1. Who this policy covers
This Privacy Policy explains how Group Guard (“Group Guard,” “we,” “us,” or “our”) handles information when you use the Group Guard website, administrative tools, APIs, bots, and related integrations.
Group Guard is the controller of information used to operate this service. VRChat, Discord, and other connected services separately control information they process under their own privacy policies.
2. Information we collect
Account and profile information
We store your preferred name, email address, password hash, verification status, roles, selected theme, pending email changes, invitations, account status, and the Terms version and time you accepted. We do not store your plaintext Group Guard password.
API and security information
API-key secrets are verified using non-recoverable keyed digests. We retain key names, selectors, display suffixes, creation and revocation information, replacements, last-use times, use counts, and related ownership metadata. Sessions, CSRF controls, authentication attempts, and infrastructure may process browser, network, request, timestamp, and error information in operational or security logs.
Discord links
Where configured, we store Discord user IDs, usernames, links between Discord and VRChat identities, and the time a link was created.
3. VRChat, group, and bot information
Authorized bot identities synchronize information made available by VRChat, which may include user profiles and identifiers; group metadata, members, roles, and moderation audit entries; worlds and instances; badges and badge assignments; status fields; images and URLs; timestamps; and related platform metadata. This information can concern people who do not have a Group Guard account.
For operator-controlled VRChat bot accounts, we store the login identifier, assignments to internal bots, health and heartbeat information, request states, timestamps, and failure diagnostics. Passwords and email or TOTP codes supplied for a login challenge are encrypted while awaiting the assigned bot and erased when consumed, cancelled, timed out, completed, or failed. Long-term VRChat session credentials remain in the bot’s separate encrypted runtime store rather than Group Guard’s web database.
When a bot cannot process platform data, it may report the operation, resource identifiers, exception class and message, a bounded stack trace, bot version, timestamps, and the attempted VRChat payload. These reports are restricted to administrators and are used to diagnose synchronization failures.
4. How we use information
- Provide accounts, group-management views, synchronization, APIs, and connected bot features.
- Authenticate people and services, enforce permissions, protect credentials, and prevent abuse.
- Send verification, password reset, invitation, email-change, security, and service messages.
- Investigate audit history, diagnose failures, respond to support and privacy requests, and improve reliability.
- Comply with law, enforce our Terms, and follow applicable platform rules.
We do not sell personal information, use it for targeted advertising, or use stored user or platform data to train artificial-intelligence or machine-learning models.
7. Retention and deletion
We keep account, community, audit, and configuration information while it is needed to provide, secure, troubleshoot, or document the service. Login challenges use short expiry periods and erase supplied secrets as described above. Invitations, sessions, bot diagnostics, API-key metadata, operational logs, and security records are retained only as long as reasonably necessary for their purpose, dispute resolution, or legal obligations.
Deleted information may remain temporarily in restricted backups until those backups rotate, unless law requires longer retention. Account-wide deletion and requests involving synchronized third-party information require a reviewed operator process so that legal, security, group-authority, and platform obligations can be considered.
8. Your choices and rights
You can update your preferred name and email, choose your visual theme, manage or revoke API keys, and end your browser session through Group Guard. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to appeal a denied request.
Use the contact details below to make a privacy or deletion request. Tell us which Group Guard, VRChat, Discord, and group identities are involved. We may verify your identity and authority before acting and may retain limited information where required for security, legal obligations, group records, or dispute resolution.
9. Security
We use administrative, technical, and organizational safeguards designed to protect information, including access controls, hashed passwords, keyed API-secret verification, CSRF protection, encrypted short-lived bot login responses, limited administrative access, and encrypted transport where deployed. No online service can guarantee absolute security, so protect your credentials and report suspected incidents promptly.
10. International processing
Group Guard and its providers may process information in the United States and other countries where protections differ from those in your home country. Where required, we use appropriate safeguards for international transfers.
11. Children
Group Guard is not directed to children under 13 or below the minimum digital-consent age in their country. We do not knowingly collect account information from someone who cannot lawfully use the service. Contact us if you believe a child provided information improperly.
12. Changes to this policy
We may update this policy as Group Guard, connected platforms, or applicable law changes. We will revise the effective date and provide additional notice when a change is material.
13. Contact
Send privacy, correction, deletion, security, safety, or platform-policy requests to [email protected].
Operator: Group Guard
Jurisdiction: United States