Shadow will only ever store the bare-minimum data needed for the site to function. We are not interested in knowing any more about you than absolutely necessary.
We do not and will never track you, attempt to identify or de-anonymize you, or sell any of your data to any third-party.
Stored data
Shadow stores the following information about you
- Discord ID — Used to authenticate you when logging in.
- Discord access token — Used to retrieve information about you from Discord (see below).
- Discord servers on Shadow — Servers you are in that the server-owner has onboarded to Shadow. We do not store your full server list.
- Discord roles on Shadow — Roles you have that a server-owner has onboarded to Shadow. We do not store your full role list.
- Site Data — Data you create on or otherwise contribute to the site. Images, reactions, comments, etc.
Accessed data
Shadow accesses, but does store, the following information about you
- All Discord servers you're in — We immediately filter out any servers that are not onboarded to this website. We do nothing with nor store your server list. It is only used when 1. you log in (to sync your account), or 2. a server owner onboards a new server to Shadow that you are a member of.
- All your roles in a Discord server — We immediately filter out any roles that are not onboarded to this website (see above). It is only used when 1. you log in (to sync your account), or 2. a server owner onboards a server you are a member of.
Shadow currently uses three third-parties:
- Discord — Authentication and authorization are powered by Discord (account creation, login, and roles).
- Hetzner — Our webhost. The box is in a datacenter in Ashburn, Virginia, United States.
- Cloudflare — CDN, DNS, and DDoS protection (and some small other things).
Shadow will retain your data unless:
- You stop using Shadow — If you do not use Shadow for 2 years (based on last login date), or
- You delete your account — You use the 'Delete Account' button found in your account settings, or
- Shadow shuts down — If Shadow ceases operation for any reason, all site data will be erased.
These actions are permanent and cannot be undone.
Security
Shadow does its best to safeguard and protect your data
- Encryption at rest — The primary Shadow database and all its logs are encrypted at rest using AES with a key rotated at least annually.
- TLS — All your connections to Shadow are encrypted using TLS v1.2 or greater (proxied through Cloudflare).
- Limited access — Shadow is operated by one person. No one else has access to the webserver, the database, or any other technical components.
- Minimal logs — Shadow stores as few operational logs as possible (to identify and fix issues/bugs) and does not intentionally track activity on the site. Operational logs are deleted regularly.
- Third-party Auth — Shadow does not store account passwords; that is handled by Discord.
Last updated: 11 January 2025