Wallu - Privacy Policy

Last updated: July 27, 2026

The short version

  • Wallu answers questions in Discord servers. To do that, it reads and temporarily stores messages from channels it has access to.
  • Message content is kept for at most 30 days. Backups expire within another 30 days, so deleted content is completely gone from our systems within about 60 days.
  • We never train AI models on your messages or content - and neither do our AI providers.
  • Any Discord user can run /opt-out to stop Wallu from processing their messages, across all servers.
  • Questions or deletion requests? Email [email protected] or join our Discord.

The rest of this page explains everything in more detail. The short version is a summary - if anything conflicts, the detailed sections below apply.

Who we are

Wallu is an AI-powered support bot for Discord, operated by an independent developer (sole trader) registered in Finland (business details available on request). This policy covers the Wallu bot, our website (wallubot.com), the admin panel (panel.wallubot.com), and related services - it explains what we collect, why, and the choices you have.

What we collect

Depending on how Wallu is used and configured on a server, we may collect:

  • Discord server data: server name, channel names and IDs, member IDs, and message content from channels the bot has access to - what's needed to understand questions and answer them.
  • Content you upload: documents, FAQs, websites you ask us to index, imported channels, and anything else you add to the bot's knowledge base.
  • Panel login data: if you sign in to the admin panel, Discord shares your basic account info (ID, username, avatar) and your server list with us. We never see your password, and Discord doesn't give us your email.
  • Website usage data: standard server logs - IP address, browser type, pages visited, timestamps.
  • Account and billing info: if you subscribe, your name, email, and billing details (handled by our payment processors, Stripe and Paddle - we never see your full card number).
  • Referral data: which server referred you, so we can hand out referral credit rewards.
  • Anything you send us directly: support emails, bug reports, feedback.

Exactly what gets collected depends on the features each server has enabled (for example, Advanced Insights stores user questions to show admins what's being asked). Server admins configure this - ask them, or us, if you're unsure.

How we use your data

The main purpose is simple: to answer questions on Discord servers using the knowledge that server's admins have set up. We also use data to:

  • Operate, maintain, and improve the service (for example, evaluating how good the bot's answers are).
  • Detect and prevent abuse, fraud, and illegal activity.
  • Communicate with you about the service (support, important updates).
  • Process payments and referral rewards.

We do not train AI models on your messages or content. Your content is only used as context ("prompts") to generate answers on your own server. Our AI providers are bound by API terms that likewise prohibit training on this data.

We do not sell your personal data to anyone.

How long we keep message content

Message content is stored encrypted at rest, and we keep it on a short leash:

  • 30 days maximum. Message content is automatically deleted within 30 days - a hard limit built into the system.
  • Deleted on Discord = deleted here. We regularly re-check stored messages. If a message was deleted on Discord, or the bot lost access to the channel or server (including being removed), we delete our copy during that re-check - always within the same 30-day window.
  • Backups expire within another 30 days. So within about 60 days of a message being deleted (or the bot being removed), no trace of its content remains anywhere in our systems, including backups.

This applies to everything that stores message content, including optional features like Advanced Insights - they follow the same 30-day limit.

Exception - your knowledge base: content you deliberately add for the bot to answer from (uploaded documents, FAQs, indexed websites, channels imported as knowledge) is kept until you delete it, since deleting it automatically would break the thing you set up. You can remove it any time in the panel.

The bot also briefly holds messages in memory (RAM) while processing them - that's how it reads and answers in real time, and it's not long-term storage.

Our own servers and backups are hosted in the EU. System logs are kept for diagnosing issues and don't include message content as a rule.

Opting out and your controls

As a Discord user:

  • Run /opt-out in any server with Wallu. This is global - Wallu will stop processing and storing your messages on every server it's in. Run it again to opt back in.
  • Opting out stops new processing immediately. Anything stored before that still ages out within the normal 30-day retention window - or contact us if you want it gone right away.

As a server admin:

  • Limit which channels the bot can access on Discord - it can't store what it can't see. We recommend only giving it access to channels where it's actually needed.
  • Manage imported data and data-storage settings at panel.wallubot.com.
  • Remove the bot from your server - stored message content then follows the deletion timeline above.

Data deletion

When you remove the bot from your server, stored message content is deleted within 30 days (fully gone, including backups, within about 60), and imported channel content and any stored credentials (like custom bot tokens) are wiped on roughly the same timeline. Anything you delete through the panel is permanently removed within 90 days. If the bot simply stays removed, all remaining server data (knowledge base, settings, files) is automatically purged within 180 days - we keep it that long so you can re-add the bot without losing your setup.

Separately, activity logs tied to individual users (who asked, voted, or changed settings) are deleted or anonymized within 180 days everywhere, including on active servers - we don't keep a long-term log of who did what.

Want something gone faster, or want everything deleted? Contact us at [email protected] or on our Discord server and we'll handle it.

Third-party services we use

Wallu is built on top of a few third-party services. They process data under their own privacy policies and our agreements with them:

  • Discord - the platform the bot runs on.
  • OpenAI and Google (Gemini) - the AI providers that generate the bot's answers.
  • Perplexity - powers the optional web search feature. If a server admin has enabled it, questions may be sent to Perplexity to search the web for an answer.
  • Anthropic - we use their Claude models as internal AI tooling to operate, maintain, and develop the service, which can involve access to service data.
  • Hetzner - our hosting provider. Our servers and backups are in their EU data centers.
  • Stripe and Paddle - payment processing.
  • Cloudflare - CDN and website security.
  • Algolia - search on our documentation site (docs.wallubot.com).
  • Google/YouTube - our website may embed YouTube videos, which are subject to Google's privacy practices.

A note on the AI providers above: they don't train models on your data, but like most AI services may retain inputs for a limited time for abuse monitoring, and may process data outside the EU.

We may add or swap providers as the service evolves - anything new will handle data under equivalent protections. This policy doesn't cover third-party websites we link to; check their policies.

Treat the bot's knowledge as public. Anything you give Wallu to answer from (documents, imported messages, FAQs) can be repeated by the AI to anyone who can talk to the bot. Don't feed it passwords, personal data, or anything confidential.

Server admins are responsible for what the bot can access. By adding Wallu to your server and granting it access to channels or data, you confirm you have the rights and any needed consents to share that content, and you're responsible for telling your members how their data is used (linking this policy works). Anything the bot can access on Discord is considered in scope for its normal operation - we are not liable for issues caused by how you've configured its access.

Security

We take reasonable technical and organizational measures to protect your data: message content is encrypted at rest, data is encrypted in transit, and access is restricted. That said, no system is 100% secure - to the extent permitted by law, we're not responsible for security incidents that happen despite reasonable safeguards. If a breach affects your personal data, we'll notify affected parties without undue delay.

Your rights (GDPR, CCPA & friends)

If you're in the EEA or UK, the GDPR gives you the right to access, correct, delete, restrict, or export your personal data, and to object to its processing. You can also complain to your local supervisory authority. Our legal bases for processing are: performing our contract with you (running the service), our legitimate interests (security, analytics, improving features), and your consent where required (which you can withdraw at any time).

If you're a California resident, the CCPA gives you similar rights: to know what personal data we've collected, to have it deleted, and to opt out of its sale. As noted above, we don't sell personal data.

Some of our providers are outside the EEA/UK; where personal data is transferred internationally we rely on safeguards like Standard Contractual Clauses.

To exercise any of these rights, email [email protected].

Cookies and website logs

We keep cookies to a minimum: essential ones only, like the login session on the admin panel. We don't use third-party advertising or analytics cookies. You can control cookies in your browser; blocking them may limit some features (like staying logged in).

One specific cookie worth knowing about: wallu_referral is set when you visit through a referral link (like wallubot.com?r=123456) and accept the cookie prompt. It's stored for 30 days and used only to credit the referring server if you add the bot.

Like practically every website, our servers keep standard access logs (IP address, browser type, pages visited, timestamps) for analytics and site administration. These aren't linked to personally identifiable profiles.

Children

Wallu is not intended for children under 13 (or the minimum age required by Discord in your country), and we don't knowingly collect their personal data. If you believe a child has provided us personal information, contact us and we'll remove it promptly.

Business transfers

If Wallu is ever acquired or merged, your data may transfer to the new owner - who must keep protecting it under this policy or one at least as protective.

For server admins: data processing

If you run a server or business using Wallu, you're the data controller for your members' data and we act as your processor. The Data Processing Agreement (DPA) in our Terms of Service covers the details. If you provide us a custom Discord bot token, we use it exclusively to run Wallu's features on your server - nothing else.

Changes to this policy

We may update this policy from time to time - the "Last updated" date at the top always reflects the current version, and updates take effect when posted here unless we state a later date. For significant changes we'll aim to give notice (for example, via our Discord or the panel).

Contact us

Questions, concerns, or requests about your data? We're happy to help: