Privacy policy
GuildControl MCP is a local stdio connector. It does not provide a hosted service, shared bot, advertising, analytics, or an operator-run collection endpoint. You supply and control the Discord application, bot, configuration, MCP host, machine, and any optional observability destination.
Credentials
Section titled “Credentials”The Discord bot token stays outside the non-secret configuration document. The connector reads it from the exact environment variable or protected file named by that configuration. The one-click MCPB asks the host for the token as a sensitive value, maps it in memory to the configuration's declared environment variable, and removes the bundle-only input before normal startup. The connector does not print, persist, return, or include the token in activity records, operation receipts, diagnostics, artifacts, or telemetry.
The connector sends the token only to Discord's fixed REST origin and, when explicitly enabled, vetted Discord Gateway or Interaction endpoints. Tests may inject a local transport or origin but production code cannot.
Migration evidence
Section titled “Migration evidence”The offline migration planner uses shipped public manifests and the credential-free target catalog. It does not inspect another checkout, source configuration, active connector policy, MCP host settings, environment values, credential files, Discord content, local records, or browser state. It contacts no network or Discord endpoint, starts no process, exports no telemetry, and changes neither deployment.
Migration reports contain public source release identities and evidence URLs, public source and target tool names, preset and recipe names, fixed placeholders, dispositions, counts, limitations, and deterministic digests. They contain no credential value, real Discord ID, local source path, username, role or channel name, message content, profile, or host-specific state. The optional mode-0600 HTML embeds the exact report but not its output path, makes no automatic request, and stores checklist and filter state only in memory. Source and Registry links navigate only when you activate them.
Host inspection evidence
Section titled “Host inspection evidence”Host configuration inspection reads only the static JSON file the operator explicitly selects. That file may contain bot tokens or other credentials placed there by a host or operator, so the connector treats all observed bytes as private even though its own generated adapters contain references rather than token values. It returns and persists no selected host path, raw file, observed value, unrelated entry, credential material, or digest of private host bytes. The deterministic inspection digest covers only fixed classifications, safe counts, privacy and file-review evidence, limitations, and the expected adapter and activation identities.
The inspector does not discover a host or home directory, resolve the connector credential, read another environment value, contact a network or Discord endpoint, start a process, edit policy or host state, create an activity or operation record, export telemetry, or retain browser state. Shared host files are projected to the connector-owned server entry and generated sensitive-input records before comparison; unrelated entries are not returned, counted, hashed, or assessed. A dedicated extension manifest is compared as a complete document because it is not a shared host configuration.
Discord data
Section titled “Discord data”Discord data is fetched only for an invoked operation within the exact configured scope and applicable Discord permissions. Results needed to answer the request are returned to the MCP host. The connector does not independently retain message content, attachment URLs, embeds, components, audit-log reasons, usernames, profile names, role names, channel names, topics, scaffold symbols, or avatars.
Supported Components V2 link-button destinations are returned transiently inside layout and plan review so the operator can inspect the complete untrusted URL. Outbound guild and private-message writes require each normalized first-hop HTTPS origin in the exact configured allowlist before Discord access. The connector never fetches a destination, resolves DNS, follows a redirect, inspects remote content, or persists the URL or origin in activity, operation, coordination, diagnostic, or telemetry state. Discord, the MCP host, the model provider, and the destination may retain or process the link under their own policies.
Managed Components V2 request Buttons return their visible labels and styles transiently during layout and plan review, but the connector generates their authenticated custom IDs internally and never returns or persists an ID or route. A click authenticates the attached source and refetches the exact source message before exposing the visible label as one transient pending request. The MCP host and model provider receive that label when they read the pending queue. The raw Interaction token remains broker-private. Persistent click activity may contain the exact guild, channel, user, Interaction, and source-message IDs, a domain-separated reference hash, button index, fixed style, timestamps, status, and sanitized error category, but never the label, request text, custom ID, route, source layout, or token.
The bot-installation audit reads the authenticated bot's complete bounded guild-membership inventory with approximate member and presence counts disabled. Each response is projected immediately to unique guild IDs; names, icons, ownership, permissions, features, counts, unknown values, and raw payloads are discarded. The result returns exact configured, installed, installed-in-scope, missing, and unexpected IDs only for scope-drift review. Unexpected installations do not become connector authority, and the audit does not change policy, leave a guild, create a record, export telemetry, or persist any result.
Conversation recall holds caller-supplied literal phrases and Discord search candidates only for one request. The recall_conversation result never echoes phrase text, usernames, profile names, channel names, or raw payloads, and never writes an index, embedding, cache, activity record, operation receipt, or telemetry field. The optional recall_discord_conversation prompt renders the caller's validated memory once as literal workflow input so the client can derive phrases; it does not persist it. Ranked targets are refetched from Discord before their bounded current context is returned. The MCP host and model provider still receive the prompt input, tool input, and returned message context under their own retention policies.
Directed coordination uses random caller-retained routing labels and strict plain-text Discord envelopes without a connector-owned registry, note board, listener, mailbox, background worker, or polling loop. Address observation returns only page-local sender labels, exact last-message IDs, counts, and timestamps; it omits bodies, tags, recipients, notification targets, profiles, and reaction users. Note inspection returns bodies only for the requested label or selected broadcasts and exact filters. No address, body, tag, recipient, notification target, cursor, observation, or routing result enters an activity record, operation receipt, durable coordination claim, diagnostic, metric, trace, cache, or local file. Labels and note content are visible and spoofable Discord data, not identity or authority. The MCP host and model provider still receive invoked tool inputs and matching transient note bodies under their own retention policies.
A command-processing signal transiently reads one exact current source message, including its content and parsed mentions, only to prove a fresh ordinary user explicitly addressed the verified bot. It returns and persists none of that content or user presentation data. Its content-free activity records contain only exact guild, channel, source-message, and activity IDs, timestamps, fixed status, and sanitized error category.
Guarded soundboard playback transiently reads one exact target voice channel, the connector's membership and roles, current bot voice state, and one exact default or allowlisted custom sound only to prove current readiness. The readiness result may return the untrusted sound name, but persistent records contain only exact guild, channel, sound, optional source-guild, and activity IDs, request and operation-key hashes, timestamps, fixed status and verification values, and sanitized error category. Channel and sound names, voice profiles and state, roles, permission overwrites and decisions, Gateway payloads, and transport causes are never persisted or exported.
An exact native attachment read refetches one current message, uses its Discord-supplied signed CDN URL internally without sending the bot credential, and returns the bounded bytes to the MCP host as native or embedded protocol content. It accepts no URL from the caller, creates no download file or cache, omits the signed and proxy URLs, scans raw bytes for active connector secrets before encoding, and overwrites its transient raw buffers afterward. The MCP host, model provider, and operating system still handle the encoded result under their own retention policies.
Optional Gateway data is bounded, privacy-projected, and held in memory. Exact soundboard playback corroboration discards non-target effects and never enters the general event feed or persistent records. Native Interaction slash-command and request-button payloads are discarded after validation; an accepted request retains only its bounded request text and minimum response capability in process, while an explicitly enabled continuation retains only the minimum rotating one-shot capability for its fixed lifetime and scope.
Your MCP host, model provider, terminal, operating system, Discord, and any software that receives a result may have separate logging, retention, and privacy behavior. Review those systems before granting the bot access to sensitive servers or channels.
Local records and observability
Section titled “Local records and observability”When configured, local activity and operation records contain only Discord identifiers, timestamps, numeric action parameters, domain-separated hashes, plan digests, strategies, sanitized errors, and outcomes. They exclude Discord content and display data. Reviewed mutations may create pending records and restart-safe checkpoints before a request so ambiguous outcomes can be reconciled without retaining content.
Metrics and traces are bounded and redacted. Export is off unless the configuration explicitly enables a fixed supported destination and supplies any secret headers outside the configuration. No ambient telemetry setting can widen an activated profile or configuration.
Control and deletion
Section titled “Control and deletion”You choose the bot's Discord permissions, exact connector scope, enabled toolsets, write capabilities, local record paths, Gateway policy, and telemetry policy. Revoke the bot token in the Discord Developer Portal to stop its use. Remove the connector from the MCP host to stop local execution. Delete any generated migration guide and configuration-selected local activity, receipt, profile, or telemetry files according to your own retention policy.
Discord processes data under Discord's privacy policy. Questions or vulnerability reports for this connector can be filed through the repository's support and security channels.
Canonical source: PRIVACY.md
Documentation generated for guildcontrol@0.0.0. Canonical source and edit history remain in the public repository. GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.