Privacy Policy
Effective June 11, 2026
01Overview
Clearwater Roleplay verification ("we", "us", "our") provides a service that links a user's Discord account to their Roblox account using Roblox's official OAuth 2.0 authorization flow. This policy explains what data we collect, why we collect it, and how we handle it.
02What we collect
When you complete a verification we receive, from Roblox:
- Your Roblox user ID (the
subclaim) - Your Roblox username and display name
- The URL of your public Roblox profile and avatar headshot
- Your Roblox account creation timestamp
From the Discord-side trigger we receive:
- Your Discord user ID (a numeric identifier)
We do not receive your Roblox password, email, payment information, friends list, private inventory, or any data outside the openid profile scopes you grant.
03Why we collect it
We use this data for one purpose: to record a verified link between your Discord account and your Roblox account so that the community systems you interact with can confirm your in-game identity. The link record is shared between the cooperating community bots that serve Clearwater Roleplay, so you only ever have to verify once. We do not sell, rent, or share this data with third parties for advertising or marketing.
04OAuth tokens
During verification we exchange a short-lived authorization code with Roblox to retrieve your public profile. The resulting access token is used once, immediately, and discarded. We do not store Roblox access tokens, refresh tokens, or ID tokens after the verification request completes.
05Cookies
During the OAuth handshake we set short-lived, HTTP-only cookies to carry the PKCE verifier and state nonce between Roblox's consent screen and our callback. These cookies expire within ten minutes and are cleared as soon as verification completes. We do not use advertising or analytics cookies.
06Retention
The Discord↔Roblox link record is retained for as long as you remain a member of a Discord community using this verification service. You can request deletion at any time by running /unlink in Discord or by contacting us (see Section 9).
07Your rights
You may at any time revoke this service's authorization from the Roblox account settings page. You may also request that we delete your link record by contacting us. Roblox's own privacy policy governs the data Roblox holds about you.
08Security
We follow standard practices for protecting OAuth credentials, including PKCE, state-parameter CSRF protection, encrypted transport (HTTPS), and least-privilege scope requests. No system is perfectly secure; we will notify affected users in the event of a breach involving identifiable data.
09Contact
For privacy questions or deletion requests, contact us at iclipse@centure.capital.
10Changes
We may update this policy from time to time. The effective date at the top of this page reflects the most recent revision. Material changes will be communicated through the Clearwater landing page.