Rank Rascal Privacy Policy
Effective Date: August 14, 2026 | Version 1.0
1. Information We Collect
Rank Rascal collects minimal, necessary public identifiers to provide Roblox gaming identity integration on Discord:
- Discord Account Data: Your Discord User ID, Guild (Server) ID, and channel context.
- Roblox Identity Data: Verified Roblox User ID, Roblox username, display name, account creation timestamp, public avatar thumbnail URL, public badge count, and public profile visibility setting.
- Rank Rascal Calculated Data: Rascal Rep score, Rotfile achievements, and server-specific preferences.
- OAuth Processing Data: Short-lived, state-hashed authorization verifiers during PKCE verification.
2. Token Retention Policy
We prioritize zero-token retention. After verifying your Roblox identity through PKCE OAuth 2.0, short-lived authorization tokens and access tokens are immediately discarded. We do not retain or store your Roblox OAuth access tokens, refresh tokens, or passwords.
3. Purpose of Processing
Collected data is processed strictly for:
- Rendering Rotfile identity cards and Drip Inspections in Discord channels
- Calculating server leaderboards and badge milestones
- Enforcing opt-in privacy controls and server-manager configuration settings
4. Deletion & /unlink-roblox Behavior
You hold total control over your data. Running /unlink-roblox in Discord instantly and permanently purges your stored Roblox account link, public profile references, and associated Rascal Rep from our database.
5. Public Profile Visibility & Witness Protection
By default, public profiles are visible on server leaderboards. Running /witness-protection enabled:true hides your profile from server leaderboards (/yapping-order) and rival checks (/fraudcheck).
6. Children & Discord 13+ Requirements
Rank Rascal is strictly intended for users aged 13 and older in compliance with Discord Terms of Service and COPPA. We do not knowingly collect data from children under 13.
7. Security Controls & Third-Party Platforms
Rank Rascal implements parameterized database statements, HTTPS encrypted transport, and state-hashed PKCE verifiers.
8. User Rights & Contact Information
For privacy inquiries, manual data export, or deletion requests, contact our privacy team:
Email: bayitanviraditya@gmail.com
