Privacy Policy

How we collect, use, and protect your information.

Effective September 6, 2026 / Last updated September 6, 2026

This Privacy Policy (“Policy”) describes how the operators of Project Goldberg (“Project Goldberg”, “we”, “us”, or “our”) collect, use, disclose, retain, and protect information from individuals (“you” or “your”) who access or use the Project Goldberg platform, including the Discord user app and this website (together, the “Service”).

Project Goldberg is an open-source intelligence application for Discord. It runs username, breach, domain, and account lookups against publicly accessible sources. This Policy is both a notice about our data practices and a description of the limits we place on ourselves. We keep very little, for a short time, and we do not build profiles of anyone.

Section 11 sets out what you are responsible for when you look somebody up. Section 12 is written for people who did not use the Service but were searched with it. Section 13 sets out your rights and how to exercise them.

1. Who we are

Project Goldberg is an independent project run by its developer. It is not a company, and it is not affiliated with, endorsed by, or connected to Discord Inc., Netflix, the television series You, or any of the platforms the Service queries.

For the purposes of the UK GDPR and the EU GDPR, we are the controller of the personal information processed through the Service, except where you direct a lookup at another person. In that case you decide who is searched and why, and you are an independent controller for that decision. Section 11 explains what that means.

All contact regarding this Policy goes through our support server. Details are in section 19.

2. Scope

This Policy applies to:

  • Anyone who installs the Project Goldberg app to their Discord account;
  • Anyone who runs a command, whether in a server, a group chat, or a direct message;
  • Anyone whose personal information is processed because someone else submitted it as a query;
  • Visitors to this website.

It does not cover Discord itself. Using the app means using Discord, and Discord collects and processes your information under its own privacy policy, which we neither control nor have access to. It also does not cover the third-party services the app queries on your behalf; those are described in section 8 and each operates under its own terms.

3. OSINT and third parties

Most privacy policies only describe what a service does with its own users’ data. This one has to describe something else as well. The Service exists to look up information about people, and the person being looked up is usually not the person running the command.

We want to be direct about what that does and does not involve. Project Goldberg maintains no database of people. It queries publicly accessible sources and public APIs in real time and returns what they say. We do not enrich, cross-reference, score, or build long-term dossiers on anyone. We do not retain search results. We do not sell access to them, and there is no aggregated index of past lookups for anyone to buy or subpoena.

In practical terms: we hold very little about you, and what the Service does hold is short-lived.

4. Information we collect

4.1 Information Discord provides when you run a command

When you invoke a slash command, Discord sends us an interaction payload. From it we process your Discord user ID and the username attached to it, the identifier of the server, channel, or direct message the command was run in where Discord supplies it, the name of the command and its timestamp, and your locale where Discord includes it so replies can be formatted sensibly.

Because Project Goldberg is a user-installed app rather than a server bot, Discord deliberately sends us less in many contexts than it would send a server bot. We only ever receive what Discord chooses to include.

4.2 The queries you submit

The values you type as command arguments are the substance of the Service. Depending on the command this may be a username, an email address, a Discord user ID, a domain name, a Minecraft or Instagram handle, or an uploaded image. Some of these are personal information about other people. We process them for one purpose: to run the lookup you asked for and return a result.

4.3 Uploaded images

The image check command receives the file you attach so it can scan it for QR codes and decode them. The image is discarded once the scan completes. We do not run facial recognition on uploaded images, and we do not use them to train anything.

4.4 Operational and diagnostic records

To keep the Service working and to enforce the usage rules, we generate technical records: error traces, rate-limit counters, latency measurements, and records of commands that failed or were blocked. These are associated with your Discord user ID.

4.5 Website visitors

This website is a static page. It runs no analytics and sets no cookies of its own. As with essentially any website, the server that hosts it may keep standard request logs containing an IP address, a user agent string, and the URL requested.

5. What we do not collect

  • The contents of your messages, other than the arguments you deliberately pass to a command.
  • Your Discord password, email address, payment details, or authentication tokens.
  • Your direct messages, your friends list, or your message history.
  • Voice or video.
  • Location data about you, beyond what an IP address in a server log implies.

We do not sell personal information. We do not share it with advertisers or data brokers, and we do not use your queries to build advertising profiles.

6. How we use information

  • To run the command you asked for and return the result to you.
  • To apply rate limits and prevent abuse of the Service and of the sources it queries.
  • To investigate reports that the usage rules have been broken, and to revoke access where they have.
  • To diagnose faults, fix defects, and monitor availability.
  • To comply with legal obligations and respond to lawful requests.

We do not use your queries or your command history for any purpose beyond those listed above.

8. Disclosure to third parties

To answer a lookup, the Service forwards your query to external sources. This means the value you searched for is disclosed to the operator of the relevant source, which handles it under its own privacy policy and may log it. Depending on the command, this can include public profile endpoints for the sites checked by the username and email commands, a breach-index provider, Discord’s own API, the Mojang and Minecraft services API, Instagram’s public endpoints, WHOIS registries, and an IP geolocation provider.

Our hosting provider processes data on our instructions in order to run the Service. Beyond that, we disclose information only where we are legally required to, such as in response to a valid order from a competent authority; where necessary to establish, exercise, or defend legal claims, or to investigate a credible report of misuse; and to Discord where required by the Discord Developer Terms of Service.

A lookup is not anonymous with respect to the sources being queried. If you search an email address, that address is sent to a breach index. If you look up a domain, the domain is sent to a WHOIS registry. We cannot control what those operators log or how long they keep it.

9. Data retention

We keep information for no longer than we need it, and the Service is designed so that we need it for very little time.

  • Query inputs are held for as long as it takes to run the lookup and return your reply, plus a short window for rate limiting and abuse prevention, after which they are discarded automatically.
  • Lookup results are not stored after the reply is sent. Nothing is cached into a searchable record of what anyone has looked up.
  • Uploaded images are discarded as soon as the scan completes.
  • Operational and diagnostic records are kept only as long as they are useful for fixing faults and preventing abuse, then rotated out.
  • Enforcement records — where access has been revoked for breaking the usage rules, we keep the user ID and the reason for as long as the revocation stands, so that it can be enforced.

Backups may hold copies for a short additional period before they rotate out of existence.

10. Data security

We take technical and organisational measures appropriate to a project of this size: encryption of data in transit, access to production systems limited to the operator, credentials kept out of source control, and retention kept deliberately short so that there is little to lose in the first place.

No system is perfectly secure and we do not claim otherwise. If we become aware of a breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and inform affected users where we are required to.

11. Your responsibilities

When you search for information about another person, you decide who to search and why. In data protection terms that generally makes you a controller for that processing, and it makes you responsible for having a lawful reason to do it. We act as a tool you direct.

The usage rules are not decoration. You must not use the Service for anything illegal, and you must not use it to stalk, harass, monitor, or track anyone without their consent. It is intended for auditing your own digital footprint, for authorized investigations, and for comparable defensive security work.

The purely personal or household exemption in data protection law is narrow and will not cover surveillance of another person. Breaking the rules can get your access revoked, and may expose you to liability that is yours rather than ours.

12. If you were searched

You may be reading this because somebody ran a lookup on you. You have rights here even though you never used the Service.

Project Goldberg does not keep a profile of you. It queries public sources live and returns what they say, so in most cases there is nothing about you sitting in our systems to delete beyond a short-lived record of the query itself. Where such a record still exists, you can ask us to erase it.

We cannot remove your information from the underlying sources, because we do not control them. To take something down you need to contact the site, service, or registry that publishes it. We are willing to tell you which sources a given result came from so that you know where to direct that request.

If you believe the Service is being used to harass or stalk you, report it to us in the support server. We will investigate and revoke access where the rules have been broken. If you are in immediate danger, contact your local emergency services.

13. Your rights

Depending on where you live, you may have some or all of the following rights over personal information we hold about you:

  • Access — ask for a copy of what we hold about you.
  • Rectification — ask us to correct information that is wrong.
  • Erasure — ask us to delete it.
  • Restriction — ask us to stop processing it while a dispute is resolved.
  • Portability — ask for it in a machine-readable form.
  • Objection — object to processing carried out on the basis of legitimate interests.
  • Withdraw consent — where we rely on consent, withdraw it at any time.

If you are a California resident, you additionally have the right to know what personal information is collected and how it is used, the right to delete it, the right to correct it, and the right not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA and CPRA.

To exercise any of these rights, contact us in the support server. We will respond within one month. We may ask you to confirm your Discord user ID so that we do not disclose one person’s information to another.

14. Automated decisions

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not profile users in that sense. Rate limiting and automated abuse prevention may temporarily block a command; you can contact us to have that reviewed by a person.

15. Children's privacy

Discord requires its users to be at least 13 years old, and older in some countries. The Service is not directed at children and must not be used by anyone below the minimum age for Discord in their country. We do not knowingly collect information from children below that age, and if we learn that we hold any, we will delete it.

16. Cookies

This website sets no cookies of its own and runs no advertising or analytics trackers. It loads its typefaces from Google Fonts, which means your browser makes a request to Google’s servers when you open the page, and Google may log your IP address as a result. Everything else on the page is served from our own host.

17. International transfers

The Service and the third-party sources described in section 8 operate in various countries, including outside the United Kingdom and the European Economic Area. Where personal information is transferred internationally, we rely on appropriate safeguards, such as the UK International Data Transfer Agreement, the UK Addendum to the European Commission’s Standard Contractual Clauses, or those Standard Contractual Clauses themselves, or on an adequacy decision where one applies.

18. Changes to this Policy

We may update this Policy as the Service changes. The date at the top of this page always reflects the current version. Where a change materially affects your rights, we will announce it in the support server before it takes effect. Continuing to use the Service after a change takes effect means you accept the updated Policy.

19. Contact

For anything in this Policy, including requests to exercise your rights, reports of misuse, or questions about where a result came from, contact us in the Project Goldberg support server.

If you are unhappy with how we have handled your information, you can complain to the data protection supervisory authority in your country. In the United Kingdom this is the Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to resolve the matter with you first.