Privacy Policy
Effective August 20, 2026. This page is a deployment placeholder and must be replaced with legally reviewed final text before public production launch.
What Realmkeeper uses
Realmkeeper processes Discord identifiers, server configuration, event details, registrations, profiles, listing information, messages, authentication records, security records, and billing/Paid Listing Credit records as needed to operate requested features.
First-party visitor measurement
Realmkeeper uses one signed, first-party pseudonymous browser identifier to estimate site-wide unique visitors and measure homepage layout exposure. PostgreSQL receives only a keyed hash of that random identifier, first- and last-seen times, and one UTC presence date per eligible day. Counts represent approximate browsers, not guaranteed unique people.
This measurement does not store the raw identifier, IP addresses, user-agent strings, referrer histories, visited-path histories, account identities, email addresses, Discord identifiers, session contents, or third-party advertising identifiers. Daily presence and detailed experiment events are retained for 90 days to understand aggregate use and improve the website.
Requests expressing Global Privacy Control or Do Not Track are excluded, as are recognized bots, crawlers, automated test fixtures, background requests, static assets, API calls, and failed pages. Disabling visitor measurement stops new presence records without deleting historical aggregates or affecting authentication, sessions, experiment assignment, or ordinary page rendering.
Realmkeeper does not use Google Analytics, third-party tracking pixels, advertising cookies, or external analytics services for this measurement.
What Realmkeeper does not do
Realmkeeper does not sell personal information or provide Discord API data to data brokers or advertising networks. The current plan does not use Discord API data or user content to train generative AI or machine-learning models.
Website security
v0.6.0 uses server-side PostgreSQL sessions, CSRF defenses, secure OAuth state handling, encryption support for OAuth tokens at rest, security headers, database constraints, and Discord permission checks for Manage Bot.