Privacy, in plain language.

Before you connect anything. We sometimes build a community a support report it never asked for, to show what we would do. In that case we joined the server through its own public invite and read what any member can read. Nothing private, nothing behind a paywall, no DMs. If that isn't welcome, every report carries a link that deletes it and everything behind it, no reply needed, and we don't contact that community again.

What we read once connected: public messages in the channels the operator enables, and nothing else. Disable a channel and we stop reading it. The bot reads and posts as itself, never as a person, with the exact permissions shown on Discord's own consent screen: it can view those channels, read their history, and send the replies an operator has approved.

What we do with it: build the community's support report, ground Lumro's draft replies in the staff's own past answers, and keep the operator's approval history. Message content is sent to our configured model provider (OpenRouter) to generate drafts, and is not used to train models.

Who can see it: the community's operators, and any AI agent they explicitly connect with a token they can revoke at any time. Report pages are private, unguessable links.

Leaving: kick the bot and all posting stops immediately, though your history stays with us until you ask for it gone. The dashboard's “disconnect & delete” is the one that erases it: every message, draft, fact, and token we hold for that community, permanently.

Questions: python8u@gmail.com