LegalPrivacy Policy
This policy explains what the Lumo Discord bot (“Lumo”, “the bot”) collects, why, where it is kept, who it is shared with, and how to get it deleted. Lumo is run by Ori, an individual developer (“I”, “me”). You can reach me through my Discord profile. Also see the Terms of Service.
The short version
- Lumo reads messages in the channels it can see so it can reply and follow the conversation. In servers with Premium, and in channels where the server has not switched the AI off, it keeps the most recent 150 messages per channel (the first 280 characters of each) for up to 3 days, then deletes them. In servers without Premium it does not keep message text. If you delete a message on Discord, Lumo deletes its saved copy too.
- When you talk to Lumo or speak to it in a voice channel, your words, images and audio are sent to xAI (the company behind Grok) to produce the answer.
- Lumo Coin wallets, activity stats (message counts, voice time, XP) and server settings are kept until they are deleted.
- Lumo does not record or save voice audio.
- The bot never asks for or stores payment details. Premium is paid through Ko-fi, which shares your name, email, the amount and any message with me. Ko-fi payment info such as your email is used only to deliver Premium and is stored hashed, never in plain text. The bot only keeps a small Premium record for each server.
- I don’t sell your data, use it for advertising, or train AI models on it.
- The server owner can run
/forgetmeto erase the saved messages, conversation memory and activity stats for their server. For anything else, message me on Discord and I will delete your data.
1. What Lumo collects
Lumo only works inside Discord servers. It does not ask for passwords, email addresses or payment details, and it has no login. Premium is paid for outside the bot, through Ko-fi (see Premium payments).
Messages in channels it can see
Lumo uses Discord’s message content access. In servers where the AI is active (servers with Premium, in channels the server has not switched off in the dashboard’s AI channels page), for each message posted in a channel it can read (whether or not the message is for Lumo) it keeps a short record: your Discord user ID and display name, the first 280 characters of the text, links in the message, links to attached or embedded images, and the time. It keeps its own replies the same way. This short-term history lets it follow a conversation and answer questions like “what were we just talking about?”. Servers without Premium, channels with the AI switched off, and direct messages get no such record. Each record is deleted after 3 days (sooner if the channel gets more than 150 newer messages), including records saved before a server’s Premium ended or a channel was switched off. If a message is deleted on Discord, its saved copy is deleted too, and if it is edited, the saved copy is updated. When asked about recent conversation, it may also save a short summary of the channel (up to 600 characters).
When you talk to Lumo
When you mention Lumo, reply to it, or address it by name, it gathers what it needs to answer: your message and display name, images you attach or point to, the text of small text-file attachments, the message you are replying to and earlier messages in that reply chain (which may be written by other people), and a few recent lines between you and the bot in that channel. This is sent to xAI to generate the reply (see Third parties).
Voice channels
When someone runs /voice (to join) or /play, Lumo joins their voice channel and listens only to the person who ran the command; other people’s audio is ignored. That person’s speech is cut into short clips (a few seconds each), and each clip is sent to xAI for transcription before Lumo checks for its name; it only answers when the transcript contains its name. Silence, very short sounds (such as a cough or a one-word “ok”) and near-silent noise are skipped on the bot’s side and not sent. Audio is not recorded or saved to disk. The last 10 voice exchanges with each person are kept in memory for follow-up questions and are cleared whenever the bot restarts.
Image and video generation
When you ask for an image, video or image edit, your prompt and any reference images are sent to xAI. Reference images can include profile pictures of members you ask about and the server’s custom emoji. The result is posted in the channel. Lumo does not keep a library of generated media; temporary audio files used for voice playback can remain on the server until it restarts. To enforce the monthly media limits (2 per person per month and 15 per server per month, images and videos together), it counts how many generations each server has used this month, and how many each person (by Discord user ID) has made in that server this month. Separate daily counts of AI replies (20 per person and 100 per server per day) are kept to enforce the daily AI reply limits.
Lumo Coins and games
For each player: your user ID, coin balance, any bet in progress, the date you last claimed your daily bonus with /coins daily and your current daily streak, and when your wallet was created. Game rounds themselves are held in memory only.
Activity, levels and ranks
For each member in each server: how many messages you have sent (in total and per channel), how long you have spent in voice channels, and your XP and level, plus the date tracking began for that server. This powers /profile and /top. Message content is not part of these stats.
In servers that turn on Levels, Lumo also keeps a separate XP count for each member in that server (just the number, never what you wrote); /forgetme erases it.
Giveaways and polls
When a server runs a giveaway, Lumo saves the prize, the end time, the required role (if any), who started it, and the Discord user IDs of the people who pressed Enter, plus the winners. For a poll it saves the question, the options, the end time, who started it and, for each person who voted, their Discord user ID and which option(s) they picked. Votes are only used to count; the poll and the web dashboard show totals, never who voted for what. Finished giveaways and polls are removed after 30 days (and only the latest 25 finished ones per server are kept). No AI is involved.
Web dashboard (beta)
If you log in to the web dashboard with Discord, it asks Discord (scopes “identify” and “guilds” only) for your user ID, name, avatar and the list of servers you are in, keeps only the ones you manage, and stores that in your login session (a signed cookie plus a session kept in the bot’s memory, which ends after 8 hours, when you log out, or when the bot restarts). Changes made from the dashboard are written to an edit history that records your Discord user ID and name, the server, what changed and when. The dashboard sets no analytics or advertising cookies.
Server settings
Settings that server administrators choose (welcome channel, auto-role, reaction roles, date channel, and log channel and events), plus a list of the servers Lumo is in (ID, name and member count) for my status view. When Lumo is added to a server, it records which account added it (that account’s Discord user ID and name, and the time) so I can manage the bot; this record is only visible to me and is deleted when Lumo leaves the server. Lumo also counts how often each custom server emoji is used and stores a short AI-written description of it.
Welcome cards
New members get a welcome card drawn by Lumo itself with their display name and, if available, their profile picture. Nothing is sent to xAI for it, and the card is posted in the server’s welcome channel and not stored by Lumo.
Server logs
If administrators turn on /setup logs, Lumo posts events to the channel they pick: joins and leaves, kicks, bans, timeouts, nickname, role and avatar changes, voice channel joins, moves and mute changes, posted invite links, message edits and deletions (including the earlier text when Discord still has it), and channel, role, emoji and server changes. These entries live in that Discord channel. Lumo only stores the log settings.
Service logs
Like most software, the bot writes operational logs for debugging. These can include user and server IDs, display names, voice transcripts and spoken replies (the first 200 characters), music search terms, short excerpts of image prompts that xAI rejected, and error details. In voice channels, transcripts of speech that did not include the bot’s name can also appear in these logs.
2. How it is used
- To run Lumo’s features: replies, vision, voice, music, media generation, games, profiles, ranks and server tools.
- To run Premium: activating codes, sending renewal reminders and switching AI features off when Premium ends.
- To enforce rate limits and monthly generation limits and to keep games fair.
- To find and fix bugs and keep the service running.
Your data is not sold, rented, used for advertising, or used by me to train AI models.
3. Where it is stored
Lumo runs on Railway, a hosting provider, on servers in the United States. Stored data (message history, wallets, activity stats, settings and Premium records) sits on the bot’s persistent storage there, and service logs are kept by Railway. If you use Lumo from outside the United States, your data is processed in the United States.
4. Third parties
- Discord. Everything you do with Lumo happens on Discord, which handles your data under the Discord Privacy Policy.
- xAI (Grok). Message text, images, text-file contents, voice audio, prompts and profile pictures described above are sent to xAI’s API to create replies, transcriptions, speech, images and videos. Grok may also run web searches to answer. xAI processes and may retain this data under its own terms and the xAI Privacy Policy.
- SoundCloud. When you use
/playor ask for a song by voice, the song name or link is looked up on SoundCloud and the audio is streamed from there. Your identity is not sent. See the SoundCloud Privacy Policy. - Open Trivia Database. Trivia in
/gamefetches questions from opentdb.com. No user data is sent. - Railway. Hosts the bot and its storage (see above).
- Ko-fi. Handles Premium payments (see Premium payments). Ko-fi sends Lumo a notice of each payment; the bot itself sends nothing to Ko-fi.
Outside these services, data is only shared if the law requires it.
6. How long it is kept
| Data | How long |
|---|---|
| Channel message history | Only in servers with Premium (and channels the AI may answer in). Up to 3 days, and only the latest 150 messages per channel. Messages older than 3 days are deleted automatically, and older ones also drop off sooner as new messages come in. Deleting a message on Discord also deletes Lumo’s saved copy. Deleting a channel or removing Lumo from a server deletes that channel’s saved messages. |
| Channel summary | One per channel, replaced when a new one is made, and deleted after 3 days. |
| Voice conversation memory | Last 10 exchanges per person, in memory only. Cleared when the bot restarts. |
| Voice audio | Not saved. Processed and discarded. |
| Lumo Coin wallets | Until deleted on request or the service shuts down. |
| Activity stats (messages, voice time, XP) | Until deleted on request or the service shuts down. |
| Premium records | Until deleted on request or the service shuts down. Records stay after Premium ends so renewals pick up where they left off. |
| Premium payment details | Held by Ko-fi and its payment providers under their policies, and in my Ko-fi account’s history. The bot keeps only a hashed email, a hashed transaction ID and the payment date: up to 60 days if a payment is never claimed, otherwise about 13 months, so a payment is never counted twice. |
| Monthly generation counter | The current month only. Older months are removed. |
| Daily AI reply counters | Per server and per day, kept for 45 days, then removed. The per-person count (per server, today only) is cleared when the day changes. |
| Per-person image counter | The current month only. Older months are removed. |
| Giveaways and polls | Finished ones are removed after 30 days, and only the latest 25 finished per server are kept. Running ones stay until they end. |
| Dashboard edit history | A capped log file; the oldest entries are discarded as it fills. |
| Server settings and emoji data | Until changed, deleted on request, or the service shuts down. Removing Lumo from a server does not delete them automatically. |
| Rate-limit timestamps | About a minute, in memory only. |
| Service logs | For the retention period set by the hosting provider. |
| Data sent to xAI | As set out in xAI’s policies. |
7. Your choices and deletion
The server owner can run /forgetme in their server to erase the saved channel messages and summaries, conversation memory (including voice turns) and activity stats for that server, after a confirmation. It keeps Premium records, server settings, usage counters and Lumo Coin wallets. For anything else, to see or delete your data, message me through my Discord profile with your Discord user ID and what you would like removed (for example, your messages in the bot’s history, your coin wallet, or your activity stats). I will delete it and let you know when it is done. Server administrators can ask me to remove all of a server’s data the same way, including its Premium record (deleting it while Premium is active ends Premium for that server).
You can also limit what Lumo sees:
- Don’t mention Lumo, reply to it or use its name in messages you don’t want it to process.
- Don’t use
/voice(to join) or/playif you don’t want your speech transcribed. - Server administrators can use Discord permissions to keep Lumo out of specific channels, or remove it from the server.
Data held by Discord, xAI or Ko-fi has to be requested from them directly.
8. Children
Discord requires users to be at least 13 years old (older in some countries), and Lumo is meant for people who meet Discord’s minimum age. It is not directed at children under 13. If you think a child under 13 has used Lumo, contact me and I will delete their data.
9. Security
Lumo’s data is kept on private hosting that only I can access, and secrets like API keys are kept out of the data store. No system is perfectly secure, so please don’t share sensitive personal information (such as passwords, financial details or health information) with the bot.
10. This website
This site is a static page hosted on GitHub Pages. It uses no cookies, analytics or tracking. It loads fonts from Google Fonts, so GitHub and Google receive standard request information such as your IP address under their own privacy policies. The home page also asks Lumo’s web dashboard for two public totals (how many servers Lumo is in and how many members they have) to show them live; that request sends no cookies, the dashboard’s host (Railway) receives the same standard request information, and the last numbers are kept in your browser’s local storage so they show up straight away next time.
11. Changes to this policy
If Lumo’s features or data practices change, I will update this page and the effective date above. If you keep using Lumo after a change, the updated policy applies.
12. Contact
Questions or requests about your data: message Ori through Discord.