Legal
Privacy Policy
Last Updated: September 8, 2026
1. Introduction
Agely LLC ("we," "us," or "our") provides age verification services for online communities. Throughout this policy, a "tenant" means the community that runs Agely and that you verify to join — today primarily a Discord server, with websites and apps to follow. Agely is the tool a tenant uses; the tenant is a separate party that receives the result of your verification. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our services.
We are committed to protecting your privacy and ensuring transparency about our data practices. This policy applies to our website, our Discord bot, and all related services, on every platform where Agely operates.
Roles under data protection law: when you verify to join a community, that community decided to require verification and receives your result, so it is the data controller and Agely LLC processes your data on its behalf as a processor under our Data Processing Agreement. Agely LLC is the data controller in its own right for your account on our website, for support and deletion requests you send us directly, for billing and usage records, and for our website analytics.
2. Information We Collect
2.1 Authentication Information
When you sign in to our website through a supported identity provider (currently Discord, via our authentication provider Clerk), Agely reads — but does not store on its own servers — your basic account details so it can show you your servers and data:
- Your account ID with that provider (for example, your Discord user ID)
- Your username, display name, and profile picture
2.2 Age Verification Data
When you complete age verification through our service, we collect and process:
- Identifiers: the community and your user ID on that platform (for example, your Discord user ID), which is how your result is linked to you and to that community
- Date of Birth: used only to calculate your age during verification, then discarded. We never store it for verification purposes (see Section 5.4 for the separate, opt-in birthday feature). We keep the computed age (for example, 34) and a coarse age band (for example, 30 to 39) with your result until you delete your data
- Age Estimation Results: summary data from facial analysis (an estimated age range)
- ID Validation Results: verification status of government-issued identification (when used)
- Face Match and Liveness Results: whether your selfie matched the photo on your ID, and whether the optional anti-spoof check passed
- Verification Media: images and video used to run the check, held only transiently while the check runs and the result is delivered, then deleted (see Section 5)
- Verification Method: which verification method(s) you used
- Verification Timestamp: when you completed verification
- Outcome and Reason: whether you were verified, held for review, or rejected, the reason recorded against a rejection, and which moderator approved or rejected you if one did
2.3 Community Data
For community owners who use our service (for example, Discord server owners), we collect:
- Community identifiers and names (for example, a Discord server ID and name)
- Configuration settings (channels, roles, workflows, message templates)
- Identifiers of service-generated verification log messages
2.4 Automatically Collected Information
When you visit our website we collect a limited amount of technical information:
- Aggregate, cookieless page-view analytics via Vercel Web Analytics — anonymous counts used to understand site traffic, with no cookies, no cross-site tracking, and no user profiles
- Standard server request logs kept by our hosting provider (Vercel) for security and reliability
3. How We Use Your Information
We use your information for the following purposes:
- Age Verification: to verify your age and provide verification results to the communities you choose to verify in
- Service Delivery: to operate, maintain, and improve our services
- Security: to detect and prevent fraud, abuse, and security threats
- Communication: to send service-related notifications and respond to your inquiries
- Legal Compliance: to comply with applicable laws, regulations, and legal processes
3.1 Legal Bases (EU/EEA, UK, and Swiss Users)
Verification is not required by law, and nobody has to complete it. It is a condition the community sets for joining, so if you decline, or stop before your image is captured, the only consequence is that the community does not grant you the access it puts behind verification. Where the GDPR or equivalent law applies, we rely on the following legal bases:
- Verification and delivery of your result: carried out on the documented instructions of the community you chose to verify in, which is the controller for that processing and is responsible for its own lawful basis. That is typically its legitimate interest in enforcing its age rules (Article 6(1)(f)) or a legal obligation (Article 6(1)(c))
- Face and ID images (special category data): the community relies on your explicit consent under Article 9(2)(a), and Agely collects that consent for it inside the verification flow. Before the first step that opens your camera you are shown a notice of what is collected, why, and for how long, and you tick a written release. Nothing is captured until you do. You can withdraw consent afterwards by deleting your data (Section 5.2)
- Your website account and dashboard: performance of a contract (Article 6(1)(b))
- Opt-in features such as birthday announcements: your consent (Article 6(1)(a))
- Security, fraud prevention, and service reliability: our legitimate interests (Article 6(1)(f))
- Legal compliance: our legal obligations (Article 6(1)(c))
4. Biometric Data Processing (Important)
Our age verification service may process biometric information (facial analysis from selfies or video). Here's what you need to know:
- Consent: before the first step that opens your camera you are shown a notice of what is collected, why, and for how long, and you tick a written release. That tick is your explicit consent to biometric processing for age verification, and nothing is captured until you give it. You can withdraw consent afterwards by deleting your data (Section 5.2)
- Agely stores no biometric media: your selfie, video, or ID image exists on our systems only for the seconds it takes to run the check and deliver the result, then our copy is deleted (24 hours maximum in rare edge cases). See Section 5 for how a tenant may keep a copy of your result
- Processing: images are analyzed by Amazon Web Services (Rekognition/Textract) to return a result. We have opted out of AWS's AI-service data retention, so AWS analyzes your image in the moment and does not retain it
- User Control: you can request immediate deletion of your data at any time (see Section 5.2)
- No sale and no profit: we do not sell, lease, trade, or otherwise profit from your biometric identifiers or biometric information. Community owners pay for the verification service itself. The only party your result is shared with is the community you chose to verify in
- Security: verification media is encrypted in transit and with AES-256 at rest while it briefly exists, in access-restricted private storage
- Purpose Limitation: biometric data is used solely for age estimation and identity verification, and for no other purpose
4.1 State Biometric Notices
- Illinois: before we collect your face or ID image we tell you in writing, on the verification screen, that biometric information is being collected, what it is used for, and how long it is kept, and we obtain your written release by a checkbox before the camera opens. We keep a record of that release (Section 5.7). Our retention schedule and destruction guidelines are in Section 5.6
- Texas: we give you notice and obtain your consent by a checkbox before capturing your face or ID image for a commercial purpose. We do not sell, lease, or otherwise disclose that data, except to deliver your result to the community you chose to verify in, where you have consented, or where the law requires it. We destroy it within seconds to 24 hours, which is well inside the one year Texas allows
- Washington: we do not enroll a biometric identifier in a database. The check runs in the moment and we keep no template and no other biometric record, so there is nothing enrolled and nothing that could be used again
- Colorado: we use biometric data only for the age check and identity match described here. We do not sell it, we do not use it to identify you for any other purpose, and we do not make consent to biometric processing a condition of anything other than the verification you chose to start. You can withdraw consent by deleting your data
5. Data Retention and Deletion
5.1 Where Your Data Lives, and Automatic Deletion
What Agely stores
- Your verification result: we keep the outcome (verified, pending, or rejected), the computed age, a coarse age band, the method used, the timestamps, and any rejection reason, until you delete it or it expires (see Section 5.5). This is what lets a community see your status without asking you to verify again
- No verification media: your selfie, video, or ID image is never kept on our systems. It exists only for the seconds it takes to run the check and deliver the result, then it is deleted (24 hours maximum in rare edge cases)
- No date of birth: used only to compute your age, then discarded. We keep the computed age and a coarse age band with your result
- The result-log reference: we store an identifier for the message your result was delivered in (for example, the Discord result-log message), so that when you delete your data we can go back and try to redact it
- In-progress verification sessions: these expire automatically after 24 hours if not completed, and any transient media is deleted with them
- Undelivered results: if a community has no result channel configured, the result and its media are held for at most 24 hours so they can be delivered once one is set, then discarded
What the tenant keeps
When your check finishes, Agely delivers the result to the tenant. What the tenant retains — and for how long — is controlled by that tenant, and depends on the tenant type:
- Discord servers: the result is delivered to the server's private moderation channel. If the server has enabled media proof, a proof image is attached to that message and lives in their Discord channel. For an ID check that image is a redacted crop showing only your face and your date of birth, not the whole document, and you see and confirm it before it is sent. When you run /reset, Agely uses the stored message reference to try to redact that copy, removing any attached image or video and generalizing the result shown, as long as the bot is still in the server with permission to edit the message. If the bot has been removed or lacks permission, we cannot reach that copy, and the server would need to delete it.
- API and embedded widgets (as Agely expands beyond Discord): results are returned to the tenant's own application; each integration's handling — including how deletion requests are honored — will be described here as it launches.
5.2 User-Initiated Deletion
You can request complete data deletion at any time:
- On Discord, use the /reset command to delete your verification data, for a single server or across every server at once
- A birthday you opted in to save is not removed by default: choose the delete option in the /reset dialog, or use /birthday
- On any platform, contact us to have your data deleted
- Our service will redact its verification log messages where it can (on Discord, we can only edit a message if the bot is still in the server with the right permissions)
- After deletion we keep a de-identified record that a verification happened in that community, with your user ID replaced, so the community keeps an accurate moderation history. It cannot be traced back to you. The record of your written release is also kept, in hashed form, for five years (Section 5.7)
- Anything the community saved outside Agely, such as its own copy of a result message, stays under that community's control
5.3 Deletion Method
We use destructive deletion (permanent removal) rather than soft deletion (flagging). When you delete your data, it is permanently removed from our systems and cannot be recovered.
5.4 Optional Opt-In Features
These features store more than the defaults above — always strictly opt-in, with your explicit consent, and always removable. (1) Birthday Announcements: if a tenant (for example, a Discord server) turns this feature on and you choose to take part, Agely stores your birth date for that server only — nowhere else. It is kept only for as long as you stay opted in and the tenant keeps the feature enabled. You can remove it anytime with /birthday or /reset, and it is automatically purged if the bot is removed from that server. (2) Saved Verification (planned, not yet available): reuse your result in other communities without verifying again. Until you opt in to a feature like this, your date of birth is never stored and verification data is handled exactly as described above.
5.5 When You Leave a Community, or a Community Removes Agely
- If you leave a Discord server: any transient proof is deleted, the result card in that server's moderation channel is redacted (image removed, age generalized), and your age band and rejection reason are cleared. Only the bare verdict (verified or rejected, the method, and the date) is kept, so that a rejected member cannot leave and rejoin to bypass the check. Running /reset removes that too
- If a community removes Agely: birthdays you saved for that community are deleted immediately. Your verification result for that community is kept until you delete it (with /reset or by contacting us), so that a community which re-adds Agely does not have to ask you to verify again
- Re-verification: a community can set a re-verification interval; when it passes, your result expires and you are asked to verify again
- We keep your result until you delete it or it expires as above, and we use it only to show your status to that community
5.6 Biometric Retention Schedule and Destruction Guidelines
This section is Agely's public written retention schedule and destruction guidelines for biometric identifiers and biometric information, published as required by the Illinois Biometric Information Privacy Act (740 ILCS 14/15(a)) and comparable state laws.
- Purpose of collection: your face image, video, or ID image is collected for one purpose, which is estimating your age and, where an ID is used, matching your face to the photo on that ID for the community you chose to verify in
- When that purpose is satisfied: the purpose is satisfied the moment your result is delivered to that community, or the moment an unfinished session expires
- Destruction schedule: the image or video is permanently destroyed within seconds of that point, and in every case within 24 hours of collection. An unfinished session expires after 24 hours and its media is destroyed with it
- Three-year backstop: in no case do we hold a biometric identifier or biometric information for longer than the earlier of the schedule above and three years after your last interaction with us
- What destruction means: permanent removal from our systems rather than flagging or archiving. Destroyed data cannot be recovered
- No templates: we do not create or keep a face template, a faceprint, or any other biometric record. Once the check has run, nothing biometric remains on our systems
- No profit: we do not sell, lease, trade, or otherwise profit from your biometric identifiers or biometric information. Community owners pay for the verification service, not for data
- Disclosure: your biometric data is disclosed only as described in Section 6, and only where you have consented or the law requires it
5.7 Pseudonymous Records That Survive Deletion
Two small records are kept in a form that does not name you. Each is keyed by a one-way hash of your user ID with a secret salt that is unique to the community, so the record can confirm whether a specific user ID is in it, but it cannot be turned back into a list of people.
- Your written release: when you tick the release before your camera opens, we keep the hashed ID, which version of the notice and release text you saw, the language it was shown in, and the time. This is our evidence that consent was given, as biometric privacy laws require, so it is not removed by /reset or by a community's deletion request. It is deleted automatically five years after it was recorded
- An under-13 block: if a check computes that you are under 13 and you are rejected, your identified records are removed straight away (see Section 9) and a hashed block is kept instead, with the method and the date, so the same user ID cannot leave and rejoin to try again. It is deleted automatically after twelve months, immediately by /reset, and on request from a parent or guardian
6. How We Share Your Information
We do not sell, rent, or trade your personal information. We may share your information only in the following circumstances:
- The tenant you're joining: your verification result (status, age band, method used) is delivered to the community you chose to verify in. That is the entire purpose of the check, and it is the only party your result is shared with
- Service Providers (subprocessors): we use a small set of trusted providers to operate the Service, and each of them acts only on our instructions: Amazon Web Services (biometric AI processing; images are analyzed transiently and, because we have opted out of AWS's AI-service data retention, are not retained by AWS), Vercel (hosting, plus the short-lived private storage that briefly holds verification media before it is delivered and deleted, and cookieless Vercel Web Analytics for our website), Neon (our database, holding verification status and settings only; no media, and no date of birth except a birthday you opt in to save for birthday announcements), and Clerk (dashboard sign-in)
- The platform your community runs on: on Discord, your result is delivered into the server through Discord, so Discord handles it under its own privacy policy and its own terms with you and with the community. Discord does not act on Agely's instructions
- Payments: purchases are handled by the platform you buy through (currently Discord); Agely never receives or stores payment card data
- Legal Requirements: when required by law, court order, or government request
- Security and Fraud Prevention: to protect our users, services, and legal rights
- Business Transfers: in the event of a merger, acquisition, or sale of assets (with continued privacy protection)
7. Your Privacy Rights
7.1 Rights for All Users
- Access: request a copy of your personal data
- Deletion: request deletion of your data (see Section 5.2) or by contacting us
- Correction: request correction of inaccurate information
- Objection: object to processing of your data for certain purposes
7.2 Additional Rights for EU/EEA Users (GDPR)
- Data Portability: receive your data in a structured, machine-readable format
- Restriction of Processing: request limitation of how we process your data
- Withdraw Consent: withdraw your consent to biometric processing at any time. Withdrawing it does not affect processing already carried out while the consent was valid. In practice you withdraw it by deleting your verification data (Section 5.2), after which you would need to verify again to regain access a community puts behind verification
- Lodge a Complaint: file a complaint with the data protection authority where you live, where you work, or where the issue arose
7.3 Additional Rights for California Users (CCPA)
- Know: request details about personal information we've collected about you
- Delete: request deletion of your personal information
- No Sale: we do not sell personal information and have not sold it in the past 12 months
- Non-Discrimination: you have the right not to be discriminated against for exercising your privacy rights
7.4 Automated Decision-Making
Age estimation and ID checks are automated: our systems compare the estimated or extracted age with the community's minimum and produce a pass, a rejection, or a referral for review. Because a rejection can block your access to a community, you have the right to ask for a human to review it. Every result is delivered to the community's moderators, who can override it in either direction, so ask them for a review. You may also contact us at privacy@agely.xyz and we will pass your request to the community, which decides the outcome.
To exercise any of these rights, use the deletion options in Section 5.2 or contact us at privacy@agely.xyz.
We respond to requests within one month. For complex requests we may take up to two further months, in which case we tell you within the first month. We may ask you to confirm that you control the account the request concerns before acting on it. If you verified in a community, that community is the controller for that data; you can contact either of us, and we will forward your request or handle it under the community's instructions.
8. Data Security
We implement industry-standard security measures to protect your information:
- Encryption: all data is encrypted in transit (HTTPS/TLS) and with AES-256 at rest on every store we use (our Neon database and Vercel Blob storage)
- Access Controls: strict access controls and authentication requirements for our systems
- Private Storage: for the brief time verification media exists on our systems, it lives in access-restricted private storage (Vercel Blob), never on public URLs
- Infrastructure: secure cloud infrastructure with Vercel, Neon, and AWS
- Breach notification: if a personal data breach affects verification data we hold on a community's behalf, we notify that community without undue delay so it can meet its own notification obligations as the controller. Where Agely is the controller in its own right (your website account, requests you send us directly, billing, and analytics), we notify you and the relevant supervisory authority where the law requires it
However, no method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
9. Children's Privacy
Communities use our service to enforce their age requirements, including platform minimums (for example, Discord's Terms of Service require users to be at least 13 years old). We process verification data for users of all ages (including minors) to provide this service.
Parents or guardians may request deletion of a minor's data by contacting us at privacy@agely.xyz.
In the EU/EEA and UK, where a community allows members below the local age of digital consent (16 in Germany and most of the EU, 13 in the UK), the consent of a parent or guardian is required before a younger member's face or ID image is processed. Communities are responsible for obtaining it. If you are a parent or guardian and did not give it, contact us and we will delete the data.
What we keep when someone is computed to be under 13 and rejected: we tell the community the check did not pass, and then we remove the identified records at once. Your status row is deleted, your user ID is removed from the verification and session records, and the result card delivered to the community is redacted so it carries no image and no exact age. What remains is a block keyed by a one-way hash of your user ID (Section 5.7), with the method and the date, so that the same user ID cannot leave and rejoin to try again. It contains no user ID in readable form, no image, no video, no date of birth, and no age. It is deleted automatically after twelve months, immediately if you run /reset, and immediately on request from a parent or guardian at privacy@agely.xyz. We will not ask the child for anything further.
10. International Data Transfers
Our services are operated from the United States. If you access our services from outside the United States, your information will be transferred to, stored, and processed in the United States.
For users in the EU/EEA, the UK, and Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where it applies), incorporated into our Data Processing Agreement with each community and into our contracts with our subprocessors, to protect your data when it is transferred to the United States. Section 10 of our Data Processing Agreement sets out which clauses we use and the choices we made under them, and you can ask us for a copy of the safeguards that apply to a particular transfer using the contact details at the end of this policy. Each subprocessor also applies the safeguards described in its own privacy policy.
11. Third-Party Links and Services
Our website and services may contain links to third-party websites and services (such as Discord). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:
- Updating the "Last Updated" date at the top of this policy
- Posting a notice on our website or support server
- Sending an email notification for significant changes (if we have your email)
Your continued use of our services after changes become effective constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
Agely LLC
A Florida limited liability company, Document No. L24000426977
7901 4th St N, Ste 300, St. Petersburg, FL 33702, United States
Represented by James Eades, Authorized Member
Email: privacy@agely.xyz
Discord Support Server: https://discord.gg/mFGC2yHkr8