1. Data Collection Scope (Minimization Principle)
GuildLink processes only public identifiers strictly necessary to orchestrate cross-server routing and mutual defense:
- Discord Guild ID: To manage member alliance topologies and active guild registries.
- Discord Channel ID: To establish channel mappings for chat, teamup, trade, and announcement webhooks.
- Discord User ID & Public Profile: To impersonate sender names and badges on relayed webhook messages.
- Threat Hashes: Anonymized fingerprints of detected phishing URLs and compromised tokens.
2. Zero Long-Term Message Persistence
Operating on Cloudflare Workers edge architecture, all relayed communications are processed ephemerally in memory and dispatched to target webhooks without persistent storage or archival in databases.
3. Real-Time Message Synchronization and Erasure
When an author or moderator edits or deletes a message in the origin server, GuildLink immediately broadcasts PATCH or DELETE requests to all partner nodes to ensure synchronized removal across the mesh.
4. Data Subject Rights and Purge Requests
Guild leadership may request the immediate deletion of all server configuration data, webhook mappings, and secret keys stored in backend databases (D1/KV).