Skip to content

Privacy Policy

What Qualia collects, who can see it, how long it is kept, and how to get a copy or delete it.

Last updated October 4, 2026

In short

  • You sign in with Discord. Qualia receives your Discord user ID, username, display name and avatar, and the list of servers you are in. From that list it keeps only the servers you own or manage. It does not receive your email address, messages or friends list.
  • Your profile is public by default. You choose most of what it shows, and you can keep it out of search.
  • When you ask a community to verify an entry, that community’s reviewers see the request. If the community has set a log channel, the Qualia bot also posts it in that channel on Discord.
  • Qualia’s database stores a keyed hash of your IP address, never the address itself.
  • There are no analytics, advertising or third-party cookies, and your information is never sold.
  • You can download your data or delete your account at any time, from Settings → Your data.
  • After you delete your account, a security audit log is kept, and your username is held for 30 days so nobody can use it to impersonate you.

1.Who we are

Qualia is an independent project that lets members of ER:LC communities build a public portfolio of the staff positions they have held, and lets communities confirm those positions. This policy explains how Qualia (“we”, “us”) handles information about members and visitors. We decide how and why that information is used, so we are responsible for it.

This policy covers the Qualia website and the Qualia bot’s posts in Discord servers. It works together with the Terms of Service and the Cookie Policy.

2.What we collect

Information Qualia collects, where it comes from and why
InformationWhere it comes fromWhy
Discord accountUser ID, username, display name and avatarDiscord, each time you sign inTo create your account and sign you in. Your avatar becomes your profile picture unless you upload your own, and your Discord username can appear on your profile.
The date your Discord account was createdWorked out from your Discord user IDStored with your Discord details to help assess reports of impersonation and abuse. Never shown publicly.
Discord servers you own or manageEach server’s ID, name and icon, whether you own it, and your permissions thereDiscord, each time you sign inTo list the servers you can register as communities on Qualia. Never shown publicly.
ProfileUsername, display name, headline, bio, pronouns and time zoneYouTo show your profile.
LinksYouTo show them on your profile.
ImagesAvatar, banner and profile backgroundYou, or a copy of your Discord avatarTo show them on your profile.
Experience entriesCommunity, department, positions with dates, a description, and the community’s Discord server if you link oneYou. The server’s ID, name and icon come from Discord, through the invite you pasteTo show your experience, and so the community can verify it.
Appearance and privacy settingsYouTo display your profile the way you chose.
Roblox accountUser ID, username and display nameYou, if you link oneTo show your Roblox username on your profile, if you choose to.
Verification requestsThe entry as it stood when you asked, your optional message, the decision, who made it and when, a note from the reviewer to you, and private notes the reviewers keep for themselvesYou and the community’s reviewersSo the community can review the entry, you can see the outcome, and there is a record of every decision.
Community rolesThe communities you registered or review for, when you were added, and settings such as a log channelYou, or the owner of the communityTo decide who can review a community’s requests and where the Qualia bot posts them.
NotificationsWhat happened, such as a decision on your request, and whether you have read itQualia, when something happens that involves youTo tell you about verification activity.
BadgesQualia’s administratorsTo show them on your profile.
SessionsA hash of your session token, your browser’s user agent, a keyed hash of your IP address, and when the session started, was last used and endsYour browser, when you sign in and use QualiaTo keep you signed in and protect your account.
Audit log entriesWhat changed and when, with your user agent and a keyed hash of your IP addressRecorded when you, a community or an administrator take certain actionsTo keep Qualia secure, prevent abuse and resolve disputes.
Rate-limit countersYour account ID, or your IP address if you are not signed inYour requestsTo slow down abuse. Held in memory only, for an hour at most.
Discord accountUser ID, username, display name and avatar
Where it comes fromDiscord, each time you sign in
WhyTo create your account and sign you in. Your avatar becomes your profile picture unless you upload your own, and your Discord username can appear on your profile.
The date your Discord account was created
Where it comes fromWorked out from your Discord user ID
WhyStored with your Discord details to help assess reports of impersonation and abuse. Never shown publicly.
Discord servers you own or manageEach server’s ID, name and icon, whether you own it, and your permissions there
Where it comes fromDiscord, each time you sign in
WhyTo list the servers you can register as communities on Qualia. Never shown publicly.
ProfileUsername, display name, headline, bio, pronouns and time zone
Where it comes fromYou
WhyTo show your profile.
Links
Where it comes fromYou
WhyTo show them on your profile.
ImagesAvatar, banner and profile background
Where it comes fromYou, or a copy of your Discord avatar
WhyTo show them on your profile.
Experience entriesCommunity, department, positions with dates, a description, and the community’s Discord server if you link one
Where it comes fromYou. The server’s ID, name and icon come from Discord, through the invite you paste
WhyTo show your experience, and so the community can verify it.
Appearance and privacy settings
Where it comes fromYou
WhyTo display your profile the way you chose.
Roblox accountUser ID, username and display name
Where it comes fromYou, if you link one
WhyTo show your Roblox username on your profile, if you choose to.
Verification requestsThe entry as it stood when you asked, your optional message, the decision, who made it and when, a note from the reviewer to you, and private notes the reviewers keep for themselves
Where it comes fromYou and the community’s reviewers
WhySo the community can review the entry, you can see the outcome, and there is a record of every decision.
Community rolesThe communities you registered or review for, when you were added, and settings such as a log channel
Where it comes fromYou, or the owner of the community
WhyTo decide who can review a community’s requests and where the Qualia bot posts them.
NotificationsWhat happened, such as a decision on your request, and whether you have read it
Where it comes fromQualia, when something happens that involves you
WhyTo tell you about verification activity.
Badges
Where it comes fromQualia’s administrators
WhyTo show them on your profile.
SessionsA hash of your session token, your browser’s user agent, a keyed hash of your IP address, and when the session started, was last used and ends
Where it comes fromYour browser, when you sign in and use Qualia
WhyTo keep you signed in and protect your account.
Audit log entriesWhat changed and when, with your user agent and a keyed hash of your IP address
Where it comes fromRecorded when you, a community or an administrator take certain actions
WhyTo keep Qualia secure, prevent abuse and resolve disputes.
Rate-limit countersYour account ID, or your IP address if you are not signed in
Where it comes fromYour requests
WhyTo slow down abuse. Held in memory only, for an hour at most.

Sign-in. Qualia asks Discord for two permissions: “identify”, to read who you are, and “guilds”, to read the list of servers you are in. Discord gives Qualia a temporary access token. Qualia uses it once, during sign-in, then asks Discord to revoke it. The token is never stored, and Qualia never sees your Discord password.

Your servers. Of the servers Discord lists, Qualia keeps only the ones you own or where you have the Administrator or Manage Server permission. The rest are discarded without being stored. The stored list is replaced each time you sign in. If Discord doesn’t return the list, the previous one is kept.

Invites. When you paste a Discord invite into an experience entry, Qualia looks it up with Discord and stores the server’s ID, name and icon. The invite link itself is not stored. Server icons are fetched from Discord by Qualia’s server and served from Qualia, so your browser never contacts Discord to show them.

Images. Every image you upload is resized and re-encoded before it is stored, which removes hidden metadata such as the location a photo was taken.

The audit log records these actions: creating your account, finishing setup, changing your username, changing your privacy settings, adding, editing or deleting an experience entry, requesting, withdrawing, deciding or revoking a verification, registering a community, adding or removing a reviewer, changing a community’s log channel, deleting your account, and every change an administrator makes. Depending on the action, an entry includes your old and new username, which privacy settings changed, the community, department, titles and dates of an experience entry, the outcome of a decision, or a revocation note. It does not include the description of an entry or your message to a community.

Hosting and network logs. Our hosting provider (Railway) and Cloudflare, the network that sits in front of Qualia, may also record technical details about requests, such as IP addresses, in their own infrastructure logs, under their own policies.

Qualia does not collect your email address, payment details or precise location, and does not read your Discord messages, your friends list or the members of your servers.

3.How we use it

  • To run Qualia: signing you in, showing your profile, saving your changes, and making listed profiles findable in search and Explore.
  • For verification: sending your requests to the community you chose, showing the decision on your entry, and telling you and the reviewers what happened.
  • For communities: listing the servers you can register, checking with Discord that you manage a server before you register it, and posting requests in the community’s log channel.
  • To keep Qualia safe: sessions, rate limits and the audit log help us protect accounts, look into reports, and enforce the Terms of Service.
  • To suggest community names: when someone adds an experience entry, Qualia suggests community names as they type. Suggestions come from communities on Qualia, including Discord servers that someone has linked an entry to, and from community names that appear on the public profiles of at least two members. Hidden entries and unlisted profiles are never used.

Qualia does not use your information for advertising, does not sell it, and does not build profiles of you for anyone else. Qualia makes no automated decisions that have legal or similarly significant effects on you. Every verification decision is made by a person.

4.Who can see it

Everyone

Profiles are public by default. Anyone, including people who are not signed in and search engines, can see:

  • your display name, username and Qualia ID;
  • your avatar, banner and profile appearance;
  • your headline, bio, pronouns and time zone, if you add them;
  • your links and badges;
  • your experience entries, their verification status, and the name and icon of the Discord server you linked to each;
  • the month you joined Qualia;
  • your Discord username, and your Roblox username if you link a Roblox account.

You can change what shows in your privacy settings, in Settings:

  • Listed in search and Explore. When this is off, your profile is left out of Qualia’s search and Explore pages, and search engines are asked not to index it. Anyone with the link can still open it.
  • Experience. Hide all of it, or only current or only past positions. You can also hide individual entries.
  • Links, badges, join date, Discord username and Roblox account. Each can be hidden.

Your display name, username, Qualia ID, images, headline, bio, pronouns, time zone and appearance are always shown. The text fields are optional; leave them empty if you don’t want them public. You do not need to use your real name.

Your Discord user ID and the list of servers you manage are never shown publicly. Qualia copies your Discord avatar into its own storage, so pages that show it don’t reveal your Discord ID. When you change your username, your old one redirects to your profile for 30 days. Public profiles don’t say who verified an entry.

Reviewers of a community you ask to verify an entry

A registered community’s owner and the reviewers they add can see each request made to that community: your display name, username, profile picture and a link to your profile; the entry’s community, department, positions, dates and description; your message, if you wrote one; and the request’s history. They see this whatever your privacy settings are. They also see entries of yours that their community has verified, so they can revoke a verification if they need to.

You see the outcome of your request, who decided it, and any note the reviewer wrote to you. You never see the reviewers’ private notes.

A community’s Discord log channel

A community’s owner can choose a channel in their Discord server as its log channel. When you ask that community to verify an entry, the Qualia bot posts the request there: your display name, username and profile picture, the community, the positions with their dates, the department, your message if you wrote one, and links to your profile and to the request. When the request is decided or withdrawn, the bot edits the post to show the outcome and the name of the reviewer who decided.

Anyone who can see that channel in that server can read the post. Who that is depends on the server’s settings, which the community controls, not Qualia. The post is stored by Discord.

If you review for a community

When you decide a request, your display name and username are shown to the member, in the request’s history, and in the community’s log channel post. Your decision is recorded with your account and your Discord user ID. Reviewers of a community can see the other reviewers on its list.

Qualia’s administrators

A small number of people chosen by the operator of Qualia are administrators. To moderate Qualia and handle reports, they can see any account and profile, including hidden entries, privacy settings, linked Discord and Roblox accounts and the audit log. They can edit profile text and links, change usernames, remove images, hide or delete experience entries, suspend accounts and award or remove badges. They can also see and decide any community’s verification requests, including members’ messages and reviewers’ private notes, as that community’s reviewers can, and edit any experience entry or set its status. Every change they make is recorded in the audit log under the administrator’s account, and a suspension is recorded with its reason.

Anything public, or posted in a Discord channel, can be seen, copied or archived by others, and Qualia cannot control copies made outside Qualia.

5.Cookies

Qualia sets three cookies: one keeps you signed in, one protects sign-in while you are on Discord, and one remembers if you turn off profile effects. There are no analytics, advertising or third-party cookies. The Cookie Policy lists them.

Qualia’s pages do not load scripts, images or fonts from other websites. Its fonts are served by Qualia itself, and Discord server icons are copied through Qualia’s server, so opening a page does not contact any other company’s servers apart from our hosting provider and Cloudflare, through which every request passes.

6.Who we share it with

  • With everyone: whatever your profile shows, as described in section 4.
  • With communities: when you ask a community to verify an entry, its reviewers see the request, and its log channel receives the post described above.
  • With our hosting provider: Railway runs Qualia’s application, database and file storage.
  • With our network provider: Cloudflare sits in front of Qualia. Every request passes through it, so it sees your IP address and the pages you open, and it keeps copies of public images for up to an hour to serve them faster.
  • When the law requires it: we may disclose information if we believe in good faith that the law requires it, or that it is necessary to protect someone’s safety or the service.

We do not sell or rent personal information, and we do not share it for advertising.

What Discord receives

  • Discord handles sign-in, so it knows when you use your Discord account to sign in to Qualia, and it gives Qualia your server list as described above.
  • When you paste an invite, Qualia asks Discord which server it belongs to. Qualia doesn’t tell Discord who pasted it.
  • When you register a server, the Qualia bot asks Discord, using your Discord user ID, whether you own that server or hold Administrator or Manage Server in it.
  • When a community has a log channel, the Qualia bot sends Discord the post described in section 4, and Discord fetches your profile picture from Qualia to show it.
  • When your Discord avatar changes, or a page needs a server icon, Qualia’s server downloads the image from Discord.

What Discord does with this is covered by Discord’s Privacy Policy.

7.How long we keep it

How long Qualia keeps each kind of information
InformationHow long
Profile, links, appearance and privacy settingsUntil you change them or delete your account.
Uploaded imagesUntil you replace or remove them, or delete your account. A replaced image is deleted.
Experience entries, their verification requests and their verification historyUntil you delete your account. An entry you delete leaves your profile straight away, but is kept, marked as deleted, until then. Deleting an entry withdraws any request that is still open.
Discord and Roblox detailsUntil you delete your account. Discord details are refreshed each time you sign in.
The list of servers you own or manageReplaced each time you sign in. Deleted when you delete your account.
Your roles in communitiesUntil the owner removes you or you delete your account.
NotificationsUntil you delete your account.
Posts in a community’s Discord log channelQualia edits a post when the request is decided or withdrawn, but never deletes it, including when you delete your account. The post stays in Discord until someone who manages that server deletes it.
SessionsA session lasts 30 days unless you sign out first. Its record is kept, marked as ended, until you delete your account.
Username historyUntil you delete your account. A username you give up is held for 30 days.
Audit logKept after your account is deleted, with no automatic expiry. The database rejects any change to an entry, or its deletion.
Invite lookups and server iconsCached in memory for a short time. Server details stay with the community on Qualia.
Rate-limit countersUp to an hour, in memory only.
Hosting provider backupsCopies may remain in backups for a limited period after deletion.
Profile, links, appearance and privacy settings
How longUntil you change them or delete your account.
Uploaded images
How longUntil you replace or remove them, or delete your account. A replaced image is deleted.
Experience entries, their verification requests and their verification history
How longUntil you delete your account. An entry you delete leaves your profile straight away, but is kept, marked as deleted, until then. Deleting an entry withdraws any request that is still open.
Discord and Roblox details
How longUntil you delete your account. Discord details are refreshed each time you sign in.
The list of servers you own or manage
How longReplaced each time you sign in. Deleted when you delete your account.
Your roles in communities
How longUntil the owner removes you or you delete your account.
Notifications
How longUntil you delete your account.
Posts in a community’s Discord log channel
How longQualia edits a post when the request is decided or withdrawn, but never deletes it, including when you delete your account. The post stays in Discord until someone who manages that server deletes it.
Sessions
How longA session lasts 30 days unless you sign out first. Its record is kept, marked as ended, until you delete your account.
Username history
How longUntil you delete your account. A username you give up is held for 30 days.
Audit log
How longKept after your account is deleted, with no automatic expiry. The database rejects any change to an entry, or its deletion.
Invite lookups and server icons
How longCached in memory for a short time. Server details stay with the community on Qualia.
Rate-limit counters
How longUp to an hour, in memory only.
Hosting provider backups
How longCopies may remain in backups for a limited period after deletion.

8.Your choices and rights

Download your data

Go to Settings → Your data to download a JSON file of the information linked to your account: your account and profile, appearance and privacy settings, links, Discord and Roblox details, the servers you own or manage and the permissions Discord reported for them, username history, experience entries with their verification history (including entries you deleted, which are kept until you delete your account), the verification requests you sent with your messages and the notes reviewers left for you, your roles in communities and the communities you registered, badges, active sessions, notifications, and your actions in the audit log. Hashes of session tokens and IP addresses are left out, because they cannot be read as information about you, and so are reviewers’ private notes, which belong to the community. If you want something that isn’t in the file, contact us.

Correct it

You can edit your profile and experience entries at any time. If a community’s verification decision about you is wrong, ask the community to correct it. If that doesn’t work, contact us.

Delete your account

Go to Settings → Your data. Deletion takes effect immediately and cannot be undone.

Removed straight away:

  • your profile, appearance settings, links and uploaded images;
  • your experience entries, including ones you deleted earlier, with their verification requests and records;
  • your linked Discord and Roblox details, the list of servers you manage, and your username history;
  • your sessions, so you are signed out everywhere;
  • your notifications, badges and roles in communities.

Kept:

  • an empty account record, renamed “Deleted account”, with its Qualia ID and the dates it was created and deleted;
  • the audit log, which includes your former usernames and the community, department, titles and dates of your experience entries, for security, abuse and dispute handling;
  • your last username, held for 30 days so nobody can take it to impersonate you;
  • if you reviewed for a community, the decisions you made on other members’ entries, with your Discord user ID, because they are part of those members’ records;
  • notifications that reviewers received about your requests, which belong to their accounts, and posts the Qualia bot made in Discord log channels, which we edit to remove your name and profile link;
  • any community you registered. It stays on Qualia without an owner, and anyone who manages its Discord server can register it again.

Copies may remain in our hosting provider’s backups for a limited period. If you sign in again later with the same Discord account, you start with a new, empty account.

Object, restrict or withdraw consent

You can object to how we use your information, or ask us to limit it, by contacting us. Some uses, such as the audit log, are needed to keep Qualia secure; if we can’t stop one, we will explain why. Where we rely on your consent, you can withdraw it at any time.

If you are in the EEA or the UK

The GDPR and the UK GDPR give you the right to access, correct and delete your personal data, to restrict or object to how it is used, to receive it in a portable format, and to withdraw consent. Use the tools above, or contact us. We will answer within one month, and may ask you to confirm the request is yours, for example by signing in. You can also complain to your local data protection authority.

We use your information to provide the service you signed up for, including sending your verification requests to the community you chose (performance of a contract); to keep Qualia secure, prevent abuse and impersonation, and keep a reliable record of verification decisions (our legitimate interests); and, where we ask for it, with your consent.

Depending on where you live, you may have similar rights elsewhere. Contact us and we will help.

9.Where your data is processed

Qualia’s servers are operated by our hosting provider and may be located outside your country, and requests reach them through Cloudflare’s worldwide network. Discord handles sign-in and stores log channel posts on its own systems. Your information may therefore be processed in a country whose data protection laws differ from those where you live.

10.How we protect it

Qualia is built to hold as little as it needs and to protect what it holds:

  • Session tokens are long and random, and only a hash of each is stored, so a copy of the database cannot be used to sign in.
  • IP addresses are stored only as a keyed hash.
  • Session cookies are HttpOnly, so scripts cannot read them. On the live site they are also Secure and locked to Qualia’s own address.
  • Discord sign-in is protected against forged requests, and the Discord access token is revoked after use.
  • The stored list of your servers is only used for display. Registering a server is checked live with Discord, and every community action is checked against the community’s reviewer list on Qualia.
  • The Qualia bot’s posts can’t mention or ping anyone.
  • A strict Content-Security-Policy allows only scripts Qualia issued for that page, blocks content from other sites, and stops other sites from embedding Qualia.
  • Uploaded images and Discord server icons are decoded and re-encoded before Qualia serves them.
  • Profile links must use https.
  • Sign-in, search, uploads, edits, invite lookups, verification requests and exports are rate-limited.
  • The audit log is append-only: the database itself rejects any change to it.

No system is perfectly secure, and we cannot promise that yours will never be compromised. If you think your account has been, end your other sessions from Settings, secure your Discord account and contact us. If you find a security problem in Qualia, please tell us privately.

11.Children

Qualia is not directed at children under 13. You must be at least 13, or older where Discord or the law where you live sets a higher age, to have an account. If we learn that an account belongs to someone below the minimum age, we will delete it. If you think a child under 13 is using Qualia, contact us.

If you are under 18, think about what you put on a public profile. You don’t need to share your real name, age or location, and you can hide most of your profile.

12.Changes to this policy

We will update this policy when Qualia changes how it handles information. The date at the top of this page shows when it last changed. If a change significantly affects you, we will tell members before it takes effect, for example with a notice on the site.