Detailed research note

Discord age assurance: transcript verification

Part of the research through 9 September 2026. This dated note preserves its original findings; later developments are discussed in the synthesis and linked profiles.

Result

The video identifies a real expansion of age-gated access and real financial/digital-identity infrastructure. It overstates the evidence when it describes universal identity uploads or treats a newly completed global rollout as established. The implementation's trust boundaries matter: Discord's age decision, third-party evidence processing, upstream credential creation, and old support-ticket retention are separate data surfaces.

Rollout versus tests

Discord announced global teen defaults on 9 February 2026, initially for March. The announcement now carries a 24 February correction postponing global age assurance to the second half of 2026. It explicitly excludes universal ID uploads/face scans and predicts more than 90% need no additional action. The original announced restrictions include adult-only Stage speaking. Narrow searches of current official sources found no September 8 relaunch notice: the latest central help page inspected (updated August 10) still describes delayed broader global expansion, and limited June–August experiments in Australia/Brazil, with Google Wallet also tested in the UK. This is evidence of a continuing plan and tests, not proof nothing changed in individual accounts after the page update.

Sources: http[local research file] (February 9; February 24 correction, Teen Safety Settings and clarification); http[local research file] (February 24; March 9 Brazil update); http[local research file] (August 10 update, opening note).

Discord's February 24 FAQ describes internal age inference from account tenure, payment method on file and activity patterns, and says message contents are excluded. The 90% figure is a company projection, not an independently measured result. http[local research file]

What is restricted

The current UK page (July 28 update) covers every new/existing UK account. Unconfirmed users retain accounts, ordinary servers, friends, DMs and voice. They cannot access age-restricted channels/servers, enable age-restricted app commands or NSFW-server access on iOS, unblur flagged media, select Show in sensitive-content filters, or disable Message Requests. Flagged media is blurred with friends/in servers and blocked in stranger DMs. Before accepting a message request, attachments are unavailable and links inert; accepting it permits normal communication subject to existing permissions. Large-server activity visibility can be changed without age assurance. Friend-request warnings cannot currently be disabled. This is not a ban on ordinary voice or all DMs. Stage-speaking restrictions are explicitly part of the announced global package and central help trigger list; the UK page does not separately list them.

Source: http[local research file] (Default Safety Settings and FAQ); Stage: global announcement above.

Methods and data boundaries

The August 10 central help page says:

Route Processing / what Discord receives Status
k-ID facial age estimation Video remains on device; Discord gets estimated age Established method
ID scan plus matching selfie Document path names k-ID and Veratad; Discord says it never sees images and receives age; images deleted after confirmation Established method
Credit card k-ID routes to Stripe; card details unseen/unretained by Discord, unretained by k-ID; Discord gets adult yes/no Limited test
Google Wallet Discord gets age group and country, other ID information stays in Wallet Limited test

Credit route excludes debit/prepaid; a possible sub-US$0.50 charge is refunded within 14 business days. Central privacy wording qualifies deletion as quick/in most cases immediate, so avoid an absolute universal instantaneous-deletion guarantee. Source: http[local research file] (Choose Your Method, privacy).

k-ID independently documents Stripe credit-card verification and Veratad ID authentication. Card verification proves adult status by the card-ownership proxy, particularly where credit ownership is adult-restricted; it is not a document-based proof of the person typing. Its wider catalogue includes other methods, which must not be presumed deployed on Discord. http[local research file] (Credit card verification; ID scan verification).

k-ID's privacy policy (updated July 10, 2026) specifies that proof data is processed by providers, k-ID receives/stores the verification result, and its on-device FAE provider is Privately. It also describes jurisdiction information, device identifiers/analytics in its wider services, and session retention determined by customers. Thus 'no retained ID image' does not mean 'no retained metadata.' Crucially, its introduction says customer-provided data processed for integrated products is governed by customer contracts; the public policy covers its controller activities. Do not apply every Family Connect or website-analytics category to Discord users without the integration-specific terms. Its generic policy says k-ID itself does not receive proof information, while Discord describes data going directly to k-ID and Veratad: best read k-ID as an orchestrated service path unless a technical integration proves which endpoint receives bytes. http[local research file] (information required for age assurance; sections 2, 5, 9).

Stripe's general policy allows transaction and verification data processing and retention after completed transactions for fraud, legal and financial obligations. Neither the Discord nor k-ID page establishes Stripe's exact retention/configuration for this integration. A refund is not evidence of data deletion. http[local research file] and http[local research file] (Security and retention).

Google's ID-pass setup requires a supported passport, its information-page and NFC-chip scans, and a face video. Automated biometric comparison or human review may be used; biometric templates are deleted following verification. The resulting pass is encrypted locally; the user reviews app-requested information before agreeing to share it. Therefore a minimal age signal to Discord can still depend on prior identity proofing at Google. http[local research file] (Create an ID pass; automated face matching; Use your ID pass; Manage your ID pass).

Document-version trap: search returned a cached June 23 variant of Discord's central page saying Google shares birthdate transiently with Discord and listing an Incode test. The live canonical August 10 page instead says age group + country and omits Incode. Use the live version for current claims; do not silently mix them or infer the engineering change/date from wording alone.

The 2025 breach

Discord's October 3 statement, updated October 9, says approximately 70,000 users MAY have had government-ID photos exposed through the customer-service ticketing incident; these related to age appeals. It also lists support communications, contact details, IP addresses and limited billing, excluding full card numbers and general chats. This does not establish 70,000 selfies, that every image was exfiltrated, or that all were publicly distributed. http[local research file]

Discord calls it compromise of support vendor 5CA. 5CA's October 14 statement (updated October 27) disputes that its own systems were breached and says one employee's actions enabled access to the client's third-party ticketing system; it also denies handling government IDs. Preserve that disagreement rather than resolve it by choosing one company's wording. Both accounts support a support-access failure; they do not identify k-ID/Stripe as breached. http[local research file]

Structural implications and unresolved checks

The substantive pattern is attribute-gated participation relying on several credential providers, rather than evidence that every platform directly builds a passport database. Card infrastructure can authorize access without being the content-moderation authority. Minimal disclosure reduces one exposure while preserving dependency on upstream proofing, eligibility rules and authentication. The old appeals channel demonstrates that exception handling and support permissions may retain identity exposure even when the normal verification flow advertises minimization.

Unknown: September account-by-account rollout coverage; Discord-specific Stripe retention and metadata linkage; implemented Wallet disclosure at the time of an individual test; audit proof of deletion/isolation; precise resolution of the 5CA disagreement. Neither a data-sale motive nor a common NGO/funder directing these Discord changes is established by these records. Discord/k-ID expressly deny selling the relevant user data; those are policy representations, not a forensic audit.