1. Operator and scope
Gage Olson / SwornHero operates StoneHaven Staff Wiki for the StoneHaven community (“we,” “us,” or “our”). Contact us at SwornHero@stonehavensmp.com.
This Policy covers the Discord login application, authorization checks, and use of the protected Staff Wiki on the StoneHavenSMP website. The service is exclusively for our own authorized staff. It is separate from Milo, the Discord–Minecraft bridge, and does not describe Milo’s chat processing or the separate BlueMap map service.
2. Information processed and why
| Information | How it is used |
|---|---|
| Discord identity | Discord user ID, username or display name, and available avatar information identify the signed-in account and display the account in the interface. |
| Server membership and roles | Discord membership information for the designated StoneHaven server is received to determine whether the required Staff role is present. The application uses role IDs to make this decision. |
| OAuth credentials | Discord access tokens, expiration information, and refresh tokens where supplied allow the website to perform membership checks and renew access to Discord’s API. |
| Session and authorization information | Session cookies, staff-access status, and the time of the last successful role check maintain login state and protect restricted content. |
| Website request and diagnostic information | Our hosting services may process IP addresses, request times, requested paths, browser or device details, response information, and errors to deliver and secure the website and diagnose problems. |
| Website analytics | Where Vercel Web Analytics is enabled, page-view and usage information such as visited URLs, referring sites, browser/device categories, and approximate location information may be processed to understand website use. |
| Correspondence | Information you provide when requesting support, reporting a problem, or exercising a privacy right is used to respond to that request. |
The Discord login requests the scopes identify and guilds.members.read. It does not request the email scope or permission to read Discord messages. Your Discord password is entered on Discord and is not received by this application. If you email us, we receive the email address you use for that correspondence.
The membership response can include information beyond the role IDs needed for the access decision. The application uses this response to check membership and the required role; it is not designed to build a directory of your other Discord communities.
3. Cookies and session behavior
The login system uses necessary cookies to maintain sessions, protect the sign-in flow, and remember recent staff verification. Blocking or deleting these cookies can prevent login or require you to sign in again.
The current implementation uses encrypted Auth.js session tokens stored in browser cookies. The session can contain Discord identity information and OAuth tokens needed by the server. OAuth tokens are not exposed through the client-facing session response. A separate encrypted authorization cookie records your Discord user ID, staff-access status, and successful-verification timestamp.
The login session is configured with a 24-hour maximum age, and the separate staff-authorization cookie is also configured with a 24-hour lifetime. Cookies can be reissued during authentication or authorization activity; these settings are not a promise that all information is deleted 24 hours after your first login.
A successful Staff-role verification can be reused for up to five minutes before a later protected request requires a fresh check. Removing a role therefore may not immediately terminate access to every already-open page or recently verified session. Previously viewed or downloaded content cannot be recalled automatically.
The current login implementation uses cookie-based sessions rather than a dedicated server-side account/session database. Hosting logs, analytics, and support correspondence are separate from those cookies.
4. Providers and access to information
Discord authenticates your account, issues OAuth tokens, and answers the membership requests authorized through login. Its handling of data is described in Discord’s Privacy Policy.
Vercel hosts the website and processes requests and associated operational information. The website includes the Vercel Web Analytics integration; analytics collection depends on its deployment settings. Vercel describes that analytics product as using no analytics cookies. This is separate from the login cookies described above. See Vercel’s Privacy Notice and Web Analytics privacy documentation.
Cloudflare provides DNS for the website domain. Under our current configuration, Cloudflare does not proxy the Staff Wiki’s web traffic. Proxying for the separate Minecraft map subdomain is outside this login service’s scope. DNS-related processing is subject to Cloudflare’s Privacy Policy.
The operator and people authorized to administer or support the service may access information needed for those responsibilities. We may also disclose information when legally required. Any disclosure of Discord API data remains subject to Discord’s restrictions and applicable law.
We do not sell personal information, use Discord identity or membership information for targeted advertising, or use it to train AI models. The login application does not relay Discord conversations to Minecraft.
5. Retention
We retain information only as needed for the purposes described here or as required by law.
- Session and authorization cookies: handled according to the lifetimes and reissuance behavior described above. Signing out is designed to clear the staff-authorization cookie and end the website login session.
- Membership responses: processed for access decisions; the current login flow does not maintain a persistent membership-history database. A recent verification result is stored in the authorization cookie.
- Hosting and diagnostic records: retention depends on enabled Vercel services, account settings, and any configured log storage. Session expiration does not automatically delete these records.
- Analytics: retained according to the enabled analytics service and its configured retention. Analytics records are separate from authentication cookies.
- Support correspondence: retained as needed to resolve requests and satisfy applicable legal obligations.
- Backups or exports, if used: subject to the retention and deletion controls of the system holding them. We address copies under our control when handling deletion requests and prevent deleted information from being restored into active use.
There is no single automatic deletion period covering all of these systems. Except where applicable law requires retention, we promptly delete Discord API data under our control when it is no longer needed for the permitted service functions, when the application stops operating, or when deletion is requested by the relevant user or Discord.
6. Signing out, disconnecting, and privacy requests
You may sign out of the website, remove its cookies from your browser, or revoke the application’s authorization through Discord’s account settings. Signing out of the website does not itself revoke the Discord OAuth authorization. Revoking authorization may not immediately erase a recently cached role check, content already displayed, or separate hosting records.
To request access, correction, or deletion of personal information under our control, email SwornHero@stonehavensmp.com. Include your Discord user ID or username and enough context to identify the request. You do not need to retain the Staff role or sign in to contact us.
We may request proportionate verification of account ownership. Do not send Discord passwords, session cookies, or access tokens. We respond within applicable legal deadlines and handle requests concerning Discord API data promptly. If a legal retention requirement limits deletion, we will explain where permitted. Discord and infrastructure providers may control some information independently; we will explain when a request needs to be directed to them.
Depending on applicable law, you may also have rights to restrict or object to processing, receive portable data, withdraw consent where processing relies on consent, and complain to a relevant data-protection authority. Withdrawing the authorization necessary for login can prevent use of the Staff Wiki. A privacy request does not itself restore or grant a staff appointment.
7. Security and staff information
The service uses Discord authentication, server-side role checks, encrypted session/authorization cookies, and access restrictions to protect staff resources. Production cookie settings restrict access from browser scripts and require secure transport. These measures do not guarantee protection against every threat.
Staff must protect their accounts and handle nonpublic documents and player information according to the Staff Wiki Terms of Service. Access to the wiki does not authorize redistribution of another person’s information.
Report suspected unauthorized access or disclosure to SwornHero@stonehavensmp.com. We investigate incidents and provide notices required by applicable law and platform obligations.
8. International processing and age eligibility
Discord and Vercel may process information in countries other than your country of residence. Their service arrangements and applicable legal transfer requirements govern the processing involved. Contact us for information about the deployment’s processing locations.
The service is not intended for people below Discord’s applicable minimum age, including children under 13. If you believe information from an ineligible child has been processed, contact us so we can investigate and address information under our control.
9. Policy changes and contact
We will update the dates above when this Policy changes and notify staff of material changes through the website or staff communications. We will obtain consent where required for changes to processing.
Gage Olson / SwornHero — StoneHaven Staff Wiki
Email: SwornHero@stonehavensmp.com