Privacy Policy
Last updated: October 7, 2026
1. Information We Collect
Onyu (hereinafter "the Bot") collects the following information to provide its services.
- Discord user ID, nickname, and avatar URL
- Discord server (guild) ID and name
- Voice channel join/leave times, channel ID, and microphone status
- Co-presence records (which members were in the voice channel together)
- Newbie mission progress and Sprout Hunt records
- Natural-language queries an administrator submits to the management assistant, and the responses generated for them
- Server join timestamp and Discord account creation timestamp
2. How We Use Information
- Providing voice channel activity statistics (dashboard visualization)
- Classifying and managing inactive members
- Analyzing relationships between members (co-presence patterns)
- Providing newbie management and onboarding features
- Generating AI-based community analysis reports
- Providing the natural-language management assistant (interpreting query intent and summarizing analysis results)
- Aggregating join patterns for server safety (detecting anomalies such as bursts of joins in a short window or an influx of newly created accounts). Only server-level aggregate figures are produced; we do not score individuals for risk, label them as "problem accounts", or take automated action on them.
3. Third-Party Disclosure
To provide AI analysis features, the Bot transmits voice activity data to the Google Gemini API. Server-level analyses such as server diagnosis and weekly reports may include the display names of top members, channels, and pairs alongside aggregated activity durations, and personalized AI comment features (your personal comment card, best-friend card comments) transmit text containing the nicknames and role names of the member and their peers. Discord user IDs are not transmitted.
The natural-language management assistant transmits the administrator's raw query text to the Google Gemini API to interpret the request. If an administrator types a specific member's nickname into the query, that text may be transmitted along with it. For interpreting analysis results, only aggregated figures are transmitted — Discord user IDs and lists identifying individuals are not.
When an administrator chooses "Ask a follow-up" on an assistant response, the administrator's immediately preceding query text in the same server and the assistant's response to it (one exchange) are also transmitted to the Google Gemini API so the new question can be interpreted accurately (if the previous query included a member's nickname, that text is included). This reuses query and response history that is already retained, so no new information is collected for this feature; only a link indicating which earlier entry the follow-up continues is recorded with the history.
No personal information is shared with any other third parties.
4. Data Retention and Deletion
Raw (detailed) voice activity data, such as join/leave records, is retained for 90 days and then deleted, while daily aggregated data is retained for up to 1 year (365 days). Data past its retention period is automatically deleted daily.
Users may request deletion of their data at any time. After logging in to the dashboard, clicking the 'Delete My Data' button under My Page > Activity will immediately delete all voice activity records, AI comment history, and natural-language management assistant query and response history for that user.
Profile information of members who left a server (nickname, avatar) is retained for up to 365 days after departure and is then automatically anonymized.
AI-generated personal comment history is retained for up to 90 days to avoid repetitive wording, after which the text is automatically anonymized (entries an administrator has rated are retained for service quality improvement). Weekly server report history is retained for service quality improvement purposes.
Natural-language management assistant query and response history is retained for 365 days and then automatically deleted.
Server settings change history (the administrator who made the change, the time of the change, and the change content) is retained for 365 days for accountability purposes — to confirm who changed what and when — and is then automatically deleted. If you request data deletion, only the information identifying you is anonymized in that history, while the change history itself is retained for audit purposes.
You may opt out of game activity (currently-playing game) tracking at any time from the Games page on the dashboard (My Page > Games). Game activity is no longer collected after you opt out, and any previously stored game activity history can be removed separately via the data deletion request described above. Voice channel join/leave events and channel duration tracking are core service functions and are not covered by this opt-out.
5. Cookies
The web dashboard stores a JWT token in an httpOnly cookie for Discord OAuth2 authentication. This cookie expires after 1 hour and is immediately deleted upon logout. No tracking cookies are used.
6. Data Security
- All API communications are encrypted via HTTPS
- Authentication tokens are protected against tampering with JWT signatures
- Database access is restricted to the server's internal network
- API requests are protected by rate limiting
7. Contact
For inquiries regarding personal information processing or data deletion requests, please contact us through the inquiry channel on the official Onyu support server (https://discord.gg/SXezuaEm4b).