Effective September 1, 2026
Privacy Policy
This policy explains what Surevia collects, why processing occurs, how long records stay, and which choices you have.
Who is responsible
Surevia operates Surevia. Contact [email protected] about privacy. Surevia acts as controller for the website, accounts, security, and service operations. A Discord server owner decides the purpose and settings for server-requested verification. For those instructions, the owner acts as controller or business and Surevia acts as processor or service provider where applicable law recognizes those roles.
Data Surevia processes
- Discord data: user ID, username, avatar reference, server ID, server name, role settings, permissions, and OAuth tokens.
- Verification data: result, risk level, security reasons, review decisions, timestamps, and role assignment jobs.
- Security data: account age, failed attempts, related attempts, join activity, network category, country context, region and city estimates, ISP and ASN details, provider classification, Turnstile response, and a keyed network fingerprint.
- Technical data: session ID, request time, rate-limit key, browser request details, and service logs.
Discord supplies account and server data. Your browser supplies request and network data. Server activity supplies join and policy data.
Surevia uses your network address during a local database lookup. Redis keeps the normalized result for up to 24 hours under a keyed hash. Verification records do not contain raw network addresses. Server staff receive a category, country context, and short reasons. They do not receive coordinates, city data, prefixes, provider details, or internal weights.
Network intelligence datasets
Surevia checks downloadable reference databases on the Surevia server. The lookup does not send your network address to the database publishers. These files map network ranges to estimates and classifications. They do not confirm a home address, a person's identity, or wrongdoing.
- IP2Location LITE DB5: approximate country, region, city, latitude, and longitude records. Surevia uses location agreement as a risk confidence signal and does not store or show coordinates.
- IP2Proxy LITE PX12: proxy type, network use, ISP, ASN, provider, last-seen, threat, residential-proxy, and fraud-score records. Surevia turns relevant records into a short connection category and risk reasons.
- MaxMind GeoLite Country, City, and ASN: approximate country, region, city, time zone, ASN, and network organization records. Surevia uses these records to compare sources and spot conflicting classifications.
Source records differ in coverage, date, and accuracy. Agreement across available sources raises assessment confidence. Missing or conflicting records lower confidence and add an uncertainty reason. Surevia does not treat one dataset match as proof of abuse. Dataset files contain network-range reference records. They do not contain Surevia member verification histories.
Surevia uses the IP2Location LITE database for IP geolocation. Surevia uses the IP2Proxy LITE database for IP geolocation. This product includes GeoLite Data created by MaxMind.
Purposes and legal bases
- Provide verification and dashboard features
- Contract performance and steps requested before service use.
- Prevent raids, fraud, and abuse
- Legitimate interests in service security and community safety.
- Keep records and answer rights requests
- Legal obligations and legitimate interests in accountability.
- Protect legal rights
- Legal obligations and legitimate interests in handling disputes.
Automated risk checks
Surevia estimates risk from account age, verification history, network classification, source agreement, recent failures, verification volume, and server activity. Assessment confidence uses low, medium, or high. A lower account age, repeated failures, a join spike, or stronger network-risk evidence increases the score. Prior success and reliable source agreement reduce uncertainty. The result approves verification, requests another check, sends a result to review, or denies access under the server policy. Ask a server administrator for human review. Surevia does not use risk results for advertising, employment, lending, insurance, or credit decisions.
Sharing and transfers
Surevia shares data with Discord for identity and server features, Cloudflare for Turnstile checks, infrastructure providers for hosting and storage, and advisers or authorities when law or safety requires access. The local IP2Location, IP2Proxy, and GeoLite lookups do not send verification requests to those publishers. Surevia does not sell personal data or share personal data for cross-context behavioral advertising. Providers receive the data needed for their work and must protect those records under their agreements.
Providers process some data outside your country. Surevia uses contractual and legal safeguards required for restricted transfers.
Retention
- OAuth and website sessions expire after 7 days.
- Verification links expire after 5 to 60 minutes, based on server settings. Proof-of-work records expire after 2 minutes.
- Verification records expire after 365 days.
- Audit records expire after 365 days.
- Raid event records expire after 90 days.
- Removed server records expire after 365 days when related records have expired.
- Rate-limit records expire after their security window.
- Normalized network lookup results expire from Redis within 24 hours. Raw network addresses are not written to verification records.
- Network reference files follow publisher update and deletion duties. Old files are replaced instead of being kept as member records.
- Completed or declined privacy request records expire after 3 years.
Surevia keeps a record longer when law, an active dispute, or a security investigation requires retention.
Your privacy rights
Your location affects available rights. Rights often include access, correction, deletion, restriction, objection, portability, consent withdrawal, and a complaint to your data protection authority. California residents also have rights to know, correct, delete, limit certain sensitive data uses, and receive equal service after a request. Surevia does not offer a financial incentive for personal data.
Surevia verifies your identity before completing a request and responds within the period required by law. Under GDPR, the standard response period is one month. Some rights have legal exceptions. You have the right to appeal a denied request and contact your local supervisory authority.
Cookies and local storage
Surevia uses one essential session cookie for sign-in, security, and saved dashboard state. Surevia does not use advertising cookies or browser local storage for tracking.
Children
Surevia is not directed to children under 13. Users must meet Discord's minimum age for their country. Contact [email protected] if a child supplied personal data.
Security
Surevia uses encrypted transport, access controls, restricted database accounts, parameterized queries, short-lived sessions, request validation, rate limits, security headers, and audit records. No service removes every security risk.
Policy changes and contact
Surevia will post a new effective date after a material policy change. Contact [email protected] with a privacy question, rights request, or data processing agreement request.
Surevia