Privacy Policy
Last updated: September 27, 2026
This privacy policy explains what data unfurl ("the bot") collects, how it's used, and your options regarding that data.
In short: unfurl never stores your messages or the links in them. Links are fixed in memory and forgotten; only anonymous usage counters remain. What unfurl keeps is your server's settings, plus your user ID if you use /optout, so it knows to leave your links alone. Optional features are off by default. Repost detection, if an admin turns it on, keeps a hashed fingerprint of each link (never the link itself) with who posted it and when, and deletes it all shortly after the feature is turned off.
What we collect
When the bot processes a link
Nothing is stored. A link that matches a supported platform is fixed in memory and immediately forgotten: not the URL, not the message it was in, not who posted it, and not where. The only trace is an anonymous counter, like how many links were fixed for each platform.
Server information
So the bot can do its job, we store:
- The server ID
- Server settings configured through
/settings
If you use /optout
unfurl keeps your Discord user ID so it knows to leave your links alone. Running /optout enabled:false deletes it.
Optional features (off by default)
The following applies only if a server admin has explicitly turned the feature on. Nothing here is collected otherwise.
- Repost detection (
/settings repost), only when enabled: a hashed fingerprint of each link (never the link itself) plus the poster's user ID and where and when it was posted, kept for the number of days the admin chose (7 by default, up to 90); turning the feature off deletes all stored hashes at the next cleanup run, usually within 24 hours - Scam guard (
/settings scamguard), only when enabled: links are compared against public phishing-domain lists (Sinking Yachts, with FishFish as a backup) and Discord's own list of bad domains; nothing extra is stored - Replace mode (
/settings replace), only when enabled: unfurl deletes the original message and reposts its text with the fixed links; nothing is stored - Fix feed and curated channel (
/settings fixfeed,/settings curator), only when enabled: links are reposted into a channel the admin picks; nothing is stored
Reactions and DM forwarding
If DM forwarding is enabled (off by default), reacting 📥 on unfurl's reply sends you the link via DM. Nothing about the reaction or the DM is stored.
What we don't collect
- Message content
- The links themselves - fixed in memory, never written to disk
- Who posted what, where, or when (repost detection, when enabled, is the one exception)
- Direct messages
- Voice or media data
- Passwords, tokens, or authentication data
Third-party services
The bot may send URLs to these external services:
- Short URL services - to expand shortened links by following redirects
- archive.today and the Internet Archive (Wayback Machine) - to find an archived copy of a paywalled article
No user data beyond the URL itself is shared with these services.
Data retention
| Data type | Retention |
|---|---|
| Server ID and settings | Until you request deletion |
Your user ID, if you used /optout |
Until you opt back in |
| Anonymous usage counters | Indefinite (contain no personal data) |
| Repost detection hashes (only while enabled) | Admin-chosen window (7 days by default); all deleted within about 24 hours of turning the feature off |
When the bot leaves a server
If the bot is removed from your server, processing stops immediately. All that remains is your server's settings and, if repost detection was on, any hashes still inside their retention window - the hashes age out on their own, and the settings are deleted on request (see below).
Your rights
You can:
- Remove the bot at any time to stop all data collection
- Disable specific features (DM forwarding, embed suppression, individual platforms) via
/settings - Use channel whitelisting/blacklisting to control where the bot operates
- Request deletion of your server's data by contacting us
- Opt out entirely: run
/optout enabled:trueanywhere (it works from a DM too) and unfurl will never fix links you post, in any server./optout enabled:falseturns it back on. For a single link, prefix it with!.
Data security
Data is stored in a managed database with encryption at rest. Access is restricted to the bot operator. We don't sell, share, or monetize user data.
Children's privacy
The bot is not directed at users under 13. We don't knowingly collect data from children. If you believe a child's data has been collected, contact us for removal.
Changes to this policy
We may update this policy from time to time. Changes will be reflected on this page with an updated date. Continued use of the bot after changes constitutes acceptance.
Contact
For questions, data deletion requests, or concerns about this policy, join our support server or email .