Privacy
Local data and credential handling in Discord Enhanced.
Privacy and local data
Discord Enhanced starts a local HTTP server bound to 127.0.0.1 for its settings panel. Runtime data is stored in:
com.buzs.discord.ulanziPlugin/.data/index.jsonThe file contains the local server port, an internal inspector token, encrypted Discord credentials and the ID of the authorized Discord account, used to limit automatic reconnects. The Client Secret uses AES-256-GCM with a key derived from the local machine and plugin UUID. This protects the file at rest from casual inspection, not from malware or another process running as the same user.
The plugin communicates with Discord Desktop over local IPC or the legacy localhost RPC fallback, and with discord.com during OAuth token exchange. Never publish a Client Secret in an issue, repository or screenshot.
The diagnostic log stays on the local computer. Since 0.1.5, it is capped at 5 MB with two rotated backups.
If the secret leaks
Reset it in the Developer Portal and use Change app in the settings panel.