Privacy Policy

Effective date: August 9, 2026 · Applies to USMBOT and this site (hq.jsglow.name)

1. Who operates this service

USMBOT is independently operated. It is not a registered company, and this policy is written on that basis rather than pretending otherwise. It is not affiliated with, endorsed by, or sponsored by Roblox Corporation, Discord Inc., the United States Department of Defense, or any branch of the United States Armed Forces. References below to "we," "us," or "the service" mean the individual(s) operating USMBOT.

2. Information we collect

We collect only what is needed to verify account ownership and administer the Discord communities that use USMBOT:

What we do not collect

  • Discord or Roblox account passwords — authentication happens entirely on Discord's and Roblox's own systems
  • Payment card or financial account information
  • Roblox inventory, avatar assets, private messages, or friends list
  • Government-issued identity documents
  • Precise device location

3. Roblox OAuth data specifically

When a member chooses to verify with Roblox, we request the OAuth scopes openid and profile from Roblox. In return, Roblox provides us with:

This exchange happens over a server-to-server request using an authorization code that Roblox issues after the member approves the request on Roblox's own page. If the OAuth scopes this service requests ever change, this policy will be updated to accurately reflect them before the change takes effect.

4. Discord data specifically

USMBOT operates as a Discord bot, which Discord's platform gives access to standard bot-scoped data for servers it is added to: user IDs, usernames, display names, role membership, and message content only where a command explicitly requires it (e.g., reading the arguments of a slash command). We do not read or store the general message history of a server.

5. Why we collect it

6. How information is used

Collected information is used to operate verification and role-sync features, to display membership/verification status to authorized server staff, and to maintain the integrity of the community. It is not used for advertising, is not analyzed to build behavioral profiles, and is not used for any purpose unrelated to operating the service.

7. Data retention

Verification links between a Discord account and a Roblox account are retained for as long as the link is active, and for a reasonable period afterward for security, dispute-resolution, and audit purposes, after which inactive records may be purged periodically. Audit and administrative history tied to a member's record is retained longer than the live verification link itself where retaining it serves a legitimate security or accountability purpose — for example, records of who approved a rank change. We do not commit to an exact universal retention window because it depends on record type; specific retention questions can be directed to the contact method below.

8. Data security

We apply reasonable technical safeguards: HTTPS-only transport, secrets and credentials kept server-side and out of client-facing code, database access restricted to the service itself, and OAuth state validation to prevent forged callbacks. That said, no online service can guarantee perfect security, and we do not claim ours is unbreakable. If a security incident affecting personal data occurs, we will take reasonable steps to investigate, contain it, and notify affected server administrators.

9. Where data is stored

Data is stored in a database operated on infrastructure controlled by the service operator, not on end-user devices, and not in any Discord message content. Backups, where they exist, are subject to the same access restrictions as the primary database.

10. We do not sell your information

We do not sell, rent, or trade personal information to third parties for marketing or any other purpose.

11. Third-party services we rely on

We do not use third-party advertising networks, analytics trackers, or session-replay tools on this site.

12. Cookies

This informational site (hq.jsglow.name) does not set tracking or advertising cookies. If a session cookie is ever introduced for an authenticated administrative area, it will be limited to what is strictly necessary to keep that session secure (e.g., marked HttpOnly and Secure), and this policy will be updated accordingly.

13. Logs

Standard web server access and error logs are kept for operational troubleshooting and abuse prevention. These logs are not used to build user profiles. We do not log OAuth authorization codes, access tokens, Discord bot tokens, Roblox client secrets, API keys, or passwords in plaintext.

14. Children's privacy

This service is intended for use in accordance with Discord's and Roblox's own minimum age requirements and terms of service. We do not knowingly direct this service at children below the age thresholds those platforms set, and we do not knowingly collect more information from a minor than that platform's own use of the service already involves. If you believe a minor's data has been collected in a manner inconsistent with this policy, contact us using the method below and we will review it.

15. Your rights & deletion requests

You may request a copy of, correction to, or deletion of the verification/account-link data associated with your Discord or Roblox account. See the dedicated Data Deletion page for the full process, what can and cannot be deleted, and identity-verification requirements for such requests.

16. Contact

Questions about this policy can be sent through the method listed on our Contact page.

17. Changes to this policy

We may update this policy as the service changes. Material changes will update the effective date above. Continued use of the service after a change takes effect constitutes acceptance of the revised policy.