Privacy Policy

Last updated 20 September 2026

Bond is a Discord bot that administers a server from a plain-language request.

1. Introduction

This policy says what reaches Bond ("we", "our", or "the Service"), what we store, who else sees any of it, and how to have it deleted.

2. Information we collect

Discord data. Bond receives your Discord user ID and username, the ID of the server it is used in, and the ID of the channel a request came from.

Bond uses the text of a message in three cases:

  • You mention Bond, or reply to one of its messages. That message is your request to it
  • An automation a server admin built reacts to messages in that server
  • A member asks Bond to read a channel they can already open. One read call returns at most 100 messages, and a channel the person asking cannot open is refused

Discord delivers every message in every channel Bond can see. Bond keeps nothing from a message, and sends nothing from it anywhere, unless one of those three cases applies to it. Nothing else opens a channel to Bond, and it cannot read a server it has not been added to.

Stored data. We store:

  • Your conversations with Bond, in Discord and in the dashboard, including what Bond read from the server to answer you
  • Memories Bond keeps about a server, and the instructions an admin writes for it
  • Automations: the flows and custom slash commands a server builds, and the data those automations write to their own stores
  • A log of recent automation runs, capped per automation and pruned as newer runs arrive. It can include the message that set a run off
  • Tool permissions you have granted per server
  • Server subscription status and token pack balances
  • Usage counts for allowances and rate limits, plus analytics events recording which features get used
  • Payment history, as transaction IDs rather than payment details
  • Images Bond generates, in object storage, and the prompt that made each one, shortened to 180 characters
  • Server logs of what Bond did, which we read to fix errors
  • Your Discord sign-in session, if you use the dashboard
  • A record that you ran /opt-out, that a direct message went out, and that Bond relayed a message for someone. None of those three holds any message text
  • If you connect ChatGPT, an encrypted OpenAI authorization credential, account email, plan type and selected model

3. How we use your information

  • To carry out your server management requests
  • To keep your permission preferences across sessions
  • To enforce weekly allowances and server safety limits
  • To take subscription payments through Polar.sh
  • To make Bond's answers better

We review conversations with Bond, with help from an AI model, to find and fix bugs. Those copies leave out the channel messages Bond read. The review files bug reports, and a bug report may quote what a member asked Bond.

We do not sell any of this, and we do not share it with advertisers or data brokers.

Bond also refuses to profile a member. It will summarize a channel, find what someone said on a topic, count who posted most, or show one member's posts so an admin can review their conduct. It will not write a personality profile, guess at someone's beliefs or private traits, or work out who is close to whom.

4. Third-party services

Bond sends data to these companies:

  • Discord, which the bot runs on
  • OpenRouter, which routes the requests Bond makes to the language model to answer you. Every one of those requests is limited to model hosts that do not train on what they receive. A host may keep a request for a short time to watch for abuse, under its own policy. We do not train any model on Discord data
  • Image generation, which is separate and which the no-training limit above does not cover, because we cannot yet confirm it for the hosts of these models. Bond generates pictures through OpenRouter (Google's Gemini 3 Pro Image and OpenAI's GPT Image 2), and, for age-restricted models, through Venice AI, Replicate and TAMS. An image prompt is written by Bond, in a run that may have read a channel first, so it can carry text drawn from messages
  • Tavily, which runs Bond's web searches. It receives the search query Bond writes, and nothing else
  • Anthropic, whose Claude model helps review conversations with Bond to find bugs, as section 3 describes
  • Polar.sh, for subscriptions and payments
  • OpenAI, if you turn on the optional ChatGPT connection: your prompts and the relevant conversation context go to OpenAI through Codex and count against your own ChatGPT allowance. If you connect your own ChatGPT account, OpenAI's retention and training settings for that account apply instead
  • Cloudflare, whose R2 storage holds the images Bond generates
  • Our hosting provider, for the server and the database

When Bond asks you to approve an action, it also sends your recent request text, the tool name and the action's details to a scoring model, under the same no-training limit. It never sends tool results, fetched messages or search results. We store the score beside your answer and use it to work out when Bond needs to ask at all.

5. Data retention

We keep what section 2 lists until it is deleted. The automation run log is the exception: it holds only recent runs and drops the rest as newer ones arrive.

Run /clear in a channel to delete your conversation with Bond in that channel, including what Bond read to answer you. It leaves your conversations in other channels alone, and it never touches anyone else's.

Remove Bond from a server and it stops receiving anything from that server. We keep that server's automations and settings so a re-invite restores them, so removal is not deletion. Ask us and we will delete them.

There is no delete-my-account button. Email contact@bondbot.gg and we will delete what you ask us to.

If you connect ChatGPT, we keep the encrypted authorization credential while the connection is off or your Bond plan is inactive, so you do not have to sign in again after resubscribing. Disconnecting ChatGPT deletes it.

6. Data security

The database listens on the server's loopback address only, so nothing on the network can reach it. The dashboard and the API are served over HTTPS. We encrypt a stored ChatGPT credential with AES-256-GCM before it reaches the database, under a key the database does not hold, and the decrypted copy lives only for the length of one request. The dashboard signs you in through Discord; our internal admin pages are limited to the bot's owner. No method of transmission over the internet is completely secure.

7. Your rights

You have the right to:

  • Ask for a copy of your stored data
  • Ask us to delete your data
  • Revoke tool permissions at any time with the /permissions commands
  • Remove Bond from your server, which stops it receiving anything from there, and ask us to delete what that server left behind
  • Disconnect ChatGPT at any time, which deletes the stored credential

Message content. Run /opt-out and Bond stops reading your messages for any AI request. Wherever Bond reads a channel after that, your messages arrive without their text, attachments or embeds. Bond also skips any write that would put that text in a log, a value in an automation's data store, a memory, or a run it has scheduled for later. Writes that do not carry your message text still happen: an automation can add one to a tally of your posts and keep your XP, your level and your name, because none of those is your message. Two things do not change. Rules an admin set up for the server still check your posts, so opting out is not a way around them. And Bond still reads a message where you mention it or reply to it, because that message is your own request.

/opt-out covers every server Bond is in, not just the one you run it in. Only you can undo it, with /opt-in. No admin, and no part of Bond, can opt you back in. Both commands work in a DM with Bond as well as in a server, and neither needs a Discord permission. Messages Bond read before you opted out stay in those conversations until they are cleared.

To exercise these rights, contact us at contact@bondbot.gg.

8. Children's privacy

Bond is for people aged 13 and over, or older where Discord sets a higher minimum. We do not knowingly collect information from children.

9. Changes to this policy

We may update this policy. We will tell users about significant changes through our Discord server, and we will update the date above.

10. Contact us

If you have questions about this policy, contact us at contact@bondbot.gg or join our Discord server.