Privacy Policy
What Qualia collects, who can see it, how long it is kept, and how to get a copy or delete it.
Last updated October 4, 2026
In short
- You sign in with Discord. Qualia receives your Discord user ID, username, display name and avatar, and the list of servers you are in. From that list it keeps only the servers you own or manage. It does not receive your email address, messages or friends list.
- Your profile is public by default. You choose most of what it shows, and you can keep it out of search.
- When you ask a community to verify an entry, that community’s reviewers see the request. If the community has set a log channel, the Qualia bot also posts it in that channel on Discord.
- Qualia’s database stores a keyed hash of your IP address, never the address itself.
- There are no analytics, advertising or third-party cookies, and your information is never sold.
- You can download your data or delete your account at any time, from Settings → Your data.
- After you delete your account, a security audit log is kept, and your username is held for 30 days so nobody can use it to impersonate you.
1.Who we are
Qualia is an independent project that lets members of ER:LC communities build a public portfolio of the staff positions they have held, and lets communities confirm those positions. This policy explains how Qualia (“we”, “us”) handles information about members and visitors. We decide how and why that information is used, so we are responsible for it.
This policy covers the Qualia website and the Qualia bot’s posts in Discord servers. It works together with the Terms of Service and the Cookie Policy.
2.What we collect
| Information | Where it comes from | Why |
|---|---|---|
| Discord accountUser ID, username, display name and avatar | Discord, each time you sign in | To create your account and sign you in. Your avatar becomes your profile picture unless you upload your own, and your Discord username can appear on your profile. |
| The date your Discord account was created | Worked out from your Discord user ID | Stored with your Discord details to help assess reports of impersonation and abuse. Never shown publicly. |
| Discord servers you own or manageEach server’s ID, name and icon, whether you own it, and your permissions there | Discord, each time you sign in | To list the servers you can register as communities on Qualia. Never shown publicly. |
| ProfileUsername, display name, headline, bio, pronouns and time zone | You | To show your profile. |
| Links | You | To show them on your profile. |
| ImagesAvatar, banner and profile background | You, or a copy of your Discord avatar | To show them on your profile. |
| Experience entriesCommunity, department, positions with dates, a description, and the community’s Discord server if you link one | You. The server’s ID, name and icon come from Discord, through the invite you paste | To show your experience, and so the community can verify it. |
| Appearance and privacy settings | You | To display your profile the way you chose. |
| Roblox accountUser ID, username and display name | You, if you link one | To show your Roblox username on your profile, if you choose to. |
| Verification requestsThe entry as it stood when you asked, your optional message, the decision, who made it and when, a note from the reviewer to you, and private notes the reviewers keep for themselves | You and the community’s reviewers | So the community can review the entry, you can see the outcome, and there is a record of every decision. |
| Community rolesThe communities you registered or review for, when you were added, and settings such as a log channel | You, or the owner of the community | To decide who can review a community’s requests and where the Qualia bot posts them. |
| NotificationsWhat happened, such as a decision on your request, and whether you have read it | Qualia, when something happens that involves you | To tell you about verification activity. |
| Badges | Qualia’s administrators | To show them on your profile. |
| SessionsA hash of your session token, your browser’s user agent, a keyed hash of your IP address, and when the session started, was last used and ends | Your browser, when you sign in and use Qualia | To keep you signed in and protect your account. |
| Audit log entriesWhat changed and when, with your user agent and a keyed hash of your IP address | Recorded when you, a community or an administrator take certain actions | To keep Qualia secure, prevent abuse and resolve disputes. |
| Rate-limit countersYour account ID, or your IP address if you are not signed in | Your requests | To slow down abuse. Held in memory only, for an hour at most. |
- Discord accountUser ID, username, display name and avatar
- Where it comes fromDiscord, each time you sign in
- WhyTo create your account and sign you in. Your avatar becomes your profile picture unless you upload your own, and your Discord username can appear on your profile.
- The date your Discord account was created
- Where it comes fromWorked out from your Discord user ID
- WhyStored with your Discord details to help assess reports of impersonation and abuse. Never shown publicly.
- Discord servers you own or manageEach server’s ID, name and icon, whether you own it, and your permissions there
- Where it comes fromDiscord, each time you sign in
- WhyTo list the servers you can register as communities on Qualia. Never shown publicly.
- ProfileUsername, display name, headline, bio, pronouns and time zone
- Where it comes fromYou
- WhyTo show your profile.
- Links
- Where it comes fromYou
- WhyTo show them on your profile.
- ImagesAvatar, banner and profile background
- Where it comes fromYou, or a copy of your Discord avatar
- WhyTo show them on your profile.
- Experience entriesCommunity, department, positions with dates, a description, and the community’s Discord server if you link one
- Where it comes fromYou. The server’s ID, name and icon come from Discord, through the invite you paste
- WhyTo show your experience, and so the community can verify it.
- Appearance and privacy settings
- Where it comes fromYou
- WhyTo display your profile the way you chose.
- Roblox accountUser ID, username and display name
- Where it comes fromYou, if you link one
- WhyTo show your Roblox username on your profile, if you choose to.
- Verification requestsThe entry as it stood when you asked, your optional message, the decision, who made it and when, a note from the reviewer to you, and private notes the reviewers keep for themselves
- Where it comes fromYou and the community’s reviewers
- WhySo the community can review the entry, you can see the outcome, and there is a record of every decision.
- Community rolesThe communities you registered or review for, when you were added, and settings such as a log channel
- Where it comes fromYou, or the owner of the community
- WhyTo decide who can review a community’s requests and where the Qualia bot posts them.
- NotificationsWhat happened, such as a decision on your request, and whether you have read it
- Where it comes fromQualia, when something happens that involves you
- WhyTo tell you about verification activity.
- Badges
- Where it comes fromQualia’s administrators
- WhyTo show them on your profile.
- SessionsA hash of your session token, your browser’s user agent, a keyed hash of your IP address, and when the session started, was last used and ends
- Where it comes fromYour browser, when you sign in and use Qualia
- WhyTo keep you signed in and protect your account.
- Audit log entriesWhat changed and when, with your user agent and a keyed hash of your IP address
- Where it comes fromRecorded when you, a community or an administrator take certain actions
- WhyTo keep Qualia secure, prevent abuse and resolve disputes.
- Rate-limit countersYour account ID, or your IP address if you are not signed in
- Where it comes fromYour requests
- WhyTo slow down abuse. Held in memory only, for an hour at most.
Sign-in. Qualia asks Discord for two permissions: “identify”, to read who you are, and “guilds”, to read the list of servers you are in. Discord gives Qualia a temporary access token. Qualia uses it once, during sign-in, then asks Discord to revoke it. The token is never stored, and Qualia never sees your Discord password.
Your servers. Of the servers Discord lists, Qualia keeps only the ones you own or where you have the Administrator or Manage Server permission. The rest are discarded without being stored. The stored list is replaced each time you sign in. If Discord doesn’t return the list, the previous one is kept.
Invites. When you paste a Discord invite into an experience entry, Qualia looks it up with Discord and stores the server’s ID, name and icon. The invite link itself is not stored. Server icons are fetched from Discord by Qualia’s server and served from Qualia, so your browser never contacts Discord to show them.
Images. Every image you upload is resized and re-encoded before it is stored, which removes hidden metadata such as the location a photo was taken.
The audit log records these actions: creating your account, finishing setup, changing your username, changing your privacy settings, adding, editing or deleting an experience entry, requesting, withdrawing, deciding or revoking a verification, registering a community, adding or removing a reviewer, changing a community’s log channel, deleting your account, and every change an administrator makes. Depending on the action, an entry includes your old and new username, which privacy settings changed, the community, department, titles and dates of an experience entry, the outcome of a decision, or a revocation note. It does not include the description of an entry or your message to a community.
Hosting and network logs. Our hosting provider (Railway) and Cloudflare, the network that sits in front of Qualia, may also record technical details about requests, such as IP addresses, in their own infrastructure logs, under their own policies.
Qualia does not collect your email address, payment details or precise location, and does not read your Discord messages, your friends list or the members of your servers.
3.How we use it
- To run Qualia: signing you in, showing your profile, saving your changes, and making listed profiles findable in search and Explore.
- For verification: sending your requests to the community you chose, showing the decision on your entry, and telling you and the reviewers what happened.
- For communities: listing the servers you can register, checking with Discord that you manage a server before you register it, and posting requests in the community’s log channel.
- To keep Qualia safe: sessions, rate limits and the audit log help us protect accounts, look into reports, and enforce the Terms of Service.
- To suggest community names: when someone adds an experience entry, Qualia suggests community names as they type. Suggestions come from communities on Qualia, including Discord servers that someone has linked an entry to, and from community names that appear on the public profiles of at least two members. Hidden entries and unlisted profiles are never used.
Qualia does not use your information for advertising, does not sell it, and does not build profiles of you for anyone else. Qualia makes no automated decisions that have legal or similarly significant effects on you. Every verification decision is made by a person.
4.Who can see it
Everyone
Profiles are public by default. Anyone, including people who are not signed in and search engines, can see:
- your display name, username and Qualia ID;
- your avatar, banner and profile appearance;
- your headline, bio, pronouns and time zone, if you add them;
- your links and badges;
- your experience entries, their verification status, and the name and icon of the Discord server you linked to each;
- the month you joined Qualia;
- your Discord username, and your Roblox username if you link a Roblox account.
You can change what shows in your privacy settings, in Settings:
- Listed in search and Explore. When this is off, your profile is left out of Qualia’s search and Explore pages, and search engines are asked not to index it. Anyone with the link can still open it.
- Experience. Hide all of it, or only current or only past positions. You can also hide individual entries.
- Links, badges, join date, Discord username and Roblox account. Each can be hidden.
Your display name, username, Qualia ID, images, headline, bio, pronouns, time zone and appearance are always shown. The text fields are optional; leave them empty if you don’t want them public. You do not need to use your real name.
Your Discord user ID and the list of servers you manage are never shown publicly. Qualia copies your Discord avatar into its own storage, so pages that show it don’t reveal your Discord ID. When you change your username, your old one redirects to your profile for 30 days. Public profiles don’t say who verified an entry.
Reviewers of a community you ask to verify an entry
A registered community’s owner and the reviewers they add can see each request made to that community: your display name, username, profile picture and a link to your profile; the entry’s community, department, positions, dates and description; your message, if you wrote one; and the request’s history. They see this whatever your privacy settings are. They also see entries of yours that their community has verified, so they can revoke a verification if they need to.
You see the outcome of your request, who decided it, and any note the reviewer wrote to you. You never see the reviewers’ private notes.
A community’s Discord log channel
A community’s owner can choose a channel in their Discord server as its log channel. When you ask that community to verify an entry, the Qualia bot posts the request there: your display name, username and profile picture, the community, the positions with their dates, the department, your message if you wrote one, and links to your profile and to the request. When the request is decided or withdrawn, the bot edits the post to show the outcome and the name of the reviewer who decided.
Anyone who can see that channel in that server can read the post. Who that is depends on the server’s settings, which the community controls, not Qualia. The post is stored by Discord.
If you review for a community
When you decide a request, your display name and username are shown to the member, in the request’s history, and in the community’s log channel post. Your decision is recorded with your account and your Discord user ID. Reviewers of a community can see the other reviewers on its list.
Qualia’s administrators
A small number of people chosen by the operator of Qualia are administrators. To moderate Qualia and handle reports, they can see any account and profile, including hidden entries, privacy settings, linked Discord and Roblox accounts and the audit log. They can edit profile text and links, change usernames, remove images, hide or delete experience entries, suspend accounts and award or remove badges. They can also see and decide any community’s verification requests, including members’ messages and reviewers’ private notes, as that community’s reviewers can, and edit any experience entry or set its status. Every change they make is recorded in the audit log under the administrator’s account, and a suspension is recorded with its reason.
Anything public, or posted in a Discord channel, can be seen, copied or archived by others, and Qualia cannot control copies made outside Qualia.
5.Cookies
Qualia sets three cookies: one keeps you signed in, one protects sign-in while you are on Discord, and one remembers if you turn off profile effects. There are no analytics, advertising or third-party cookies. The Cookie Policy lists them.
Qualia’s pages do not load scripts, images or fonts from other websites. Its fonts are served by Qualia itself, and Discord server icons are copied through Qualia’s server, so opening a page does not contact any other company’s servers apart from our hosting provider and Cloudflare, through which every request passes.
6.Who we share it with
- With everyone: whatever your profile shows, as described in section 4.
- With communities: when you ask a community to verify an entry, its reviewers see the request, and its log channel receives the post described above.
- With our hosting provider: Railway runs Qualia’s application, database and file storage.
- With our network provider: Cloudflare sits in front of Qualia. Every request passes through it, so it sees your IP address and the pages you open, and it keeps copies of public images for up to an hour to serve them faster.
- When the law requires it: we may disclose information if we believe in good faith that the law requires it, or that it is necessary to protect someone’s safety or the service.
We do not sell or rent personal information, and we do not share it for advertising.
What Discord receives
- Discord handles sign-in, so it knows when you use your Discord account to sign in to Qualia, and it gives Qualia your server list as described above.
- When you paste an invite, Qualia asks Discord which server it belongs to. Qualia doesn’t tell Discord who pasted it.
- When you register a server, the Qualia bot asks Discord, using your Discord user ID, whether you own that server or hold Administrator or Manage Server in it.
- When a community has a log channel, the Qualia bot sends Discord the post described in section 4, and Discord fetches your profile picture from Qualia to show it.
- When your Discord avatar changes, or a page needs a server icon, Qualia’s server downloads the image from Discord.
What Discord does with this is covered by Discord’s Privacy Policy.
7.How long we keep it
| Information | How long |
|---|---|
| Profile, links, appearance and privacy settings | Until you change them or delete your account. |
| Uploaded images | Until you replace or remove them, or delete your account. A replaced image is deleted. |
| Experience entries, their verification requests and their verification history | Until you delete your account. An entry you delete leaves your profile straight away, but is kept, marked as deleted, until then. Deleting an entry withdraws any request that is still open. |
| Discord and Roblox details | Until you delete your account. Discord details are refreshed each time you sign in. |
| The list of servers you own or manage | Replaced each time you sign in. Deleted when you delete your account. |
| Your roles in communities | Until the owner removes you or you delete your account. |
| Notifications | Until you delete your account. |
| Posts in a community’s Discord log channel | Qualia edits a post when the request is decided or withdrawn, but never deletes it, including when you delete your account. The post stays in Discord until someone who manages that server deletes it. |
| Sessions | A session lasts 30 days unless you sign out first. Its record is kept, marked as ended, until you delete your account. |
| Username history | Until you delete your account. A username you give up is held for 30 days. |
| Audit log | Kept after your account is deleted, with no automatic expiry. The database rejects any change to an entry, or its deletion. |
| Invite lookups and server icons | Cached in memory for a short time. Server details stay with the community on Qualia. |
| Rate-limit counters | Up to an hour, in memory only. |
| Hosting provider backups | Copies may remain in backups for a limited period after deletion. |
- Profile, links, appearance and privacy settings
- How longUntil you change them or delete your account.
- Uploaded images
- How longUntil you replace or remove them, or delete your account. A replaced image is deleted.
- Experience entries, their verification requests and their verification history
- How longUntil you delete your account. An entry you delete leaves your profile straight away, but is kept, marked as deleted, until then. Deleting an entry withdraws any request that is still open.
- Discord and Roblox details
- How longUntil you delete your account. Discord details are refreshed each time you sign in.
- The list of servers you own or manage
- How longReplaced each time you sign in. Deleted when you delete your account.
- Your roles in communities
- How longUntil the owner removes you or you delete your account.
- Notifications
- How longUntil you delete your account.
- Posts in a community’s Discord log channel
- How longQualia edits a post when the request is decided or withdrawn, but never deletes it, including when you delete your account. The post stays in Discord until someone who manages that server deletes it.
- Sessions
- How longA session lasts 30 days unless you sign out first. Its record is kept, marked as ended, until you delete your account.
- Username history
- How longUntil you delete your account. A username you give up is held for 30 days.
- Audit log
- How longKept after your account is deleted, with no automatic expiry. The database rejects any change to an entry, or its deletion.
- Invite lookups and server icons
- How longCached in memory for a short time. Server details stay with the community on Qualia.
- Rate-limit counters
- How longUp to an hour, in memory only.
- Hosting provider backups
- How longCopies may remain in backups for a limited period after deletion.
8.Your choices and rights
Download your data
Go to Settings → Your data to download a JSON file of the information linked to your account: your account and profile, appearance and privacy settings, links, Discord and Roblox details, the servers you own or manage and the permissions Discord reported for them, username history, experience entries with their verification history (including entries you deleted, which are kept until you delete your account), the verification requests you sent with your messages and the notes reviewers left for you, your roles in communities and the communities you registered, badges, active sessions, notifications, and your actions in the audit log. Hashes of session tokens and IP addresses are left out, because they cannot be read as information about you, and so are reviewers’ private notes, which belong to the community. If you want something that isn’t in the file, contact us.
Correct it
You can edit your profile and experience entries at any time. If a community’s verification decision about you is wrong, ask the community to correct it. If that doesn’t work, contact us.
Delete your account
Go to Settings → Your data. Deletion takes effect immediately and cannot be undone.
Removed straight away:
- your profile, appearance settings, links and uploaded images;
- your experience entries, including ones you deleted earlier, with their verification requests and records;
- your linked Discord and Roblox details, the list of servers you manage, and your username history;
- your sessions, so you are signed out everywhere;
- your notifications, badges and roles in communities.
Kept:
- an empty account record, renamed “Deleted account”, with its Qualia ID and the dates it was created and deleted;
- the audit log, which includes your former usernames and the community, department, titles and dates of your experience entries, for security, abuse and dispute handling;
- your last username, held for 30 days so nobody can take it to impersonate you;
- if you reviewed for a community, the decisions you made on other members’ entries, with your Discord user ID, because they are part of those members’ records;
- notifications that reviewers received about your requests, which belong to their accounts, and posts the Qualia bot made in Discord log channels, which we edit to remove your name and profile link;
- any community you registered. It stays on Qualia without an owner, and anyone who manages its Discord server can register it again.
Copies may remain in our hosting provider’s backups for a limited period. If you sign in again later with the same Discord account, you start with a new, empty account.
Object, restrict or withdraw consent
You can object to how we use your information, or ask us to limit it, by contacting us. Some uses, such as the audit log, are needed to keep Qualia secure; if we can’t stop one, we will explain why. Where we rely on your consent, you can withdraw it at any time.
If you are in the EEA or the UK
The GDPR and the UK GDPR give you the right to access, correct and delete your personal data, to restrict or object to how it is used, to receive it in a portable format, and to withdraw consent. Use the tools above, or contact us. We will answer within one month, and may ask you to confirm the request is yours, for example by signing in. You can also complain to your local data protection authority.
We use your information to provide the service you signed up for, including sending your verification requests to the community you chose (performance of a contract); to keep Qualia secure, prevent abuse and impersonation, and keep a reliable record of verification decisions (our legitimate interests); and, where we ask for it, with your consent.
Depending on where you live, you may have similar rights elsewhere. Contact us and we will help.
9.Where your data is processed
Qualia’s servers are operated by our hosting provider and may be located outside your country, and requests reach them through Cloudflare’s worldwide network. Discord handles sign-in and stores log channel posts on its own systems. Your information may therefore be processed in a country whose data protection laws differ from those where you live.
10.How we protect it
Qualia is built to hold as little as it needs and to protect what it holds:
- Session tokens are long and random, and only a hash of each is stored, so a copy of the database cannot be used to sign in.
- IP addresses are stored only as a keyed hash.
- Session cookies are HttpOnly, so scripts cannot read them. On the live site they are also Secure and locked to Qualia’s own address.
- Discord sign-in is protected against forged requests, and the Discord access token is revoked after use.
- The stored list of your servers is only used for display. Registering a server is checked live with Discord, and every community action is checked against the community’s reviewer list on Qualia.
- The Qualia bot’s posts can’t mention or ping anyone.
- A strict Content-Security-Policy allows only scripts Qualia issued for that page, blocks content from other sites, and stops other sites from embedding Qualia.
- Uploaded images and Discord server icons are decoded and re-encoded before Qualia serves them.
- Profile links must use https.
- Sign-in, search, uploads, edits, invite lookups, verification requests and exports are rate-limited.
- The audit log is append-only: the database itself rejects any change to it.
No system is perfectly secure, and we cannot promise that yours will never be compromised. If you think your account has been, end your other sessions from Settings, secure your Discord account and contact us. If you find a security problem in Qualia, please tell us privately.
11.Children
Qualia is not directed at children under 13. You must be at least 13, or older where Discord or the law where you live sets a higher age, to have an account. If we learn that an account belongs to someone below the minimum age, we will delete it. If you think a child under 13 is using Qualia, contact us.
If you are under 18, think about what you put on a public profile. You don’t need to share your real name, age or location, and you can hide most of your profile.
12.Changes to this policy
We will update this policy when Qualia changes how it handles information. The date at the top of this page shows when it last changed. If a change significantly affects you, we will tell members before it takes effect, for example with a notice on the site.