CustomBadges for Discord 的隐私政策
CustomBadges for Discord 作者: ItzMeShadow999
Last updated: September 7, 2026
CustomBadges ("the extension") adds custom profile badges to Discord, visible across discord.com (With UserScript or Chrome Extc), and compatible client mods. This policy explains what data the extension collects, why, and how it's handled.
1. Discord identity data (read from the page, not from Discord's API)
While you browse Discord, the extension reads text already visible to you in the page (usernames, user IDs, and avatar URLs) in order to match badges to the correct profiles and display them. This is read directly from the DOM of pages you're already logged into; the extension does not call Discord's private API or access any data you couldn't already see yourself.
2. Account verification via Discord OAuth
To publish or edit your own badge, you must verify your Discord account once. This uses Discord's official OAuth login with the identify scope only, which shares your username, avatar, and Discord user ID. We never see or request your Discord password, and we do not request access to your messages, servers, friends list, or any other scope.
3. Session token
After OAuth verification, our backend issues a session token, a credential we generate and sign ourselves (not a Discord token or cookie). You paste this token into the extension once, and it's stored locally in your browser settings. It's then sent to our backend as a Bearer credential whenever you publish or edit your badge, or check your write budget. This token:
- Is never sent to Discord and grants no access to your Discord account itself.
- Does not expire automatically; it remains valid until you or we revoke it.
- Can be revoked on request (see "Your choices" below).
4. Badge content
Any badge text, style choices, or image URLs you create are stored on our backend and served publicly to other users viewing your badge (since badges are meant to be seen by others on Discord).
5. Badge images
If you upload a badge image, it's hosted on a third-party image host you chose (e.g., catbox.moe, i.pinimg.com, i.ibb.co). We don't host images ourselves. We only store and serve the URL.
- Discord passwords or native Discord auth tokens/cookies
- Message content, DMs, or server content
- Browsing activity outside of badge-relevant Discord pages
- Any data via tracking pixels, analytics, or advertising SDKs
Badge data and session tokens are processed by our backend, a Cloudflare Worker at
custom-badges.shadow-164.workers.dev. No data is sold or shared with third parties beyond the image hosts you choose to use for badge images.- Revoke your session token: contact us via https://custombadges.pages.dev/ to have your token invalidated. You can also stop using the extension at any time, which stops all further data collection.
- Delete your badge: contact us via the site above to have your published badge and associated data removed from our backend.
- Uninstall: removing the extension stops all DOM reading and local storage of your session token going forward.
If this policy changes, the update will be posted here with a revised "Last updated" date.
Questions about this policy or your data: https://custombadges.pages.dev/