1. Scope
This policy explains how Utilize and its connected services, Formalize and Vocalize (together, the “Services”), handle information. It applies when you use the website, sign in with Discord, interact with a connected bot, complete a Formalize form, or participate in a Discord server using the Services. Discord and individual server operators may have separate privacy responsibilities and policies.
2. Information we process
Depending on the features used, we may process:
- Discord account data: user name, avatar, and user, server, channel, role, and message identifiers;
- authentication data: Discord authorisation tokens, secure session identifiers, sign-in times, and session-expiry information;
- server configuration: selected categories, channels, roles, permissions, form settings, room settings, blocked-name rules, and administrator choices;
- Formalize information: form questions, responses, uploaded files, submission times, delivery status, application channel identifiers, staff assignments, review status, internal notes, and version history;
- Vocalize information: voice-room joins and leaves, room ownership and controls, time in voice channels, optional XP, levels and ranks, configured role assignments, moderation notes, and action history;
- support information: contact details, server name, request summary, support messages, reference number, and resolution status;
- technical information: command usage, timestamps, errors, security events, and operational logs.
We do not intentionally collect ordinary Discord message content except information deliberately submitted through a Service feature, such as a form response, file, staff note, moderation note, or command.
3. Sources of information
Information comes from you, authorised server staff, Discord’s API, and the operation of the Services. Server administrators decide which optional features are enabled and which staff roles can access administrative information.
4. How we use information
We process information to authenticate users; display servers they are authorised to manage; operate forms, submissions, temporary voice rooms, logging, moderation, and optional XP features; create requested Discord channels; preserve settings and drafts; secure and troubleshoot the Services; prevent misuse; respond to support requests; and comply with legal obligations.
5. Legal bases
Where data-protection law requires a legal basis, processing may rely on performance of a service requested by you or a server administrator, legitimate interests in providing and securing the Services, compliance with legal obligations, and consent where specifically required. Server operators remain responsible for identifying an appropriate basis for forms and other processing they configure.
6. How information is shared
Information may be shown to authorised server staff or members through dashboards, private application channels, bot responses, logs, profiles, or leaderboards according to configured Discord permissions. Information may also be processed by Discord and infrastructure providers, or disclosed to professional advisers, during a business transfer, when required by law, or where necessary to protect rights and safety. We do not sell personal information or use it for targeted advertising.
7. Retention and deletion
Server configuration and active feature data are retained while needed to provide the Services. Formalize submissions and uploaded files are retained until deleted by authorised staff or removed under the server’s configured archived-submission retention setting. Form versions are limited to the most recent 20 saved versions. Support requests are retained while open and for as long as reasonably needed to document and resolve the request. Authentication sessions are normally valid for up to 30 days. Operational and security logs are kept only as long as reasonably necessary. Backups may retain deleted information for a limited period before replacement.
8. Security
We use reasonable technical and organisational safeguards, including access controls and restricted storage, designed to protect information. No online service can guarantee absolute security. Administrators should grant only required permissions, regularly review staff access, and avoid requesting or storing unnecessary sensitive information.
9. Your choices and rights
You can limit processing by leaving a participating server, avoiding optional features, signing out, or asking a server administrator to correct or delete relevant information. Depending on where you live, you may have rights to access, correct, delete, restrict, object to processing, or obtain a portable copy of certain information. A request should include your Discord user ID and enough server context to locate the relevant records.
10. Children
The Services are not directed to children below the minimum age permitted by Discord or applicable law. Contact us if you believe a child’s information has been handled improperly.
11. International transfers
Discord, hosting providers, server operators, and users may operate in different countries. Information may therefore be processed outside your country. Appropriate safeguards will be used where required.
12. Changes and contact
We may update this policy as the Services, our practices, or legal requirements change. The effective date will be revised when an update is published. For privacy questions or rights requests, use the Utilize support centre and request a private contact method. Do not post personal information in a public support request.