Back to home
Legal

Privacy Policy

Last updated: July 12, 2026

Link Protect is a Discord moderation bot and companion app that automatically blocks unwanted links and keeps servers safe. This policy explains exactly what data we use, why, and what we never touch. We keep it minimal on purpose.

Who we are

“Link Protect” (the “Service”) consists of the Link Protect Discord bot, the website at link-protect.com, and the Link Protect iOS app. The Service is operated as an independent project. You can reach us anytime through our support server.

What we collect

We only collect what is needed to run the Service:

  • Discord account basics — when you sign in with Discord (on the website or in the app), we use the identify and guilds OAuth scopes to read your Discord user ID, username and avatar, and the list of servers you are a member of. This is used solely to authenticate you and show the servers you can manage.
  • Server configuration — the settings you choose for a server (active blockers, warning thresholds, whitelists, custom blacklists, log channel). Stored per server so the bot can enforce them.
  • Moderation history — when the bot acts on a message (warn, timeout, kick, ban) it records the action type, the reason, the affected user’s ID, the channel ID and a timestamp. This powers warning counts, statistics and the activity log.
  • Scam Shield flags — when the bot catches an account mass-posting the same scam message across several channels, it records that account’s Discord user ID together with incident counters and timestamps in a shared flag list, so servers that opt in can automatically remove known scam accounts. Flags are created exclusively by the bot observing this behaviour live, never from reports or keyword matches. As the sole exception to our no-message-content rule, the offending scam message itself (its text and attachment file names/links) is retained as evidence so a flag can be reviewed fairly — it is deleted automatically the moment the flag is removed. Flagged users can appeal at link-protect.com/appeal; flags can also be reviewed via our support server.
  • Member join events — on servers that enable the Scam Shield join check, the bot receives member join events and compares the joining account’s user ID against the flag list in memory. Join events are not stored; only if a flagged account is removed does a moderation-history entry (as above) get written.
  • Push notifications (app only) — if you enable notifications, we store your device’s push token and your notification preferences so we can deliver alerts. You can turn this off anytime in iOS Settings.
  • Link checker — your IP address — the public link checker at link-protect.com/check is usable without an account. To stop it being abused as a free scanning service, we keep the IP address of the requesting device in a short-lived counter. Legal basis: our legitimate interest in protecting the Service against abuse (Art. 6(1)(f) GDPR). The counter is kept for at most 60 minutes and is then deleted; it is never combined with your Discord account and never used for analytics.
  • Link checker — the URL you submit — the address you enter is checked against our own threat database and, if unknown, submitted to Google Safe Browsing for a verdict. That transfer goes to Google Ireland Limited / Google LLC and may involve a transfer to the USA on the basis of the EU standard contractual clauses. The verdict is cached so the same link is not looked up twice.
  • Block details (server logs) — from bot version 3.1.0 each automatic block records which rule matched, the matched domain and an excerpt of the message that triggered it, so a server’s moderators can verify and, if necessary, correct a wrong decision. This excerpt is visible only to people with access to that server’s dashboard and is removed with the rest of the moderation history.
  • Resolved target addresses — for links the bot examines, the IP address of the target website (not of any user) may be resolved and cached for up to an hour to recognise scam infrastructure that keeps changing domains. This is an address of a server, not of a person.
  • Hosting logs — our hosting providers (Vercel for the website, our own server for the API) create technical logs that can contain IP addresses, for the purpose of operating and securing the Service (Art. 6(1)(f) GDPR).

What we do NOT collect

  • We do not store the content of your messages. Messages are scanned in memory only to detect links, then discarded.
  • We do not collect your email, phone number, address or payment information.
  • We do not collect the IP addresses of Discord users. Discord does not make them available to bots, and we make no attempt to obtain them by other means (such as tracking links or logging redirects).
  • We do not use any advertising or cross-app tracking, and the app shows no ads. There is no “Sign in with Apple” because the app is purely a client for Discord.

How we use your data

Your data is used only to operate the Service: to authenticate you, to show and let you configure the servers you manage, to enforce your protection settings, to display statistics and logs, and to deliver the notifications you opt into. We do not sell your data, and we do not share it for marketing.

Third parties

To function, the Service necessarily interacts with:

  • Discord — to authenticate you and to perform moderation. Your use of Discord is governed by Discord’s own Privacy Policy.
  • Apple Push Notification service — used only to deliver push notifications you enable. Apple receives the device token needed for delivery.

Data retention & deletion

Server configuration and moderation history are kept while the bot is in your server so it can keep working. Removing the bot from a server stops all data collection for that server, and you can request deletion of a server’s stored data through our support server. Push tokens are removed automatically when they become invalid (for example, when you disable notifications or uninstall the app).

Children

The Service is not directed at children under 13, and you must meet Discord’s minimum age requirement to use it.

Security

We take reasonable technical measures to protect your data. Access tokens are stored securely (in the iOS Keychain on device), and no Discord client secret is ever shipped in the app. No method of transmission or storage is 100% secure, but we keep the data we hold deliberately minimal.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above. Continued use of the Service after an update means you accept the revised policy.

Contact

Questions or data requests? Reach us in the Link Protect support server.