1. The short version
Summary Bot never persists Discord message content. Transcripts are held in memory for the active request, sent to the selected AI provider to produce the result, and then discarded by Summary Bot.
- Before reading, Summary Bot checks that the requester can access the channel.
- Public recaps use only sources visible to the whole audience that will receive them.
- The database stores settings, identifiers needed to operate the app, entitlements, and usage counts—not transcripts, questions, prompts, or generated message content.
- Members can exclude their messages from summaries and can delete the identifiable profile data Summary Bot holds about them.
- Server admins can make a channel off limits to everyone, including themselves.
2. Scope and roles
This policy covers the Summary Bot Discord application (the “Bot”) and the public website at trysummarybot.com (the “Site”). “Summary Bot,” “we,” and “us” refer to the operator of those services.
Discord independently controls the Discord platform, accounts, messages, purchases, and platform-level logs. Your use of Discord is also governed by Discord’s Privacy Policy. A Discord server’s owner and administrators choose whether to install the Bot and configure server-level privacy settings.
3. How message content is processed
When content is read
Summary Bot reads messages when a member asks it to perform an action such as a catch-up, cited question, recast, mention-agent turn, scheduled recap, live summary, or welcome summary. It does not build a permanent archive of channel messages.
Permission and privacy filtering
The Bot verifies Discord access before fetching content. It excludes channels blocked by server administrators and removes messages from members who opted out before a transcript is sent to an AI provider. For a public recap, it narrows source channels to those visible to the full intended audience.
AI processing
The temporary transcript, the instruction needed to perform the requested feature, and relevant conversation context are transmitted to either OpenAI or Anthropic to generate a response. The result is returned to Discord. Those providers process data under their own terms and privacy policies; their practices are not controlled by Summary Bot.
If a member saves a personal OpenAI or Anthropic API key, the key may be used for that member’s overage requests after server credits run out. A saved key never changes Discord permissions or the server’s plan.
4. Data we store
Summary Bot stores only the data needed to operate the service, honor preferences, enforce plans, account for credits, prevent abuse, and diagnose failures. Depending on how the Bot is used, this can include:
- Discord identifiers and basic profile fields: user, server, channel, role, and command-related identifiers; server names; and user or display names needed for app behavior.
- Configuration: setup status, allowed or blocked channels, admin-only restrictions, schedules, live-summary settings, orientation settings, saved presets, and member opt-outs.
- Purchases and entitlements: the server’s Discord subscription entitlement, plan period, credit balance, and top-up accounting.
- Usage and safety records: bounded counts of actions, messages read, credits spent, provider token classes, errors, and anti-abuse counters.
- Optional API keys: a member’s saved provider key, stored in encrypted form for later use.
- Operational logs: stable command names, bounded failure codes, performance information, and trace identifiers used to operate and troubleshoot the service.
We do not store Discord transcripts, message bodies, /ask questions, raw prompts, generated summaries, or derived message content in the application database or product analytics.
5. How stored data is used
We use the data described above to:
- perform commands and deliver scheduled, live, and welcome summaries;
- apply Discord permissions, member opt-outs, and server privacy settings;
- remember catch-up progress and product preferences;
- recognize subscriptions and top-ups, meter credits, and enforce published limits;
- protect the service and providers from abusive or unexpectedly costly use;
- monitor reliability, investigate errors, and improve aggregate product behavior; and
- comply with applicable legal obligations and enforce the Terms of Service.
We do not sell personal data, use Discord message content for advertising, or build individual activity rankings.
6. Service providers
Summary Bot depends on a small number of providers that process data for their respective functions:
- Discord hosts the platform, delivers interactions and messages, supplies permissions, and handles Premium App purchases.
- OpenAI and Anthropic process temporary prompts and conversation context when their models are selected for an AI action.
- Google Cloud supplies production infrastructure, operational monitoring, and encrypted database backup storage.
- Vercel hosts this public website and may process ordinary request and security metadata when the Site is visited.
We may disclose information when required by law, to protect rights or safety, or in connection with a service transfer. We do not give providers more data than is reasonably needed for their function.
7. Retention and deletion
Message transcripts and generated content are not persisted by Summary Bot. Other data is retained according to its operational purpose:
- Current profiles, settings, schedules, opt-outs, entitlements, credit balances, and daily usage aggregates remain while needed to provide the service or until they are deleted through the controls below.
- Raw usage events are partitioned by month. They are normally retained for up to six months and may be removed sooner as the database approaches its storage limit. Durable aggregate counts remain until deletion.
- Short-lived spend, refusal, and per-member credit ledgers are pruned after their reporting or safety window. Today’s anti-abuse count lasts until its daily reset.
- Operational logs and monitoring data follow the configured retention periods of the hosting and monitoring systems.
- Deleted database records may remain in encrypted backups until those backups rotate out of their lifecycle.
Messages and bot responses posted in Discord are retained by Discord according to the server’s actions and Discord’s policies. Deleting a Summary Bot profile does not delete content already posted to Discord.
8. Your privacy controls
Controls for every member
- /privacy info explains current behavior inside Discord.
- /privacy optout excludes your messages from every summary in that server.
- /privacy welcome stops or resumes welcome summaries globally for your Discord profile.
- /privacy forget deletes your profile, saved API key, presets, opt-outs, schedules you own, memberships, and identifiable usage history across every server where the Bot is installed.
After /privacy forget, only the current day’s bounded per-member credit count remains until its daily reset so profile recreation cannot bypass the server safeguard. A paid balance belongs to the Discord server, not an individual profile.
Controls for server administrators
- /privacy channel can block a channel for everyone, including server administrators.
- /privacy restrict can require the Manage Server permission for every summary in that server.
- Removing the Bot stops future processing in that server. Discord content already posted remains governed by Discord and the server.
For an access or deletion request that cannot be completed through Discord commands, contact us through the Summary Bot support server. We may need to verify control of the relevant Discord account.
9. Security
We use technical and organizational safeguards appropriate to the service, including permission checks before message access, encryption for saved provider keys, bounded analytics labels, restricted production access, database backups, and confirmation before mention-agent tools perform a write.
No system can guarantee absolute security. If you believe you found a vulnerability or data incident, report it privately through the support server and avoid posting sensitive details publicly.
10. Website data
The public Site is static. It does not provide user accounts, run advertising trackers, or set application analytics cookies. The hosting provider may collect standard request information such as IP address, user agent, requested URL, timestamps, and security events to deliver and protect the Site.
Links to Discord and other providers take you to services governed by their own policies.
11. Age requirements
Summary Bot is intended only for people old enough to use Discord in their country. Discord requires users to be at least 13 in most countries and sets a higher minimum in some locations. If you are not permitted to use Discord, you may not use Summary Bot.
12. Changes and contact
We may update this policy as the service, providers, or legal requirements change. Material updates will be posted here with a revised effective date. Continued use after an update means the revised policy applies going forward.
Questions, privacy requests, and security reports can be sent through the Summary Bot support server. Please do not include message content, API keys, or other secrets in a public channel.