Last updated: July 27, 2026
/opt-out to stop Wallu from processing their messages, across all servers.The rest of this page explains everything in more detail. The short version is a summary - if anything conflicts, the detailed sections below apply.
Wallu is an AI-powered support bot for Discord, operated by an independent developer (sole trader) registered in Finland (business details available on request). This policy covers the Wallu bot, our website (wallubot.com), the admin panel (panel.wallubot.com), and related services - it explains what we collect, why, and the choices you have.
Depending on how Wallu is used and configured on a server, we may collect:
Exactly what gets collected depends on the features each server has enabled (for example, Advanced Insights stores user questions to show admins what's being asked). Server admins configure this - ask them, or us, if you're unsure.
The main purpose is simple: to answer questions on Discord servers using the knowledge that server's admins have set up. We also use data to:
We do not train AI models on your messages or content. Your content is only used as context ("prompts") to generate answers on your own server. Our AI providers are bound by API terms that likewise prohibit training on this data.
We do not sell your personal data to anyone.
Message content is stored encrypted at rest, and we keep it on a short leash:
This applies to everything that stores message content, including optional features like Advanced Insights - they follow the same 30-day limit.
Exception - your knowledge base: content you deliberately add for the bot to answer from (uploaded documents, FAQs, indexed websites, channels imported as knowledge) is kept until you delete it, since deleting it automatically would break the thing you set up. You can remove it any time in the panel.
The bot also briefly holds messages in memory (RAM) while processing them - that's how it reads and answers in real time, and it's not long-term storage.
Our own servers and backups are hosted in the EU. System logs are kept for diagnosing issues and don't include message content as a rule.
As a Discord user:
/opt-out in any server with Wallu. This is global - Wallu will stop processing and storing your messages on every server it's in. Run it again to opt back in.As a server admin:
When you remove the bot from your server, stored message content is deleted within 30 days (fully gone, including backups, within about 60), and imported channel content and any stored credentials (like custom bot tokens) are wiped on roughly the same timeline. Anything you delete through the panel is permanently removed within 90 days. If the bot simply stays removed, all remaining server data (knowledge base, settings, files) is automatically purged within 180 days - we keep it that long so you can re-add the bot without losing your setup.
Separately, activity logs tied to individual users (who asked, voted, or changed settings) are deleted or anonymized within 180 days everywhere, including on active servers - we don't keep a long-term log of who did what.
Want something gone faster, or want everything deleted? Contact us at [email protected] or on our Discord server and we'll handle it.
Wallu is built on top of a few third-party services. They process data under their own privacy policies and our agreements with them:
A note on the AI providers above: they don't train models on your data, but like most AI services may retain inputs for a limited time for abuse monitoring, and may process data outside the EU.
We may add or swap providers as the service evolves - anything new will handle data under equivalent protections. This policy doesn't cover third-party websites we link to; check their policies.
Treat the bot's knowledge as public. Anything you give Wallu to answer from (documents, imported messages, FAQs) can be repeated by the AI to anyone who can talk to the bot. Don't feed it passwords, personal data, or anything confidential.
Server admins are responsible for what the bot can access. By adding Wallu to your server and granting it access to channels or data, you confirm you have the rights and any needed consents to share that content, and you're responsible for telling your members how their data is used (linking this policy works). Anything the bot can access on Discord is considered in scope for its normal operation - we are not liable for issues caused by how you've configured its access.
We take reasonable technical and organizational measures to protect your data: message content is encrypted at rest, data is encrypted in transit, and access is restricted. That said, no system is 100% secure - to the extent permitted by law, we're not responsible for security incidents that happen despite reasonable safeguards. If a breach affects your personal data, we'll notify affected parties without undue delay.
If you're in the EEA or UK, the GDPR gives you the right to access, correct, delete, restrict, or export your personal data, and to object to its processing. You can also complain to your local supervisory authority. Our legal bases for processing are: performing our contract with you (running the service), our legitimate interests (security, analytics, improving features), and your consent where required (which you can withdraw at any time).
If you're a California resident, the CCPA gives you similar rights: to know what personal data we've collected, to have it deleted, and to opt out of its sale. As noted above, we don't sell personal data.
Some of our providers are outside the EEA/UK; where personal data is transferred internationally we rely on safeguards like Standard Contractual Clauses.
To exercise any of these rights, email [email protected].
Wallu is not intended for children under 13 (or the minimum age required by Discord in your country), and we don't knowingly collect their personal data. If you believe a child has provided us personal information, contact us and we'll remove it promptly.
If Wallu is ever acquired or merged, your data may transfer to the new owner - who must keep protecting it under this policy or one at least as protective.
If you run a server or business using Wallu, you're the data controller for your members' data and we act as your processor. The Data Processing Agreement (DPA) in our Terms of Service covers the details. If you provide us a custom Discord bot token, we use it exclusively to run Wallu's features on your server - nothing else.
We may update this policy from time to time - the "Last updated" date at the top always reflects the current version, and updates take effect when posted here unless we state a later date. For significant changes we'll aim to give notice (for example, via our Discord or the panel).
Questions, concerns, or requests about your data? We're happy to help: