1. Who we are
This Privacy Policy describes how Tacot Studio (“we,” “us”) collects, uses, and shares information when you use Tacot: the Discord bot, tacot.org, the dashboard and control panel, support/tickets, hosting and related tools, and operator consoles (including talk-as-bot).
Operators listed in the bot’s !info command act for Tacot Studio. Contact: Discord !info or support.
By using Tacot you agree to this Policy and our Terms of Service. If you do not agree, do not invite or use the bot or website.
2. Scope
This Policy covers data processed because you (or a server you join) use Tacot. Discord is a separate controller of the Discord platform. Discord’s own privacy policy applies to your Discord account. We also process data only as needed to provide features a server has enabled.
3. Information we collect
Depending on which features are used, we may process:
- Discord identifiers — user IDs, usernames/display names, avatars, server IDs, channel IDs, role IDs, message IDs, and similar snowflakes the Discord API provides.
- OAuth / website login — when you sign in to the dashboard we receive the Discord account you authorize (typically ID, username, avatar, and the servers you can manage) plus session cookies so you stay logged in.
- Server configuration — prefixes, modules, welcome/goodbye/boost settings, automod, logs, tickets, giveaways, automations, feeds, and other settings staff save.
- Economy and progression — taco balances, bank, inventory, marketplace listings, XP/levels, streaks, cooldowns, quests, custom server currencies, and related transaction history.
- Moderation and safety — warnings, cases, mutes/bans recorded by Tacot, tickets and transcripts, reports, automod hits, security incidents, and similar staff-created records.
- Message content (limited) — we process message content when a feature requires it (for example automod, logging you enabled, tickets/modmail, AI chat, music commands, or operator talk-as-bot). We do not store every message in every channel by default.
- Direct messages — only if you message the bot (commands, modmail/support you start, or owner/operator workflows). We do not scrape unrelated private DMs between other users.
- AI inputs/outputs — prompts and replies when AI chat, setup copy, or similar features run.
- AI conversation memories — short lasting facts we extract from AI chat (or that you save with
!remember), stored against your Discord user ID so later AI replies can stay consistent. See section 8. - Media metadata — attachment URLs, embed data, and stickers the Discord API returns when those features display or moderate content.
- Music taste — likes/dislikes you set.
- Votes — timestamps if you vote on listing sites such as top.gg (for rewards).
- Support and commerce — website support tickets, custom-bot or hosting requests, and payment references if you pay through a processor we use (we do not store full card numbers).
- Technical logs — IP address, user agent, and similar request metadata on the website; error logs; rate-limit and abuse signals.
- Integrations you connect — RSS/Twitch/YouTube/GitHub/Minecraft/Roblox/webhook URLs and last-check state for feeds you configure.
4. How we use information
- Provide, operate, and improve the bot, website, and dashboard.
- Run features a server enables (economy, leveling, tickets, music, automod, AI chat, etc.).
- Personalize AI replies using conversation memories you create by talking to the AI (or by
!remember). - Authenticate dashboard users and remember sessions.
- Prevent spam, raids, fraud, and other abuse; enforce our Terms.
- Provide customer support and operator tools (including viewing/sending in channels the bot can access, when used for support or operations).
- Process optional payments and fulfill hosting or coding orders.
- Comply with law and Discord’s Developer Terms of Service / policies.
5. Operator access (important)
Tacot is hosted and operated by Tacot Studio. If a server invites Tacot, operators may access content the bot is technically able to see in that server — including recent channel messages, embeds, attachments the API returns, tickets, and settings — using operator tools such as the website talk console and owner dashboard. That access is for support, safety, debugging, and operating the service.
Server admins who invite Tacot are responsible for telling their members that a third-party bot (and its operators) can process content in channels the bot can read. Restrict the bot’s channel permissions if you do not want that.
6. Legal bases (where applicable)
Where data-protection laws such as the GDPR apply, we process data to perform the service you request, for our legitimate interests in running a safe bot, with consent where we ask for it, and to comply with legal obligations.
7. What we do not do
- We do not sell personal data, including AI conversation memories.
- We do not use your Discord messages or memories to train Tacot’s own foundation models. Third-party AI providers may process prompts (and injected memories) under their terms when you use AI features.
- We do not use conversation memories for advertising.
- We do not mass-DM every member of a server. Broadcast/mail is opt-in (
!subscribeor equivalent). - We do not auto-create vanity URLs or bulk advertising invites.
- Virtual tacos and items have no real-world cash value.
8. AI conversation memories
When you use Tacot AI, we may save a small profile of lasting facts about you so the bot can remember you across later chats, like a friend would. This is separate from Discord’s own message history.
- What is stored — short facts (for example “goes by Jay,” “likes Minecraft”), a category, and timestamps. We do not keep a full recording of every AI message as a “memory.” We also store whether you turned memories off and when you last talked to the AI (so the idle timer works).
- Where they apply — memories are keyed to your Discord user ID and may be used in any Tacot AI chat: servers, DMs, personas/custom bots, and the logged-in website helper.
- How they are created — simple pattern matching on what you say, optional extra extraction by a model, and facts you save yourself with
!remember. - How they are used — relevant facts are inserted into the AI prompt for your later replies. That means model providers listed in section 9 may see those facts when generating an answer.
- What we try not to store — passwords, API keys, phone numbers, emails, street addresses, sexual content, and stated ages under 13. Filters can miss things. Do not send secrets or other people’s private data into AI chat.
- Retention — all of a user’s conversation memories are deleted after seven (7) days with no AI conversation. Talking to the AI again starts a new file. You can delete one fact, delete all, or opt out at any time (below).
- Your controls —
!memory(list / on / off),!remember …,!forget 2or!forget all.!memory offstops new saves and wipes stored facts. - Legal basis (where GDPR or similar laws apply) — performance of the AI chat feature you choose to use, and our legitimate interest in making that chat consistent. You can object by turning memories off. Using AI after this Policy’s update is your agreement to this processing.
Deleting memories does not delete Discord messages, ticket logs, or copies that a third-party AI host may retain under its own policy. Backups of our database may hold a fact for a short extra period until they rotate.
9. Sharing and processors
We share information with:
- Discord — to run the bot and OAuth login.
- Infrastructure — hosting, reverse proxy, and CDN (including Cloudflare) that carry traffic and may process IPs and URLs.
- AI providers when AI is used — which may include Groq, xAI, Google Gemini, OpenRouter, Cerebras, or a locally hosted model. Prompts may include your conversation memories. Do not send secrets into AI chat.
- Listing sites such as top.gg for optional votes and public bot stats.
- Payment processors (for example Stripe or similar) if you pay us; they process your payment details under their policies.
- Optional databases such as MongoDB if enabled as a mirror of bot data.
- Authorities if required by law or to protect people from serious harm.
We may also disclose information to a successor if Tacot Studio is transferred, with notice where required.
10. Cookies and similar tech
The website uses cookies or local storage for login sessions, theme preference, and similar site function. We do not run third-party advertising trackers on legal pages. Blocking cookies may break dashboard login.
11. Retention and deletion
We keep data while a feature needs it, while Tacot remains in a server, or while a user profile is active, then for a reasonable period for backups, abuse prevention, and legal holds. Removing the bot from a server stops new collection there; some global user economy data may remain if you use Tacot elsewhere.
AI conversation memories are deleted after seven days of no AI chat, or sooner if you run !forget all or !memory off. That timer is based on last AI conversation, not on calendar age of each fact.
To request deletion or a copy of data we hold, contact operators via !info or support from the Discord account the request concerns. We may need to verify identity and may retain limited records if required for safety or law.
12. Security
We use reasonable technical and organizational measures (access controls, HTTPS on the public site, secrets stored on the host). No method of transmission or storage is 100% secure.
13. International transfers
Tacot may be hosted and processed in countries other than yours. By using the service you understand your information may be transferred to those locations.
14. Children
Tacot is intended for users who meet Discord’s minimum age (generally 13+, or higher where Discord or law requires). We do not knowingly collect personal information from children in violation of COPPA or similar laws. Conversation memories are not meant for children under that age; we try not to store stated ages under 13. If you believe a child has provided data contrary to those rules, contact us and we will delete it where required.
15. Your choices
- Leave a server or remove Tacot to stop most in-server collection.
- Do not enable AI, logging, or tickets if you do not want those features to process content.
- For AI memories:
!memoryto see them,!forget allto wipe,!memory offto stop saving. Staff can also!ai offin a channel. - Revoke Discord OAuth for tacot.org in Discord’s Authorized Apps to end dashboard access.
- Use
!privacy/ this page for the current policy;!infoto reach operators.
16. Changes
We may update this Policy. The “Last updated” date at the top will change. Continued use after an update means you accept the revised Policy. Material changes may also be noted on the website or support server.
17. Contact
Tacot Studio · Discord !info · Support server · https://tacot.org/privacy · https://tacot.org/terms
In Discord: !privacy · !terms.