Privacy policy · Last updated August 25, 2026
Privacy policy
ServerSift is a discovery site for Discord communities. We designed it to work with the smallest amount of data we can get away with. This page explains exactly what we collect, why, and what we deliberately do not collect.
The short version
- Visitors can search and browse without an account. We set one random cookie to count sessions and stop double-counting.
- Signing in uses Discord with only the
identifyandguildsscopes. We never see your password or your messages. - Our bot measures how many messages a listed server sends per hour. It does not read, store, or export message content.
- We do not build profiles of Discord members, track people across other sites, or sell data.
- Precise IP addresses are never stored. We keep a one-way hash for abuse prevention only.
Data we collect from visitors
When you use the site we record first-party analytics events such as a page view, a search, a click on “Join Server”, or a report. Each event carries: an anonymous session id (random, set in a cookie, not linked to your Discord account), a coarse device type (desktop, mobile, tablet), the referring site with query strings removed, a country code when our hosting provider supplies one, the page or search term involved, and a timestamp. We use these to understand which servers people find useful and to detect abuse. Raw events are deleted after 180 days; aggregate daily counts are kept longer.
We also use PostHog, a product-analytics service, to understand how the site is used. This includes session replay: an anonymised recording of how pages are scrolled and clicked, together with browser console messages and the timing and headers (never the contents) of requests to our own site. Everything you type is masked, request bodies are not recorded, your account menu and the admin area are never captured, and no Discord identity is attached (signed-in visitors are represented only by an internal account id). We also collect click and scroll heatmaps, page performance measurements (how fast pages load and respond), error reports when something on the site breaks (from your browser and from our servers, linked to the same anonymous PostHog identifier so we can see what led to the error), and we may occasionally show a short in-app survey. We honour the Do Not Track andGlobal Privacy Control browser signals: when either is on, session replay is disabled for your visit. PostHog data is processed under our instructions and is never used for advertising.
Data we collect when you sign in
Signing in with Discord gives us your Discord user id, username, display name and avatar, plus the list of servers you belong to and your permissions in them. We use the server list only to show you which servers you are allowed to submit. Your OAuth tokens are stored encrypted so we can refresh that list without asking you to sign in again; you can revoke access at any time from Discord’s Authorized Apps settings. We keep a session record (a hashed token, when it was last used, and your browser’s user-agent string) for 30 days of inactivity.
Data we collect about listed servers
Server owners submit their listing: name, descriptions, category, tags, language, region, optional links and a public invite. We also store public metadata Discord exposes about the server (icon, banner, approximate member and online counts, creation date). If the owner adds our bot, the bot records per-server, per-hour aggregate counts: number of messages, number of channels with activity, and, where necessary for spike detection, the number of distinct authors in that hour. These numbers are aggregate. We never store who wrote a message or what it said, and the bot does not request Discord’s message-content intent.
Moderation data
Listing text and imagery are scanned by automated moderation. We store the provider used, its model version, the category scores it returned and the decision we made, so moderators can audit outcomes. Reports you file store the reason, optional details, and an identifier (your account id, anonymous session id, or hashed IP) so we can rate-limit and de-duplicate reports. Reporter identities are visible only to ServerSift moderators.
Cookies
ss_anon— random anonymous session id for analytics de-duplication (400 days).ss_session— your sign-in session (30 days, sliding).- Short-lived cookies during Discord login (10 minutes).
ph_*— PostHog product-analytics identifiers and session-replay state (first-party, served from this domain).
We do not use advertising cookies or third-party tracking pixels. Sponsored placements are contextual (based on the page) and never on who you are.
What we never collect
Message content, direct messages, member lists, relationships, presence histories, voice activity, or per-user activity. We do not scrape Discord; every server on ServerSift was submitted by someone authorised to manage it.
Sharing
We share data only with the infrastructure that runs the site (hosting, database, optional content-moderation API for listing text) and when required by law. Moderation providers receive listing text, report text and appeal text — never visitor identities.
Retention
- Raw analytics events: 180 days. Daily rollups: indefinitely, aggregate only.
- Activity measurements: 90 days of hourly data; rolled-up activity status kept with the listing.
- Sessions: 30 days after last use. OAuth tokens: until you revoke access or delete your account.
- Moderation and audit records: kept while the listing exists and for a reasonable period afterwards to handle appeals and repeat abuse.
Your choices
Owners can remove a listing from their dashboard at any time. Anyone can ask us to delete their account data or remove a server from the directory through the reporting and removal page. Removing our bot from your server stops activity measurement immediately.
Contact
Questions about privacy can be sent through the contact details on the reporting and removal page.