ZeroDay
HomeFeatures PremiumCommunity
Sign In Sign Up

Privacy Policy

Last updated: June 2026  ·  Effective immediately upon account creation or bot installation

Your privacy matters to us. This policy explains exactly what data ZeroDay collects, why we collect it, how it is stored, and your rights over it. We do not sell your data to third parties. Ever.

Contents

  1. Who We Are
  2. What Data We Collect
  3. How We Collect Data
  4. Why We Use Your Data
  5. Data Storage & Security
  6. Data Sharing
  7. Data Retention
  8. Cookies & Local Storage
  9. Your Rights
  10. Children's Privacy
  11. Third-Party Services
  12. Changes to This Policy
  13. Contact

1. Who We Are

ZeroDay is operated (zeroday-bot.netlify.app). When this policy refers to "ZeroDay", "we", "us", or "our", it means ZeroDay and the ZeroDay platform including the Discord bot and website at zeroday-bot.netlify.app.

For privacy-related questions, contact us via our support server: discord.gg/Ke6exB4368

2. What Data We Collect

DataSourcePurposeRequired?
Discord User IDDiscord OAuthAccount identification, Account ID generationYes
Discord Username & AvatarDiscord OAuthProfile display, public profileYes
Display Name, Username, BioYou (profile settings)Public profile customizationNo
Recovery EmailYou (account settings)Account recovery, optional notificationsNo
GitHub / Website linksYou (profile settings)Public profile displayNo
Discord Server IDsYou (server settings)Server linking & integrationsNo
Certification submission dataYou (cert form)Certification verificationOnly if submitting
Review content & ratingYou (review form)Community reviewsOnly if submitting
Login timestamps & eventsAutomatic on loginSecurity monitoring, account safetyYes
Plan & payment statusPayment processorAccess control for premium featuresIf purchasing premium

We do not collect: passwords, Discord message content, IP addresses beyond login security checks, or browsing history.

3. How We Collect Data

3.1 Discord OAuth

When you sign in with Discord, Discord sends us your user ID, username, avatar hash, and email (if your Discord account has one and you grant permission). We use the identify scope — we do not read your messages, servers, or friends list.

3.2 Directly from You

When you fill in your profile, submit a certification, write a review, or link a server — you provide that data directly. You control what you share.

3.3 Automatically

We record login events (timestamp, success/failure) for account security purposes. We do not use tracking pixels, fingerprinting, or analytics beyond what is necessary for the Service to function.

3.4 Discord Bot

When the ZeroDay bot is added to a Discord server, it may process message content only to execute commands directed at it. It does not store message content, read private messages, or log conversations.

4. Why We Use Your Data

  • To provide the Service — your Discord ID and profile data are needed to create and operate your account
  • To secure your account — login events are monitored to detect unauthorized access and protect your account
  • To verify certifications — certification submission data is used solely to process your verification request
  • To display public profiles — if you opt in to a public profile, your display name, avatar, bio, and links are shown publicly
  • To send notifications — only if you opt in and provide a recovery email
  • To improve the Service — aggregate, anonymized usage data may be used to understand how ZeroDay is used and improve it
  • To enforce our Terms — audit logs of moderation actions are kept to ensure accountability

We do not use your data for advertising, profiling, or any purpose not listed above.

5. Data Storage & Security

Your data is stored in Supabase, a cloud database provider with encryption at rest and in transit. Our website and serverless functions are hosted on Netlify with HTTPS enforced on all connections.

We implement the following security measures:

  • All data transmitted over HTTPS/TLS
  • Database access restricted to server-side functions only — never exposed directly to the browser
  • Authentication tokens stored in your browser's local storage and never sent to third parties
  • Account auto-lock after repeated failed login attempts
  • Login from unrecognized sources triggers internal security alerts
  • Admin and moderation actions are logged with timestamps and actor identity

No method of transmission or storage is 100% secure. While we take commercially reasonable precautions, we cannot guarantee absolute security of your data.

6. Data Sharing

We do not sell your data. We do not share your personal data with advertisers, data brokers, or any third parties for commercial purposes.

We may share data in the following limited circumstances:

  • Service providers — Supabase (database), Netlify (hosting), Resend (transactional email). These providers process data on our behalf under their own privacy policies and are contractually restricted from using your data for their own purposes
  • Discord — When you use bot commands or submit reviews that mirror to Discord, relevant data appears in your designated Discord channels
  • Legal requirements — We may disclose data if required by law, court order, or to protect the rights, property, or safety of ZeroDay, our users, or the public
  • Business transfer — In the event of a merger or acquisition, your data may be transferred as part of that transaction with appropriate notice to you

Your public profile data (display name, avatar, bio, links) is visible to anyone who visits your profile URL if you have public profiles enabled in your privacy settings.

7. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service.

  • Account data — retained until you delete your account
  • Reviews — retained indefinitely as they are community content. Removed reviews are flagged in the database but may be retained for moderation records
  • Certification submissions — retained for the life of your account as proof of verified credentials
  • Audit logs — retained for 12 months for security and moderation accountability
  • Login event logs — retained for 90 days

When you delete your account, we will delete your personal profile data within 30 days. Some anonymized or aggregated data may be retained longer for Service improvement purposes.

8. Cookies & Local Storage

ZeroDay does not use tracking cookies or advertising cookies.

We use browser local storage to store your authentication token and cached profile data on your device. This is necessary for the Service to function — it keeps you signed in between visits. This data stays on your device and is never sent to third parties.

Clearing your browser's local storage will sign you out of ZeroDay. You can do this at any time from your browser settings.

Our hosting provider (Netlify) may set technical cookies necessary for CDN and security functions. These are not used for tracking.

9. Your Rights

Depending on where you are located, you may have the following rights regarding your personal data:

  • Access — Request a copy of the personal data we hold about you
  • Correction — Update inaccurate or incomplete data via your account dashboard at any time
  • Deletion — Delete your account and associated personal data from your account dashboard
  • Portability — Request your data in a portable format
  • Restriction — Request we restrict processing of your data in certain circumstances
  • Objection — Object to processing of your data for specific purposes
  • Withdraw consent — Where processing is based on consent (e.g. marketing emails), withdraw it at any time

To exercise any of these rights, contact us via our support server. We will respond within 30 days. We may need to verify your identity before fulfilling requests.

If you are in the European Economic Area (EEA) or UK, you also have the right to lodge a complaint with your local data protection authority.

10. Children's Privacy

ZeroDay is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected data from a child under 13, please contact us immediately and we will delete it.

Users between 13 and 18 should have parental consent before using ZeroDay, consistent with Discord's own Terms of Service.

11. Third-Party Services

ZeroDay integrates with the following third-party services. Their privacy practices are governed by their own policies:

  • Discord — discord.com/privacy
  • Supabase — supabase.com/privacy
  • Netlify — netlify.com/privacy
  • Resend — resend.com/privacy (transactional email only)
  • NVD / NIST — nvd.nist.gov (CVE data, no personal data shared)

CVE and threat intelligence data is sourced from the NVD public API. No personal data is sent to NVD.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and announce it in our Discord support server. Continued use of ZeroDay after changes take effect constitutes acceptance of the revised policy.

13. Contact

For privacy questions, data requests, or concerns, contact us via our support server:

discord.gg/Ke6exB4368

We aim to respond to all privacy inquiries within 30 days.

← Terms of Service ← Back to Home
© 2026 ZeroDay Bot — ZeroDay
Terms of Service Privacy Policy Support