1. Data Collection (Principle of Minimization)
Portico adheres to strict data minimization, processing only metadata essential for verification and protection:
- Discord User ID, Username, Avatar hash, and Telegram User ID: To recognize members and grant appropriate role credentials.
- Guild ID and Channel ID: To route verification prompts, audit logs, and anti-raid security alerts to designated staff channels.
- Public Wallet Address: Collected solely if Web3 SIWE verification is enabled, ensuring anti-Sybil uniqueness. We NEVER ask for, collect, or store private keys or seed phrases.
- Transient Nonces & Captcha Challenges: Cached in Cloudflare KV with a 5-minute time-to-live (TTL), destroyed immediately upon completion or expiration.
- Account Risk Scores: Registration age, default avatar flag, and threat flags evaluated transiently upon guild join without continuous profiling.
2. Data Storage & Edge Infrastructure Security
All persistent state (role mapping tables, anti-Sybil unique constraints, audit entries) is housed within SOC 2 compliant Cloudflare D1 and edge KV databases, protected via TLS 1.3 and Web Crypto Ed25519 signature validation.
3. Zero Chat Message Logging Assurance
Portico possesses no capability or permissions to monitor, read, cache, or log standard server chat messages. The bot processes Discord Interaction payloads and Telegram Webhook updates exclusively.
4. Platform Compliance & User Rights
Portico fully complies with Discord Developer Policies and Telegram Bot API guidelines. Users retain the right to query and request erasure of their associated wallet and role mappings at any time.