1. Scope

This policy covers the Jambot Discord bot, GrandJam AI and Deep Work, Jambot AI DMs, DuckDuckGo search, generated AI attachments, support tickets, the public website, and the member-verification service. Discord server administrators may also have their own rules and Discord logging outside Jambot.

2. GrandJam acknowledgement

3. AI, file, DM, and search records

GrandJam and search records
DataWhy Jambot uses itWhere or how long
AI server messagesUser identity, server and channel, the message sent to GrandJam, Jambot's answer, token count when available, and provider or model label are recorded for debugging, abuse review, and moderation.Sent to the private ai-server-messages channel in the configured Jambot record server. The current bot does not implement automatic expiry for these Discord audit messages.
Generated AI filesWhen GrandJam attaches generated project files to an answer, the same generated attachments can be copied to the private AI audit message so the logged record matches what the user received.Stored as Discord attachments in the relevant private AI record channel, subject to Discord and server retention.
AI DMsDM prompts and Jambot answers are recorded under the same acknowledged logging rule.Sent to the private ai-dms channel. Normal DM usage is also counted per user and UTC date for the daily limit.
DuckDuckGo searchThe query plus returned result titles and URLs are recorded so acknowledged search use can be reviewed.Sent to the private search-logs channel. Search uses the bot's configured safe-search behavior.
Suspicious and system eventsClearly action-oriented abusive AI requests, GrandJam grants, DM rewards, AI errors, and administrative activity may be recorded for moderation and debugging.Private suspicious-users and system-audit channels, plus relevant Firestore records. AI suspicious-request logging by itself does not automatically punish the user.
Privacy acknowledgementRemember whether the user accepted or revoked the AI and search notice.Firestore record keyed by Discord user ID until changed or deleted.

4. AI providers and Deep Work

When GrandJam answers, the prompt and conversation context needed for the request are sent to the configured AI provider. Deep Work may perform multiple provider calls for planning, an optional first build, review or final generation, and file repackaging. If web research is used, the returned search context can also be included in those model calls.

Jambot can use Cloudflare Workers AI and Groq with failover and can be configured to prefer separate extended models for Deep Work. Provider services process requests under their own terms and operational logging. Jambot does not place provider API credentials in public Discord messages or saved AI error details.

Visible Deep Work updates contain only high-level statuses and plan summaries. The bot is designed not to publish hidden chain-of-thought.

5. AI DM limits

Normal acknowledged users can use up to five Jambot AI DMs per UTC day. A per-day Firestore counter enforces the limit. Jambot admins and users specifically rewarded by a Jambot admin can bypass that daily limit until the reward is removed.

6. Tickets

Ticket channels are created inside the participating Discord server. The ticket opener, selected support roles, and Jambot receive channel access. The configured support roles can be pinged when a ticket opens. Servers may optionally keep ticket open and close logs in a configured Discord channel. Closing a ticket deletes the ticket channel after confirmation, subject to Discord's own retention and audit behavior.

7. Verification and website data

Verification remains separate from GrandJam. Discord user and guild IDs are bound when the verification request is created. The website does not request Discord OAuth access or a Discord password. Short-lived request status, timestamps, Turnstile results, network-derived security information, and keyed network hashes may be processed for verification, anti-abuse, and website visit counting as described by the deployed verification code.

The raw network address is used during a request but the application database uses keyed hashes for the visit cooldown and network reputation records. Hosting providers may retain their own operational logs.

8. Server-local moderation data

Warnings, active mutes, user history, settings, verification configuration, raid-protection configuration, and backups are stored under the relevant Discord guild ID. Those ordinary moderation and backup features remain guild-scoped. The separate Jambot record server is used for the acknowledged GrandJam, search, attachment, and central audit categories described above.

9. Advertising

Google AdSense ownership code is present on selected public content pages. If advertising is enabled, Google may receive ordinary request, device, cookie or local-storage, consent, and ad-interaction information under Google's own policies. Jambot does not sell personal information.

10. Choices and questions

Use /privacy to review or change the Jambot AI and search acknowledgement. Server administrators control their own Jambot configuration and can contact official support for operational questions. Never place a password, bot token, private key, API key, or active verification secret into an AI prompt, support ticket, public message, or bug report.