumbnails, groups). No other sites are accessed.
You can sign out from the extension popup at any time, which clears the stored token, or remove the extension entirely. To delete votes, reports or uploaded evidence tied to your Discord ID, contact privacy@technified.xyz. We never sell or share this data with third parties.
When you open a ticket, the messages, attachments, and metadata in that channel are stored so the server's staff can review and respond. Ticket data is visible to that server's staff and to Technified for abuse prevention.
When a ticket is closed, a transcript may be generated and stored as a file. Transcripts are accessible to authorized staff of the server that created them.
You can request deletion of your messages from a transcript by contacting privacy@technified.xyz with the ticket ID. Server owners can also delete their server's transcripts directly from the dashboard.
Bans, mutes, kicks, warns, and notes are stored with the target user ID, the staff member who issued the action, the reason, and timestamps. These records back the cross-platform moderation features.
Configuration changes made through the dashboard or API are written to an audit log so server owners can see who changed what and when. Audit logs are visible to authorized staff of that server.
Moderation and audit data for a server are visible to that server's authorized staff. Cross-server visibility is limited to Shield, which only contains external Roblox users (see the Shield section above).
We use your data to provide verification services, maintain role synchronization, deliver moderation features, and power all other features you have configured.
Your information helps us detect and prevent fraudulent activity, abuse, and unauthorized access to our systems.
Anonymous usage data helps us understand how users interact with Technified and improve the platform.
We process your account information, role bindings, server configuration, tickets, applications, and appeals because it is necessary to provide the service you signed up for.
We process log data, moderation records, Shield entries, votes and reports, and error monitoring data based on our legitimate interest in keeping the service secure, preventing abuse, and protecting Roblox and Discord communities. You can object to this processing at any time (see Your Rights).
Where we rely on your consent, for example for optional features that say so explicitly, you can withdraw it at any time with effect for the future.
All data is encrypted in transit using TLS 1.3. Session tokens are stored in HttpOnly cookies with AES-256 encryption applied to sensitive stored values.
We implement strict access controls and authentication measures to protect your data from unauthorized access.
All endpoints are protected by Cloudflare's global DDoS mitigation, ensuring availability and protection against volumetric attacks.
We conduct regular security audits and vulnerability assessments to ensure your data remains protected.
We never sell your personal information to third parties. Your data is yours.
We use Cloudflare, Inc. for hosting, storage, and CDN, and Sentry (Functional Software, Inc.) for error monitoring. Both act as processors on our behalf, and we share only the minimum data necessary for them to provide their service.
We may disclose information if required by law, court order, or to protect our rights and the safety of our users.
Technified runs on Cloudflare's global edge network, so requests may be processed in data centers outside the EU/EEA, including in the United States. Cloudflare is certified under the EU-US Data Privacy Framework and additionally offers EU Standard Contractual Clauses.
Our error monitoring data is stored in Sentry's EU (Germany) region. Because Sentry is a US company, limited access from the US cannot be ruled out; transfers are safeguarded by the EU-US Data Privacy Framework and EU Standard Contractual Clauses.
Wherever data leaves the EU/EEA, we rely on an adequacy decision or appropriate safeguards under Art. 46 GDPR, such as Standard Contractual Clauses. You can contact privacy@technified.xyz for more information about these safeguards.
Discord and Roblox account links are kept while your account is active. If you remove the link or stop using Technified for 24 months, the link is deleted.
Server configuration, role bindings, and moderation records are kept while the bot is in your server. If the bot is removed, this data is retained for 90 days in case you reinstall, then deleted.
Verification logs, API access logs, and audit logs are retained for 90 days, after which they are deleted automatically.
Open tickets are kept while the ticket is active. Transcripts of closed tickets are automatically deleted one year after they are created, and can be deleted earlier by the server owner or on request.
Shield entries are retained as long as they remain valid. Entries can be removed earlier on substantiated request. See the Shield section above.
Encrypted backups may retain copies of deleted data for up to 30 days after deletion before they roll off.
You can request access to your data or request deletion at any time by contacting us at privacy@technified.xyz.
You have the right to have inaccurate data corrected, to request that processing be restricted, and to object to processing based on legitimate interests. Contact privacy@technified.xyz to exercise these rights.
You have the right to receive your data in a structured, machine-readable format upon request.
If you believe our processing of your data violates the GDPR, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your residence or workplace.
You can opt out of our services at any time by removing Technified from your Discord server. Stored data will be retained only as required by law.
You must be at least 13 years old to use Technified, consistent with Discord's and Roblox's Terms of Service.
We do not knowingly collect personal data from users under 13. If we become aware that we have collected such data, we will delete it promptly.
If you have any questions about this policy or how we handle your data, reach out.