What we collect
When you connect Discord, we receive your Discord user ID, username, avatar, email address and email-verification status. With your permission, we also read the IDs and names of Discord servers you belong to so we can confirm membership in California State Roleplay.
We record the IP address used to finish verification, its network or hosting provider, and whether an IP intelligence service identifies it as a datacenter, VPN, proxy or Tor connection. We also keep the approximate IP country and city, network type, hostname and organisation when the provider supplies them. These classifications are estimates and can be wrong. We also record verification times and the Roblox account you confirm through our Discord bot.
When you finish verification, we collect browser-reported screen dimensions, pixel density, device category, operating system, browser, user-agent, language, timezone, touch support, logical processor count, and available graphics renderer/vendor information. Some browsers hide or alter these values. We create a keyed profile fingerprint and use a random first-party device cookie that expires after 90 days; the cookie value is stored in records as a keyed identifier.
Why we use it
We use this information to connect your website check to the correct Discord account, grant server access, investigate abuse and help moderators identify possible ban evasion. Staff may compare device identifiers, profile fingerprints and shared IPs across verified accounts to investigate possible ban evasion. These signals can be shared, changed or spoofed; a match does not prove two accounts belong to one person. Device matches and VPN, proxy and Tor classifications do not automatically block verification.
How it is stored
Website email, network and device information is encrypted before it is saved. Device identifiers and fingerprints use a server-held key and are specific to this site. Raw device-cookie values are not saved in account records. Session links are temporary, and stored link and browser-session identifiers are hashed. Production connections use HTTPS. Private bot endpoints require a server-held credential; personal verification records are not sent to ordinary browser responses.
Authorized server staff can see your verification details in the admin-only Discord verification-log channel in our private log server. Information displayed in those Discord messages is protected by that channel’s access permissions rather than our database encryption.
Services involved
Discord provides sign-in and account information. Cloudflare provides hosting, network protection and the Turnstile captcha. Proxycheck.io processes your IP address to supply network classifications. Bloxlink and Roblox provide the linked Roblox profile used by our bot. These services process information under their own privacy policies.
Retention and requests
Website sessions expire after ten minutes. Website-held email, network and device data is removed after the bot acknowledges the completed verification; expired sessions are cleaned up by scheduled maintenance, normally within ten minutes. Account records are retained for server access and moderation. Admin unverification removes your account entry, while historical moderation logs may remain.
Contact the California State Roleplay administration team through Discord to request access, correction or deletion of your information, or to ask how it was used in a moderation decision.
Casino accounts
Casino sign-in requests your Discord identity and membership information for California State Roleplay to check your verified role. A limited Discord access token is encrypted on the server for these checks and never sent to your browser. Casino sessions last up to seven days, limited by the Discord token expiry. Verified-role checks are reused briefly to avoid unnecessary Discord requests. Removing the verified role or leaving the server revokes casino access through the bot. Signing out deletes the session and revokes the token. Scheduled maintenance removes expired sessions.
We retain coin balances, economy transactions, cooldowns and game rounds to keep Discord and website balances consistent and resolve interrupted games. Signed-in verified members can see recent bets with the player’s Discord username and avatar, game, bet, payout and time. These game feeds do not contain verification emails, IP addresses or device fingerprints.
Local preview
The local design preview skips Discord sign-in and uses a demonstration security check. It does not collect your Discord email, classify your IP address, grant server roles or create a real verification record.
