Opal
HomeFeaturesDocsToSPrivacyLoginDiscord ↗

Privacy Policy

Last updated: September 12, 2026
This policy covers the Opal Discord bot and the Opal website/profile service. Privacy questions and deletion requests can be raised through the official Opal support Discord.

1. What Opal provides

Opal provides Discord staff-management features and an optional website account/profile service. Website accounts use Discord OAuth for authentication.

2. Discord bot information

Depending on the features a community enables, Opal may process Discord server IDs, user IDs, role IDs, channel IDs, staff records, notes, warnings, reviews, availability, leave requests, access restrictions, verification settings and audit-log configuration.

Opal does not use Discord's Message Content privileged gateway intent to ingest ordinary server conversations. Text deliberately submitted to an Opal command, modal or form is processed because the user submitted it to that feature.

3. Website account information

When you sign in to the Opal website with Discord, Opal requests Discord's identify OAuth scope. This can provide your Discord user ID, username, global display name and avatar. Opal does not receive or store your Discord password.

Opal does not keep Discord OAuth access or refresh tokens after the login flow is complete. The website creates its own random session token and stores only a cryptographic hash of that token in the database.

4. Profile information

If you create a public profile, information you choose to publish may include your profile URL, display name, bio, country indicator, profile details such as About, Location, Website, Focus, Company or Pronouns, social links, avatar, banner, background and appearance settings. Public profile information is visible to anyone who visits your profile URL.

Badges such as Opal or Administrator are assigned by the service and cannot be self-assigned through the profile editor.

5. Uploaded images

Profile images are stored in Cloudflare R2. Uploads are limited to approved image types and file sizes. Each profile account is limited to 30 MB of uploaded profile images and 20 upload attempts per 24 hours. Opal does not allow arbitrary HTML, JavaScript, SVG or custom code uploads through the profile editor.

6. Sessions and security information

The website stores active session records including a hashed session token, session creation/expiry timestamps, whether the session was remembered, recent activity time and a limited browser user-agent string so you can recognize and revoke sessions. IP addresses are not stored as profile data. A privacy-preserving keyed hash may be used temporarily for rate limiting and abuse prevention.

7. Cookies

Opal uses strictly necessary cookies for Discord OAuth state validation and website login sessions. The session cookie is HttpOnly, Secure and SameSite=Lax. If you choose "Keep me signed in," the session may remain valid for up to 30 days unless you log out or revoke it. Non-remembered sessions expire sooner.

8. Why information is processed

Information is processed to provide Opal features, authenticate users, display public profiles, store user-selected customization, enforce permissions and product rules, prevent abuse, maintain service security, diagnose failures and comply with valid legal obligations.

9. Service providers

Opal uses Cloudflare services for website hosting, server-side functions, database storage and profile image storage. Discord provides authentication and bot-platform services. These providers process information as necessary to deliver their services under their own applicable terms and privacy policies.

10. Data sharing

Opal does not sell personal data. Information may be disclosed when required by law, necessary to protect Opal or its users, or necessary to investigate serious abuse or security threats.

11. Retention

Discord bot data is retained while needed to provide enabled features. Website account/profile data is retained until the user deletes the website account or the service removes it for a valid operational, legal or abuse-related reason. Security logs and backups may persist for a limited rotation period.

12. Account deletion

Website users can delete their account from the dashboard. This removes the website account, public profile, profile details, social links, website sessions and uploaded profile images controlled by the profile service. Deleting the website account does not automatically erase records created by the Discord bot inside communities because those are a separate service context.

Requests concerning Discord-bot data can be raised through the official support Discord. Authorized community management may also use Opal's wipe tooling where available.

13. Security

Opal uses measures including Discord OAuth, random server-side sessions, hashed session tokens, HttpOnly/Secure cookies, CSRF checks, input validation, restricted image types, rate limiting, parameterized database queries, access checks and security headers. No online service can guarantee absolute security.

14. Children's privacy

Opal is intended for users who are permitted to use Discord under Discord's age requirements and applicable law.

15. Changes

This policy may be updated when Opal's functionality, infrastructure or legal obligations change. Material changes may be announced through the official Opal Discord.

16. Contact

For privacy questions or requests, contact us through the official Opal Discord.

Opal

Staff management for Discord communities.

ProductFeaturesDocumentationProfiles
LegalTerms of ServicePrivacy Policy
CommunitySupport Discord ↗
© 2026 Opal. All rights reserved.Not affiliated with or endorsed by Discord Inc.