Privacy Policy
Pursuant to Art. 13, 14 GDPR and § 13 TMG (German Telemedia Act)
1. Controller
Arne WernerHauptstr. 234B
26639 Wiesmoor
Germany
Email: arne.werner87@gmail.com
2. Data Processing Principles
TrustCord is designed as a privacy-minimised service following a process-and-purge model. We process personal data only to the strictly necessary extent (data minimisation pursuant to Art. 5(1)(c) GDPR).
- No storage of identity documents or document images
- No storage of selfies, liveness videos, or biometric templates
- No storage of names, addresses, dates of birth, or document numbers
- No storage of MRZ data or nationality/gender data
- No storage of raw verification provider responses or decision data
3. Verification Data Processed by TrustCord
TrustCord may process:
- Discord user ID
- Discord server ID
- Verification status (verified / declined / in review / expired / failed)
- Liveness result
- Face-match result
- Optional age-threshold result (e.g. 18+)
- Verification timestamp
- Expiry timestamp
- Provider session reference
- Deletion/audit events
TrustCord does not store:
- Identity documents or document images
- Selfies or liveness videos
- Names, addresses, or dates of birth
- Document numbers or MRZ data
- Biometric templates
- Raw provider responses
4. Purpose and Legal Basis
Processing occurs for the purpose of realness, anti-bot, and (where enabled) age-threshold verification for Discord server access.
- Legal basis: Art. 6(1)(b) GDPR (performance of contract) for registered server administrators; Art. 6(1)(a) GDPR (consent) for end users who voluntarily initiate verification.
- BYOK mode: When a server owner connects their own verification provider account, the provider-side processing is controlled by that server owner. TrustCord stores only the minimised result it receives or derives for role assignment and auditability. Provider-side retention, access and deletion settings must be configured by the server owner in their provider account.
- TrustCord-managed mode (where offered): TrustCord applies a process-and-purge approach - provider verification data is processed for the verification decision, TrustCord stores only the minimised result, and the provider session is deleted after processing where supported.
5. Third-Party Provider – Didit
Verification sessions are processed via the third-party provider Didit (didit.me). Didit processes the user's identity document and selfie as part of the verification process where the enabled workflow requires it. TrustCord receives from Didit only the sanitised verification result described in section 3 above, together with an opaque session/vendor reference that does not itself contain Discord identifiers. Raw data (documents, images, decision payloads) remain with the third-party provider and are never stored, logged, or displayed by TrustCord. Where technically supported and permitted by the connected API key, TrustCord attempts to delete the Didit-side session immediately after processing.
Didit maintains its own security and compliance certifications, including SOC 2 Type I (SOC 2 Type II in progress), ISO 27001, ISO 27017, and ISO 27018, iBeta Level 1 (ISO 30107-3) liveness/anti-spoofing testing, and states that it is compliant with the GDPR in its role as data processor. These certifications and compliance claims are made and maintained by Didit; TrustCord does not independently audit or certify Didit's infrastructure.
Please refer to Didit's privacy policy: didit.me/privacy
6. Automated Decision-Making
The verification result (e.g. verified / declined) is generated by Didit's automated, AI-assisted checks (document authenticity analysis, face-match, and liveness/anti-spoofing detection) without a review step by TrustCord itself. This may constitute automated decision-making within the meaning of Art. 22 GDPR. Where Didit's own process flags a session for manual review, the result is not finalised automatically - the verification remains in review until that process concludes.
You may contact us at the address in section 1 to request review of a verification decision as it applies to your access to a Discord server. TrustCord itself does not access, alter, or override Didit's underlying document or biometric assessment, since that data is not transmitted to or stored by TrustCord (see section 3) - any request to review the verification assessment itself must be directed to Didit as the entity that performed it.
7. International Transfers
Where third-party providers (e.g. Didit) process data outside the European Economic Area, this is done on the basis of appropriate safeguards pursuant to Art. 46 GDPR (standard contractual clauses). Please refer to the respective provider's privacy policy for details.
8. Retention Period
Verification records are stored by default for 12 months (configurable per server between 1 and 36 months). After expiry or upon deletion by the user, all personal data is irreversibly anonymised.
9. Your Rights (Art. 15–22 GDPR)
You have the right to:
- Access (Art. 15 GDPR): Use the Discord command
/privacy(choose “Export my data”) to receive a copy of your data immediately, or contact us to request it directly. - Rectification (Art. 16 GDPR): Correction of inaccurate data.
- Erasure (Art. 17 GDPR): Use the Discord command
/privacy(choose “Delete my data”) to delete all your data immediately and irreversibly. - Restriction of processing (Art. 18 GDPR)
- Objection (Art. 21 GDPR)
- Data portability (Art. 20 GDPR)
- Right not to be subject to automated decision-making (Art. 22 GDPR): See section 6 for details on how the verification decision is made and how to request review.
- Withdrawal of consent (Art. 7(3) GDPR): At any time via
/privacy(choose “Delete my data”).
To exercise your rights, please contact: arne.werner87@gmail.com
10. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority. For Lower Saxony, Germany:
Landesbeauftragte für den Datenschutz Niedersachsen (LfD) - State Commissioner for Data Protection Lower SaxonyPrinzenstraße 5
30159 Hannover
www.lfd.niedersachsen.de
11. Data Security
All API keys are stored encrypted with AES-256-GCM. Communication between the Discord bot and API uses encrypted connections exclusively. Webhook messages are verified with HMAC-SHA256 where a webhook signature secret is configured.
12. Web Dashboard Access Data (Server Administrators)
Signing in to the web dashboard with Discord is separate from the verification data described in section 3, and applies only to server administrators who use the dashboard - not to members who verify via /verify. TrustCord stores:
- Discord user ID
- A Discord OAuth access and refresh token pair, used solely to check which Discord servers you administer before showing or changing that server’s settings
- An opaque browser-session token (not a Discord token) identifying your signed-in session
TrustCord does not store your Discord username, avatar, or email address for dashboard sign-in - these are discarded before storage. Your Discord token is revoked at Discord once your last active dashboard session ends - whether by signing out, by that session expiring without further activity, or by deleting your data via /privacy - and not while another dashboard session of yours is still active.
Last updated: July 2026 · This privacy policy applies to the TrustCord service.