Privacy policy
What Jambot records before it talks, researches, builds, or verifies.
Jambot separates ordinary server tools from AI and search. AI and DuckDuckGo research require a global acknowledgement that explains the private logging behavior first.
Effective and last updated: August 17, 2026
1. Scope
This policy covers the Jambot Discord bot, GrandJam AI and Deep Work, Jambot AI DMs, DuckDuckGo search, generated AI attachments, support tickets, the public website, and the member-verification service. Discord server administrators may also have their own rules and Discord logging outside Jambot.
2. GrandJam acknowledgement
- Before Jambot uses AI or DuckDuckGo search for a user, the user must acknowledge the Jambot privacy notice.
- The acknowledgement is stored by Discord user ID and applies across servers and DMs.
/privacyshows the current state and allows the user to change it.- Passive or random GrandJam observation does not send an unacknowledged user's message to the AI provider or central audit server.
- The notice tells users not to send passwords, tokens, private keys, or other secrets.
3. AI, file, DM, and search records
| Data | Why Jambot uses it | Where or how long |
|---|---|---|
| AI server messages | User identity, server and channel, the message sent to GrandJam, Jambot's answer, token count when available, and provider or model label are recorded for debugging, abuse review, and moderation. | Sent to the private ai-server-messages channel in the configured Jambot record server. The current bot does not implement automatic expiry for these Discord audit messages. |
| Generated AI files | When GrandJam attaches generated project files to an answer, the same generated attachments can be copied to the private AI audit message so the logged record matches what the user received. | Stored as Discord attachments in the relevant private AI record channel, subject to Discord and server retention. |
| AI DMs | DM prompts and Jambot answers are recorded under the same acknowledged logging rule. | Sent to the private ai-dms channel. Normal DM usage is also counted per user and UTC date for the daily limit. |
| DuckDuckGo search | The query plus returned result titles and URLs are recorded so acknowledged search use can be reviewed. | Sent to the private search-logs channel. Search uses the bot's configured safe-search behavior. |
| Suspicious and system events | Clearly action-oriented abusive AI requests, GrandJam grants, DM rewards, AI errors, and administrative activity may be recorded for moderation and debugging. | Private suspicious-users and system-audit channels, plus relevant Firestore records. AI suspicious-request logging by itself does not automatically punish the user. |
| Privacy acknowledgement | Remember whether the user accepted or revoked the AI and search notice. | Firestore record keyed by Discord user ID until changed or deleted. |
4. AI providers and Deep Work
When GrandJam answers, the prompt and conversation context needed for the request are sent to the configured AI provider. Deep Work may perform multiple provider calls for planning, an optional first build, review or final generation, and file repackaging. If web research is used, the returned search context can also be included in those model calls.
Jambot can use Cloudflare Workers AI and Groq with failover and can be configured to prefer separate extended models for Deep Work. Provider services process requests under their own terms and operational logging. Jambot does not place provider API credentials in public Discord messages or saved AI error details.
Visible Deep Work updates contain only high-level statuses and plan summaries. The bot is designed not to publish hidden chain-of-thought.
5. AI DM limits
Normal acknowledged users can use up to five Jambot AI DMs per UTC day. A per-day Firestore counter enforces the limit. Jambot admins and users specifically rewarded by a Jambot admin can bypass that daily limit until the reward is removed.
6. Tickets
Ticket channels are created inside the participating Discord server. The ticket opener, selected support roles, and Jambot receive channel access. The configured support roles can be pinged when a ticket opens. Servers may optionally keep ticket open and close logs in a configured Discord channel. Closing a ticket deletes the ticket channel after confirmation, subject to Discord's own retention and audit behavior.
7. Verification and website data
Verification remains separate from GrandJam. Discord user and guild IDs are bound when the verification request is created. The website does not request Discord OAuth access or a Discord password. Short-lived request status, timestamps, Turnstile results, network-derived security information, and keyed network hashes may be processed for verification, anti-abuse, and website visit counting as described by the deployed verification code.
The raw network address is used during a request but the application database uses keyed hashes for the visit cooldown and network reputation records. Hosting providers may retain their own operational logs.
8. Server-local moderation data
Warnings, active mutes, user history, settings, verification configuration, raid-protection configuration, and backups are stored under the relevant Discord guild ID. Those ordinary moderation and backup features remain guild-scoped. The separate Jambot record server is used for the acknowledged GrandJam, search, attachment, and central audit categories described above.
9. Advertising
Google AdSense ownership code is present on selected public content pages. If advertising is enabled, Google may receive ordinary request, device, cookie or local-storage, consent, and ad-interaction information under Google's own policies. Jambot does not sell personal information.
10. Choices and questions
Use /privacy to review or change the Jambot AI and search acknowledgement. Server administrators control their own Jambot configuration and can contact official support for operational questions. Never place a password, bot token, private key, API key, or active verification secret into an AI prompt, support ticket, public message, or bug report.