1. Introduction
This Privacy Policy describes how MonkeyBot ("the Bot", "the Service"), operated by MonkeyBot ("we", "us", "our"), collects, uses, stores, and shares information when you interact with the Bot through Discord.
By using MonkeyBot, you consent to the data practices described in this policy.
2. Information We Collect
2.1 Information You Provide
- Messages you send to the Bot: The text content of commands and prompts you submit (your "Input").
- Images you attach: If you attach images to commands that support them (such as
,ape or ,aper), those images are processed but not permanently stored.
2.2 Payment Information
If you purchase a subscription, payment is processed by Stripe, Inc. We do not directly collect or store your full credit card number. Stripe collects and processes your payment information under their own privacy policy. We receive and store:
- Your email address (provided during checkout).
- Stripe customer and subscription identifiers.
- Payment status and billing cycle information.
- Whether your subscription is active, past due, or canceled.
2.3 Information Collected Automatically
- Discord User ID: Your unique Discord identifier.
- Discord Username: Your Discord display name.
- Server (Guild) ID: The Discord server where you use the Bot.
- Command Usage Data: Which commands you use and when.
- Token Usage: The number of AI tokens consumed by your requests and the estimated cost per request.
- Image/Video/Search Counts: How many images, videos, and live searches you have used (for daily and monthly limit tracking).
- Model Preference: Which AI model you have selected as your default.
- Moderation Flags: If your content is flagged by our automated moderation system, the category and flagged content are logged.
3. How We Use Your Information
We use the information we collect to:
- Provide the Service: Process your commands, send your Input to AI providers, and return Output to you.
- Maintain Conversation History: Store recent conversation messages to provide context for follow-up interactions. Conversations are automatically deleted after 20 minutes of inactivity.
- Enforce Usage Limits: Track daily and monthly usage of image generation, video generation, and live search features.
- Track Costs: Log per-request API costs for operational and billing purposes.
- Monitor for Abuse: Identify and prevent violations of our Terms of Service and Acceptable Use Policy through automated content moderation.
- Enforce Moderation: Issue warnings, strikes, temporary suspensions, and permanent bans for policy violations.
- Improve the Service: Understand usage patterns to improve bot functionality.
4. Third-Party Data Sharing
Your messages (Input) are sent to third-party AI service providers for processing. This is essential to how the Service works.
| Provider | Service | What Is Shared |
|---|
| xAI | Grok (chat, search, image gen, video gen) | Message text, conversation history, attached images |
| Anthropic | Claude (chat) | Message text, conversation history, attached images |
| OpenAI | ChatGPT (chat) and content moderation | Message text, conversation history, attached images |
| Google | Gemini (chat) | Message text, conversation history, attached images |
| Stripe | Payment processing | Email address, payment method details, billing information |
Each provider processes your data under their own terms and privacy policies. Under our agreements with these providers, your Input submitted through the API is not used to train their AI models.
We also use OpenAI's Moderation API to check messages for content policy violations before they are sent to any AI provider. This means your message text is sent to OpenAI for moderation purposes regardless of which AI model you are using.
We do not sell your personal information to third parties.
We may share information with law enforcement or government authorities if required by law or if we reasonably believe it is necessary to prevent harm or address violations of law.
5. Data Retention
- Conversation History: Automatically deleted after 20 minutes of inactivity. You can also manually clear your history using the
,apec command. - Daily Usage Counts: Per-user daily usage counts (images, videos, searches) reset every 24 hours.
- Monthly Usage Counts: Per-server monthly usage counts reset on a 30-day rolling window.
- User Records: Your Discord User ID, username, and model preference are retained as long as your account exists. You may request deletion at any time (see Section 8).
- Cost Tracking: Per-request cost data (model, token counts, estimated cost) is retained for operational and billing purposes.
- Moderation Records: Strike history and ban records are retained to enforce our content policies.
- Message Logs: An audit log of messages sent to the bot is retained for abuse prevention and compliance purposes.
6. Data Security
We use reasonable administrative, technical, and physical safeguards to protect your information. These include:
- Database access restricted to authorized personnel only.
- Encrypted connections (HTTPS/TLS) to AI provider APIs.
- Environment variables used for all API keys and credentials (not hardcoded).
- SSRF protection on image URL fetching to prevent server-side request forgery.
- PII detection that blocks sensitive data (credit cards, SSNs, etc.) before it reaches any AI provider.
Your data is stored on servers located in the United States. By using the Service, you consent to the transfer and storage of your data in the United States.
No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
7. Children's Privacy
MonkeyBot is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will take steps to delete such information.
If you are between 13 and the age of majority in your jurisdiction, you may only use the Service with the consent of a parent or legal guardian.
8. Your Rights
You have the following rights regarding your data:
- Access: You may request information about what data we hold about you.
- Deletion: You may request deletion of your data by contacting us (see Section 11). You can also clear your conversation history using the
,apec command. - Correction: You may request correction of inaccurate data.
- Portability: You may request a copy of your data in a portable format.
To exercise these rights, contact us using the information in Section 11. We will respond to requests within 30 days.
Depending on your jurisdiction, you may have additional rights under applicable privacy laws (such as GDPR, CCPA/CPRA, or LGPD). We will comply with all applicable privacy laws.
9. Cookies & Tracking
The MonkeyBot Discord bot does not use cookies. Our website at monkeybot.app uses the following cookies:
- Session cookies (httpOnly, Secure): Used to maintain your login state, checkout flow, and subscription management sessions. Expire within 30 minutes to 7 days depending on type.
- Authentication cookies (httpOnly, Secure): Used to keep you logged in after connecting your Discord account. Expires after 7 days.
We do not use advertising cookies, third-party tracking cookies, or analytics cookies. We do not serve ads.
10. Changes to This Policy
We may update this Privacy Policy at any time. Material changes will be communicated through our website or Discord. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
11. Contact
For questions about this Privacy Policy or to exercise your data rights, contact us at:
- Email: support@monkeybot.app
- Website: monkeybot.app