Vaultspark

Privacy Policy

How Vaultspark handles data

Effective and last updated: August 23, 2026

Short version: Vaultspark stores Discord identifiers and game progress needed to run the collection game. It does not sell data, run advertising, or permanently store ordinary message bodies.

1. Scope

This policy applies when you use the Vaultspark Discord application ("Vaultspark," "the bot," "we," or "us"). Vaultspark is currently a controlled beta operated through Discord. Discord's own services and data practices are governed by Discord's policies.

2. Information Vaultspark processes

Discord identifiers

Vaultspark processes Discord user IDs to identify player accounts. It may also process server (guild), channel, message, and interaction identifiers when needed for commands, server-local encounters, leaderboards, duplicate settlement protection, and troubleshooting.

Collection and game state

Vaultspark stores information needed to preserve your game progress, including:

Serialized-card provenance

Premium, event, founder, and promotional cards may retain an ownership history. That history can include the original owner's Discord user ID, later owner IDs, acquisition source and date, and transfer count. Provenance is part of the collectible and may be visible to other players through card certificates or history views.

Operational telemetry and logs

Vaultspark records structured events such as pack openings, binder filters, dashboard actions, research outcomes, expedition stages, encounter wins, and trades. These records may contain a Discord user or server ID, timestamp, release phase, odds version, card or set identifier, and the outcome needed to measure reliability or prevent duplicate rewards. Technical error logs may also contain timestamps, component names, and relevant Discord identifiers.

3. Message content

Prefix commands and chat-triggered encounters require Vaultspark to process message content as it arrives from Discord. Ordinary message bodies are not placed in Vaultspark's game database or telemetry log.

When server-local encounters are enabled, Vaultspark normalizes an eligible message and stores a one-way SHA-256 hash of it, together with the most recent eligible author's Discord ID. This is used only to reject repeated messages and consecutive-message farming. The stored hash is replaced when the next eligible message advances that server's encounter counter. Quiz answers are evaluated to settle an attempt but are not copied into telemetry.

4. How information is used

Vaultspark uses this information to:

5. Information Vaultspark does not request

Vaultspark does not request your Discord password, bot token, payment-card information, government identification, precise location, contacts, or browsing history. Vaultspark has no paid products, cash-out system, advertising, or sale of personal information.

6. Sharing and service providers

Information is processed through Discord and the infrastructure used to host Vaultspark and its PostgreSQL database. Those providers process data only as needed to deliver their services. We may disclose limited information when required by law, to protect users or the service, or to investigate abuse. Vaultspark does not sell or rent personal information to third parties. Its cached card catalog and artwork pipeline do not send player information to a card-data API during commands.

7. What other players can see

Discord commands may display your Discord name or mention, collection totals, showcased cards, master-set progress, server ranking, encounter wins, trade status, and serialized-card provenance. Private interaction responses are used where the game calls for hidden choices, but information you intentionally publish in a server can be seen by people with access to that channel.

8. Retention and deletion

Game state is retained while needed to operate Vaultspark and preserve collection integrity. Settled trades, provenance, audit events, and aggregate statistics may be retained to prevent fraud, duplicate rewards, or broken ownership histories. Expired operational records and technical logs may be deleted or aggregated when they are no longer reasonably needed.

You may request access, correction, export, or deletion by contacting the Vaultspark operator in a Discord server where the bot is installed. If you cannot reach the operator directly, ask that server's administrators to relay the request. Include your Discord user ID and do not send passwords or account tokens. Deletion requests may remove active profile and inventory data while replacing identifiers in provenance, trade, or anti-abuse records with an anonymous marker where retention is needed for service integrity or legal obligations. Deleting Vaultspark data does not delete messages retained by Discord or a Discord server.

9. Security

Vaultspark uses access controls, a dedicated database boundary, atomic game settlements, and limited telemetry fields to reduce risk. No service can guarantee perfect security. If you believe Vaultspark exposed information or behaved unexpectedly, stop using it and contact the operator promptly.

10. Age requirements

You must meet the minimum age required to use Discord in your country and comply with Discord's Terms of Service. Vaultspark is not directed to children who are not eligible to use Discord.

11. Changes

This policy may change as Vaultspark adds features or service providers. Material changes will be reflected by the date at the top of this page and, when practical, announced through the bot or its testing community. Continued use after an update means the revised policy applies going forward.

12. Contact

Contact the Vaultspark operator through a Discord server where Vaultspark is installed. For privacy requests, include your Discord user ID and the words "Vaultspark privacy request" so the request can be identified and handled.

Read the Vaultspark Terms of Service