Furcord Group Developer & Bot Platform Policy
- Effective Date
- October 5, 2026
- Entity
- Furcord Group (“Furcord”, “we”, “us”, or “our”)
- Corporate Mailing Address
- P.O. Box 6174, Lubbock, TX 79493
- Developer Support
- support@furcord.org
This Developer & Bot Platform Policy governs all developers, applications, automated bots, integrations, and external tools accessing the Furcord API, Gateway, or Webhooks (collectively, “Developer Applications”).
1. Developer Agreement & Eligibility
- Acceptance: Creating an Application or obtaining API keys binds you and your development team to this Policy and the Furcord Terms of Use.
- Minimum Age: Developers must be at least thirteen (13) years of age (or the age required to consent to digital contracts in their jurisdiction).
- Corporate Authority: If creating Applications on behalf of an organization or business entity, you represent and warrant that you possess the full legal authority to bind that entity to this Policy.
2. Mandatory Bot Verification & Privileged Gateway Intents
- Verification Threshold: Any Bot or Application that joins more than 75 Furcord servers must undergo mandatory Developer Identity Verification.
- Privileged Gateway Intents: Access to sensitive Gateway streams (including Server Members Intent, Presence Intent, and Message Content Intent) requires explicit approval through the Developer Portal. Developers must articulate a legitimate, functional need for the requested data before privileged access is granted.
- Discretionary Revocation: Furcord Group reserves the right to audit, deny, or revoke verification and privileged intents at any time for security, privacy, or policy violations.
3. API Usage, Rate Limits, & Technical Standards
To ensure network integrity and equal access across all servers, developers must program their Applications to adhere to Furcord technical standards:
- Rate Limits: Applications must strictly respect all HTTP and Gateway rate limits communicated via response headers (including X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset-After).
- HTTP 429 Handling: Upon receiving an HTTP 429 Too Many Requests status code, your Application must immediately back off and delay subsequent calls according to the duration specified in the retry_after payload.
- Invalid Request Ceiling: Making more than 10,000 invalid requests (HTTP 401, 403, or 429) within any 10-minute window will result in an automated platform firewall ban of your bot’s IP address.
- No Circumvention: You may not use request proxies, IP rotation, multi-bot pooling, or duplicate client accounts to bypass established rate limits.
- Self-Bots Prohibited: Automating normal user accounts (“self-bots”) or using user authentication tokens to interact with private APIs is strictly banned and triggers permanent account and IP termination.
4. Data Privacy, Retention, & Protection Rules
- Principle of Data Minimization: You may only request, collect, and process user data that is strictly necessary for your Application’s stated, approved features.
- No Commercialization or Sale: You may never sell, license, trade, rent, or disclose Furcord API data, message logs, or user identifiers to third-party data brokers, advertising networks, or data brokers.
- No Model Training on User Messages: You may not use private message content, channel transcripts, or attachments obtained through the Furcord API to train machine learning or large language models without express prior written consent from Furcord Group.
- Mandatory Data Deletion:
- Developers must provide a clear mechanism for server owners and individual users to request the permanent deletion of their stored data.
- When a Bot is removed (“kicked” or “banned”) from a server, the Application must purge all data specific to that server within thirty (30) days, unless required by law.
- Security & Tokens: Bot tokens and client secrets must be kept confidential in encrypted secret vaults. Tokens must never be committed to public code repositories (e.g., GitHub). Leaked tokens will be invalidated immediately by automated scanners.
5. Community Safety & Prohibited Bot Functions
Your Bot or Application must not facilitate or execute:
- Spam & Mass Direct Messaging: Sending unsolicited promotional direct messages, mass server invites, or commercial advertisements.
- Fake Engagement: Artificially inflating member counts, ping-bombing users, or generating automated fake channel chatter to manipulate server metrics.
- Credential Harvesting: Phishing, requesting user passwords, logging authorization tokens, or tricking users into revealing sensitive identity credentials.
- Malicious Utility: Performing destructive administrative actions without server owner authorization (such as mass-banning all members, deleting all channels, or “nuking” servers).
6. Developer Enforcement & Indemnification
- Enforcement Discretion: Violations of this Policy may result in API rate-limit reductions, revocation of privileged gateway intents, deletion of bot applications, or permanent termination of the developer’s Furcord account.
- Indemnification: You agree to indemnify, defend, and hold harmless Furcord Group from any claims, damages, or regulatory fines resulting from your Application’s unauthorized data collection, security breaches, or policy non-compliance.