Privacy Policy

Last updated: August 2026

1. Introduction

At CloudCord, your privacy is our top priority. Because of the nature of client modifications, we believe in complete transparency. This Privacy Policy outlines what information we collect, how it is used, and why we do not want your personal data.

2. Information We Collect

CloudCord is designed to keep most configuration data locally on your device. We do not sell personal data or collect Discord passwords or raw account tokens.

3. Discord Data and Tokens

For required community membership, CloudCord uses Discord OAuth2 with the limited identify and guilds.join scopes. The service receives your Discord user ID and a temporary scoped OAuth access token, uses it to add your account to the official CloudCord server, and does not store that OAuth access token after the join completes. CloudCord stores a hashed device credential, your Discord user ID, the accepted Terms version, and membership-check timestamps. CloudCord does not collect your Discord password, raw account token, messages, or cookies.

4. Third-Party Plugins

While the core CloudCord client respects your privacy, third-party plugins installed by you may have their own data collection practices. If you install a plugin that connects to an external API (for example, a translation plugin or an image host), that plugin may share your data with third parties. We urge you to review the source code or privacy policies of third-party plugins before installing them.

5. Security

We are committed to ensuring that your information is secure. In order to prevent unauthorized access or disclosure, we have made the CloudCord injector open-source, allowing security researchers to independently verify that no malicious data exfiltration is occurring.

6. Changes to this Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page. You are advised to review this Privacy Policy periodically for any changes.

7. Service and Diagnostic Data

Our servers may temporarily process request timestamps, network addresses, user-agent information, response codes, rate-limit events, and error details needed to operate, secure, and troubleshoot the website and APIs. We minimize this information and do not use it to read Discord messages.

8. Cloud Synchronization

If you enable StoreCloud, selected settings, plugin configuration, themes, profiles, or other supported client data may be transmitted to CloudCord for synchronization. Stored synchronization payloads are encrypted by the service. Cloud synchronization is optional unless a feature clearly states otherwise.

9. Data Retention

Local data remains until you remove it or uninstall CloudCord. Membership device records are retained while required to verify access and may be removed when the service is reset or the record is no longer needed. Operational logs are retained only as reasonably necessary for security and troubleshooting.

10. Data Sharing

We do not sell personal data. Information may be processed by infrastructure providers that host CloudCord, by Discord during OAuth and membership operations, or when required by law, necessary to protect users, or needed to investigate abuse. Third-party plugins remain governed by their own practices.

11. User Choices

You may decline OAuth authorization, disable optional synchronization, remove plugins and themes, leave the CloudCord server, clear local settings, or stop using CloudCord. Declining or revoking a required authorization may make CloudCord unavailable until authorization is completed again.

12. Security Limitations

We use reasonable safeguards, including scoped OAuth access, hashed device credentials, encryption for supported synchronized data, rate limits, and restricted server credentials. No system is perfectly secure, and users should keep devices updated and avoid untrusted plugins.

13. Contact and Requests

Privacy or security requests may be submitted through the official CloudCord support channels listed on the website. We may need to verify that a requester controls the relevant account or device record before acting on a request.