The referenced write-up based on the Persona front end code is here: https://vmfunc.re/blog/persona I definitely recommend reading this primary source before drawing conclusions about the code as most of the secondary reporting is quite low quality.
I read it and, maybe it’s because I’ve spent too much time in fintech, I don’t share most of the concerns. The differences in proclaimed data retention periods is concerning though. The rest is par for the course for KYC/AML.
My takeaway was that in this case, even an author with a clear and extreme bias against this sort of thing could find only unfortunately-common bad practices rather than deeply nefarious intent. Of course, this is just the front-end code, but this just looks like a KYC platform to me. Most of the secondary reports on this write-up seem to completely ignore section 0x13 and jump to the specific conclusions the author does not draw.
The fact that we've created a system where Discord need and want a KYC platform is a different and quite strange thing, but the KYC platform itself just looks like what it says on the tin.