APEXGuard

APEX Legal

Privacy Policy

How APEX processes identity, safety, server, request, audit, and technical information.

Last updated: 2026-06-21

1. Overview

APEX Guard ("APEX," "we," "our," or "us") is a professional child/community safety SaaS for Roblox-connected Discord communities.

APEX helps participating communities verify Discord-to-Roblox identities, configure Force Account Link, review safety-risk accounts, run scans, notify staff, process reports, maintain Member Review and Activity Log records, support privacy/deletion/correction/appeal-review requests, and manage retention and safety-record governance.

APEX is not a public blacklist, public reputation score, or public shame list. APEX safety signals are not legal determinations, public accusations, guarantees, or public reputation scores. They are private safety-review inputs used to support child/community safety workflows.

This Privacy Policy explains what information APEX may process, why we process it, how identity linking and safety signals may be used, how long information may be retained, and how users may submit privacy, deletion, correction, objection, or appeal-review requests.

Some future features may be unavailable, disabled, or subject to additional review. APEX should not describe a feature as available until it is implemented.

2. Information APEX May Process

APEX may process different categories of information depending on how a community uses APEX and how a user interacts with the service.

Discord Account Data

APEX may process Discord account information such as:

  • Discord user ID
  • username
  • display name
  • avatar URL
  • server membership context where APEX is installed
  • staff role or permission context relevant to APEX access
  • authentication information provided through Discord OAuth

APEX uses this information to provide login, dashboard access, server configuration, staff permissions, identity verification, safety review, audit integrity, and abuse-prevention workflows.

Roblox Account Data

APEX may process Roblox account information such as:

  • Roblox user ID
  • username
  • display name
  • avatar/profile URL
  • public profile link
  • account-verification information provided through Roblox OAuth or approved account-linking workflows

APEX uses this information to verify Roblox account ownership, support Discord-to-Roblox identity linking, reduce impersonation, support Force Account Link, and assist child/community safety workflows.

Discord-to-Roblox Identity-Link Data

APEX may process verified or attempted links between Discord accounts and Roblox accounts. This may include link status, verification timestamps, server-local link mirrors, Force Account Link status, and account-linking audit records.

APEX uses Discord-to-Roblox identity-link data only for legitimate safety and service purposes, including:

  • account ownership verification
  • Force Account Link
  • server-local safety workflows
  • anti-impersonation
  • anti-evasion
  • appeal/correction handling
  • audit integrity
  • legitimate child/community safety purposes

APEX does not operate a public identity database. Identity-link information is not for public lookup, resale, general browsing, staff curiosity, or public posting. Access is limited by role, purpose, server context, and safety need.

Where identity-link information is no longer needed, APEX may delete, reduce, or de-identify it. Where necessary and proportionate for child/community safety, anti-evasion, appeal processing, correction handling, audit integrity, legal obligations, or legal claims, APEX may retain a limited safety or account-correlation record.

Server/Guild Data

When APEX is installed or configured in a Discord server, APEX may process server configuration data such as:

  • server ID
  • configured channels
  • configured staff roles
  • Force Account Link settings
  • notification settings
  • scan settings
  • moderation workflow settings
  • Activity Log records
  • report status records
  • Member Review or Flagged Member records

APEX uses this data to operate the bot, dashboard, safety workflows, account-linking features, staff notifications, reports, scans, audit logs, and server-local safety configuration.

Safety Signal Data

APEX may process safety signals related to Roblox or Discord accounts. Safety signals may come from APEX review workflows, reports, scans, server-local context, third-party safety providers, appeal/correction history, or platform trust and safety review.

Safety signals are private review inputs. They are not legal determinations, public accusations, guarantees, or public reputation scores.

Report Data

APEX may process reports submitted through APEX or approved community workflows. Report data may include:

  • account identifiers
  • Roblox profile links
  • Discord user references
  • server or group context
  • timestamps
  • descriptions
  • non-illegal screenshots where legally safe
  • report status
  • owner-safe summaries
  • reviewer notes
  • audit references

Reports are moving toward APEX-central intake and admin review. Server-local workflows may still exist depending on product configuration.

APEX does not invite users to upload illegal content. Do not upload sexual images of minors, illegal material, exploitative material, or content that you do not have a lawful basis to submit.

Appeal, Correction, Deletion, and Privacy Request Data

APEX may process:

  • platform appeal-review requests
  • privacy requests
  • deletion requests
  • correction requests
  • objection requests
  • user-safe request status messages
  • admin review decisions
  • internal request notes
  • audit records linked to requests

APEX uses this data to handle user rights, review potential inaccuracies, process appeal-review requests, maintain audit integrity, and document request outcomes.

Activity and Audit Data

APEX may process Activity Log and audit records such as:

  • settings changes
  • report status changes
  • admin review actions
  • request status changes
  • appeal/correction/deletion review actions
  • safety review events
  • access control events
  • privacy audit events

Audit records help support accountability, abuse prevention, service security, retention review, and legal or safety obligations.

Technical and Security Data

APEX may process limited technical and security information such as login timestamps, authentication status, session metadata, request metadata, and security logs.

This Privacy Policy does not authorize broad tracking, browser extension telemetry, device fingerprint correlation, payment-data safety correlation, or public lookup systems.

3. Why APEX Processes Information

APEX may process information for purposes including:

  • providing the APEX dashboard and Discord bot
  • verifying Discord-to-Roblox account ownership
  • configuring Force Account Link
  • supporting server-local identity verification
  • helping communities identify accounts that may need safety review
  • processing reports through APEX-central or approved server workflows
  • supporting Member Review, Flagged Member, scan, notification, and Activity Log workflows
  • handling privacy, deletion, correction, objection, and appeal-review requests
  • preventing abuse, impersonation, account theft, evasion, or misuse of APEX
  • maintaining audit integrity
  • protecting service security
  • complying with legal obligations
  • preserving records where necessary for legal claims, safety review, legal hold awareness, or audit integrity
  • improving APEX safety and reliability in a proportionate way

4. Legal Bases and Safety Purposes

Where applicable law requires a lawful basis, APEX may rely on different bases depending on the processing activity. These may include service necessity, contract necessity, legitimate safety purposes, legal obligations, consent where applicable, or other bases recognized by applicable law.

APEX's legitimate safety purposes may include child/community safety, abuse prevention, anti-evasion, impersonation prevention, account-link integrity, appeal processing, correction handling, audit integrity, security, and defense of legal claims.

Lawyer review needed: final lawful-basis wording should be reviewed for each jurisdiction where APEX operates, targets users, or processes data.

5. Cross-Platform Identity Linking

Discord-to-Roblox identity linking is a core APEX safety and verification feature. It helps communities confirm account ownership, reduce impersonation, support Force Account Link, and handle safety review workflows.

APEX should not use identity-link information as a public identity database. Identity-link information is not intended for public lookup, resale, general browsing, staff curiosity, public posting, or public accusation.

Access to identity-link information should be limited by role, purpose, server context, and safety need. Server owners and staff should receive only the information needed for legitimate server-local safety workflows.

6. Private Safety Check / Member Review Tools

APEX may provide private safety check or member review tools that allow authorized server staff to check whether a member requires safety review.

These tools are private staff tools. They are not member-facing lookup services, public reputation systems, public safety scores, public accusation tools, or public posting tools.

Where implemented, these tools should be:

  • staff-only
  • permissioned
  • private, ephemeral, or limited to configured staff channels
  • audited
  • rate-limited where appropriate
  • limited to owner-safe wording

Results should use limited owner-safe wording such as:

  • review recommended
  • no active APEX safety status found
  • appeal or correction pending
  • status corrected or reduced

A result of 'no active APEX safety status found' does not guarantee that an account is safe. It only means that APEX did not return an active safety status in that workflow at that time.

APEX should not expose raw evidence, thresholds, detection methods, provider internals, reporter identities, staff-only notes, legal hold data, or platform trust and safety internals through safety check or member review tools.

7. Data Minimization

APEX is designed to process information that is reasonably necessary for the relevant feature, safety purpose, account verification, report, appeal, correction, retention review, audit requirement, or legal obligation.

APEX should avoid retaining ordinary profile data, avatar URLs, stale usernames, raw evidence, private messages, raw provider payloads, or unrelated personal data longer than necessary.

8. Limited Safety Records

Where necessary and proportionate, APEX may retain a limited safety record.

A limited safety record should contain only what is necessary for the safety purpose. It should not automatically include full profile history, stale usernames, avatar URLs, raw reports, raw evidence, private messages, staff speculation, or unrelated personal data.

A limited safety record may include:

  • account identifiers
  • verified account-link references
  • reviewed safety status
  • source category
  • owner-safe summary
  • appeal or correction status where applicable
  • review dates
  • retention dates
  • legal hold awareness
  • audit references

APEX should periodically review retained safety records and delete, reduce, or archive records when they are no longer necessary.

Limited safety records are access-controlled. They are not public accusations, public reputation scores, public shame pages, or public lists.

9. Third-Party Safety Providers

APEX may use third-party safety providers as safety-signal sources, including RoteCtor if used.

Third-party safety provider signals are review inputs. They are not automatic enforcement decisions, legal determinations, or guarantees.

APEX may combine third-party signals with server context, identity-link information, reports, appeal history, correction history, audit history, and platform trust and safety review.

APEX should not expose raw third-party provider data, hidden provider logic, provider thresholds, or provider internals to ordinary users or normal server staff.

APEX may retain minimal derived safety summaries only where necessary and proportionate for operational safety, audit integrity, appeal, correction, retention, or legal reasons.

APEX may change, disable, remove, or replace third-party safety provider integrations.

APEX does not resell raw third-party provider databases.

10. Roblox Group and Game Management Connections

Servers on eligible plans (group management with Premium, game management with Ultimate) may connect APEX to a Roblox group or Roblox experience. Connections are made through Roblox's official OAuth sign-in by a person who administers that group or experience. APEX never sees or stores Roblox passwords.

What APEX Stores for a Management Connection

  • An authorization token issued by Roblox, stored encrypted (AES-256-GCM) — plaintext tokens are never written to storage and are never shown in any dashboard or client
  • The permission scopes Roblox granted to the connection
  • The Roblox user ID and username of the authorizing account
  • The Discord account ID of the administrator who connected it
  • Connection and refresh timestamps
  • The configured Roblox group ID and universe ID (identifiers only)

What Management Connections Are Used For

  • Removing a member with a confirmed member review case from the connected Roblox group, when the server has enabled group actions
  • Restricting (banning) a member with a confirmed member review case from the connected Roblox experience, when the server has enabled game actions
  • Checking new group joiners against that server's existing confirmed member review cases (screening alone alerts staff and takes no action)

Every management action is opt-in per server and disabled by default, is anchored to a confirmed member review case rather than a free-form target, is rate-limited, and is recorded in the server's Activity Log. Test mode allows servers to validate actions without executing them.

Revoking a Management Connection

A server administrator may disconnect a management connection from the dashboard at any time, which deletes the stored authorization. The authorizing user may also revoke APEX's access in Roblox account settings. After revocation, management actions stop; anything already queued fails safely and is recorded.

Records of executed management actions are retained under the Retention section for accountability, appeal, and audit purposes even after a connection is removed.

11. Reports and Evidence

Reports should focus on account identifiers, timestamps, public links, descriptions, and non-illegal context.

APEX may accept, reject, remove, restrict, redact, or summarize report content that is unsafe, unnecessary, unlawful, or outside APEX's purpose.

Do not upload sexual images of minors, illegal material, exploitative material, or content that you do not have a lawful basis to submit.

If someone is in immediate danger, contact emergency services. Serious child-safety concerns should be reported to appropriate official reporting channels or law enforcement.

If APEX does not currently support evidence upload, APEX should not imply that evidence upload is available.

12. Children and Minors

APEX is designed for communities where minors may be present.

APEX aims to:

  • minimize minor-related data
  • avoid unnecessary age collection
  • avoid public lookup for minors
  • use high privacy defaults
  • restrict access to sensitive records
  • use owner-safe summaries where possible
  • avoid exposing harmful material to ordinary users, server staff, or volunteers
  • support review, correction, deletion, and appeal-review workflows where appropriate

APEX does not replace parents, guardians, emergency services, law enforcement, Discord, Roblox, or official reporting channels.

Parent/guardian workflows require lawyer review before being offered as a formal process.

13. Retention

APEX retains information based on purpose, necessity, sensitivity, safety relevance, appeal status, correction status, audit needs, legal obligations, and retention review.

APEX does not keep personal data forever by default.

Safe or no-action data should be deleted or reduced quickly. Raw evidence, where used, should expire faster than summaries. Limited safety records should have retention review dates and should be deleted, reduced, or archived when no longer necessary.

More information is available in the Data Retention Policy.

14. Security and Access Controls

APEX uses access controls designed to limit who can view sensitive records. Server owners and staff should see only server-relevant information and owner-safe summaries.

Platform trust and safety records, internal notes, protected evidence, legal hold awareness, account-correlation records, and sensitive audit details are restricted to authorized APEX platform roles.

No system can be guaranteed perfectly secure. APEX works to reduce risk through data minimization, access control, audit logs, safe disclosure practices, and retention review.

15. User Rights and Requests

Depending on your location and applicable law, you may have rights to request access, deletion, correction, objection, restriction, portability, or review of certain processing.

APEX provides request workflows for privacy requests, deletion requests, correction requests, objection requests, and appeal-review requests.

APEX may deny or partially fulfill a request where continued limited retention is necessary and proportionate for safety, security, audit integrity, legal obligations, anti-evasion, appeal processing, correction handling, or legal claims.

16. International Users

APEX may be used by communities and users in different countries. Data protection rights and obligations may vary by location.

APEX's policies are designed to be privacy-conscious and safety-focused, but jurisdiction-specific legal review may be required.

Lawyer review needed: international transfer, representative, controller/processor, and local jurisdiction terms.

17. Product Behavior Must Match Policy

Some APEX features may be unavailable, disabled, limited, or subject to additional review.

APEX should not describe a workflow as available until that workflow is implemented. If a workflow is not implemented, APEX should describe it as future/planned or omit it.

18. Contact

Privacy requests, deletion requests, correction requests, and appeal-review requests should be submitted through the dashboard where available.

Contact information is available on the APEX Contact page.

19. Changes to this Policy

APEX may update this Privacy Policy as the service changes. The latest version will be posted on this page with a Last updated date.

Requests and Contact

APEX provides request paths for privacy, deletion, correction, objection, and appeal-review concerns. Use the dashboard where available.

If you cannot access the dashboard, use the contact information on the Contact page. APEX may need to verify account ownership before disclosing, deleting, correcting, or reviewing account-related information.

POLICY STATUS

These policies describe APEX's current public posture and may change as the service evolves. Jurisdiction-specific terms and planned workflows remain subject to qualified legal review.