Privacy Policy
Effective: 08/20/2026 (v3)
Overview
identities.dev (the "Site") is operated by Silver Dev Studios (an unregistered, non-trademarked project) and operated in California, USA. This Privacy Policy explains what information the Site collects, how it is stored, and the choices you have. The Site lets you build a profile from visual blocks; some features require a Discord account.
What we collect
- Discord profile data. When you sign in with Discord, the Site receives your Discord user ID, username, display name, and avatar URL via Discord OAuth2. This is used to identify you and to author your profile.
- Email & password (local accounts). If you create an email/password account, the email, username, and a salted PBKDF2-SHA-256 password-derived hash are stored only in your browser's local storage. The salt is a cryptographically random value generated per account. The plaintext password is never sent to the server or written to any file or service.
- Profile content. The text, links, images, and configuration you add to your profile.
- Uploaded images. Images you upload are downscaled and stored as data URLs in your browser's local storage so you can reuse them.
- Legal-consent records. When you accept the Terms and this Privacy Policy, the Site records the document versions you accepted and the date/time of acceptance, tied either to a browser-generated anonymous id or, if you're signed in, to your Discord id/username. This log is kept to demonstrate that consent was given.
Where your data lives
- Your browser. Your session, local accounts, in-progress profiles, and uploaded images are stored in
localStorageon your device. The Site does not run a profile database for unpublished work — clearing your browser storage removes it. - Published profiles. When you publish a profile, its content (title, generated code, block tree, Discord ID, and an "updated" timestamp) is committed to a private GitHub repository. Although the repository is private, the Site serves published profiles publicly through its API, so anyone with the profile URL (
/u/<username>) can view a published profile. Do not put sensitive personal information in a published profile. - Public information can escape our control. Anything you intentionally publish in a profile is public information: other users can view, copy, cache, screenshot, or share it, and it may remain accessible through third-party caches, archives, screenshots, or other copies that we do not control. Publish only what you're comfortable making public.
What the server sees transiently
During the Discord sign-in flow, your Discord access token is exchanged server-side so the Site can fetch your profile once. Standard request logs (which may include your IP address) may be produced by the hosting provider (Render), and the application itself may generate logs (for example request or error logs). These logs are used for security, abuse prevention, debugging, and service reliability — not for advertising or behavioral profiling. Log retention is determined by our configuration and the hosting provider's available retention controls.
Third parties
- Discord — authentication and avatar delivery (Discord's CDN). Subject to Discord's own Privacy Policy.
- GitHub — stores published profiles in a private repository.
- Render — hosts the Site, including its request logs.
The Site does not use advertising or third-party analytics trackers.
Discord data & Developer Policy compliance
The Site uses Discord's API under Discord's Developer Terms of Service and Developer Policy. Discord end-user data we receive (your user ID, username, display name, avatar, and — only for users who share a guild with our Bot — live presence) is used solely to provide the Site's features: signing you in, attributing authorship of profiles, rendering live presence blocks you build, and answering the Bot's slash commands.
- We do not sell, rent, trade, or monetize Discord end-user data, and we do not use it for advertising or profiling.
- We keep only the Discord data the Site needs (your ID/username/avatar, and presence for shared-guild users) — no bulk collection.
- Received vs. stored vs. transient. Your Discord ID is stored with a published profile; your username, display name, and avatar are used to sign you in and to author your profile; live presence (shared-guild users) is held in the Bot's memory only; your Discord OAuth access token is used transiently during sign-in and publishing and is not stored server-side; and slash-command invocations are processed to respond to the command. No other Discord data is persisted.
- How presence flows. The Bot connects to Discord's gateway and holds presence for shared-guild users in memory only; the Site's public presence API serves whatever the Bot currently holds; and a profile page (your browser) fetches it from that API. We don't log or persist presence.
- Why we store your Discord ID in published profiles. The Discord user ID is a stable identifier that connects a published profile to its Discord account; it is used only for features that need it (authorship attribution, live presence blocks, and the Bot's
/profilescommand). - To have us delete Discord data associated with you: delete your published profiles from the editor, revoke the application in your Discord authorized-apps settings, and/or email info@identities-dev.com. We honor deletion requests as required by Discord's Developer Policy and applicable law. Deleting a profile removes it from the active repository and public API; residual copies may remain in backups or logs only where necessary for security, legal, or operational purposes.
Your choices
- Clear your browser's
localStorageto remove your local session, accounts, and unpublished profiles. - Delete a published profile from within the editor, which removes it from the active repository and the public API (subject to the backup/log exception above).
- Revoke the identities.dev application from your Discord authorized apps to disconnect sign-in.
Security
Local account passwords are salted and hashed in your browser with PBKDF2-SHA-256 before storage and are never transmitted in plaintext. Because local accounts live in your browser's localStorage, any script running in the Site's origin could potentially access them — browser storage is inherently less protected than a server-side credential store. Losing your local credentials (clearing browser data, switching devices) can permanently lose access to a local account, since we never receive your password. No method of transmission or storage is fully secure, and we cannot guarantee absolute security.
Retention
- Local browser data (session, local accounts, unpublished profiles, uploaded images) — kept until you clear your browser storage.
- Published profiles — kept until you delete them or they are removed under the Terms of Service.
- Moderation flags & records — kept while needed to enforce the Terms and operate the appeals process.
- Legal-consent records (version + acceptance timestamps) — kept while the service operates, to demonstrate when and which documents you accepted.
- Server/hosting logs (which may include IP addresses) — retained according to our configuration and the hosting provider's available retention controls.
- Backups — deleted content may remain in backups until those backups rotate or are removed according to our operational needs.
Children under 13
The Site is not directed to children under 13, and we do not knowingly collect personal information from them. If we learn that we have collected personal information from a child under 13, we will take reasonable steps to delete that information and disable the associated account. Users aged 13–17 are welcome, but being allowed to use the Site does not mean a profile should contain sensitive personal information — published profiles are public, so think carefully about what you share.
Age
You must be at least 13 years old to use the Site; features that use Discord additionally require you to meet the minimum age Discord sets for your country, if higher. Where local law requires a higher age for consent to data processing, that higher age applies.
Content removal
The Site may remove content that violates the Terms of Service. See the Terms for the reporting, review, and appeal process.
Changes to this policy
We may update this Privacy Policy. When we do, the version id and "Effective" date above change, the prior text stays readable from the version history below, and the Site prompts you to accept the new version before you continue using it (until you accept, Site use is restricted). Accepting records the new version id and the acceptance time.
Contact
For questions about this policy, email info@identities-dev.com or reach out in the identities.dev Discord server.
Version history
- v3 · 08/20/2026 (viewing) Precision pass: received-vs-stored-vs-transient Discord data breakdown, public-information warning tied to uncontrolled copies, iteration count removed from the hashing description, application logs acknowledged, and a 13–17 caution added to the Children under 13 section.
- v2 · 08/20/2026 Review pass: PBKDF2 password-hashing description, public-information warning, IP-log purpose, presence-flow & Discord-ID purpose explanations, backup-aware deletion, itemized retention, a Children under 13 section, and age rules aligned with the Terms.
- v1 · 08/19/2026 First published Site Privacy Policy.