Group Guard
  • Login
    • Light
    • Dark
    • Auto

The legal details

Privacy Policy

What Group Guard stores, why it is needed, and the choices you have.

Effective October 7, 2026

On this page

Who this covers Information we collect Platform and bot data How we use it How it is shared Cookies and local storage Retention and deletion Your choices and rights Security International processing Children Policy changes Contact

1. Who this policy covers

This Privacy Policy explains how Group Guard (“Group Guard,” “we,” “us,” or “our”) handles information when you use the Group Guard website, administrative tools, APIs, bots, and related integrations.

Group Guard is the controller of information used to operate this service. VRChat, Discord, and other connected services separately control information they process under their own privacy policies.

2. Information we collect

Account and profile information

We store your preferred name, email address, password hash, verification status, roles, selected theme, pending email changes, invitations, account status, and the Terms version and time you accepted. We do not store your plaintext Group Guard password.

API and security information

API-key secrets are verified using non-recoverable keyed digests. We retain key names, selectors, display suffixes, creation and revocation information, replacements, last-use times, use counts, and related ownership metadata. Sessions, CSRF controls, authentication attempts, and infrastructure may process browser, network, request, timestamp, and error information in operational or security logs.

Discord links

Where configured, we store Discord user IDs, usernames, links between Discord and VRChat identities, and the time a link was created.

3. VRChat, group, and bot information

Authorized bot identities synchronize information made available by VRChat, which may include user profiles and identifiers; group metadata, members, roles, and moderation audit entries; worlds and instances; badges and badge assignments; status fields; images and URLs; timestamps; and related platform metadata. This information can concern people who do not have a Group Guard account.

For operator-controlled VRChat bot accounts, we store the login identifier, assignments to internal bots, health and heartbeat information, request states, timestamps, and failure diagnostics. Passwords and email or TOTP codes supplied for a login challenge are encrypted while awaiting the assigned bot and erased when consumed, cancelled, timed out, completed, or failed. Long-term VRChat session credentials remain in the bot’s separate encrypted runtime store rather than Group Guard’s web database.

When a bot cannot process platform data, it may report the operation, resource identifiers, exception class and message, a bounded stack trace, bot version, timestamps, and the attempted VRChat payload. These reports are restricted to administrators and are used to diagnose synchronization failures.

4. How we use information

  • Provide accounts, group-management views, synchronization, APIs, and connected bot features.
  • Authenticate people and services, enforce permissions, protect credentials, and prevent abuse.
  • Send verification, password reset, invitation, email-change, security, and service messages.
  • Investigate audit history, diagnose failures, respond to support and privacy requests, and improve reliability.
  • Comply with law, enforce our Terms, and follow applicable platform rules.

We do not sell personal information, use it for targeted advertising, or use stored user or platform data to train artificial-intelligence or machine-learning models.

5. How information is shared

Authorized users and bots. Administrators and authorized group users can access information needed for their roles. Assigned internal bots receive the VRChat login identifiers and operational instructions needed to perform synchronization.

Connected platforms. We exchange requests and the minimum necessary information with VRChat or Discord when an authorized feature uses those services. Their own policies apply to information they process.

Service providers. Hosting, database, backup, security, and transactional-email providers may process information on our behalf under appropriate confidentiality and data-protection obligations.

Legal and safety needs. We may disclose information when reasonably necessary to comply with law, protect people or systems, investigate abuse, establish legal claims, or complete a business transfer with appropriate safeguards and notice where required.

6. Cookies and local storage

Group Guard uses essential first-party cookies for sessions, sign-in persistence, and CSRF protection. Your browser stores light or dark mode and administrator-sidebar preferences locally. These technologies support requested features; they are not advertising or cross-site tracking tools.

7. Retention and deletion

We keep account, community, audit, and configuration information while it is needed to provide, secure, troubleshoot, or document the service. Login challenges use short expiry periods and erase supplied secrets as described above. Invitations, sessions, bot diagnostics, API-key metadata, operational logs, and security records are retained only as long as reasonably necessary for their purpose, dispute resolution, or legal obligations.

Deleted information may remain temporarily in restricted backups until those backups rotate, unless law requires longer retention. Account-wide deletion and requests involving synchronized third-party information require a reviewed operator process so that legal, security, group-authority, and platform obligations can be considered.

8. Your choices and rights

You can update your preferred name and email, choose your visual theme, manage or revoke API keys, and end your browser session through Group Guard. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to appeal a denied request.

Use the contact details below to make a privacy or deletion request. Tell us which Group Guard, VRChat, Discord, and group identities are involved. We may verify your identity and authority before acting and may retain limited information where required for security, legal obligations, group records, or dispute resolution.

9. Security

We use administrative, technical, and organizational safeguards designed to protect information, including access controls, hashed passwords, keyed API-secret verification, CSRF protection, encrypted short-lived bot login responses, limited administrative access, and encrypted transport where deployed. No online service can guarantee absolute security, so protect your credentials and report suspected incidents promptly.

10. International processing

Group Guard and its providers may process information in the United States and other countries where protections differ from those in your home country. Where required, we use appropriate safeguards for international transfers.

11. Children

Group Guard is not directed to children under 13 or below the minimum digital-consent age in their country. We do not knowingly collect account information from someone who cannot lawfully use the service. Contact us if you believe a child provided information improperly.

12. Changes to this policy

We may update this policy as Group Guard, connected platforms, or applicable law changes. We will revise the effective date and provide additional notice when a change is material.

13. Contact

Send privacy, correction, deletion, security, safety, or platform-policy requests to [email protected].

Operator: Group Guard
Jurisdiction: United States

Group Guard Tools for the people who look after their communities.
Terms Privacy Contact