Dark Forge Automation uses information needed to provide, secure, support, and operate requested websites, dashboards, Discord bots, Custom Development Services, and community-safety workflows. We do not sell personal information. Privacy questions and requests may be sent to DarkForgeAutomation@protonmail.com.
Who and what this policy covers
This policy applies to Dark Forge Automation websites, dashboards, portals, downloads, Discord applications and bots—including Foundry and StormVault—Custom Development Services, support, hosting, and related services that link to this policy. Discord and other providers are separate services with their own policies. Customers and Discord server owners may also have responsibilities for information they direct Dark Forge to process.
Information we process
- Discord and account data: Discord user IDs, usernames, display names, server IDs, channel and role IDs, permissions, server settings, authorization records, and interaction records.
- Submitted content: support tickets, feedback, applications, reviews, project inquiries, safety reports, case notes, messages, uploaded files, and evidence.
- Safety and moderation data: reported account IDs, case references, evidence, review decisions, appeals, moderation actions, reasons, timestamps, assignments, threat indicators, Network Incident history, containment history, and audit records.
- Custom Development data: approved scope, Orders, acceptance records, Customer Materials, project working files, build artifacts, configuration, deployment information, repositories, and project communications.
- Credentials and delegated access: OAuth grants, scoped API keys, bot tokens, application secrets, service accounts, temporary credentials, repository access, hosting access, and other delegated permissions supplied when reasonably needed for a project or Service.
- Website inquiries: name, email address, optional Discord username, community size, service interest, and project details submitted through contact forms.
- Operational data: security events, access logs, errors, health information, entitlement status, backup metadata, and limited technical information needed to protect and operate Services.
- Business records: Orders, invoices, payments, accepted scopes, project acceptance, material scope changes, and other records reasonably needed for contracts, accounting, disputes, and legal obligations.
Do not submit personal-account passwords, payment-card numbers, government identifiers, medical records, illegal material, or information unnecessary for the requested workflow. Do not upload sensitive evidence to a public Discord channel. Customers must have authority to provide credentials, Customer Materials, and other data submitted for a project.
Why we use information
We use information to provide requested features and Custom Development, authenticate and authorize access, configure and deploy projects, route support, process applications and reviews, investigate safety reports, maintain auditability, coordinate authorized security activity, detect and prevent abuse, troubleshoot failures, process plan entitlements, communicate with users, maintain business records, comply with legal obligations, and protect Services and communities.
We do not use Discord data for unrelated behavioral advertising or sell personal information.
Custom Development access and credentials
Dark Forge requests only credentials and access reasonably necessary for agreed work. Where reasonably available, official OAuth, scoped API keys, service accounts, delegated or team access, temporary credentials, provider-supported collaborator access, and limited repository or hosting permissions are preferred over shared passwords.
Dark Forge uses Customer-provided access only as reasonably needed for the project or Service, restricts it to people who need it, avoids unnecessary duplication, and does not intentionally commit secrets to public repositories. Temporary local copies and access no longer reasonably needed are removed or revoked where practical, subject to security, dispute, backup, contractual, and legal requirements.
Customers should remove unnecessary collaborator access and rotate temporary or shared credentials after handoff or suspected exposure where appropriate. Customer credentials are separate from Dark Forge master infrastructure credentials and credentials belonging to other customers.
Customer choices and privacy requests
Where a workflow requests optional or sensitive information, the Service may ask for acknowledgement before submission. A person may decline optional information, although the related feature may not work. A private review does not authorize public testimonial publication without separate confirmation.
Depending on applicable law and the nature of the record, a person may request access, correction, deletion, restriction, objection, withdrawal of consent, or a copy of personal information by emailing DarkForgeAutomation@protonmail.com. Dark Forge may need to verify the requester and coordinate with a Discord server owner or Customer that controls community data.
A request does not automatically require immediate deletion of every record. Some records may involve other people or communities, shared security history, active investigations, audit integrity, fraud prevention, contractual obligations, or legal requirements. Dark Forge will evaluate requests under applicable law and will not rely on this policy to deny a right that cannot lawfully be denied. No general downloadable evidence or security-record export feature is promised.
Retention guidelines
Dark Forge aims to keep information long enough for the purpose for which it was collected, support, safety review, appeals, security, abuse prevention, accountability, contracts, and legal obligations without retaining it indefinitely. A documented hold, active investigation, unresolved safety matter, fraud review, dispute, backup lifecycle, contractual requirement, or law may require longer retention.
| Record type | Default retention | After the period |
|---|---|---|
| Custom Development working materials | Up to 90 days after project completion or formal inactive archival | May be deleted unless still needed for an approved purpose, dispute, security, backup, contract, or law |
| Customer credentials and temporary access | Only while reasonably needed for the project or Service | Remove or revoke where practical; rotate Customer-controlled credentials where appropriate |
| StormVault reports and case records | While active; then 24 months after closure or archival | Delete or de-identify unless a documented hold or another lawful need applies |
| StormVault evidence files | While the case is active; then 12 months after closure | Secure deletion, subject to safety, dispute, or legal hold |
| Foundry support tickets and transcripts | 180 days after closure | Delete attachments and transcript content; retain minimal operational records if reasonably needed |
| StormVault support and security communications | While needed for support, cases, security, audit, or dispute handling | Delete, de-identify, or retain only a limited record under the applicable security and legal basis |
| Staff applications | 12 months after the final decision | Delete answers and attachments unless an ongoing documented relationship or lawful need applies |
| Feedback and private reviews | 12 months after submission or moderation | Delete or anonymize unused submissions; approved public reviews remain until withdrawn or removed |
| Audit, security, threat, and access logs | 24 months | Delete or aggregate when no longer needed for security, fraud prevention, audit, or accountability |
| Orders, invoices, acceptance, and business records | As reasonably needed for contracts, accounting, taxes, disputes, and legal obligations | Delete or minimize when no longer lawfully needed |
| Backups | Until the applicable backup rotation completes, targeted at 90 days | Deleted active data may remain in protected backup copies until rotation |
These are operating guidelines, not promises of exact deletion on a particular day. Custom Development retention does not require deletion of reusable Provider Materials or create permanent project backup. Business records, credentials, StormVault security data, and managed-product data have separate purposes and lifecycles.
StormVault downgrade and cancellation
An ordinary plan downgrade or paid-plan cancellation does not automatically erase legitimate cases, evidence, appeals, audit history, support messages, threat detections, containment history, authorized Network Incident history, or other security records. Existing evidence is not automatically deleted because a lower plan limits new evidence.
Premium configuration may be preserved where safe while premium execution becomes disabled or read-only. During an applicable seven-calendar-day downgrade grace period, historical records and excess ordinary snapshots are not immediately purged solely because the lower plan has a smaller limit. After grace, eligible ordinary snapshots may be reduced through normal retention while protected, incident, pre-restore, active-recovery, security-required, or audit-required snapshots may follow a separate lifecycle.
Downgrade retention remains limited by the retention schedule, authorization, lawful deletion obligations, security and audit needs, disputes, and applicable law. It is not a promise of permanent storage.
Server deregistration, account or organization deletion
Server deregistration may disable monitoring, protection, Safety Network participation, new snapshots and recovery, notifications, and operational access after a safe technical transition. It does not automatically erase cases, evidence, appeals, audit history, detections, Network Incident history, support records, snapshots, or recovery history. Those records enter their applicable retention and deletion lifecycle.
Organization or account deletion must not indiscriminately delete another organization's private records, shared Network Incident history, records required for security or audit integrity, legally retained material, or information affecting another person's or community's rights. The requester may lose operational access while eligible organization-owned contributions may be corrected or withdrawn through an authorized process.
Re-registering a server does not guarantee restoration of every previous configuration, entitlement, snapshot, recovery record, or Safety Network state.
Safety Network and Network Incidents
Safety Network participation is opt-in for active participating communities. Network coordination may use authorized account or domain indicators, incident notices, participation records, and anonymous or attributed information according to settings and workflow. Private evidence, reporter identity, private cases, and internal staff notes are not automatically shared.
Free and Silver communities may receive privacy-safe safety warnings where current StormVault policy permits. Gold is required for active Safety Network participation. Ending Gold or leaving the Safety Network stops new participation and coordination actions after a safe transition but does not automatically erase authorized historical or audit records.
A participating community may raise a good-faith concern about inaccurate, outdated, misattributed, or improperly shared information. Dark Forge may review, correct, withdraw, or annotate eligible information and preserve an appropriate restricted audit history of the original event and later action. One community cannot use correction or deletion to rewrite another community's private records.
Security, fraud, and Service termination
Dark Forge may preserve limited records reasonably needed to investigate serious prohibited use, malicious reporting, fraud, credential compromise, unauthorized access, security-tool abuse, disputes, or threats to customers or systems. Suspension or termination does not authorize indiscriminate destruction of Customer Data or indefinite retention without a legitimate basis.
When a material credential or data-security incident is identified, Dark Forge will investigate, take reasonable containment and remediation steps, and provide notice where appropriate and required by applicable law. This policy does not promise a fixed notification deadline beyond requirements that apply by law.
Service discontinuation and business wind-down
If StormVault or another Service is permanently discontinued, active bots, dashboards, protection, Safety Network operations, snapshot creation, recovery, support, or hosting may cease. Where reasonably practical, Dark Forge will evaluate which data can lawfully and technically be made available, which records must remain for a limited lawful purpose, and what deletion or backup-rotation process applies. This does not promise a currently unsupported export system.
If Dark Forge ceases operations, similar data-minimization, security, lawful-retention, and deletion principles apply where legally and practically possible. No continuity or recovery beyond Dark Forge's lawful and practical ability is guaranteed.
Sharing and service providers
Information may be processed by Discord; hosting, infrastructure, database, backup, monitoring, repository, deployment, email, support, media, API, and payment providers; and professional advisers where reasonably needed to provide or protect a Service. Providers may process information in countries other than the user's own and operate under their own terms and privacy practices.
Dark Forge does not sell personal information. Information may be disclosed when authorized by the Customer or user, required by law, reasonably necessary to protect users or systems, or involved in a business transfer with appropriate safeguards.
Security
Dark Forge uses measures such as access controls, least-privilege permissions, protected dashboards, private staff areas, secret management, encrypted connections where supported, backups, monitoring, and audit records. No system is perfectly secure. Suspected exposure or abuse should be reported promptly to DarkForgeAutomation@protonmail.com.
Children
Services are not directed to children below the minimum age required by Discord or applicable law. Dark Forge does not knowingly solicit information from children in violation of applicable requirements. Contact us if you believe a child submitted personal information so it can be reviewed and deleted where appropriate.
International processing and legal rights
Depending on where a person lives, applicable law may provide rights to access, correct, delete, restrict, object to, or receive a copy of personal information and to complain to a data-protection regulator. Nothing in this policy limits rights that cannot lawfully be limited.
Changes and contact
Dark Forge may update this policy when Services, providers, practices, or legal requirements change. Material changes will receive notice appropriate to the change and applicable law and will be posted with updated effective-date information.
Privacy questions and requests may be sent to DarkForgeAutomation@protonmail.com.