Skip to contentApplyDesk

2026-09-20

How to run a Discord whitelist application that does not leak

Whitelist and member-vetting forms for Minecraft, roleplay, and gated Discord servers: what to ask, what to hide, and how to review without doxxing people.

Identifiers you can check. Nothing you cannot protect.

A whitelist is not a staff hire, but it is still vetting. Minecraft, roleplay, and invite-only Discords collect in-game names, lore samples, and sometimes age. The leak risk is the same: a public Google Form, a Sheet with everyone’s Minecraft username, and a rejected player with a grudge.

Ask for identifiers you can check

  • Discord login so the whitelist is bound to an account, not a typed tag.
  • In-game name and a screenshot or UUID you can verify, not a story about how long they have played.
  • A short sample of how they actually play or write — one scene, not a novel.
  • Account age if you are tired of week-old accounts farming kits.

Do not collect what you will not protect

A public Form plus a Sheet is how names leak.

Real names, voice intro videos, and government IDs show up on some “serious RP” forms. If you are not a business with a retention policy, do not ask. Age is only justified if the community is 18+ and you will refuse underage applicants. “How old are you?” as flavour is how you accidentally store children’s data.

Keep rejects out of the member list

The apply link can be public. The answers cannot. Review in a queue your staff can open, not in a channel that scrolls. When you approve, the bot can add the whitelist role. When you reject, a short reason in Discord is enough — do not paste their lore into general.

If someone should never apply again, that belongs on a ban list, not in a staff member’s memory. Whitelist drama repeats; your process should not.

Run this on ApplyDesk
Copy is fine for a one-off. A queue, Discord login, and a bot that assigns the role is how you stop losing applications in staff chat.