01 Scope and Operator
This Policy covers trustbadge.dev, its API, participating TrustBadge VRChat world prefabs, administrative tools, and support workflows operated by the TrustBadge team. It does not cover VRChat, Discord, world owners, or other third parties operating under their own policies.
02 Data We Collect
When a player submits verification, we process and store:
- Permanent VRChat user ID
- Current VRChat display name at the time of a check
- TrustBadge status, such as verified, unverified, or banned
- Verification, recheck, and last-seen timestamps
- Limited event logs, including event type, participating world tag or ID, result, and technical error detail
For administrators, Discord OAuth provides the Discord user ID, username, and display name needed to authorize and display the session. World-owner records may include a world tag and an encrypted or protected Discord webhook configuration.
03 Data We Do Not Collect
TrustBadge does not request or receive identity documents, selfies, legal names, dates of birth, street addresses, VRChat passwords, VRChat email addresses, payment card information, or the evidence VRChat used for its age-verification decision.
04 How We Use Data
- Resolve a display name to the correct permanent VRChat account
- Check and remember the account's eligible status
- Return access decisions to participating worlds
- Recheck existing records and prevent copied-name impersonation
- Operate rate limits, security controls, audit logs, bans, maintenance, and support
- Produce aggregate service analytics and diagnose failures
We do not sell personal data, build advertising profiles, or use verification records for targeted advertising.
06 Retention
Verification records remain while needed to provide reusable access, until the record is administratively removed, or until a valid deletion request is completed. Security and administrative logs are retained only as long as reasonably needed for abuse prevention, incident review, and service operation. Backups may retain deleted data for a limited rotation period before automatic replacement. A ban record may be retained where necessary to prevent renewed abuse, subject to applicable law.
07 Security
TrustBadge uses encrypted transport, restricted administrative access, credential separation, encrypted product-key envelopes, rate limits, audit logging, and protected hosting controls. No system is perfectly secure. If we identify a material incident affecting covered data, we will investigate and provide notice where required.
08 Your Choices and Rights
Depending on your location, you may request access, correction, deletion, restriction, portability, or an explanation of data associated with your VRChat account. You may also object or withdraw consent where applicable. Removal means participating worlds will no longer recognize the prior TrustBadge result and you must verify again for future access.
To protect records from unauthorized deletion, we may ask you to verify control of the relevant VRChat account. We will only request the minimum proof needed and will never ask for your password or identity document.
10 Age, Location, and Changes
TrustBadge is designed for access to 18+ spaces and is not directed to children. Service providers may process data in countries different from yours under their own safeguards. We may update this Policy when service behavior, providers, or legal requirements change. The effective date at the top identifies the current version.
11 Data Removal and Support
Join the official TrustBadge Discord and open a private support ticket for data access, correction, removal, privacy questions, or general support. Include your VRChat display name and explain the request. Do not post account details in public channels. We will respond through the ticket and may request account-control verification before changing a record.