CordAI — Privacy Policy

Last updated: 29 June 2026

This Privacy Policy explains how CordAI (the “Bot”, “we”, “us”), operated by j4tz, processes information when you add it to or interact with it on a Discord server. We are committed to data minimisation and to complying with applicable data-protection laws — including the EU General Data Protection Regulation (GDPR), the ePrivacy Directive, the UK GDPR, Brazil’s LGPD and the California CCPA/CPRA — as well as the Discord Developer Terms of Service and the Discord Developer Policy.

1. Information we process

The Bot does not read or store the general message history of your server, and it does not request the privileged “Message Content” intent.

2. How we use this information

We process the above solely to (a) execute the management actions you request (creating or editing channels, roles, permissions, webhooks, tickets, etc.), and (b) operate, secure and debug the service. We use Discord data only as necessary to provide CordAI’s stated functionality. We never sell your data, and we never share it with data brokers, advertising networks, profiling services or any other monetisation service.

3. Legal bases (GDPR Art. 6)

We rely on: performance of a service you request (Art. 6(1)(b)); your consent, given by choosing to use the Bot (Art. 6(1)(a)); and our legitimate interest in operating and securing the service (Art. 6(1)(f)).

4. Third-party services

No AI/ML training on Discord data. CordAI does not use any data obtained through Discord to train artificial-intelligence or machine-learning models. The only data sent to OpenAI is the command text you explicitly provide when invoking the Bot, used solely to generate the action you requested (inference). OpenAI does not use data submitted through its API to train its models.

5. Data retention

Conversational context is kept only in memory for the duration of an interaction and is discarded afterwards; CordAI does not maintain a long-term database of your messages. Operational logs are kept only as long as needed for security and debugging and are then deleted. If the Bot is removed from a server, any data specific to that server is deleted within a reasonable timeframe.

6. International transfers

Some processors (e.g. OpenAI) may process data outside the European Economic Area, including in the United States. Such transfers rely on appropriate safeguards (e.g. Standard Contractual Clauses or an adequacy decision) as provided by those processors.

7. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict or object to the processing of your personal data, and to data portability. You can request modification or deletion of your data at any time by contacting us, and we will action it within a reasonable timeframe. You may also lodge a complaint with your local supervisory authority (in Spain, the AEPD).

8. Children

The Bot is not directed at children under the minimum age required to use Discord in their country (at least 13). We do not knowingly process data of children below that age.

9. Security

We apply reasonable technical and organisational measures to protect the limited data we process, including restricting who can command the Bot and keeping credentials out of source control.

10. Changes to this policy

We may update this Privacy Policy. The “Last updated” date above reflects the latest version; material changes will be reflected on this page.

11. Contact

For privacy questions or to exercise your rights, contact contact@j4tz.es.