Kokosik — Privacy Policy

Last updated: 14 August 2026 · Applies to the Discord application Kokosik

Kokosik is a self-hosted, private Discord assistant operated by an individual. It is not offered to the public, and only people on its allow-list can use it. This policy explains what data the bot handles, why, where it goes, and how long it is kept.

1. Who operates Kokosik

Kokosik is operated by Bohdan Petrenko ("the operator", "we"), acting as the data controller. The bot runs on a private server under the operator's sole control. There is no company, no third-party staff, and no commercial use.

Contact for any privacy question or request: contact@rup.rocks.

2. Scope

This policy covers the Kokosik Discord bot only. It does not cover Discord itself — your use of Discord is governed by Discord's Privacy Policy.

Kokosik is installed in two Discord servers: the small private server of under 100 members it was built for, and the community server of the Runic Library game project, where it was added for that project's team. It has no public invite link.

Access is deny-by-default in both. Nobody can invoke the bot unless a manager has explicitly added them to its allow-list, by user ID or by role. If you are not on that list, the bot refuses your request before reading, storing or transmitting anything you sent. Managers can also deny individual users and roles outright, or switch on a lockdown mode that restricts the bot to managers alone. Within each server the bot operates only in the channels designated for it.

3. When Kokosik reads anything at all

Kokosik does not silently monitor, archive, or index the server. It has no message database, and it does not copy channel history anywhere. It processes content only in these situations:

4. What data is processed

DataWhy
The text of a message you send to the bot, and its image attachments or image linksTo understand and answer your request
The text of a message you reply to when invoking the botSo requests like "translate this" or "explain this" have their subject
Messages the bot fetches on demand from a channel or search, at a user's explicit requestTo answer questions about recent conversation, find a message, or summarise a discussion
Your voice audio while the assistant is actively listening after its wake wordTo transcribe your spoken request
Your Discord user ID, username, display name, server nickname, roles, and voice-channel stateTo address you correctly, and to apply access rules and permission checks
The server's member list with each member's roles, fetched on demand at a user's explicit requestTo answer questions such as "who has the Admin role?" and to find a member whose name is only partly remembered
Server and channel IDs and namesTo give the assistant context about where it is
Token-usage counters per request (numbers only, no content)To monitor cost and detect misuse
Notes ("memories") the assistant is asked to rememberTo recall facts and preferences across conversations

Kokosik does not collect email addresses, payment details, IP addresses, or precise location. It does not request Discord's Presence privileged intent and never receives or stores your online status, activity, or what you are playing.

Member lists are read only at the moment a user asks a question that needs them, and only to produce that one answer. The bot does not keep a roster, does not track joins and leaves, and does not subscribe to member-update events.

5. Where data goes outside Discord

To generate answers, Kokosik sends the content of your request — and anything it fetched from Discord in order to answer it, which may include message content or member names and roles — to third-party AI providers over an encrypted connection:

Wake-word detection and speech synthesis run entirely on the operator's own machine and are never transmitted to any third party. Audio captured before the wake word is not sent anywhere.

No data is sold, rented, shared for advertising, or disclosed to anyone else, except where the operator is legally compelled to do so.

6. Is my data used to train AI models?

No. The operator does not train, fine-tune, or evaluate any model on your messages, voice, or any other data from the server, and both providers above are contractually barred from training on it.

7. What is stored on the operator's server, and for how long

Deleted automatically after 30 days

Kept until deleted on request

Data held by the AI providers is subject to their own 30-day windows described in section 5. Files the bot posts into Discord (such as a saved recording) remain in Discord and are governed by Discord's own retention; anyone with permission in the channel can delete them.

Everything is stored on a private server, on an encrypted connection to the database, and is accessible only to the operator.

8. Your choices

Not using it

You are excluded already unless somebody put you on the allow-list. If a manager has not added you or one of your roles to it, the bot refuses everything you send it and processes nothing of yours.

Even if you are on the list, Kokosik never acts on its own. If you do not mention it, do not post in its channel, do not trigger an activation pattern, and do not speak to it in voice, it does not process your messages.

Opting out entirely

Ask a server manager to add you to the bot's deny list (/access-userAdd to Blacklist), or write to the address in section 1. Once you are on that list the bot refuses every request from you, in text and in voice, before any of your content is processed or sent anywhere.

To be transparent about the limit of this: opting out stops the bot from acting on your requests and from processing what you send it. It does not retroactively remove your past messages from a channel that another user may later ask the bot to summarise. If you want your messages excluded from that as well, contact the operator and it will be arranged.

Access and deletion

You may ask what the bot has stored about you, ask for it to be corrected, or ask for it to be deleted. Requests are handled personally and normally within 30 days. There is no charge.

If you are in the EU/EEA or the UK

Processing is based on legitimate interest in operating a private assistant for a small community, and on your voluntary act of invoking it. You have the rights of access, rectification, erasure, restriction, objection, and portability, and the right to lodge a complaint with your local data protection authority.

9. Security

The bot runs on private servers maintained by the operator. Stored data is held on block storage that the hosting provider encrypts at rest. Traffic to Discord and to the AI providers is encrypted in transit over HTTPS, and the bot's connection to its database requires TLS. API credentials are held in configuration files outside version control. Access to the machines and to the database is limited to the operator. No system is perfectly secure, and no guarantee of absolute security is offered.

10. Children

Kokosik is not directed at children. Discord requires users to be at least 13, or older where local law demands it. If the operator learns that data belonging to a child below the applicable age has been stored, it will be deleted.

11. Removal of the bot

If Kokosik is removed from the server, its stored memories, configuration, and usage records for that server are deleted within 30 days.

12. Changes

This policy may be updated. Material changes will be announced in the server channel where the bot operates, and the date at the top of this page will change.

13. Contact

Questions, access requests, and deletion requests: contact@rup.rocks.