Community

Trust and safety

What logging in actually gives us, the data we hold and the data we never touch, how we test that it is safe, and what to do when something goes wrong.

Last revised Sep 28, 2026

Start here

Asking you to trust a website is easy. Showing you why is harder, so this page tries to do the harder one. It covers what logging in with Discord actually hands over, what this site keeps and what it never touches, who can see which parts of it, how the code is tested, and what happens when somebody behaves badly.

None of it asks you to take our word for anything we could have checked instead. Where a sentence here is a fact about the database or the code, it was read out of the code before it was written down. Where something is a limit rather than a feature, it is on this page too, because a trust page that only lists the good parts is an advertisement.

If something has already happened and you need help now: every piece of content on the site has a report link, and the fastest human is a Recruitment Manager on the Forever WoW Discord. If someone is in real danger, skip both and call your local emergency services.

Logging in with Discord, explained simply

Imagine a doorman who knows everyone. You do not hand him your house keys — you point at him and he nods, and the person at the door writes down your name. That is what logging in with Discord is. Discord is the doorman, your password is the house key, and we only ever get the nod and the name.

The technical name for this is OAuth, and the only part of it you need to believe is the part you can check yourself: when Discord asks whether it is all right, the page listing what we want to know is written by Discord, not by us. Read it. It will tell you the same thing this page does.

  1. You knock

    You press “Log in with Discord”. We never ask you for a password, because we do not have one to ask for.

  2. Discord asks you

    Discord shows you a page: “this site wants to know who you are — is that all right?” That page belongs to Discord. We cannot see it or change it.

  3. You say yes

    You tap yes on Discord’s page. If you have to type a password, you are typing it into Discord. It never passes through us.

  4. We get a name badge

    Discord hands us a little badge with your username, your display name and your picture on it. That is the whole login.

What is not on the badge

  • your password
  • your email address
  • your private messages
  • your friends list
  • the other servers you are in
  • anything you do on Discord outside this community
In the wording Discord uses, we ask for one permission and it is called identify — the smallest one on the list. Knowing which roles you hold is a separate thing and does not come from you: the community’s own bot can see the Forever WoW member list, the same way any member can. We never ask you for permission to read your servers, because we never read them.

What we take, and what we never take

Almost everything the site knows about you is something you typed into it on purpose, and you can change or remove most of it yourself whenever you like.

The more useful half of this is the second column. A promise not to look at something is only as good as the people making it; not having a place to put it in the first place is a different kind of assurance, and it is the kind this site prefers. There is no column in the database for your email address, because the login never asks Discord for one.

Addresses are worth being precise about rather than boasting about. Early versions of this site did store your IP address against your login session. A change in 2026 removed that column outright and scrubbed the addresses already recorded, and nothing has written one since. The single remaining exception is the emergency admin login, which has to count failed attempts from one visitor and keeps a one-way hash rather than the address to do it. We would rather tell you that than round it up to “never”.

  • Four cookies, all of them ours and all of them doing a job: the one that keeps you logged in, a short-lived one during login that stops somebody forging it, one that remembers if a Discord check failed, and one that remembers which colour theme you picked. None of them follow you anywhere.
  • The compare feature keeps your shortlist in your own browser. That list never reaches us at all.
  • Cloudflare delivers every page and therefore sees the request, as any web host must. Discord knows you logged in, because you logged in with Discord. Those are properties of using the internet, not choices we made, and we have listed them rather than let them go unsaid.

What we hold

  • Your Discord identityuser ID, username, display name, avatar
  • Whether you are in the serverand which roles you hold, because that decides what you can do here
  • What you writeyour profile, guild pages, applications and their messages, posts, comments, events
  • Two timestampswhen you last logged in, and roughly when you were last active
  • Your own listssaved guilds, blocks, notifications and the reports you have filed

Nearly all of it is something you typed on purpose, and you can edit or remove most of it yourself.

What we never hold

  • Your passwordthe site has none of its own and never sees your Discord one
  • Your email addresswe do not ask Discord for it and it is never stored
  • Your IP addressnot stored. The one place that has to count attempts per visitor — the emergency admin login — keeps a one-way hash of it instead
  • Anything for advertisersno ads, no ad network, nothing sold or shared
  • Any tracking or analyticsno pixels, no beacons, no session recording, no analytics product of any kind
  • Payment detailsnothing here costs money, so there is nothing to take

Not “we promise not to look”. There is no column for these, so there is nothing to look at.

Two honest footnotes, because a page that only lists the flattering parts is an advertisement. First, addresses: the site used to keep one per login session, and a change in 2026 deleted that column and scrubbed the old rows. The only address handling left is the emergency admin login, which stores a one-way hash so it can count failed attempts without knowing who they came from. Second, other companies: Cloudflare delivers every page and therefore sees the request, as any host must, and the typeface comes from Google Fonts. If you are signed in, your own avatar is still fetched from Discord’s servers to show it to you. Nobody else’s is, and that is the whole list.

Who can see what

Four levels, and nothing quietly moves between them. The one people most often get wrong is the last: moderators are not reading your application threads. Reporting a message is what puts it in front of a person, and without that it stays between you and the guild.

  • One thing worth knowing before you rely on it: deleting your own Inn post or comment hides it rather than erasing it. It leaves the site immediately and nobody browsing can reach it, but the text stays in the database and a moderator can still read it. If you need something actually gone, ask a Recruitment Manager rather than pressing delete and assuming.
  • Public

    Anyone on the internet, including search engines

    Published guild pages, visible player profiles, Inn posts and comments, events

  • One guild

    You and that guild’s recruiting team, nobody else

    Your application, its answers and the whole message thread

  • Only you

    Nobody but you, while you are logged in

    Your saved guilds, your blocks, your notifications, the reports you have filed

  • Moderators

    Recruitment Managers and admins — but only once something is reported

    Reported content, and a reported application message. Not threads nobody reported

You choose which tier your profile sits in, and you can hide it at any time. The bottom row is the one people assume wrongly: a moderator cannot browse application threads. Reporting a message is what puts it in front of them.

How we test that it is safe

Security on a site like this is mostly unglamorous: check every input, trust nothing a browser sends, let one place and only one place turn text into HTML, and write a test for each of those so that a future change cannot quietly undo them.

That last part is the part worth describing, because it is the only one you can hold us to. There are more than 780 automated tests across more than 40 files, and they do not run against a mock — they run on a real Worker against a real database, exercising logins, permission boundaries, who can see whose application, and the text sanitiser that stands between a user’s post and your browser.

The site is also read deliberately for weaknesses rather than only for bugs, and any finding is argued against before it is believed. Most do not survive that, which is exactly why it is worth doing: an audit that confirms everything it suspects is not an audit.

  1. The compiler checks it

    The whole codebase is type-checked in strict mode before anything ships. A whole class of mistakes cannot reach the site.

  2. Hundreds of automated tests run

    More than 780 of them across more than 40 files, on a real Worker against a real database. They cover logins, permissions, who can see what, and the text sanitiser.

  3. Attack-minded review

    Changes are read with an attacker’s eye, and findings are argued against before they are believed — most turn out to be wrong, which is the point.

  4. Then it deploys

    Database changes are backed up first and verified afterwards. A change that fails any step above does not go out.

And what we do not have

  • No independent penetration test by an outside firm
  • No bug bounty programme
  • No formal certification of any kind
  • Tests are run by hand before a deploy, not automatically on every change
A volunteer project that claimed a security certification would be lying to you, so here is the honest version: careful engineering and a lot of tests, with none of the assurances that only money buys. Judge it accordingly, and keep your Discord account locked down regardless.

Reporting content

You can report a guild page, a player profile, an Inn post, an Inn comment, an event, a guild post or a message inside an application thread. The report goes only to the moderators, along with a link to the content and the reason you wrote.

The person you report is never told who reported them. You cannot report your own content — edit or delete it instead — and reporting the same thing twice does nothing beyond the first time, so there is no need to file it again while you wait.

  • Say what you saw and where. Between ten and two thousand characters; you do not need to argue the case.
  • Five reports per account per rolling day. That is enough for any honest use, and the limit exists so nobody can bury the queue.
  • A report on an application message only works if you are actually part of that thread. Nobody can use a report to read a conversation they are not in.
  • False reports filed to harass someone are themselves a guidelines violation, and they are logged against the reporter.

Blocking someone

Blocking is the tool you control, and it is separate from reporting. It cuts off messages and invites in both directions immediately — they cannot contact you and you cannot contact them, which is deliberate, because a block that only worked one way would just be a trap for the person who set it.

The other person is not told. You can see and undo your blocks from your own settings at any time. Block first if you want the contact to stop now; report as well if the behaviour deserves a moderator, because a block protects you and only you.

What the moderators can do

Recruitment Managers and admins can hide any piece of content, suspend or ban an account, and suspend a guild page separately from the accounts that run it — so a bad page does not have to mean banning its members, and a banned member does not take their guild down with them.

Every moderation action is written to an audit log with the name of the person who took it and when. That log is for holding the team to its own standards, not for publishing, and it is visible to staff only.

What the moderators cannot do

This is the part most safety pages leave out. The limits are real and you should plan around them.

  • They cannot read application threads that nobody has reported. Reporting a message is what puts it in front of a moderator; without that, a private thread stays private.
  • They cannot see your Discord password, your email address, your Discord DMs or anything you do on Discord outside this community’s server.
  • They cannot act inside World of Warcraft. Nothing decided here removes anyone from a guild in the game, recovers anything you handed over, or reaches a game account.
  • They cannot verify that anyone is who they say they are. A Discord login proves control of a Discord account and nothing else.
  • They are volunteers in a handful of timezones. There is no round-the-clock queue and no service-level promise. Most things are looked at within a day; some take longer.

A guild page is not an endorsement

Nobody vets guilds here. A guild page means somebody filled in a form, not that the site checked their raid history, their loot council or how they treat people. The freshness labels tell you a guild confirmed it was still recruiting recently; they do not tell you the page is true.

The fit score is arithmetic on what both sides typed. It cannot tell you whether you will enjoy their company, and it does not try to. You are about to spend your evenings with these people, so a few minutes of ordinary caution costs nothing.

  • Talk to them in voice before you commit to anything. Text hides a lot.
  • Ask about the things that cause arguments later: loot, attendance, benching, what happens when a raid is short.
  • Look at whether the page matches the conversation. A page promising three raid nights and officers who cannot name them is telling you something.
  • Trust the feeling. You do not owe a guild an explanation for walking away, and leaving is a single action on your side.

Scams, gold selling and phishing

Real-money trading and phishing are against the guidelines and will get an account banned on the first offence. They are also the most likely way a player here comes to actual harm, so know the shapes they take.

  • Nobody legitimate needs your game password, your Battle.net details or a one-time code. Not an officer, not a moderator, not the site, not Blizzard.
  • Gold selling, paid boosts, account sales and “I’ll carry you for real money” are all banned here, and every one of them is a way to lose an account.
  • Be wary of a link that wants you to log in again — a fake Discord or Battle.net login page is the oldest trick there is. Check the address bar before you type anything.
  • Be wary of anyone in a hurry, especially one who wants to move off the site and onto an unfamiliar platform immediately.
  • A guild’s Discord invite appears on your application only after they accept you. Anything else claiming to be an official invite link did not come from us.

Your account

You log in with Discord and nothing else. The site never sees your Discord password and has no password of its own to steal, which means the security of your account here is the security of your Discord account. Turn on two-factor authentication there; it is the single most useful thing you can do.

A session lasts fourteen days. Log out on a shared or borrowed computer. If you think somebody else has used your account, tell a Recruitment Manager on Discord and change your Discord password first.

If it is serious

Threats of violence, anything sexual involving a minor, doxxing, or somebody talking about harming themselves: go straight to a Recruitment Manager on Discord rather than filing a report and waiting. Say that it is urgent.

We are a group of volunteers running a guild finder. We are not an emergency service, we have no way to reach anyone offline, and we cannot help somebody who is in immediate danger. If a person is at risk right now, contact your local emergency services or a crisis line in your country. That is not us passing the problem along; it is the honest limit of what a website can do.

Appeals and second opinions

Every decision here is made by a person, and people get things wrong. If a moderator hid your content, suspended your page or banned your account and you think it was a mistake, ask a Recruitment Manager on Discord and say what you think happened.

Appeals are read by someone, not by a script. Arguing your case in public rarely helps and never speeds it up; asking plainly, once, usually does.