Skip to content

Privacy Policy

Last updated 26 September 2026. This will change as Referr does.

Referr gives a community its own campaign links, and shows who joined through which one. This page explains what that requires us to know, and what we do with it. If you use Referr, work in an organization that does, or joined a Discord server through a Referr link, this covers you.

Opting out

Anyone can ask Referr not to track them, in every server at once, with no Referr account: use the opt-out page, or type /referr-privacy in any server that has Referr's bot. We then keep only your Discord id, so we remember you asked, and delete everything we held about you: which link you used, when you joined and left, and when you took part. Your later joins still add one to a campaign's total, with nothing about you attached. You can opt back in the same way.

What we collect if you have an account

You sign in with Discord, or with a link we email you. With Discord, we ask for your Discord id, your display name and the list of servers you're in, so we can check which ones you manage. With email, we keep your address. Either way we keep a name to show your teammates, and a session so you stay signed in. Your browser also keeps which organization you last opened, so your account page can show it. We store only a one-way code of your session and of each sign-in link, never the link itself. We don't keep the rest of your server list. Your Discord picture, on your account menu, is looked up from Discord when it's shown, not kept in our database.

In an organization, we keep who belongs to it, their role, which projects they can see, and a log of changes to who the owners and admins are. An invitation keeps the address it was sent to until it's used, withdrawn or expires. If an organization was made with a complimentary sign-up link, we keep which one.

Paying for Referr

Paddle.com sells Referr's paid plan for us, as the merchant of record. You pay on Paddle's form, which Paddle shows inside Referr's checkout page in its own frame, so your card and billing address go to Paddle and never reach Referr. Paddle's own privacy notice covers what it keeps. From Paddle we keep only the ids of the organization's Paddle customer and subscription, whether the subscription is active, how often it's billed, how many extra domains it pays for, and when it next renews or ends. The checkout and the page Paddle's emails link to for paying are the only pages on Referr that load a script from someone else: Paddle's.

What we collect once a server adds Referr's bot

The server's id and name, who owns it, its member count once an hour, and which of its roles you've named as manager roles. Then, for each campaign you make: its name, where you said the link would be posted, and the Discord invite Referr created for it.

What we collect about people who join through a campaign link

Their Discord id and when they joined, so the join can be counted. If we can tell which campaign the link belongs to, that's recorded too, along with why we think so. If a server holds new members in a screening step, we note when they clear it, and we note when they leave, so a campaign's numbers stay accurate over time.

We don't store their avatar, display name, or email. The name and picture shown next to a join are looked up from Discord when the page loads, not kept in our database.

People who click a Referr link

A campaign's website link (on go.referr.fyi, or on an organization's own domain) counts the click, then sends the visitor straight on to the server's Discord invite. A short link on an organization's own domain works the same way, and sends the visitor to the address the organization chose. For each click we record the day and the hour, the website it came from (reddit.com), and the page on that website when it shares one, without anything after a ? or #. Most browsers share only the website. We also record the country Cloudflare places the visitor in, the kind of device (phone, tablet or computer), the browser's language, and any tag added to the link, like ?ref=newsletter.

All of it is kept as counts for each link and day, never as a record of one visit. We don't record IP addresses, set cookies, or keep anything that could tell one visitor apart from another.

So that one person reloading a link doesn't count many times, a visitor is counted once an hour per link. To do that, a one-way code made from their IP address, the link and the hour is held in Cloudflare's short-term cache for one hour, then discarded. It never reaches our database. Link previews made by apps and search engines are not counted at all.

Shared campaign results

Someone who works on a project can share a campaign's results as a link, for example with the studio or publisher behind it. That page shows totals only: how many joined, stayed, clicked and took part, by source. It never shows who joined. The link can be revoked at any time, and it stops working at once. Shared pages are kept out of search engines.

Member activity, only if an organization turns it on

An organization's owners and admins can turn on member activity for a server, to see which campaigns bring people who take part. For each person who joined after it was turned on, we record two times: the first time they sent a message or joined a voice channel, and the first time they did so between 30 and 44 days after joining. We never receive or store what anybody wrote, which channel it was in, or how many messages they sent.

To know when someone is active, Referr's bot is told by Discord that a message was sent in any server it is in. For servers that have not turned member activity on, that is dropped the moment it arrives, and nothing about it is recorded. It can be turned off at any time, in the project's settings.

What we use it for

Working out which campaign a join or a click came from, and showing that to the people who run the campaign. Nothing else. We don't sell it, run ads against it, or hand it to data brokers, and there's no analytics tracker on this site watching what you do.

Who can see a project's data

The members of the organization the project belongs to, as its owners and admins allow: owners and admins see every project, and other members see the projects chosen for them. For a project with a Discord server, people who manage that server can see it too: anyone with the server's own Manage Server permission, by default, and anyone holding a role named as a manager role. Either can be turned off in the project's settings.

Where this runs

The dashboard and the database are Cloudflare Workers and Cloudflare D1, and sign-in emails are sent through Cloudflare's email service. A small always-on service on Fly.io holds the connection to Discord's live event stream open and passes join and leave events along. Paddle takes payments. Each exists to run Referr, not as data buyers of their own, and Discord itself is the platform all of this is built on.

How long we keep it

If Referr's bot is removed from a server, we stop tracking it at once, and 30 days later we delete what came from it: its joins, leaves, member counts and activity. Adding the bot back within those 30 days keeps the history. A deleted organization, with everything in it, goes 30 days after it's deleted. Ended sessions and used sign-in links are cleared daily.

Your choices

Opt out as above, or remove the bot from a server and Referr stops watching it. To ask about, correct, or delete data tied to a Discord id or an email address, write to privacy@referr.fyi from an address we can use to follow up, or with enough to identify the request.

If you run a server

Your own members may have rights over their data under laws that apply to your community, separate from what this page covers for Referr itself. Adding the bot is a good moment to let your members know it's there, what it does, and that /referr-privacy lets them opt out.

Changes to this policy

Referr is early, and this page will be updated as the product changes. We'll change the date at the top when we do.

Contact

privacy@referr.fyi

See also the Terms of Service.