---
title: "Privacy Policy"
description: "What Bond receives from Discord, what we store, who we send requests to, how long we keep any of it, and how to have it deleted."
canonical_url: "https://www.bondbot.gg/privacy"
last_updated: "2026-10-02"
---

# Privacy Policy

Last updated 2 October 2026

Bond is a Discord bot that administers a server from a plain-language request.

## 1. Introduction

This policy says what reaches Bond ("we", "our", or "the Service"), what we
store, who else sees any of it, and how to have it deleted.

## 2. Information we collect

Discord data. Bond receives your Discord user ID and username, the ID of the
server it is used in, and the ID of the channel a request came from.

Bond uses the text of a message in three cases:

- You mention Bond, or reply to one of its messages. That message is your
  request to it
- An automation a server admin built reacts to messages in that server
- A member asks Bond to read a channel they can already open. One read call
  returns at most 100 messages, and a channel the person asking cannot open is
  refused

Discord delivers every message in every channel Bond can see. Bond keeps nothing
from a message, and sends nothing from it anywhere, unless one of those three
cases applies to it. Nothing else opens a channel to Bond, and it cannot read a
server it has not been added to.

Stored data. We store:

- Your conversations with Bond, in Discord, in the dashboard and through an AI
  app you connected, including what Bond read from the server to answer you
- Memories Bond keeps about a server, and the instructions an admin writes for it
- Automations: the flows and custom slash commands a server builds, and the data
  those automations write to their own stores
- A log of recent automation runs, capped per automation and pruned as newer
  runs arrive. It can include the message that set a run off
- Tool permissions you have granted per server
- Server subscription status and token pack balances
- Usage counts for allowances and rate limits, plus analytics events recording
  which features get used
- When you click an install link on this website, the kind of site that sent
  you (a category such as a search engine, not the full address), the
  `utm_source` tag, which page you landed on and clicked from, and whether a
  browser or an automated tool made the click, without setting a cookie or
  storing anything in your browser
- Payment history, as transaction IDs rather than payment details
- Images Bond generates, in object storage, and the prompt that made each one,
  shortened to 180 characters
- Server logs of what Bond did, which we read to fix errors
- Your Discord sign-in session, if you use the dashboard
- A record that you ran `/opt-out`, that a direct message went out, and that
  Bond relayed a message for someone. None of those three holds any message text
- If you connect ChatGPT, an encrypted OpenAI authorization credential, account
  email, plan type and selected model
- If you connect an AI app to Bond's MCP server (Claude, ChatGPT or another
  MCP client): the app's name, what you allowed it to do, when you connected
  it and when it was last used, the list of your servers Discord gave Bond
  when you signed in, and the tokens Bond gave the app, stored only as hashes. For each call the app makes, a log row with your
  Discord ID, the server, the tool's name, the app and the outcome. That row
  holds no arguments, no results and no message text

## 3. How we use your information

- To carry out your server management requests
- To keep your permission preferences across sessions
- To enforce weekly allowances and server safety limits
- To take subscription payments through Polar.sh
- To make Bond's answers better

We review conversations with Bond, with help from an AI model, to find and fix
bugs. Those copies leave out the channel messages Bond read. The review files
bug reports, and a bug report may quote what a member asked Bond.

We do not sell any of this, and we do not share it with advertisers or data
brokers.

Bond also refuses to profile a member. It will summarize a channel, find what
someone said on a topic, count who posted most, or show one member's posts so an
admin can review their conduct. It will not write a personality profile, guess
at someone's beliefs or private traits, or work out who is close to whom.

## 4. Third-party services

Bond sends data to these companies:

- **Discord**, which the bot runs on
- **OpenAI and OpenRouter**, for the requests Bond makes to the language model
  to answer you. The model is OpenAI's, and each request goes either to OpenAI
  directly or through OpenRouter, which limits it to model hosts that do not
  train on what they receive. OpenAI does not train on what Bond sends it. A
  host may keep a request for a short time to watch for abuse, under its own
  policy; for OpenAI that is up to 30 days. We do not train any model on
  Discord data
- **Image generation**, which is separate and which the no-training limit above
  does not cover, because we cannot yet confirm it for the hosts of these
  models. Bond generates pictures through OpenRouter (Google's Gemini 3 Pro Image
  and OpenAI's GPT Image 2), and, for age-restricted models, through Venice AI,
  Replicate and TAMS. An image prompt is written by Bond, in a run that may have
  read a channel first, so it can carry text drawn from messages
- **Tavily**, which runs Bond's web searches. It receives the search query Bond
  writes, and nothing else
- **Anthropic**, whose Claude model helps review conversations with Bond to find
  bugs, as section 3 describes
- **Polar.sh**, for subscriptions and payments
- **OpenAI**, if you turn on the optional ChatGPT connection: your prompts and
  the relevant conversation context go to OpenAI through Codex and count against
  your own ChatGPT allowance. If you connect your own ChatGPT account, OpenAI's
  retention and training settings for that account apply instead
- **An AI app you connect**, if you connect one to Bond's MCP server. It
  receives what each tool it calls returns: what your own Discord permissions
  already let you see in that server, and Bond's own data for it. The app
  never gets your Discord token. What the app does with what it receives is
  under that app's privacy policy, not this one
- **Cloudflare**, whose R2 storage holds the images Bond generates
- **Our hosting provider**, for the server and the database

When Bond asks you to approve an action, it also sends your recent request text,
the tool name and the action's details to a scoring model, under the same
no-training limit. It never sends tool results, fetched messages or
search results. We store the score beside your answer and use it to work out
when Bond needs to ask at all.

## 5. Data retention

We keep what section 2 lists until it is deleted. The automation run log is the
exception: it holds only recent runs and drops the rest as newer ones arrive.

When Bond deletes or replaces a memory on its own, we keep a copy for
30 days so it can be restored. When you delete a
memory, it is gone at once.

Run `/clear` in a channel to delete your conversation with Bond in that
channel, including what Bond read to answer you. It leaves your conversations
in other channels alone, and it never touches anyone else's.

Remove Bond from a server and it stops receiving anything from that server. We
keep that server's automations and settings so a re-invite restores them, so
removal is not deletion. Ask us and we will delete them.

There is no delete-my-account button. Email
[contact@bondbot.gg](mailto:contact@bondbot.gg) and we will delete what you ask
us to.

If you connect ChatGPT, we keep the encrypted authorization credential while the
connection is off or your Bond plan is inactive, so you do not have to sign in
again after resubscribing. Disconnecting ChatGPT deletes it.

If you connect an AI app to Bond's MCP server, the log row for each call is
deleted after 30 days. Disconnect the app from
Connected apps in the dashboard and its access ends at once. We keep the
record of the connection, marked as ended, until you ask us to delete it.

## 6. Data security

The database listens on the server's loopback address only, so nothing on the
network can reach it. The dashboard and the API are served over HTTPS. We
encrypt a stored ChatGPT credential with AES-256-GCM before it reaches the
database, under a key the database does not hold, and the decrypted copy lives
only for the length of one request. The dashboard signs you in through Discord;
our internal admin pages are limited to the bot's owner. No method of
transmission over the internet is completely secure.

## 7. Your rights

You have the right to:

- Ask for a copy of your stored data
- Ask us to delete your data
- Revoke tool permissions at any time with the `/permissions` commands
- Remove Bond from your server, which stops it receiving anything from there,
  and ask us to delete what that server left behind
- Disconnect ChatGPT at any time, which deletes the stored credential
- Disconnect an AI app you connected to Bond at any time, from Connected apps
  in the dashboard

Message content. Run `/opt-out` and Bond stops reading your messages for any
AI request. Wherever Bond reads a channel after that, your messages arrive
without their text, attachments or embeds. Bond also skips any write that would
put that text in a log, a value in an automation's data store, a memory, or a
run it has scheduled for later. Writes that do not carry your message text
still happen: an automation can add one to a tally of your posts and keep your
XP, your level and your name, because none of those is your message. Two
things do not change. Rules an admin set up for the server still check your posts, so
opting out is not a way around them. And Bond still reads a message where you
mention it or reply to it, because that message is your own request.

`/opt-out` covers every server Bond is in, not just the one you run it in.
Only you can undo it, with `/opt-in`. No admin, and no part of Bond, can opt
you back in. Both commands work in a DM with Bond as well as in a server, and
neither needs a Discord permission. Messages Bond read before you opted out stay
in those conversations until they are cleared.

To exercise these rights, contact us at [contact@bondbot.gg](mailto:contact@bondbot.gg).

## 8. Children's privacy

Bond is for people aged 13 and over, or older where Discord sets a higher
minimum. We do not knowingly collect information from children.

## 9. Changes to this policy

We may update this policy. We will tell users about significant changes through
our Discord server, and we will update the date above.

## 10. Contact us

If you have questions about this policy, contact us at
[contact@bondbot.gg](mailto:contact@bondbot.gg) or join our
[Discord server](https://discord.gg/AgMTkZx9T5).
