> For the complete documentation index, see [llms.txt](https://privacy.perkinsfund.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://privacy.perkinsfund.org/policy-and-terms-review-discord-communications-platform.md).

# Policy & Terms Review; Discord (Communications Platform)

![Discord Logo](https://1654062542-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKcT3SZLCzeIq3NtZ0mdS%2Fuploads%2Fgit-blob-87028d16fefe8e61370de3890c63d497050cb06a%2FDiscord-Logo.jpg?alt=media)

Discord is a global voice, video, and text communications platform, claiming in excess of 150 million monthly active users and more than 19 million active weekly servers, one of the most visited websites in the world. Yet to IPO, but reportedly seeking to go public with a reported target valuation in excess of $15 billion.

This article consists of a review of Discord’s;

* [Privacy Policy](https://discord.com/privacy)
* [Term of Service](https://discord.com/terms)
* [Information About Local Privacy Laws](https://discord.com/terms/local-laws)
* [Cookie Policy](https://discord.com/terms/cookie-policy)
* [How long Discord keeps your information](https://support.discord.com/hc/en-us/articles/5431812448791-How-long-Discord-keeps-your-information)
* [Related Companies](https://support.discord.com/hc/en-us/articles/4410339409047-Related-Companies)
* [End-To-End Encryption for Audio and Video](https://support.discord.com/hc/en-us/articles/25968222946071-End-to-End-Encryption-for-Audio-and-Video)
* [Data Processing Agreement](https://support.discord.com/hc/en-us/articles/37891902561687-Data-Processing-Agreement-Discord-as-a-Processor)
* [Approach to Content Moderation](https://discord.com/safety/our-approach-to-content-moderation)
* [How We Leverage Machine Learning to Fight CSAM](https://discord.com/safety/how-discord-leverages-machine-learning-to-fight-csam)
* [Transparency Reports](https://discord.com/safety-transparency)
* [EU Terrorist Content Online Regulation Transparency Report](https://cdn.discordapp.com/assets/transparency-reports/TCO-Report-2026.pdf)
* [Addressing Harmful off Platform Behaviour](https://discord.com/safety/addressing-harmful-off-platform-behavior)
* [Safety Reporting Network](https://discord.com/safety/safety-reporting-network-commitment)
* [Discord Letter to UK House of Commons April 2024](https://committees.parliament.uk/publications/44386/documents/220713/default/)
* [Teen Default Experience Globally](https://discord.com/press-releases/discord-launches-teen-by-default-settings-globally)
* [Age Assurance for UK Users](https://support.discord.com/hc/en-us/articles/33362401287959-Age-Assurance-for-UK-Users)
* [Data Request Reporting Metrics](https://support.discord.com/hc/en-us/articles/4410339387671-Data-Request-Reporting-Metrics)

## WHAT INFORMATION IS COLLECTED BY DISCORD

* Username
* Password
* Name
* Email address
* Verified phone number
* Date of birth
* Display name
* Messages
* Voice messages
* Custom emoji’s
* Files / documents shared through the service
* Payment information (where user subscribes/makes a purchase) including; full name, billing address, last four digits of card number (even where paying via third party processor).
* If selling on Discord, bank account information, tax ID, copy of Government issued ID.
* The friends a user has
* The users, bots and apps a user engages with
* The servers and communities user joins and participates in
* When discord is running, identifies other applications on the device
* Roles in any servers
* Content moderation decisions made by the user (where applicable)
* *“limited information from your device while Discord is running”*, with no further elaboration
* Contacts (where synced)
* IP address
* Operating system
* Browser information
* Device settings
* Pages, servers and channels a user visits, for how long, when.
* Connected services account profile information and associated data
* Demographic information
* Where age verification is required, copy of Government issued ID and photo and/or video of users face (biometric information)
* Any shared photographs, images, video recordings, voice recordings
* Contents of messages shared on the platform (within servers)
* Inference data about the user

4/10 to Discord for not being transparent in a clear way about what data is collected, I do not feel confident that this tells the whole story, this information was spread across many policies, many of which tended to be descriptive of categories and not specific about the data itself. This does not empower users to understand what’s what, contrary to Discords claims that users understanding their data policies is important to them.

## DATA RETENTION

Discord state they do not store the streaming content when a user shares their screen, but that they do retain the thumbnail cover image for a *“short period of time”.*

*“We **generally** do not store the contents of video or voice calls or channels”*

*“We retain personal information until we determine it is no longer needed for the processing purposes for which we collected or retain it or for legal compliance”*

Documents submitted to complete ID verification are subject to k-ID’s privacy policy and data retention policy.

If an appeal relating to ID age verification is submitted, it is deleted within sixty (60) days after the age appeal ticket is closed.

Database backups are stored for 30–45 days.

If a user has been reported or flagged for violations they may retain that information for up to two years.

If a user deletes their account, the account is typically placed on hold for 15–30 days for recovery in the instance it was unintentionally deleted. Following that period of expiry Discord begin the process of deleting identifiable information and anonymising or aggregating other information, it can take up to 45 days to delete the users information from back ups.

They retain aggregated and anonymised information indefinitely.

## WHAT IS DISCLOSED AND WITH WHO

To provide their services, Discord may share information within their group of related companies (Discord International, Discord Netherlands, Backgammon Merger Sub II LLC and Discord Canada Holdings), in addition to;

* Vendors
* Payment processors
* Sellers
* Cloud hosting provider (Google Cloud)
* Advertising platforms (LiveRamp)
* Analytics and measurement partners
* Related companies (including parents, affiliates, subsidiaries)
* Age verification partner(s) (k-ID)
* Connected apps

Discord are not overly transparent about who the above companies (subprocessors) are, apart from Google, LiveRamp and k-ID in buried policies, naming only their core categories within core policies, restricting any users ability to assert their data rights with third parties, since any data shared with third parties becomes subject to that company’s privacy policy.

They state they also may disclose information to comply with the law including meeting national security or law enforcement requirements, to which they added *“where allowed and feasible, we may attempt to provide you with prior notice before disclosing your information in response to such a request”*

Information may be anonymised such that it *“cannot reasonably be used to identify you”*

Images and Videos shared via Discord are scanned by PhotoDNA in efforts to detect then remove any CSAM alongside hashing and other techniques.

## TERMS OF SERVICE

Starts with standard arbitration clause and class-action waiver (applies to US & Canada based Discord users).

Minimum age of 13 to use the services.

Any content is the users, they grant Discord a licence for the purpose of providing, developing and improving their services. The licence is worldwide, non-exclusive, royalty free, sublicensable and transferrable.

Unlike a lot of other online services we have reviewed in this series so far, Discord does not have any term or policy relating to sex offenders not being permitted to use their platform, they do have a zero-tolerance approach to their community terms and standards.

## COOKIES

Discord do not state in any of their documentation the specific cookies they work with nor those of third parties they support beyond stating they are in the “strictly necessary, functional and performance” categories. This is very unhelpful for consumers, I’m not sure this level of lack of transparency alongside aforementioned vagueness is compliant with UK and EU GDPR regulations.

## ADDITIONAL CONSIDERATIONS

Discord state that audio and video calls on Discord are end-to-end encrypted by default.

## AGE VERIFICATION

To comply with recent legislation such as the UK Online Safety Act (OSA), Discord are introducing age verification requirements in order for users to use the service without any age related restrictions to their account.

This roll out is expected in the second half of 2026 according to a [9th February announcement from Discord](https://discord.com/press-releases/discord-launches-teen-by-default-settings-globally).

The globally phased roll out will apply to new and existing users, will involve a blanket switch to a *“teen default experience”* consisting of updated communication settings, restricted access to age-gated spaces and content filtering.

To remove the teen default experience will mean some may be required to engage in the age verification process. This will be either inferred age, or through the user submitting a copy of their Government issued ID to the verification partner, along with selfies in photo and video format.

Discord’s original partner for age verification was going to be Persona, that is no longer the case. Instead Discord are partnering with [k-ID](https://k-id.com/).

On a related but separate note; k-ID’s ISO’s and SOC 2 is audited by Prescient Security, powered by Vanta.

Why is this relevant? Some in the information security and cyber security space might be familiar with the recent very public fiasco relating to YC backed and AI powered compliance company Delve.

Prescient Security were one of the auditors for Delve’s higher profile clients, they made a public statement in late March 2025 to their LinkedIn business page stating they had *“formally disengaged from Delve in September 2025”*, and that they *“stand firmly behind the integrity, independence and rigour of our audit processes”.*

Loveable, Bland, Syskit, and others (customers who were audited and certified by Prescient Security), also released similarly worded public statements around the same time confirming Prescient Security as their auditor whilst seeking to distance themselves from Delve.

All of them appear since (viewable in public records) to have re-audited and re-certified through different auditors despite their certifications not being expired and allegedly sound.

Do you know how unusual that is? No company tends to willingly re-audit or recertify early with a second partner before their certifications have expired, let alone multiple with a shared prior auditor.

Anyway, key privacy protections of Discord's age-assurance approach include;

On device professing (they claim video selfies for age estimation never leave a users device).

Identity documents submitted to their vendor partners are *“deleted quickly”*

It is important to remember that any Goverment issued ID shared with any ID verification partner becomes subject to that partners privacy policies, and any partners they in turn work with to provide their service.

You can read more about the Discord age assurance roll out [here](https://discord.com/press-releases/discord-launches-teen-by-default-settings-globally) and [here](https://support.discord.com/hc/en-us/articles/33362401287959-Age-Assurance-for-UK-Users).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://privacy.perkinsfund.org/policy-and-terms-review-discord-communications-platform.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
