Skip to content
Lumo
Get started Features Commands Premium FAQ Dashboard Beta
Appearance
Seasonal
Open dashboard Beta Add to Discord
Get started Features Commands Premium FAQ About the dashboard Beta Open dashboard Beta Add to Discord
Appearance
Seasonal
Lumo the robot giving a saluteLegal

Privacy Policy

Effective October 8, 2026

This policy explains what the Lumo Discord bot (“Lumo”, “the bot”) collects, why, where it is kept, who it is shared with, and how to get it deleted. Lumo is run by Ori, an individual developer (“I”, “me”). You can reach me through my Discord profile. Also see the Terms of Service.

The short version

  • Lumo reads messages in the channels it can see so it can reply and follow the conversation. In servers with Premium, and in channels where the server has not switched the AI off, it keeps the most recent 150 messages per channel (the first 280 characters of each) for up to 3 days, then deletes them. In servers without Premium it does not keep message text. If you delete a message on Discord, Lumo deletes its saved copy too.
  • When you talk to Lumo or speak to it in a voice channel, your words, images and audio are sent to xAI (the company behind Grok) to produce the answer.
  • Lumo Coin wallets, activity stats (message counts, voice time, XP) and server settings are kept until they are deleted.
  • Lumo does not record or save voice audio.
  • The bot never asks for or stores payment details. Premium is paid through Ko-fi, which shares your name, email, the amount and any message with me. Ko-fi payment info such as your email is used only to deliver Premium and is stored hashed, never in plain text. The bot only keeps a small Premium record for each server.
  • I don’t sell your data, use it for advertising, or train AI models on it.
  • The server owner can run /forgetme to erase the saved messages, conversation memory and activity stats for their server. For anything else, message me on Discord and I will delete your data.
On this page
  1. What Lumo collects
  2. How it is used
  3. Where it is stored
  4. Third parties
  5. Premium payments
  6. How long it is kept
  7. Your choices and deletion
  8. Children
  9. Security
  10. This website
  11. Changes to this policy
  12. Contact

1. What Lumo collects

Lumo only works inside Discord servers. It does not ask for passwords, email addresses or payment details, and it has no login. Premium is paid for outside the bot, through Ko-fi (see Premium payments).

Messages in channels it can see

Lumo uses Discord’s message content access. In servers where the AI is active (servers with Premium, in channels the server has not switched off in the dashboard’s AI channels page), for each message posted in a channel it can read (whether or not the message is for Lumo) it keeps a short record: your Discord user ID and display name, the first 280 characters of the text, links in the message, links to attached or embedded images, and the time. It keeps its own replies the same way. This short-term history lets it follow a conversation and answer questions like “what were we just talking about?”. Servers without Premium, channels with the AI switched off, and direct messages get no such record. Each record is deleted after 3 days (sooner if the channel gets more than 150 newer messages), including records saved before a server’s Premium ended or a channel was switched off. If a message is deleted on Discord, its saved copy is deleted too, and if it is edited, the saved copy is updated. When asked about recent conversation, it may also save a short summary of the channel (up to 600 characters).

When you talk to Lumo

When you mention Lumo, reply to it, or address it by name, it gathers what it needs to answer: your message and display name, images you attach or point to, the text of small text-file attachments, the message you are replying to and earlier messages in that reply chain (which may be written by other people), and a few recent lines between you and the bot in that channel. This is sent to xAI to generate the reply (see Third parties).

Voice channels

When someone runs /voice (to join) or /play, Lumo joins their voice channel and listens only to the person who ran the command; other people’s audio is ignored. That person’s speech is cut into short clips (a few seconds each), and each clip is sent to xAI for transcription before Lumo checks for its name; it only answers when the transcript contains its name. Silence, very short sounds (such as a cough or a one-word “ok”) and near-silent noise are skipped on the bot’s side and not sent. Audio is not recorded or saved to disk. The last 10 voice exchanges with each person are kept in memory for follow-up questions and are cleared whenever the bot restarts.

Image and video generation

When you ask for an image, video or image edit, your prompt and any reference images are sent to xAI. Reference images can include profile pictures of members you ask about and the server’s custom emoji. The result is posted in the channel. Lumo does not keep a library of generated media; temporary audio files used for voice playback can remain on the server until it restarts. To enforce the monthly media limits (2 per person per month and 15 per server per month, images and videos together), it counts how many generations each server has used this month, and how many each person (by Discord user ID) has made in that server this month. Separate daily counts of AI replies (20 per person and 100 per server per day) are kept to enforce the daily AI reply limits.

Lumo Coins and games

For each player: your user ID, coin balance, any bet in progress, the date you last claimed your daily bonus with /coins daily and your current daily streak, and when your wallet was created. Game rounds themselves are held in memory only.

Activity, levels and ranks

For each member in each server: how many messages you have sent (in total and per channel), how long you have spent in voice channels, and your XP and level, plus the date tracking began for that server. This powers /profile and /top. Message content is not part of these stats.

In servers that turn on Levels, Lumo also keeps a separate XP count for each member in that server (just the number, never what you wrote); /forgetme erases it.

Giveaways and polls

When a server runs a giveaway, Lumo saves the prize, the end time, the required role (if any), who started it, and the Discord user IDs of the people who pressed Enter, plus the winners. For a poll it saves the question, the options, the end time, who started it and, for each person who voted, their Discord user ID and which option(s) they picked. Votes are only used to count; the poll and the web dashboard show totals, never who voted for what. Finished giveaways and polls are removed after 30 days (and only the latest 25 finished ones per server are kept). No AI is involved.

Web dashboard (beta)

If you log in to the web dashboard with Discord, it asks Discord (scopes “identify” and “guilds” only) for your user ID, name, avatar and the list of servers you are in, keeps only the ones you manage, and stores that in your login session (a signed cookie plus a session kept in the bot’s memory, which ends after 8 hours, when you log out, or when the bot restarts). Changes made from the dashboard are written to an edit history that records your Discord user ID and name, the server, what changed and when. The dashboard sets no analytics or advertising cookies.

Server settings

Settings that server administrators choose (welcome channel, auto-role, reaction roles, date channel, and log channel and events), plus a list of the servers Lumo is in (ID, name and member count) for my status view. When Lumo is added to a server, it records which account added it (that account’s Discord user ID and name, and the time) so I can manage the bot; this record is only visible to me and is deleted when Lumo leaves the server. Lumo also counts how often each custom server emoji is used and stores a short AI-written description of it.

Welcome cards

New members get a welcome card drawn by Lumo itself with their display name and, if available, their profile picture. Nothing is sent to xAI for it, and the card is posted in the server’s welcome channel and not stored by Lumo.

Server logs

If administrators turn on /setup logs, Lumo posts events to the channel they pick: joins and leaves, kicks, bans, timeouts, nickname, role and avatar changes, voice channel joins, moves and mute changes, posted invite links, message edits and deletions (including the earlier text when Discord still has it), and channel, role, emoji and server changes. These entries live in that Discord channel. Lumo only stores the log settings.

Service logs

Like most software, the bot writes operational logs for debugging. These can include user and server IDs, display names, voice transcripts and spoken replies (the first 200 characters), music search terms, short excerpts of image prompts that xAI rejected, and error details. In voice channels, transcripts of speech that did not include the bot’s name can also appear in these logs.

2. How it is used

  • To run Lumo’s features: replies, vision, voice, music, media generation, games, profiles, ranks and server tools.
  • To run Premium: activating codes, sending renewal reminders and switching AI features off when Premium ends.
  • To enforce rate limits and monthly generation limits and to keep games fair.
  • To find and fix bugs and keep the service running.

Your data is not sold, rented, used for advertising, or used by me to train AI models.

3. Where it is stored

Lumo runs on Railway, a hosting provider, on servers in the United States. Stored data (message history, wallets, activity stats, settings and Premium records) sits on the bot’s persistent storage there, and service logs are kept by Railway. If you use Lumo from outside the United States, your data is processed in the United States.

4. Third parties

  • Discord. Everything you do with Lumo happens on Discord, which handles your data under the Discord Privacy Policy.
  • xAI (Grok). Message text, images, text-file contents, voice audio, prompts and profile pictures described above are sent to xAI’s API to create replies, transcriptions, speech, images and videos. Grok may also run web searches to answer. xAI processes and may retain this data under its own terms and the xAI Privacy Policy.
  • SoundCloud. When you use /play or ask for a song by voice, the song name or link is looked up on SoundCloud and the audio is streamed from there. Your identity is not sent. See the SoundCloud Privacy Policy.
  • Open Trivia Database. Trivia in /game fetches questions from opentdb.com. No user data is sent.
  • Railway. Hosts the bot and its storage (see above).
  • Ko-fi. Handles Premium payments (see Premium payments). Ko-fi sends Lumo a notice of each payment; the bot itself sends nothing to Ko-fi.

Outside these services, data is only shared if the law requires it.

5. Premium payments

Lumo itself never asks for or stores payment details. Premium is paid for outside the bot, as a membership on Ko-fi.

  • When you pay. Ko-fi and its payment providers handle the payment. As the creator being paid, I receive the details Ko-fi shares with creators, such as your name, email address, the amount, and any message you add. Ko-fi handles your payment information under the Ko-fi Privacy Policy.
  • Turning Premium on. Ko-fi sends Lumo a notice of each payment. Lumo uses your email (and your Discord user ID, if Ko-fi includes it, only to DM you a code) just to deliver Premium. It stores the email only as a salted hash, so it can’t be read back, plus a hashed transaction ID and the payment date. Your name, message and the amount are not stored. A payment nobody claims is forgotten after 60 days.
  • What the bot stores. For each Premium server: the server ID, how Premium was granted (for example, a Ko-fi membership or a redeemed code), its status and expiry date, and the user ID of the person who claimed or redeemed it and when. For Ko-fi members, the hashed email is linked to the server so renewals extend it. It also notes whether the renewal reminder and end notice were sent.

This record is used only to run Premium: activating payments and codes, sending the reminder 3 days before Premium ends and the notice when it ends (in the server’s system channel, or by DM to the person who last redeemed a code or to the server owner), and switching AI features off at expiry.

6. How long it is kept

DataHow long
Channel message historyOnly in servers with Premium (and channels the AI may answer in). Up to 3 days, and only the latest 150 messages per channel. Messages older than 3 days are deleted automatically, and older ones also drop off sooner as new messages come in. Deleting a message on Discord also deletes Lumo’s saved copy. Deleting a channel or removing Lumo from a server deletes that channel’s saved messages.
Channel summaryOne per channel, replaced when a new one is made, and deleted after 3 days.
Voice conversation memoryLast 10 exchanges per person, in memory only. Cleared when the bot restarts.
Voice audioNot saved. Processed and discarded.
Lumo Coin walletsUntil deleted on request or the service shuts down.
Activity stats (messages, voice time, XP)Until deleted on request or the service shuts down.
Premium recordsUntil deleted on request or the service shuts down. Records stay after Premium ends so renewals pick up where they left off.
Premium payment detailsHeld by Ko-fi and its payment providers under their policies, and in my Ko-fi account’s history. The bot keeps only a hashed email, a hashed transaction ID and the payment date: up to 60 days if a payment is never claimed, otherwise about 13 months, so a payment is never counted twice.
Monthly generation counterThe current month only. Older months are removed.
Daily AI reply countersPer server and per day, kept for 45 days, then removed. The per-person count (per server, today only) is cleared when the day changes.
Per-person image counterThe current month only. Older months are removed.
Giveaways and pollsFinished ones are removed after 30 days, and only the latest 25 finished per server are kept. Running ones stay until they end.
Dashboard edit historyA capped log file; the oldest entries are discarded as it fills.
Server settings and emoji dataUntil changed, deleted on request, or the service shuts down. Removing Lumo from a server does not delete them automatically.
Rate-limit timestampsAbout a minute, in memory only.
Service logsFor the retention period set by the hosting provider.
Data sent to xAIAs set out in xAI’s policies.

7. Your choices and deletion

The server owner can run /forgetme in their server to erase the saved channel messages and summaries, conversation memory (including voice turns) and activity stats for that server, after a confirmation. It keeps Premium records, server settings, usage counters and Lumo Coin wallets. For anything else, to see or delete your data, message me through my Discord profile with your Discord user ID and what you would like removed (for example, your messages in the bot’s history, your coin wallet, or your activity stats). I will delete it and let you know when it is done. Server administrators can ask me to remove all of a server’s data the same way, including its Premium record (deleting it while Premium is active ends Premium for that server).

You can also limit what Lumo sees:

  • Don’t mention Lumo, reply to it or use its name in messages you don’t want it to process.
  • Don’t use /voice (to join) or /play if you don’t want your speech transcribed.
  • Server administrators can use Discord permissions to keep Lumo out of specific channels, or remove it from the server.

Data held by Discord, xAI or Ko-fi has to be requested from them directly.

8. Children

Discord requires users to be at least 13 years old (older in some countries), and Lumo is meant for people who meet Discord’s minimum age. It is not directed at children under 13. If you think a child under 13 has used Lumo, contact me and I will delete their data.

9. Security

Lumo’s data is kept on private hosting that only I can access, and secrets like API keys are kept out of the data store. No system is perfectly secure, so please don’t share sensitive personal information (such as passwords, financial details or health information) with the bot.

10. This website

This site is a static page hosted on GitHub Pages. It uses no cookies, analytics or tracking. It loads fonts from Google Fonts, so GitHub and Google receive standard request information such as your IP address under their own privacy policies. The home page also asks Lumo’s web dashboard for two public totals (how many servers Lumo is in and how many members they have) to show them live; that request sends no cookies, the dashboard’s host (Railway) receives the same standard request information, and the last numbers are kept in your browser’s local storage so they show up straight away next time.

11. Changes to this policy

If Lumo’s features or data practices change, I will update this page and the effective date above. If you keep using Lumo after a change, the updated policy applies.

12. Contact

Questions or requests about your data: message Ori through Discord.

Lumo

Thanks for stopping by!

An AI-powered Discord bot for music, games and server tools. Built and maintained by @OniSyris.

Explore

Get started Features Commands Premium FAQ Changelog Open dashboard Beta About the dashboard

Support

Join our support server Message Ori on Discord Claim Premium Permissions explained Status

Legal

Terms of Service Privacy Policy
Not affiliated with Discord. Lumo Coins are play money with no real-world value. Music: Outer Space Loop by wipics (CC0).