This Privacy Policy describes how Clear ("we", "us", "our") handles personal data through the Clear Discord bot and its web dashboard (the "Service"). When a server administrator directs Clear to verify a member, we act largely as a data processor carrying out that server's instructions and as an independent controller for limited purposes of our own — operating, securing, metering, and improving the Service, and complying with law. Server administrators are themselves responsible for having a lawful basis to request verification of their own members; see Section 4 of our Terms of Service.
/idcheck access to.We do not use verification data for advertising, and we do not sell personal data to third parties.
Didit — our identity verification provider. The document capture, liveness check, and face match happen directly on Didit's hosted verification page; Didit processes that data and returns a decision to us. Didit maintains its own data retention and deletion practices, described at docs.didit.me and its privacy policy at didit.me.
Discord — used for authentication (OAuth sign-in), role management, and delivering bot messages. See Discord's Privacy Policy.
We do not otherwise share personal data with third parties except as required by law or to protect the rights, safety, or property of the Operator, our users, or others.
An open verification link expires automatically 10 minutes after it is created if not completed, and the underlying Didit session is deleted roughly 15 minutes after that. A completed verification's decision data and document images are archived in our database so the requesting server's administrators can review it later; images are served only to authorized administrators of that server. A server administrator (or a full-access administrator of the Service) can permanently delete any verification record, including its archived images, from the dashboard at any time — this cannot be undone. We also periodically purge stale, never-completed sessions.
We retain a server's configuration and usage/billing history for as long as Clear remains installed in that server (or as needed for legitimate business/legal purposes after removal), and dashboard sign-in sessions expire automatically after 7 days.
The dashboard is gated behind Discord OAuth login; access to a server's data is scoped to administrators of that specific server (or the Service's full-access administrator). Session cookies are httpOnly and never exposed to client-side scripts. Webhook events from Didit are authenticated with an HMAC signature and a timestamp window to prevent replay or forgery. API keys and other secrets are kept server-side and are never sent to the browser. No method of storage or transmission is 100% secure, and we cannot guarantee absolute security.
Clear exists to help Discord servers enforce their own age requirements, which necessarily means some verification attempts will come from users who do not meet a server's minimum age — that is the expected outcome of a failed check, not a violation of this policy. That said, the Service is not directed at children, and use of Discord itself is subject to Discord's own minimum age requirements. If you believe a child's data has been submitted to us in a manner inconsistent with applicable law, contact us using the details in Contact and we will take appropriate action, which may include deleting the record.
Our infrastructure and our sub-processor Didit may process and store data in countries other than your own, including the United States and countries within the European Economic Area. Where required, we rely on appropriate safeguards for such transfers.
Depending on your location, you may have rights to access, correct, or request deletion of your personal data. For data submitted through a specific server's /idcheck, the fastest path is usually that server's administrator, who can delete the record directly from the dashboard. You can also contact us directly using the details in Contact, and we will route or fulfill the request as appropriate. You may decline to complete any verification request at any time.
The Service does not currently process payments directly. If paid plans are enabled in the future, payment card and billing details will be collected and processed by a third-party payment processor (currently planned to be Stripe) under that processor's own privacy policy — we do not store full payment card numbers ourselves.
We may update this Privacy Policy from time to time. We will revise the "Last updated" date above when we do, and material changes will be reflected here.
Questions, requests, or concerns about this Privacy Policy can be sent to majorsboy1@gmail.com.