REALIES HQ • PRIVACY

Privacy Policy

Effective Date: September 20, 2026 · Last Updated: September 20, 2026

YOUR PRIVACY MATTERS.

This Privacy Policy explains how Realies HQ may collect, receive, generate, use, disclose, retain, secure, and otherwise process information through the Realies HQ website at https://realies.ttmdev.xyz/, the Discord verification system, the Realies HQ Discord bot, security tools, dashboards, and related services (collectively, the "Service").

The Service is intended for a private Discord community and is designed primarily for authentication, verification, access control, moderation support, fraud prevention, anti-raid protection, and Server security.

1. Scope

This Policy applies to information processed through the Realies HQ Service. It does not replace the privacy policies of Discord or other third-party services. When you use Discord, Discord may independently collect and process information under its own policies and contractual terms.

This Policy also does not govern information that Realies HQ does not control or information collected by third-party websites after you leave the Service.

2. Independent Third-Party Service

Realies HQ is an independent third-party service and is not owned, sponsored, endorsed, or operated by Discord Inc. Discord is a separate data controller or service provider for information it processes through its own platform, subject to Discord's applicable policies.

When you authenticate with Discord, Discord may process authentication and account information according to Discord's own privacy practices. Realies HQ receives only information made available through the applicable authentication flow and permissions.

3. Categories of Information We May Process

Depending on how you use the Service and the current configuration, we may process several categories of information.

3.1 Discord Account Information

This may include a Discord user identifier, username, display name, avatar-related information, account-related timestamps that can be derived from a Discord identifier, and information necessary to associate an authenticated account with a Server member.

3.2 Discord Server Membership Information

The Service may determine whether your Discord account is a member of the Realies HQ Server. For authorized administrative functionality, the system may also process information needed to determine whether a user has relevant administrative permissions.

3.3 Verification Information

The Service may create records showing whether an account has completed verification, when verification occurred, the Server associated with the record, and relevant technical security results.

3.4 Security and Risk Information

The Service may process security indicators such as account age, risk score, risk level, VPN indicators, proxy indicators, TOR indicators, duplicate indicators, anti-raid signals, quarantine status, verification status, and related security events.

3.5 Network Information

During website access, the Service may receive a network address such as an IP address from the user's connection or from infrastructure used to deliver the website. The Service may use network information for security, abuse prevention, troubleshooting, rate limiting, fraud prevention, and security classification.

3.6 Hashed IP Information

The current verification implementation is designed to store the IP address as a one-way cryptographic hash rather than as the original plain-text address in the verification record. A hash is not automatically anonymous and should still be treated as security-related information because it can be used as a consistency or duplicate-detection signal.

Hashing does not make information magically impossible to identify. The operator therefore does not represent that a hashed network value is anonymous in every legal or technical circumstance.

3.7 Logs and Technical Events

The Service may generate operational records such as authentication events, verification events, security events, role changes, errors, administrative actions, timestamps, request information, and system diagnostics.

3.8 Information You Voluntarily Provide

You may voluntarily provide information when communicating with Staff, reporting a problem, submitting a request, or interacting with a form. You should not provide passwords, authentication codes, payment-card information, government identification numbers, private keys, or other unnecessary sensitive information.

4. Information We Do Not Intend to Collect Through the Verification Form

The Realies HQ verification flow is not designed to request your Discord password, Discord recovery code, payment-card number, banking credentials, or government identification document.

If a person claiming to represent Realies HQ asks for such information, do not provide it. Use Discord's official account-security procedures and treat the request as potentially fraudulent.

5. How Information Is Collected

Information may be collected directly from your interaction with the Service, from Discord through an authorized authentication flow, from the Server's Discord environment, from technical infrastructure used to operate the website, from security systems, or from information you voluntarily provide.

Some information may be generated automatically as a consequence of using the Service. For example, a verification timestamp, risk score, security record, or hashed network value may be created when you complete verification.

6. Purposes of Processing

We may process information for the following purposes:

  • Authenticate Discord accounts;
  • Confirm Server membership;
  • Complete member verification;
  • Assign or remove verification-related Discord roles;
  • Restrict access for unverified or quarantined accounts;
  • Detect and reduce raids, spam, abuse, and account cycling;
  • Identify technical security signals;
  • Calculate security risk indicators;
  • Maintain security and moderation records;
  • Investigate suspected abuse;
  • Prevent unauthorized access;
  • Maintain service reliability;
  • Diagnose technical failures;
  • Enforce the Terms of Service and Server rules;
  • Comply with applicable law and valid legal requests;
  • Establish, exercise, or defend legal claims;
  • Protect users, Staff, the Server, the Service, and third parties; and
  • Maintain and improve the security architecture.

7. Security and Fraud Prevention

The Service is specifically designed to process certain information for security purposes. This means that information that might be unnecessary for an ordinary website may be necessary for a private Discord security system.

For example, a security system may need to determine whether the same technical network signal has appeared across multiple verification events, whether a newly created Discord account has characteristics associated with elevated risk, or whether a join pattern resembles a coordinated raid.

Security processing is intended to reduce risk. It does not establish criminal conduct, identity, intent, or personal character.

8. VPN, Proxy, and TOR Detection

The Service may compare a network address against locally maintained CIDR lists or other technical security data. A match may result in a VPN, proxy, or TOR indicator being recorded.

These checks are imperfect. Network providers change addresses, privacy services change infrastructure, shared networks can create false positives, and not every service is detectable. The absence of a match does not mean that a connection is definitely not a VPN, proxy, or TOR connection.

The Service does not represent that network classification is a definitive identity or location determination.

9. Automated Risk Processing

The Service may automatically calculate a risk score from configurable signals. The score may be used to determine whether additional restrictions or quarantine are appropriate.

Automated processing may consider factors such as account age, VPN status, proxy status, TOR status, duplicate indicators, raid indicators, or other security events. The exact formula and thresholds may change as the security system evolves.

An automated score is not a legal determination, criminal-history determination, credit score, identity score, or statement that a person is dangerous or dishonest.

10. Automated Decisions and Human Review

Some access-control actions may be performed automatically. Depending on the configuration, a user may receive an unverified role, quarantine role, verified role, or restricted access without manual review.

Authorized Staff may be able to review or change certain automated results. However, not every automated action necessarily receives individual human review before it occurs.

Where applicable privacy law grants a specific right concerning solely automated decisions with legal or similarly significant effects, the operator will address that right according to the applicable law and circumstances.

11. Discord OAuth2 and Permissions

Realies HQ may use Discord OAuth2 to authenticate users. The application may request scopes necessary to identify the account and confirm Server membership or other required information.

OAuth authorization does not give Realies HQ your Discord password. You authenticate with Discord itself.

Discord independently processes authentication information. Review Discord's current privacy policy and authorization interface for information about Discord's own processing.

12. Cookies and Sessions

The website may use session technology to remember that a user has authenticated. Session information may be stored using a server-side session mechanism and may include a session identifier or authentication state.

Cookies or similar technologies may be required for login, security, session continuity, and protection against unauthorized use. Disabling cookies may prevent authentication or verification from functioning.

The Service is not intended to use cookies for third-party behavioral advertising under the current implementation.

13. No Sale of Personal Information for Advertising

The current Realies HQ implementation is not designed to sell personal information or share personal information for cross-context behavioral advertising.

The Service is a private security and verification system rather than an advertising platform. If this changes, the operator should update this Policy and implement any legally required notice and opt-out mechanisms before the changed practice begins.

14. Service Providers

We may use infrastructure providers to host the website, database, application, authentication sessions, logs, or related components. Providers may process information on our behalf as necessary to provide infrastructure and technical services.

Examples may include cloud hosting, database hosting, reverse proxies, security infrastructure, monitoring, or email/notification infrastructure if introduced in the future.

Service providers are expected to receive only information reasonably necessary for the services they provide, subject to the actual provider configuration and applicable law.

15. Discord as a Third Party

Discord may process information independently when you use Discord, including information associated with your account, communications, devices, and use of Discord. Realies HQ does not control Discord's internal data practices.

A Realies HQ verification page should never be interpreted as replacing Discord's privacy documentation.

16. Legal Disclosures

We may disclose or preserve information when reasonably necessary to comply with valid legal process, applicable law, court orders, subpoenas, governmental requests, regulatory requirements, or other legally enforceable obligations.

We may also disclose information where reasonably necessary to protect the rights, safety, security, or property of the Service, Server, users, Staff, or third parties, subject to applicable law.

Where legally permitted, the operator may evaluate the scope and validity of a legal request before producing information.

17. Security Incidents

If a security incident occurs, the operator may investigate affected systems, contain the incident, preserve relevant evidence, reset credentials or sessions, improve controls, and provide notices where required by applicable law.

Because legal notification obligations depend on jurisdiction, information involved, the nature of the incident, and applicable statutory definitions, the operator will determine notification obligations based on the law applicable to the incident.

18. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted by law.

Retention periods may differ by category. Verification records may need to remain available to preserve the integrity of access-control history. Security records may need to remain available to investigate repeated abuse, account cycling, raids, fraud, or security incidents. Legal records may need to be retained to establish or defend claims.

Retention is not necessarily measured from the date a user leaves the Discord Server because certain security or legal purposes may continue afterward.

19. Backups and Disaster Recovery

Deleted or expired information may remain temporarily in encrypted or access-controlled backups where immediate deletion is technically impracticable. Backup copies may be overwritten according to the backup lifecycle.

Backups are not intended to be used for ordinary operational access after information has been deleted from the active system unless necessary for restoration, security, legal, or disaster-recovery purposes.

20. Data Deletion

Where applicable law provides a deletion right, the operator may delete information subject to legal and security exceptions.

Deletion may not require immediate removal from every technical system. Information may remain temporarily in backups, audit logs, security records, legal files, fraud-prevention records, or other systems where retention is permitted or required by law.

Some information may be retained in a minimized form to record that a security event occurred, prevent repeated abuse, establish or defend legal claims, or comply with law.

21. Data Minimization

The Service is designed to process information relevant to its security and verification functions. We do not intend to collect unrelated personal information merely because it is available.

Users should avoid voluntarily submitting unnecessary sensitive information. If a user submits information that the Service does not need, the operator may delete or otherwise handle it according to applicable law and operational requirements.

22. Data Accuracy

Some information may come from third parties, automated systems, or technical classification lists and may therefore be inaccurate or incomplete.

We do not guarantee that every security signal is correct. A user may be associated with a shared network, mobile carrier, corporate network, VPN, proxy, privacy service, or other infrastructure that affects technical classification.

23. Security Measures

Depending on the deployment, reasonable technical and organizational safeguards may include access controls, role restrictions, encrypted transport, protected environment variables, session controls, database access controls, authentication protections, logging, backups, least-privilege practices, software updates, and administrative restrictions.

No security system can guarantee absolute protection. Threat actors may discover vulnerabilities, providers may experience incidents, credentials may be compromised, and infrastructure may fail.

24. Access to Security Records

Security records are intended for legitimate operational and security purposes. Access may be restricted to authorized Staff or systems with a legitimate need to access the information.

Security records should not be publicly redistributed, sold, posted as public profiles, or used for unrelated purposes. Nothing in this Policy prevents disclosure that is required or permitted by law.

25. International Processing

The operator or its service providers may process information in the United States and other countries. A user accessing the Service from another country acknowledges that information may be transferred to jurisdictions with different privacy laws.

Where applicable law requires specific transfer safeguards, the operator intends to use an appropriate legally recognized mechanism.

26. U.S. Privacy Framework

United States privacy obligations vary by state, business size, revenue, data practices, thresholds, exemptions, and the type of information involved. This Policy is intended to provide a broad description of Realies HQ information practices while recognizing that not every U.S. privacy statute necessarily applies to every operator or user.

Where a privacy law applies, the operator will comply with the rights and obligations applicable to the relevant processing activity.

27. California Privacy Rights

Where the California Consumer Privacy Act, as amended, applies, California residents may have rights that can include rights to know or access information, delete information, correct inaccurate information, obtain certain information in a portable format, and opt out of certain sales, sharing, targeted advertising, or certain profiling activities where applicable.

These rights are subject to statutory exceptions and verification requirements. Not every right applies to every category of information or every business.

The current Service is not intended to sell or share personal information for cross-context behavioral advertising. If that changes, the operator should revise this Policy and implement applicable controls.

28. State Privacy Rights Beyond California

Residents of states with comprehensive privacy laws may have additional rights depending on the applicable statute. These may include rights to access, correct, delete, obtain a copy of data, opt out of targeted advertising or certain profiling, limit certain sensitive-data processing, or appeal a denied privacy request.

The availability of a particular right depends on the applicable law and whether the operator and processing fall within that law's scope.

29. Verification of Privacy Requests

Where a law provides an individual privacy right, the operator may take reasonable steps to verify the identity or authority of the person making the request. Verification may be more rigorous for requests that could expose, modify, or delete sensitive information.

Users should not include passwords, authentication codes, payment-card numbers, or government identification documents in an ordinary privacy request unless a legally required secure verification process specifically requests such information.

30. Authorized Agents

Where applicable law permits an authorized agent to make a privacy request on behalf of a consumer, the operator may require evidence of the agent's authority and may independently verify the consumer's identity as permitted or required by law.

31. Appeals

Where applicable law provides a right to appeal a decision concerning a privacy request, the operator will provide an appeal process consistent with that law. An appeal should identify the original request and the reason the requester believes the decision should be reconsidered.

32. Universal Opt-Out Signals

Where a U.S. state law requires recognition of a browser-based universal opt-out mechanism and the requirement applies to the Service, the operator will implement the mechanism to the extent required by applicable law and supported by the website's technical environment.

33. Sensitive Information

The Service is not designed to intentionally collect sensitive information such as precise medical information, financial account credentials, passwords, or government identity documents through ordinary verification. If sensitive information is voluntarily submitted, it may nevertheless be processed incidentally and handled according to applicable law.

34. Children's Privacy

The Service is not directed to children under 13 and we do not knowingly solicit personal information from children under 13. Discord may impose additional age requirements depending on jurisdiction.

If we become aware that information from a child under 13 has been collected through the Service in circumstances where collection was not permitted, we may take reasonable steps to delete it subject to applicable law.

35. Third-Party Links

The website may link to Discord or other third-party services. We do not control third-party privacy practices. A link does not mean that Realies HQ adopts the third party's privacy policy.

36. Corporate Transactions

If the Service is involved in a merger, acquisition, financing, restructuring, sale of assets, bankruptcy proceeding, or similar transaction, information may be transferred as part of the transaction subject to applicable law.

37. Security and Anti-Abuse Records After Server Departure

Leaving the Discord Server does not necessarily require immediate deletion of every security record. Limited records may be retained when reasonably necessary to investigate prior abuse, prevent repeated account cycling, maintain security integrity, establish or defend legal claims, or comply with law.

Retention for these purposes does not mean that the user remains a Server member or that the information is made publicly available.

38. Fraud Prevention and Abuse Prevention

Security records may be used to detect repeated verification attempts, coordinated attacks, automated abuse, fraudulent behavior, account cycling, impersonation, or other activity that threatens the Service or Server.

These systems may produce false positives or false negatives. The operator may prioritize protection of the Server while maintaining procedures for appropriate review or correction where available.

39. No Absolute Security Guarantee

We take reasonable measures appropriate to the Service, but no Internet-connected system can guarantee absolute security. Risks include unauthorized access, compromised credentials, malware, software vulnerabilities, infrastructure failure, provider incidents, human error, misconfiguration, and sophisticated attacks.

40. Privacy by Design Intent

The Service is intended to use the minimum technical information reasonably necessary for verification and security. The implementation may use pseudonymous identifiers, role-based access, hashed network values, and restricted administrative access where appropriate.

Privacy by design is an operational goal, not a guarantee that no personal information will ever be processed.

41. Data Processing Changes

If the Service introduces new data categories, analytics, advertising, materially different profiling, new authentication providers, new security providers, or substantially different retention practices, this Policy should be reviewed and updated before or when the change becomes effective, as required by applicable law.

42. Accuracy of Public Privacy Statements

This Policy is intended to describe the actual Service. The operator should not use this Policy to claim that information is never collected, never disclosed, always encrypted, permanently deleted, anonymous, or otherwise treated in a manner that the technical implementation does not support.

If an implementation changes, the operator should update the Policy so that public statements remain materially accurate.

43. Changes to This Privacy Policy

We may update this Policy when the Service changes, laws change, security practices change, providers change, or additional processing is introduced. The revised version will be posted on this page with an updated Last Updated date.

Where applicable law requires notice, consent, or another procedure for a material change, the operator will follow the applicable requirement.

44. No Contractual Waiver of Mandatory Privacy Rights

Nothing in this Policy is intended to waive, restrict, or eliminate a privacy right that applicable law makes non-waivable. Where a statutory requirement conflicts with a statement in this Policy, the mandatory legal requirement controls to the extent of the conflict.

45. Interpretation

Headings are provided for convenience. References to information include information in digital, electronic, or other forms. References to laws include amendments and successor laws where applicable.

46. Retention Exceptions

Even where an ordinary operational retention period has expired, limited information may remain where necessary for security investigations, fraud prevention, legal obligations, litigation holds, backup restoration, audit integrity, incident response, or other purposes permitted by applicable law.

47. Law Enforcement Cooperation

We may cooperate with law enforcement and governmental authorities when required or permitted by law. We may preserve information in response to a lawful preservation request or other legally valid process.

48. Legal Claims and Evidence Preservation

Information may be retained where reasonably necessary to establish, exercise, or defend legal claims, investigate suspected unlawful conduct, preserve evidence, or protect the legal interests of the operator, users, Staff, or third parties.

49. No Sale or Advertising Profile Commitment

The Service is intended to function as a private verification and security system rather than an advertising or data-broker platform. Under the current implementation, security and verification information is not intended to be sold as a commercial identity profile or used to construct advertising profiles.

50. User Responsibility

Users are responsible for protecting their Discord account, avoiding disclosure of credentials, reviewing OAuth permissions before authorization, and using the Service through legitimate interfaces. Users should report suspected account compromise through appropriate Discord security channels.

51. Privacy Requests Do Not Automatically Override Security Requirements

A privacy request does not automatically require immediate deletion of information where retention is permitted or required for security, fraud prevention, legal compliance, legal claims, or another applicable exception. The operator will evaluate requests under the law that applies to the particular request.

52. Technical Limitations

Security systems may be affected by network address reuse, shared IP addresses, carrier-grade NAT, VPN gateways, proxies, mobile networks, cloud infrastructure, API limitations, stale intelligence lists, and incomplete third-party information.

Accordingly, technical security records should not be treated as conclusive proof of a person's identity, physical location, intent, or conduct.

53. No Promise of Perfect Detection

Realies HQ does not promise that every VPN, proxy, TOR relay, bot, alt account, raid, malicious actor, compromised account, or abusive user will be detected. Security controls are designed to reduce risk rather than eliminate risk.

54. Effective Date and Versioning

This version is effective September 20, 2026. Future versions may replace this version. Earlier versions may be retained internally where appropriate for legal, audit, or historical purposes.

55. Final Privacy Statement

Realies HQ is designed around a specific operational purpose: helping a private Discord community verify members and reduce security abuse. The Service may therefore process technical information that is reasonably connected to authentication, verification, fraud prevention, moderation support, and Server protection.

We intend to limit processing to legitimate operational purposes, apply reasonable security controls, and maintain public privacy statements that accurately describe the implementation. No policy can eliminate every privacy or security risk, and no technical security signal should be treated as infallible.

REALIES HQ • PRIVACY

This Privacy Policy should be read together with the Realies HQ Terms of Service. By using the Service, you acknowledge that you have had an opportunity to review both documents.