Corner Gift portal
Terms of Service Privacy Policy Back to sign-in

Legal

Privacy Policy

Effective date: August 4, 2026 · Last updated: August 4, 2026

This Policy explains how Corner (“we,” “us”) collects, uses, and shares information when you use the Gift Portal at securegifts.org, our Discord bot, and related services. It reflects how the product works today. See also our Terms of Service.

  1. 1. Who we are
  2. 2. Information we collect
  3. 3. How we use information
  4. 4. How we share information
  5. 5. Cookies & similar technologies
  6. 6. Retention
  7. 7. Security
  8. 8. Your choices & rights
  9. 9. Children
  10. 10. International transfers
  11. 11. Changes
  12. 12. Contact

1. Who we are

Corner operates a community Fortnite gift portal and Discord bot for the securegifts / Corner community. For privacy questions or deletion requests, use portal Support or the Discord server at discord.gg/securegifts.

2. Information we collect

2.1 Account & Discord sign-in

When you sign in, we use Discord OAuth with the identify scope only. We receive your Discord user ID, username, global display name, and avatar information. We do not request your Discord email address through OAuth. Discord’s access token is used briefly to fetch your profile and is not stored as a long-lived credential in our database.

2.2 Profile & service data we store

Depending on features you use, we may store:

  • Linked Fortnite / Epic display name and Epic account ID
  • Community V-Bucks balances (including borrowed/reserved amounts and related lender links)
  • Gift unlock windows, beta-tester flags, daily shop-reminder preference
  • Encrypted two-factor authentication secrets and related lockout counters when you enable 2FA
  • Shop ownership / cosmetic caches used to power the portal
  • Recent V-Bucks transfer recipients (and any you choose to hide)
  • Gift requests, confirmations, tracking, and failure records
  • Gifting-account assignments (mapping your Discord ID to an operator gifting account)
  • Rate-limit and anti-abuse counters

2.3 Support chat & feedback

  • Support messages you send (and staff replies), stored in our database
  • Optional image attachments, stored in object storage and removed when the chat closes
  • Feedback text submitted through Discord, typically delivered to staff via webhook

2.4 Purchases

If you buy a V-Bucks pack, we store order records such as your Discord ID, username/display name, package details, amounts, currency, status, Stripe session / payment intent identifiers, timestamps, and fulfillment-related fields. Payment card data is handled by Stripe on Stripe-hosted Checkout; we do not store full card numbers. Stripe may collect email or billing details on its pages according to Stripe’s policies.

2.5 Discord bot activity

In the Corner Discord server(s) where the bot is present, the bot may process slash commands, buttons, modals, direct messages we send you (for example reminders or transfer offers), and—when certain voice/AI features are enabled—message or voice content needed to provide those features.

2.6 Technical & security data

  • Session data needed to keep you signed in
  • IP addresses in short-lived audit / rate-limit logging (not stored as a permanent field on your user profile)
  • Basic device/browser storage for UI preferences (see Cookies)

2.7 Operator accounts (not your Epic password)

To send gifts, we store encrypted Epic device-auth credentials for operator-owned gifting accounts. End users do not log in with Epic OAuth on the portal; you typically provide a Fortnite display name for linking and gifting eligibility checks.

3. How we use information

We use information to:

  • Authenticate you and operate the portal and bot
  • Link Fortnite identities, check friendship / gift eligibility, and fulfill gifts
  • Maintain balances, transfers, shop views, reminders, and related features
  • Process payments and deliver purchased V-Bucks packs
  • Provide support, moderate abuse, enforce our Terms, and keep the service secure
  • Operate optional AI-assisted voice/text features when those modes are active
  • Improve reliability (for example rate limiting, maintenance, versioning)

We do not sell your personal information. We do not use advertising pixels or third-party marketing analytics suites in the portal codebase.

4. How we share information

We share information with processors and platforms only as needed to run Corner, including:

  • Discord — login, bot features, webhooks, community messaging
  • Epic Games / Fortnite-related APIs — friends, gifting, and catalog operations via operator gifting accounts
  • MongoDB — primary application database and, in some setups, session storage
  • Redis (optional) — session storage
  • Stripe — checkout and payment processing
  • Cloudflare — CDN / proxy for securegifts.org; Cloudflare R2 for support images
  • OpenAI and ElevenLabs — when voice/AI chat features are used, relevant prompts or audio may be sent to those providers
  • fortnite-api.com, fortnite.gg, and similar sources — shop/cosmetic display data
  • Gofile — temporary file hosting for certain media conversion flows
  • Google Fonts — font delivery for the portal UI

Staff with developer-panel access can look up user records needed for support and operations (balances, linked names, 2FA status, orders, support threads, and similar). We may also disclose information if required by law or to protect users, our systems, or our rights.

5. Cookies & similar technologies

  • Session cookie corner.sid — httpOnly session cookie used to keep you signed in (typically up to about 7 days). It is marked Secure in production configurations.
  • CSRF token — stored in the server session and sent with mutating API requests; not a separate tracking cookie.
  • localStorage / sessionStorage — UI preferences such as visual-effects / performance mode (including auto-tier choices) and active tab state.

We do not set Google Analytics, Meta Pixel, or similar advertising cookies in the portal. Third parties you interact with (Discord, Stripe, Google Fonts, Cloudflare) may set their own cookies or process technical data under their policies.

6. Retention

  • Sessions — expire with the session cookie / store TTL (about 7 days of inactivity or cookie lifetime).
  • Support images — deleted from object storage when a chat closes.
  • Closed support chats — retained about 7 days, then hard-deleted.
  • Idle support — chats may auto-close after about 24 hours without a customer reply after staff messages.
  • Account, balance, gift, and purchase records — kept while needed to operate Corner, prevent abuse, and complete fulfillment, unless you successfully request deletion or we purge them as part of operations.
  • Temporary convert uploads — scheduled for deletion after processing.
  • In-memory AI conversation turns — short-lived process memory for active voice/text sessions; not written as permanent chat history in the database.

7. Security

We use industry-common protections appropriate to a small community service, including HTTPS (in production deployments), httpOnly session cookies, CSRF protection on mutating API routes, rate limiting, encrypted storage of sensitive secrets such as 2FA and operator Epic device credentials, and security headers. No method of transmission or storage is 100% secure. Please protect your Discord account and enable 2FA where offered.

8. Your choices & rights

Depending on where you live, you may have rights to access, correct, or delete personal data, or to object to certain processing. Corner does not currently offer a fully automated self-service “delete my account” or data-export button in the portal.

To request access or deletion, contact us via portal Support or Discord and include your Discord username / ID. We may need to verify you control that Discord account. We may retain limited information when required for security, fraud prevention, dispute resolution, or legal obligations (for example certain payment records).

You can sign out to end your portal session. You can revoke Corner’s Discord authorization in your Discord authorized-app settings. You can turn off daily shop reminders in Settings when that feature is available to you.

9. Children

Corner is intended for users who meet Discord’s and Epic’s minimum age requirements. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information, contact us and we will take reasonable steps to delete it.

10. International transfers

We and our processors (including cloud and API providers listed above) may process data in the United States and other countries. If you use Corner from elsewhere, you understand your information may be transferred to and processed in those locations.

11. Changes

We may update this Policy as the product changes. We will revise the “Last updated” date at the top. Material changes may also be announced in Discord or on the portal when practical.

12. Contact

Privacy requests: portal Support after sign-in, or discord.gg/securegifts.

© Corner · securegifts.org Unofficial community service — not affiliated with Epic Games.