Discord started as a gaming chat tool and grew into one of the most widely used communication platforms in the world, spanning gaming communities, professional servers, hobbyist groups, fan communities, and increasingly spaces for sharing files, running businesses, and maintaining friendships. Hundreds of millions of people use it for conversations they consider private. Many store files there through bots and direct messages. And yet Discord collects significantly more data than most users realize — a fact that became unavoidable when the platform announced mandatory age verification in early 2026 and triggered one of the year’s most visible privacy backlashes.
Understanding what Discord collects — and what the age verification controversy revealed about the company’s relationship to user data — is worth doing whether or not you use Discord as any kind of memory or file storage tool.
What Discord Actually Collects
Discord’s privacy policy describes a broad range of data collection that most users haven’t read carefully. The platform collects:
Account and identity data. Your email address, username, phone number (if provided for two-factor authentication), and date of birth. If you use Discord’s Nitro subscription, your payment details are also stored.
Message content and metadata. Every message you send — in direct messages, group chats, and servers — along with when it was sent, to whom, and from which device. Discord is explicit that messages are not end-to-end encrypted; the platform can read them. The company has provided message content to law enforcement in response to valid legal requests, which is documented in its transparency reports.
Voice and video data. Discord logs that you participated in voice or video calls, with whom, and for how long. The content of voice calls is not stored as audio, but metadata about your calling patterns is.
Activity and behavior. Every server you join, every channel you visit, every reaction you leave. Discord tracks how you move through the platform to build a behavioral profile used for product development and, on the free tier, advertising.
Device and connection information. Your IP address, device identifiers, operating system, browser type, and information about your device’s hardware. Discord logs this each time you connect.
Rich Presence data. If you have Rich Presence enabled, Discord can see what games you’re playing, what apps are running on your device, and your current activity — and can share that information with people on your friends list.
Inferred data. Discord uses the data it collects to infer information about your preferences, interests, and demographics for use in advertising targeting on the free tier.
The Age Verification Announcement and What Happened Next
In early 2026, Discord announced a mandatory global age verification system set to roll out in March. Under the plan, certain users — those in jurisdictions with specific legal requirements or flagged by Discord’s systems as potentially underage — would be required to verify their age by submitting a photo ID and a selfie to a third-party verification service before regaining access.
The backlash was immediate and intense.
Users raised several specific concerns:
The data being collected was unusually sensitive. A government ID and a facial scan are not comparable to an email address or username. They’re biometric and documentary proof of identity, creating a combination that would be highly damaging if exposed.
Third-party handling. Discord was using an external age verification service, not handling the process in-house. Third-party data processors are an additional attack surface — and as users quickly noted, there had already been a potential breach at a third-party Discord customer service provider in late 2025 that may have exposed tens of thousands of users’ ID scans.
No transparent data handling policy. Discord’s initial announcement was vague about how long the ID and facial scan data would be retained, who the third-party service was in each jurisdiction, and what would happen to that data after verification was complete.
The scope was unclear. Discord said age verification would apply in countries with explicit legal requirements first (the UK, Australia, and Brazil), but the announcement implied a global rollout later. Users in regions where the legal requirement was less clear worried about being swept in.
Discord’s CTO acknowledged that the company had “missed the mark” in its communication and postponed the global rollout until the second half of 2026 to rethink the approach. In jurisdictions with hard legal deadlines, verification continued.
The episode illustrates a pattern worth watching: platforms under regulatory pressure to verify user ages often respond by collecting more documentation, not by redesigning their systems to need less. The users most exposed are the ones who were already using the platform as a trusted communication channel.
Discord as File Storage: What That Actually Means
Many Discord users don’t think of themselves as using a file storage platform — but functionally, many are. Direct messages routinely contain attachments: photos shared between friends, documents sent to colleagues in a Discord workspace, audio clips, video files. Bots allow users to upload and retrieve files through Discord’s infrastructure. Servers run archives of media files, documents, and links.
When you share a file through Discord, that file is stored on Discord’s servers. The file is not end-to-end encrypted. Discord can access it. If the file is in a direct message or private channel, it’s still processed and stored in plaintext on Discord’s infrastructure, accessible to the platform itself and to any law enforcement request that meets the threshold for disclosure.
Files attached to direct messages are typically accessible via direct URL — meaning the link can be shared with anyone who has it, and files are not uniquely tied to your account in a way that prevents external access.
This is not unusual compared to how most messaging platforms handle attachments. But it is meaningfully different from a dedicated file storage tool built around access control and encryption for stored content.
What Discord’s Business Model Means for Privacy
Discord operates on a freemium model: the free tier is supported by advertising; the paid Nitro tier removes ads and unlocks additional features. Discord has stated that it does not sell personal data to third parties, which is accurate but somewhat narrowly phrased — advertising targeting doesn’t require selling data; it can be accomplished by allowing advertisers to reach audiences defined by Discord’s own data, without the raw data leaving the platform.
For free users, the data collected about your behavior, interests, and demographics is the basis for advertising targeting. That’s a straightforward exchange that most people understand at a general level, even if they haven’t read the specifics.
The issue with Discord isn’t that its model is uniquely problematic — it’s that the platform is often used in ways that don’t match how people mentally categorize the service. People often compartmentalize Discord as “chat” rather than as a data-collecting platform, and behave differently in that mental frame. Private messages to close friends feel qualitatively different from public posts on a social media feed — but from a data architecture standpoint, they’re more similar than they appear.
What Changed (and What Hasn’t)
Discord has improved some privacy controls over the years. Users can:
- Request a full export of their account data under GDPR provisions (if located in a covered jurisdiction) or via Discord’s Privacy & Safety settings
- Opt out of certain types of personalization in User Settings > Privacy & Safety > How We Use Your Data
- Disable Rich Presence for individual apps through the Activity Status settings
- Turn off “Allow Discord to track screen reader usage” and similar diagnostic data settings
These controls give users some visibility and limited opt-out options. They don’t change the fundamental architecture: messages and files are stored server-side without end-to-end encryption, and Discord retains the ability to access content in response to valid legal requests.
The age verification controversy didn’t alter the underlying data collection practices that made submitting a government ID feel risky. It revealed them more clearly to users who had never thought much about where their data went.
A Different Standard for Personal Files
The Discord situation is a useful point of comparison for thinking about what you want from a personal file storage tool. Discord is optimized for real-time communication and community — it’s good at those things, and the data collection that happens alongside them is a structural part of how the platform operates.
Files shared in Discord exist in a context that wasn’t designed for long-term personal archiving with access controls. They’re accessible via URL, stored on infrastructure built for a messaging product, and subject to the same legal disclosure process that applies to messages.
A dedicated tool for personal memory and file storage makes different choices by design. daftei stores what you upload — photos, documents, voice notes — encrypted in transit with TLS 1.3 and at rest with AES-256, never sells your data, never trains third-party AI on your content, and never shows you ads. Files aren’t stored alongside chat logs or accessible via direct URL to anyone who finds a link.
The age verification debate has been framed primarily as a story about safety versus privacy. The longer-running question — what data are you creating by using a particular tool, and who can access it — applies regardless of what regulation prompts a given moment of visibility. It’s worth asking that question about every tool where files you care about end up.
What You Can Do Now
If Discord is part of how you currently manage files or personal communications:
Review what you’ve shared. Discord’s data export (Privacy & Safety settings) gives you a picture of what’s stored. You may find more than you expected.
Check your privacy settings. User Settings > Privacy & Safety includes controls over data use, activity display, and diagnostic sharing that most users haven’t touched since creating their account.
Consider what Discord is the right tool for. It’s an excellent real-time communication platform. It’s not designed to be a secure personal file archive, and using it that way creates exposure that wasn’t part of the implicit deal when you joined.
Separate communication from storage. Tools built specifically for private file storage operate under different privacy models than communication platforms. If the files matter to you beyond the conversation that prompted you to share them, storing them somewhere designed for that purpose is worth the extra step.
The age verification controversy won’t be the last time Discord’s data practices become visible. But you don’t need a controversy to take a clear-eyed look at what any platform knows about you and whether that matches how you’re using it.