The short version
Jarvis (the "bot" or "service") is a Discord app. We collect the minimum data needed to make the bot work. We don't sell your data, use it for marketing, or look at it for fun - but to make the bot work, your messages, supported command/context-menu inputs, and voice audio captured after someone explicitly runs /voice are sent to third-party AI providers. If a server enables voice-message transcription, audio attachments posted as Discord voice messages may also be sent for speech-to-text. /play by itself does not put Jarvis into listening mode.
Abuse-detection notice: Your stored memories may be read by automated abuse-prevention systems and processed by external tools that facilitate abuse detection. If you do not agree, run /opt out and discontinue use of Jarvis. Removing the bot from one server does not delete your memories or stop this processing while you keep using Jarvis elsewhere - only /opt out plus discontinuing use does that.
Controller & legal bases
The independent operator of the hosted Jarvis service ("we" or the "Jarvis operator") is the controller for personal data Jarvis processes outside Discord's own service. Jarvis is not affiliated with, sponsored by, or endorsed by Discord. You can contact the controller at dev@jorvis.org or through the support server linked below.
Depending on the feature and applicable law, we process data because it is necessary to provide the service you request; because we have legitimate interests in securing, debugging, rate-limiting, and improving the reliability of the service and preventing abuse; to comply with legal obligations; or with consent where consent is required for an optional feature or non-essential website analytics. You may object to processing based on legitimate interests and may withdraw consent at any time, without affecting processing that was lawful before withdrawal.
What we actually collect
- Message content - For AI chat, when you talk to Jarvis directly (mention him, reply to him, use a wake word, run a command, or use a context-menu action). Regular one-to-one AI chat DMs are disabled to prevent abuse, but some supported commands and context-menu actions may be available in Discord private, group, or user-install contexts. A few opt-in server features an admin can switch on do read messages or attachments in the channels they are scoped to - such as the counting game and voice-message transcription (see "Server engagement features"). Outside an active AI chat or those features, the bot does not read the surrounding channel.
- Conversation context - When message-content features are enabled and recent channel context is available, Jarvis reads a small recent window from the same channel before your message (currently up to 7 usable messages) to follow the live conversation. If you're replying to a specific message, he reads that one too and is told who wrote it, so he doesn't mistake their words - or his own - for yours. Messages from anyone who has opted out via
/opt outare skipped, whether they fall in that recent window or are the message you replied to. None of this context is stored as memory - it's fetched fresh each time and forgotten after he replies. - Voice transcriptions - Live voice chat starts only after someone explicitly runs
/voice./playor sharing a voice channel with Jarvis does not make him listen. Once/voiceis active, he only processes audio from opted-in users. In solo calls, Jarvis may process speech without a wake word for lower latency. In multi-user calls, he usually requires his name as a wake word, but may process short follow-up speech from the active speaker during an ongoing exchange. If a server enables voice-message transcription, Jarvis may download a Discord voice-message attachment, transcribe it, and post the transcript. Raw audio is not intentionally recorded or stored. It is processed live for speech-to-text and then discarded; resulting transcript text may be sent through the AI flow or posted as a transcript depending on the feature. - Conversation history ("memories") - Your messages, his replies, timestamps, and basic identifiers so the bot can remember who you are. These memories are tied to your account, not to any one server - they are stored per user and travel with you across every server you share with Jarvis, encrypted at rest. When you ask him something, he uses keyword matching to pull up the most relevant past conversations - not just the latest ones. This is how memory works without dumping the full channel into context.
- Tool and audit records - When an AI-selected server tool runs, we may store a limited audit record containing the action, actor ID, target IDs, source, outcome, guild ID, and timestamp for abuse prevention, debugging, rate limiting, and server-owner accountability. Auditable slash commands and tool actions may also post a redacted record to a server-configured audit channel. Stored and channel-posted audit records are deliberately redacted: they do not include prompt or message bodies, tool arguments, raw errors, tokens, or secrets. Stored tool records are limited to a rolling 100 records per server and expire after 30 days. Discord audit-channel copies remain subject to that server's Discord retention and deletion controls. Sensitive tools remain permission-gated.
- GIF and media data - GIF lookup may use URLs previously posted by Discord users, Klipy, Tenor, GIPHY, or search providers. We may store GIF URLs that users voluntarily post so the bot can reuse organic GIFs later. We do not pre-review every third-party GIF, and those URLs can expire, be deleted, or point to third-party content we do not control.
- Portal login data - If you sign in to the web portal with Discord OAuth, we store your Discord user ID, username, global display name, avatar hash, OAuth access token, OAuth refresh token, token expiry, session ID, and session timestamps so the portal can identify you and show servers you can manage. The portal requests the Discord
identifyandguildsscopes. - Server safety snapshots - For anti-abuse, recovery, and owner-accountability features, Jarvis may store server identity, channel and role metadata, permission overwrites, emoji/sticker metadata, webhook metadata, invite metadata, AutoMod metadata, scheduled-event metadata, selected rules/system/announcement channel messages, member metadata, and role membership. This depends on bot permissions and enabled security features.
- Operational metadata - Usage logs, event data, and reliability signals. Subject to TTL.
- Abuse-prevention counters - Per-server and per-user request counts and AI token totals, kept solely to ensure the service stays functional for everyone. We don't review your messages here - we count requests. Auto-deleted after 30 days.
- Member data - Only for status channels. Not retained beyond what the feature needs.
What we do with it
Exactly what you'd expect:
- Send your message to a third-party AI provider to generate a response (see "Third-party services" below for who and how).
- Keep conversation memory so context persists between sessions - per user and across every server you use the bot in, surfaced by keyword relevance, not just recency.
- Handle real-time voice processing - hearing you, talking back. Voice audio is sent to NVIDIA NIM for transcription and synthesis.
- Run AutoMod, stats, and other server-management features.
- Log and audit AI tool calls so we can investigate abuse, permission bypass attempts, spam, and unsafe automation.
- Operate the web portal, validate server access, and keep portal sessions secure.
- Maintain server safety snapshots for abuse investigation, recovery, and owner accountability.
- Keep the service running and prevent abuse.
Data protection
We store only what is required for functionality and safety, with strict retention limits and access controls. Stored data is encrypted at rest in the hosted service. Decryption only happens when Jarvis actually needs it to reply to you or when automated abuse-detection systems flag a record for review. When a message is sent to a third-party AI provider for processing, it leaves our system; at that point, the provider's own security and data practices apply, governed by the policies we link below. We do not train or fine-tune AI models on Discord message content.
Retention & deletion
Conversation memory data is retained for 30 days. To remove it sooner, run /opt out - this immediately purges stored conversation memories across every server and stops future memory retention, with no support ticket required. /clear resets your current conversation context. Because memories are tied to your account rather than a server, an /opt out wipe applies everywhere you use Jarvis at once.
Abuse-prevention counters (per-server and per-user request and token totals) are kept for the same 30-day window and then auto-deleted. They exist only to keep the service functional for all users.
Stored tool and audit records use a rolling limit of 100 records per server and a 30-day expiry. Redacted copies posted to a server's configured Discord audit channel are Discord messages controlled by that server and remain until Discord or an authorized server member deletes them.
Portal sessions expire automatically, and logging out deletes the current session cookie and server-side session record. Operational, abuse-prevention, and server-safety records may remain until their retention windows expire. If you want broader deletion beyond conversation memories, contact us.
Third-party services & transfers
Jarvis operates on Discord. Your Discord account, server membership, messages, attachments, and interactions are also governed by Discord's Terms of Service, Privacy Policy, Community Guidelines, Developer Terms, and Developer Policy.
Depending on availability and the requested feature, Jarvis may route AI data to NVIDIA, Mistral AI, Google Gemini, OpenAI, or DeepSeek. Ollama may run open-weight models on infrastructure controlled by the Jarvis operator, in which case the request is not disclosed to Ollama merely because its software is used; if an Ollama-hosted endpoint is configured, Ollama's own terms apply. Each external provider processes data under its own terms and privacy policy. We configure services to minimize retention and provider training where those controls are available, but we cannot replace or override a provider's published terms.
Voice features use NVIDIA NIM for speech-to-text and text-to-speech. Audio is transmitted securely to NVIDIA for processing.
Cloudflare may provide network, security, caching, and website-analytics infrastructure, but is not used as an AI model provider. Providers and infrastructure may process data outside your country, including in countries that may not offer equivalent legal protection. Where required, transfers are based on an adequacy decision, approved standard contractual clauses, or another lawful transfer mechanism. Contact us to ask about the mechanism relevant to your data.
GIF and media features may use Klipy, Tenor, GIPHY, or URLs previously posted by Discord users. GIF queries and selected URLs may be sent to those services, and resulting media is governed by their own terms, availability, moderation, and privacy practices.
Relevant privacy policies: NVIDIA · Mistral AI · Google · OpenAI · DeepSeek · Ollama · Cloudflare · Klipy · Tenor · GIPHY
Website analytics & cookies
The website always uses strictly necessary security and portal-session mechanisms when you sign in. Depending on deployment configuration, public pages may also load either Cloudflare Web Analytics or Google Analytics - not both through Jarvis's built-in configuration. These services may receive your IP address, user agent, device and browser information, referring page, pages visited, and timestamps. Google Analytics may use cookies or similar browser storage; Cloudflare describes its Web Analytics product as privacy-focused and may process request metadata at its network edge. You can block non-essential analytics through browser or network controls. Where applicable law requires consent, non-essential analytics must be enabled only after that consent is obtained.
Your rights
Depending on where you live, you may have the right to ask for access to, correction of, or deletion of your personal data; restriction of processing; data portability; and information about how your data is used and shared. You may object to processing based on legitimate interests and withdraw consent where processing relies on consent. You also have the right to complain to your local data-protection authority. These rights may be limited where an exemption applies, and we may need to verify your identity before acting on a request.
- Delete stored conversation memories with
/opt out- it wipes your memories across every server at once, since they are tied to your account rather than any one server. (Data already sent to AI providers is subject to their own retention policies.) - Delete portal sessions by logging out or using logout-all where available.
- Remove the bot from a server to stop further collection there. Note this does not by itself delete your personal memories, which are account-scoped; use
/opt outfor that. - Contact us with questions or deletion requests covering other retained operational records.
Jarvis does not use personal data to make decisions intended to produce legal or similarly significant effects. Some permission-gated moderation tools can affect access to a Discord server; ask that server's moderators or contact us if you want a disputed bot action reviewed.
Server engagement features
Some optional server features store a small amount of data scoped to that one server - not to your account-level memory. A server admin can turn any of these off with /features, and all of it is permanently deleted when Jarvis is removed from the server. None of it is sold, used for marketing, or shared beyond what the feature needs.
- Leveling - if a server enables it, Jarvis counts how many messages you send in that server and awards activity XP and a level (shown via
/rankand/leaderboard). We store your XP, level, and message count per server. We do not store the content of those messages - only that a message happened, plus a one-minute anti-spam timestamp. This is separate from the Stark Bucks economy, and a server admin can reset it at any time. - Starboard - if a server enables it, when a message collects enough star reactions Jarvis reposts it to a highlights channel. We store a small mapping - the original message's ID, the starboard copy's ID, and the current star count - so the highlight stays up to date. The highlight is rendered live from the original message; we do not store the message's text in our database.
- Giveaways - if you click "Enter" on a giveaway, we store your user ID on that giveaway's entrant list so we can draw a winner and stop you entering twice. The list is deleted with the giveaway.
- Tickets - if a server uses ticket support, opening one creates a private thread; we store the thread ID, your user ID (as the opener), and whether it is open or closed. When a ticket is closed, staff may save a text transcript to a staff-only log channel they configured. Ticket records are deleted when Jarvis leaves the server.
- Birthdays - entirely optional. If you run
/birthday setwe store the month and day you provide and your user ID - never the year. It is used to post a birthday greeting (and optionally grant a temporary role for the day) in the server you set it in. Remove it any time with/birthday clear. - Counting - if a server runs the counting game, we store the current number, the ID of the last person who counted (to stop one person counting twice in a row), and the record. This is one of the few features that reads messages in a normal channel, and it is limited to the single counting channel an admin designates. It requires the operator to enable Discord's Message Content intent.
When Jarvis leaves a server
If Jarvis is removed from a server, we retain removal-scoped server metadata and safety records for 30 days to investigate abuse, support recovery, and protect other servers. This may include name, ID, icon, member count, aggregated request/token counters, server configuration, channel/role/permission metadata, AutoMod metadata, invite or webhook metadata, scheduled-event metadata, selected rules/system/announcement messages, and member/role metadata. After 30 days, this data is deleted. The server's own config is no longer active. Your personal memories are account-scoped, so removing the bot from one server does not delete them. To erase your memories everywhere at once, run /opt out.
Contact & complaints
Send privacy requests to the Jarvis operator at the email below. Include your Discord user ID and the request you want us to handle; do not send passwords, tokens, or unnecessary message content. If you are in the EEA, UK, or another jurisdiction with a data-protection regulator, you may also complain directly to the supervisory authority where you live or work.
Discord: https://discord.com/invite/ksXzuBtmK5
Email: dev@jorvis.org