ReForge Extensions · Product-specific disclosure
Discord Member Exporter Privacy Policy
This notice explains what Discord Member Exporter processes when you capture a Discord server channel, collect accessible member information, request detailed profiles, create a local export, or schedule a background export. It supplements the general ReForge Extensions privacy policy; where the two differ, this notice controls for this product.
Plain-language summary
- The extension must capture your Discord access token and selected server/channel context after you open Discord. It keeps that credential in protected
chrome.storage.localso user-requested manual and scheduled exports can continue in the background after Discord is closed. - The token is sent to Discord REST and Gateway services to perform the export. It is not sent to ReForge product analytics, the ReForge payment/configuration API, or the logging endpoint.
- Member rows can include identifiers, names, roles, join dates, presence/activity, profile fields, Nitro/boost information, bios, pronouns, connected accounts, badges and mutual counts, depending on the options you select.
- Member data is processed in the extension, temporarily placed in IndexedDB while the requested file is prepared, saved through Chrome Downloads, and deleted from the temporary result store after the download attempt. The extension does not keep a download-history copy.
- Settings, schedules, saved Discord access, the last selected mode, task state, export counters and SDK state remain in local extension storage until changed, cleared or removed with the extension.
- ReForge services receive product configuration, optional account/subscription data and limited operational events. Those events may include an installation identifier, app/browser metadata, account email when signed in, the user action name, selected mode/format and counts, but not Discord tokens or member-row content.
Chrome Web Store Limited Use statement: data obtained from Discord is used only to provide the member collection, profile lookup, file export and schedule features requested by the user. It is not sold, rented, used for personalized advertising or remarketing, supplied to data brokers, or used for credit evaluation or lending decisions.
Credential notice: a Discord access token can act as an authentication credential. The extension restricts its local storage to trusted extension contexts, but local extension storage is not described as end-to-end encrypted. Use Chrome on a device and browser profile you trust, and use the “Clear saved Discord access” control when you no longer need background exports.
1. Data processed by the extension
1.1 Discord access and target context
- Source: the active
https://discord.com/*page after you open Discord. The page-world script observes Discord authorization headers and the Discord Gateway identify payload, and may read the token value Discord has placed in page local storage. - Fields: Discord access token, Discord client build number, guild/server ID, channel ID, server name, channel name, server icon URL, Discord-reported member count, tab ID and update time.
- Purpose: remember the selected export target, authenticate requests to Discord, refresh server/channel metadata, connect to the Discord Gateway, and allow background or scheduled exports after the Discord tab is closed.
- Storage: the token and saved target use
chrome.storage.local. The background callschrome.storage.local.setAccessLevel({ accessLevel: "TRUSTED_CONTEXTS" })so content scripts cannot directly read extension local storage. Per-tab context may also exist temporarily inchrome.storage.session.
1.2 Member list and profile data
- Basic collection: Discord user ID, username, discriminator where present, server nickname, avatar URL, role IDs, server join time, presence status and current activity.
- Derived fields: account creation time derived from the Discord snowflake ID and the selected export columns.
- Optional detailed profile collection: global name, legacy username, profile or server bio, pronouns, Nitro tier/type/since date, server boost date, accent color, public flags, primary guild or clan tag, avatar decoration, connected account type/name, badge descriptions, mutual guild count, mutual friend count, verification-pending state and communication-timeout date.
- Purpose: construct the exact spreadsheet or data file and optional avatar archive requested by the user, including any user-selected Nitro filter and columns.
- Storage and deletion: active rows are held in extension memory. A completed task is written to an IndexedDB database named
discord-member-exporteronly long enough for the offscreen document to create the file. The result is cleared at the next run, after the download attempt, after supported startup cleanup, or when the task is cleared.
1.3 Settings, schedules, task state and local statistics
- Settings: language, theme, Fast/Deep mode, member limit, detailed-profile switch, Nitro tier filter, output format, avatar ZIP switch, Downloads subfolder, selected columns and filename template.
- Schedules: task ID, enabled state, local execution time, saved Discord target, settings snapshot, creation/update time, last execution, last result count, last limit state and last error.
- Task and statistics: current task phase and progress, result/download status, successful-export count, exported-member count and last-export time.
- No retained export history: the extension does not retain past member files or a list of completed download results. Files already saved to your Downloads folder remain on your device until you remove them.
1.4 ReForge SDK state and optional account data
- The SDK stores a product-scoped installation UUID and installation time, cached encrypted product configuration, review-prompt state, device ID, and—if you choose to sign in—an authentication token, email address and cached subscription/user status.
- If account or paid-plan features are enabled and you use them, the ReForge API can process your email address, password, one-time email code, challenge ID, device ID, login token, product ID, subscription status, selected plan, checkout request and portal request. Passwords and one-time codes are used for the requested authentication call and are not included in custom analytics events.
- If you submit a one-to-three-star review response, the rating and optional improvement reason you enter are sent as a review event. Higher ratings can open the Chrome Web Store review page.
1.5 Data not requested as a Chrome permission
- The manifest does not request
cookies,history,browsingData,webRequest,scripting,nativeMessagingor broad access to all websites. - The code does not directly enumerate Cookie values, browser history, bookmarks, unrelated page content, form entries or keystrokes. Detailed Discord profile requests use
credentials: "include", so Chrome may attach browser-managed Discord cookies to Discord itself, but the extension does not read those Cookie values or send them to ReForge.
2. Chrome permissions and host access
storage
Stores the settings, last selected mode, schedules, saved Discord token and target, task snapshot, statistics, session context and SDK state described above.
tabs
Finds the active Discord tab during initial capture or target refresh, receives the selected tab ID/URL, requests current context from the Discord content script and opens extension pages. It is not used to collect a history of unrelated browsing.
sidePanel
Provides the extension’s primary member-export interface in Chrome Side Panel. The product does not use a browser-action popup.
downloads
Saves the requested XLSX, XLS, CSV or JSON file and optional avatar ZIP archives into Chrome Downloads, including the relative subfolder selected by the user, and observes completion or interruption of the created download.
alarms
Creates and reconciles the daily local alarms for schedules you explicitly save. Chrome must be running for an alarm to execute.
offscreen
Creates a short-lived offscreen document with the BLOBS reason so a Manifest V3 background task can generate Blob-based files and call Chrome Downloads even when the Side Panel and Discord page are closed.
Discord hosts
https://discord.com/* and https://*.discord.com/* allow initial credential/target capture and Discord REST requests. https://gateway.discord.gg/* allows the background WebSocket used for Fast range requests and Deep member searches. https://cdn.discordapp.com/* is used for server icons and user avatars, including optional local ZIP creation.
ReForge service hosts
https://api.reforgeextensions.com/* provides product configuration and optional account, subscription, checkout and portal operations. https://reforgeextensions.cn-hangzhou.log.aliyuncs.com/* receives the limited SDK operational events described below.
3. Network processing and third parties
Discord REST API, Gateway and CDN
The extension sends the saved Discord token to Discord to refresh guild/channel metadata, connect to the Discord Gateway, request member ranges or name-prefix search results, and—when selected—request individual profile records. Avatar requests go to Discord’s CDN. These requests are made directly from your browser to Discord; ReForge does not proxy the Discord member rows, profile responses, token or avatar bytes.
ReForge configuration, account and subscription API
The SDK requests the product configuration for discord-member-exporter. If you use optional account or plan features, it also sends the account, device, login, checkout or portal fields needed for that action. Authentication responses and cached user information are stored in product-scoped extension storage. The current configuration may present the product as free; the code retains account and future plan capability.
Aliyun Log Service operational events
The SDK can send install/update events and user-action events to the product logstore. Base fields can include event time, event category/action, product ID, extension version, installation UUID/time, operating-system category, browser category, language and paid-plan type. If the user has signed into the ReForge SDK, the account email may also be included in the SDK event context.
User-action extras can include low-sensitivity selections or counts such as Fast/Deep mode, export format, detailed-profile switch, requested or collected count, setting name, schedule time/enabled state, plan, star rating and an optional low-rating reason. The extension does not intentionally put the Discord token, guild/channel names or IDs, member IDs, usernames, bios, connected accounts, member rows, avatar URLs, export filenames or downloaded files into those custom event payloads. Automatic context synchronization, progress broadcasts, Gateway retries, alarm firing and automatic file creation are not custom product events.
Payment and review destinations
If a paid plan is enabled and you request checkout or subscription management, the ReForge API returns a hosted page URL and Chrome opens that page. The payment page and its providers process the information you submit there under their own privacy terms. A positive review action can open the Chrome Web Store review page.
Retention
Local settings, saved Discord access, schedules, statistics and SDK state remain until you change or clear them, clear extension storage, or uninstall the extension, subject to Chrome storage behavior. Per-tab session data ends with the browser session or cleanup. Temporary member results are removed after the file-generation lifecycle described above. ReForge API and logging-provider records are kept only as reasonably necessary for configuration, account/subscription administration, security, support and operational analysis, and legal compliance; this code audit does not establish a fixed server-side retention period.
4. Your choices and controls
- Choose Fast or Deep mode, set a member limit, turn detailed profiles and avatar ZIPs on or off, and select the exact export columns and output format.
- Pause, resume, stop or finish an active run early. A non-empty partial result can still be saved as a successful export.
- Create, enable, disable, run or delete scheduled tasks from the dedicated schedule tab.
- Use “Clear saved Discord access” to remove the locally saved Discord token and target. Background and scheduled exports will require a new Discord capture afterward.
- Sign out of the optional ReForge account flow to remove product-scoped account authentication and cached user data. Review state and installation identity may remain until extension storage is cleared or the extension is uninstalled.
- Clear Chrome extension data or uninstall Discord Member Exporter to remove its remaining local storage. Files already downloaded are not automatically deleted.
- Contact [email protected] for privacy questions or access/deletion requests relating to information you voluntarily provided to ReForge.
5. Security, children, availability and updates
ReForge API requests use HTTPS/TLS and the Discord Gateway uses WSS/TLS. The extension limits host access to Discord, Discord’s CDN/Gateway and the named ReForge service endpoints. Local storage access is restricted to trusted extension contexts where supported.
This product is not directed to children under 13. We may update this notice when permissions, data flows, providers, account features or legal requirements change, and will update the date at the top.
Chrome Web Store item ID pepmcocbelnifgakobdfdfdcekipefmb has been reserved for this product, but the public store listing was not yet available when this notice was published on August 5, 2026.
Discord Member Exporter is an independent product and is not affiliated with Discord. Use it only for information your account is authorized to access and in accordance with applicable rules and law.