Privacy Policy
Last updated 28 August 2026.
Overview
Records Portal is run by Madison Bureau of Investigations, a fictional roleplay community — see the notice at the top of every page. Whilst the setting itself is fictional, the account information and activity records handled by this site belong to real people, and as a result this Privacy Policy describes, honestly and in plain language, what we collect and why we collect it. This is to ensure that visitors and members understand how their information is used before they continue using the site.
Information we collect
- Discord identity. When you sign in with Discord, we receive your Discord User ID and display name — via the
identifyOAuth scope only, as we do not request your email address — and we separately look up which roles you hold within this community's Discord Server. This is to determine what you are allowed to read or edit on the site, ensuring that access decisions match the permissions already assigned in Discord. - Content you submit. Any documents, edits, and images you create or upload through the site are stored, alongside the account that made each change. This is important because it preserves authorship, allows other members to see who contributed what, and provides the foundation for the version history and audit trail described below.
- Access codes. If you set a code to gate a document, we store that code as a hashed value only — never in plain text, and never inside an Audit Log. This is to ensure that the code cannot be read back by Administrators or exposed if logs are reviewed.
- Activity records. For every access-relevant action — such as viewing a gated document, creating or editing content, uploading an image, a failed sign-in, or a permissions change — we record who performed the action, what it was, and the IP address of the request. This allows the site's Administrators to investigate misuse or unauthorised behaviour without needing to guess what happened.
How we use it
We use the information listed above strictly to operate the site: deciding what you are allowed to see or change, keeping a record of who wrote or edited what, and maintaining an Audit Trail that Administrators can use to investigate misuse or unauthorised access. We do not use anything here for advertising, and we do not run any third-party analytics or tracking scripts, this is to ensure that your activity on the site is not shared with advertising networks.
Cookies & sessions
When you sign in, the site sets a single HTTP-only Session Cookie, valid for 12 hours, which points to a Session Record held server-side — this is to ensure that a Session can be revoked at any time without needing to retrieve the cookie from your browser. When you enter a document's access code, a second HTTP-only cookie is set, scoped only to that document and valid for one hour. Neither cookie is used for tracking, and there are no third-party or advertising cookies on this site.
Retention
Sessions expire after 12 hours, cached Discord role lookups expire after 5 minutes. Documents are versioned and soft-deleted rather than erased outright — meaning a "deleted" document is hidden from normal view but remains recoverable by an Administrator, this is to preserve the shared record and protect against accidental loss. Activity Logs are currently kept indefinitely, as we do not yet run an automatic purge; this may change in the future, and any change will be reflected in this Policy.
Sharing
Furthermore, we do not sell or share your information with advertisers or data brokers. Your Discord ID and role membership are read from Discord's API to make access-control decisions, and the underlying data continues to be governed by Discord's own Privacy Policy. Everything else is stored on Cloudflare's infrastructure — D1, R2, and KV — and is not shared outside this site's Administrators, this is to ensure that third parties cannot purchase or reuse your information for their own purposes.
Your choices
You can revoke this site's access to your Discord account at any time through your Discord settings, which will stop future role lookups from taking place. To ask about, correct, or request deletion of data we hold about you, contact an Administrator — details are below. However, because documents are shared community records with an edit history, we may not be able to fully erase past versions or Audit Entries without breaking that history for other members; when this happens, we will always explain what we can and cannot do, and why.
Children
This site is an extension of a Discord-based community, and as a result it inherits Discord's own age requirements. We do not knowingly collect information from anyone below the minimum age Discord itself requires for an account, this is to ensure that we do not process data that Discord considers to belong to a child user.
Changes to this policy
If this Policy changes in a way that materially affects how your data is handled, we will update the date above and, for significant changes, post a notice in the community. This is to ensure that members are aware of any change that affects their rights or the data we collect.
Contact
Questions about this Policy, or any request relating to your data, should be directed to a Madison Bureau of Investigations Administrator — compliance@mdsnbi.com.

