Who this policy covers
This is the privacy policy for Disco, Discord application 1546791291965149195, and its connected Big If True website controls. Big If True is operated by HiLleywyn. Contact the operator through the private request center; choose Policy question for privacy or identity-verification problems. You can submit a general question without signing in.
Effective 15 September 2026. Server owners decide where a bot is installed and which features are enabled. They may keep separate moderation records. Discord and linked third-party services operate under their own policies. This page describes our processing; it does not grant access to a channel or change Discord’s terms.
What comes in, and why
Prompts, replies, supported attachments and tool results; relevant permitted channel messages; user/server/channel/message IDs and names; optional recent turns, facts, summaries and saved context; thread ownership, recall codes and context links; saved replies and workspace files; role/access information; model usage, reset credits and operational failures. The currently loaded bot is focused on AI; retired economy and game commands are not part of this guide.
| Source | Purpose | Who can see the result |
|---|---|---|
| A command, mention, button or form you use | Provide the feature you requested; validate eligibility and prevent duplicate actions | A channel answer is visible to people who can view that channel. A private/ephemeral interface has a narrower audience. |
| Permitted server events and history | Support enabled features and relevant context; apply optional privacy preferences | Authorized bot infrastructure and the feature’s intended audience. Private channel access is checked. |
| Website Discord sign-in | Associate preferences and requests with the right Discord account; check membership in the configured Big If True server to hide its Join buttons | You and authorized operators; public comments/reactions show your chosen Discord identity. |
| Operational records | Protect the service, enforce usage limits, reconcile actions and investigate failures | Authorized operators and necessary infrastructure providers. |
| A report or feedback submission | Review the issue, communicate an outcome and prevent abuse of the reporting system | The requester and authorized reviewers. We do not publish a report or automatically send it to its subject. |
Do not submit passwords, access tokens, payment-card details, identity documents or other unnecessary sensitive information. If sensitive content appears in a relevant message, report or attachment, it may be processed as part of that feature; avoid including it and request removal if needed. We do not sell personal data, create advertising audiences from Discord conversations, or use Discord message content to train our own models.
Why we process personal data
Where a legal basis is required, processing a requested command, storing an item you choose to save and maintaining your account support the service agreement. Necessary security, moderation, reliability and abuse-prevention processing support legitimate interests, subject to the rights and reasonable expectations of affected people. Legal obligations can require limited records or disclosures. Optional processing must use consent where applicable law requires it; a default setting does not replace a legally required consent. You can withdraw an optional choice without changing the lawfulness of earlier processing. Contact the operator to object, request restrictions or ask which basis applies to a particular record.
Your choices, with the tradeoffs
Use your privacy controls after Discord sign-in. Settings apply to the signed-in Discord ID across supported deployments, rather than to everyone in a server. Optional processing defaults to enabled unless you or an existing server-scoped setting has disabled it.
- AI memory and ambient context: for Big, Disco and Ticker, turning this off prevents supported personal-memory reads/writes and excludes your authored messages from new ambient channel-context retrieval. Explicit requests you send still need to be processed. A reply may be less personalized, and the bot may need you to repeat context.
- Custodian activity statistics: turning this off stops new optional message/reaction activity earning and associated level/streak statistics. You will stop earning through those paths. Existing scores and earned roles are not automatically removed.
- Ticker optional analytics: turning this off stops new optional command telemetry from being retained. Quotes, charts and alerts still work; essential accounting and failure/security processing continue.
- Existing material: a setting is not a retroactive erasure. Old saved replies, shared summaries, public posts, quotes supplied by other people and provider records may still contain earlier material. Request deletion for a review of those copies.
- Notifications and stored features: use Account settings for Big topic notifications and the bot’s own remove/unsave/alert controls for user-created items. Removing a bot stops future event access; it does not itself erase stored data.
Disco’s ,disco optout is an additional server-scoped control. A global website opt-in does not override an existing server opt-out. Safety enforcement, permission checks, requested transactions, request receipts and usage limits are essential to providing the service and cannot be disabled with optional switches. A change cannot recall a request already sent to a provider or a message already posted.
AI, tools and service providers
When you use AI, selected prompts, relevant context, permitted attachments and tool results may be sent to OpenRouter and the model provider selected for that request.
Big, Disco and Ticker share AI infrastructure, memory services and a usage ledger, with bot identities and access checks preserved. A staff-started cross-bot exchange supplies all three participants with its topic, relevant channel material and the complete current exchange; the completed exchange can be recalled in a relevant later discussion. It does not authorize unrelated private-channel access.
| Provider / recipient | Information involved | Reason |
|---|---|---|
| Discord | Bot events, commands, messages, application identity and permissions | Run the Discord application and deliver interactions. |
| OpenRouter and the selected AI model provider | Content and context needed for an AI request, tool results and request metadata; only when an AI feature is invoked | Generate an answer or supported content. Provider routing and retention depend on the selected model and account configuration. |
| News/search sources and retrieval providers | Search terms, article URLs and necessary request metadata | Retrieve sources for research or news. Do not include unnecessary personal details in searches. |
| CoinGecko, Finnhub, Alternative.me and TradingView | Requested symbols, chart options and network request metadata when using market tools | Provide Ticker’s market data, sentiment and chart rendering. |
| GIPHY / configured GIF provider | A GIF search term and network metadata when that feature is used | Return requested GIFs. |
| Cloudflare and hosting infrastructure | Website request IP/network metadata, requested paths and traffic processed through the service | Deliver and protect the website and API. |
| Authorized operators and server moderators | Only records relevant to operations or the server’s configured moderation features | Provide support, safety review, access decisions and incident response. |
We do not promise that every provider offers zero retention or that every selected model uses identical data practices. Provider-side retention, subprocessors and international processing follow their applicable agreements and settings. We do not give providers a general right to train on Discord content through this policy. Data can be processed outside your country. Where law requires a transfer safeguard or other protection, the operator must apply it before that processing.
Provider references: Discord privacy · OpenRouter privacy · Cloudflare privacy. These links leave Big If True.
Storage, retention and security
Recent AI turns expire from Redis after one hour. Background memory events are pruned after seven days, with a recent-message buffer used for memory refresh. Unsaved chat threads are eligible for deletion after 12 hours idle. Saving or linking a thread retains its context longer. Persistent facts, summaries, saved replies, workspace files, usage records and completed shared exchanges do not have one universal automatic expiry.
Bot records use PostgreSQL; recent AI state uses Redis. Big’s website and story/community records use SQLite and local service storage. Files and generated artifacts may also use service-managed disk storage. Access is restricted to the bot services and authorized operators; browser connections use HTTPS. Private request text and reviewer notes are encrypted before storage, with the key kept separately from the request database.
We do not claim that every legacy database, log or backup has application-level encryption. Encryption and retention also depend on the host and backup configuration. A published policy alone is not proof of an independently audited security certification.
| Website record | Retention / behavior |
|---|---|
| Discord OAuth authorization state | Expires after 10 minutes. Used to bind the login to the browser. |
| Website session | Expires after 7 days; the server stores a token hash. Sign-out revokes that session. |
| Discord OAuth access token | Used to fetch your identify profile, then revoked; not retained in your browser or the account database. |
| Privacy preference and policy acknowledgment | Kept to apply your choice and record the policy version you marked as read. Ask to remove it; removing an opt-out record can restore a default, so the operator may retain a minimal suppression record at your request. |
| Private requests and review notes | Retained while handling the request and any necessary follow-up or abuse/legal dispute. No fixed automatic expiry is currently configured; request removal or a retention explanation. |
| Security and infrastructure logs / backups | Retention is configuration-dependent. A deletion review must identify applicable copies and any restricted legal/security hold; no unsupported fixed backup-erasure deadline is promised. |
We retain information only for a service purpose, a necessary security or dispute purpose, or a legal obligation. Records without an automatic expiry still require operator review and deletion when no longer needed. If a security incident affects your data, we will investigate, take protective action and notify affected people and Discord where required.
Access, correction and deletion
Request deletion Ask for your data
- Sign in with the Discord account concerned. Choose this bot or all four, specify what you want removed or exported, and include relevant server/message IDs if useful. We do not ask for a password or government ID in this form.
- You receive a private request ID and can follow its status, add information or withdraw the request. “Received” means saved for review; it does not mean data has already been deleted.
- A reviewer verifies scope and checks the bot databases, saved material, derived context, relevant files and backups. They can ask for more information without exposing another person’s records.
- We act without undue delay, subject to applicable legal time limits. The response records what was removed, corrected or supplied, what remains, why it remains, and any further steps or retention period. There is no automatic promise of instant deletion.
- Deletion can remove memories, saved items, scores or feature state and cannot reliably be undone. It may stop associated alerts or personalized behavior. Public messages already delivered to Discord and copies made by others are separate; the reviewer will explain which bot-controlled copies can be removed.
- Essential suppression, security, moderation evidence or legal records may need restricted retention. We will explain a refusal or partial outcome rather than silently treating it as complete. You may appeal through the same request.
Depending on your location, you may also have rights to object, restrict processing, withdraw consent, receive portable data or complain to a data-protection authority. We honor applicable rights without charging for an ordinary request or retaliating for using them. If you cannot sign in, submit a Policy question explaining the access problem so the operator can arrange proportionate verification.
Gateway intents: which events arrive
An intent controls which Discord events an application receives. It is separate from a permission to act in a channel. Message Content and Server Members are privileged intents and can require Discord approval. Receiving an event does not mean every field is permanently stored.
| Intent | Status | Specific purpose or limitation |
|---|---|---|
| Guilds | Enabled | Resolve servers, channels, threads, roles and access. |
| Server Members | Privileged · enabled | Maintain member identity and role/access context for eligible conversations, private tools and thread features. Loss of this subscription limits automatic member updates. |
| Message Content | Privileged · enabled | Read prefix requests, conversation replies and relevant accessible channel context. Without approval, ordinary unmentioned server messages cannot supply that context. |
| Guild / Direct Messages | Enabled | Process supported server requests and private workspace messages. |
| Guild / Direct Reactions | Enabled by framework defaults | Support reaction-based answer feedback where configured. |
| Guild Moderation / Expressions / Integrations / Webhooks / Invites | Enabled by framework defaults | These event subscriptions remain enabled in the common client. The active AI-only feature set has no general need to collect their events; enabling an intent alone does not create a stored record. |
| Guild Voice States / Guild and Direct Typing | Enabled by framework defaults | No active voice recording, typing analytics or voice feature is advertised. These subscriptions are broader than the current feature need. |
| Guild Scheduled Events / Auto Moderation Configuration and Execution / Guild and Direct Message Polls | Enabled by framework defaults | The active AI-only feature set does not require broad event collection from these subscriptions. |
| Presence | Not requested | No online-status or activity monitoring. |
No bot requests the privileged Presence intent. Discord’s gateway documentation defines the event families and approval rules.
Every permission, explained
This inventory separates a feature’s purpose from the effective grant observed in the Big If True server on 15 September 2026. Other servers can grant a different set, and channel overwrites can narrow access. A permission does not automatically authorize every member to invoke a staff action. Server owners can inspect the bot role and channel permissions in Discord.
This bot does not need Administrator. Permissions with no current feature purpose are called out below even if inherited from the server.
The application install scopes are bot and, where application commands are offered, applications.commands. Website sign-in requests only identify; it does not request email, connections, access to your DMs or permission to join servers for you. The Use Application Commands permission is a member permission and is distinct from the installation scope.
| Permission | Feature status | Why it is there / why it is unnecessary | Audited grant |
|---|---|---|---|
| Create Instant Invite | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Kick Members | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Ban Members | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Administrator | Not needed | Not required by the feature permission registry. It grants all permissions and bypasses channel restrictions; it is broader than the features need. | Not granted in audited server |
| Manage Channels | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Manage Server | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Add Reactions | Feature use | Record or show supported answer feedback. | Granted in audited server |
| View Audit Log | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Priority Speaker | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Video | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| View Channel | Feature use | See only channels available to the bot. | Granted in audited server |
| Send Messages | Feature use | Post requested answers and configured feature messages. | Granted in audited server |
| Send TTS Messages | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Manage Messages | Feature use | Maintain bot control panels and thread messages. | Granted in audited server |
| Embed Links | Feature use | Show rich source links and panels. | Granted in audited server |
| Attach Files | Feature use | Deliver generated images, charts or requested exports. | Granted in audited server |
| Read Message History | Feature use | Retrieve a permitted reply target or relevant earlier messages. | Granted in audited server |
| Mention Everyone | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Use External Emojis | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| View Server Insights | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Connect | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Speak | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Mute Members | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Deafen Members | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Move Members | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Use Voice Activity | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Change Nickname | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Granted in audited server |
| Manage Nicknames | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Manage Roles | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Manage Webhooks | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Manage Guild Expressions | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Use Application Commands | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Request to Speak | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Granted in audited server |
| Manage Events | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Manage Threads | Feature use | Archive or remove managed chat threads and maintain their controls. | Granted in audited server |
| Create Public Threads | Feature use | Create opt-in conversation threads. | Granted in audited server |
| Create Private Threads | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Use External Stickers | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Send Messages in Threads | Feature use | Answer and update feature posts inside accessible threads. | Granted in audited server |
| Use Activities | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Timeout Members | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| View Creator Monetization Analytics | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Use Soundboard | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Create Guild Expressions | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Create Events | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Use External Sounds | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Send Voice Messages | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Set Voice Channel Status | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Send Polls | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Use External Apps | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
| Pin Messages | Feature use | Pin a conversation control panel where this permission is separately required. | Not granted in audited server |
| Bypass Slowmode | Not needed | No current advertised feature requires this permission. An inherited or manual grant does not establish a feature need. | Not granted in audited server |
Private-thread access and role hierarchy still need explicit checks in features that read or act for a member. A moderator capability is not a member command. Discord’s permission reference explains the platform-level effects, aliases and hierarchy. This inventory includes all currently documented permission flags; newly added Discord flags require a fresh review.
Cookies and local preferences
The website checks only the signed-in account’s membership in the configured Big If True server using the bot’s existing access. It does not request your server list through OAuth. The result is cached in server memory for up to 60 seconds, or 10 seconds after a failed check, and is not added to your stored profile. The website uses a secure, HttpOnly session cookie and a short-lived OAuth state cookie for sign-in. CSRF checks protect account writes. A local browser preference remembers your light/dark theme. Draft action state may be kept in session storage to resume a requested action after login. The bot hub does not add advertising cookies or third-party analytics scripts. Cloudflare and linked services may process their own technical records under their policies. Signing out does not erase account data; clearing browser storage does not delete bot records.
Questions, complaints and changes
Use the request center for a privacy question, correction, complaint or appeal. Use Abuse report for harmful use by a user, server or application. Reports are reviewed privately; relevant allegations or evidence may be shared in a limited way when needed to investigate, enforce rules or comply with law. We do not promise absolute anonymity where identification is necessary or legally required.
Material changes will update the effective date and a plain-language change note on this page. We will provide additional notice where required before materially different processing. A privacy setting does not become consent to unrelated processing. Children below Discord’s minimum age for their country must not use the apps; if we learn that an ineligible child’s data was collected, we will review and remove it as required.
Version note, 15 September 2026: first unified bot policy hub, per-bot optional processing controls and private request tracking.
Try a real-life example
“Wait, what happens if…?”
I turn memory off, then ask a question.
The bot processes your new request and the context you explicitly supply. It stops supported optional personal-memory use. It still accounts for usage and may post the answer where you asked. Old posts and summaries need a separate deletion review.
I disagree with a bot or a moderation result.
Challenge the answer, inspect its sources, or request a human review. Disagreement is allowed. Threats, harassment and attempts to access someone else’s private records are not.
I submit an abuse report without signing in.
You receive a secret receipt. Keep it: it opens the private report and follow-up thread. Losing it can mean losing access. Reports are reviewed, not automatically published or sent to the subject.
I want all four bots to forget me.
Choose “All four bots” and “Delete my data” in the request center. Verify your Discord identity, specify the scope and follow the review. The final note should explain any retained essential records and external copies.
Your copy, your pace.
Keep this page, ask about a clause, or optionally record that you have read this version. Marking it as read does not change your privacy settings or waive any rights.
