Skip to content
Decibot
Who it's for How it works Pricing FAQ Sign in
Add to Discord

Privacy Policy

Last updated: July 31, 2026

On this page
  1. Who we are
  2. Data we collect
  3. How we use your data
  4. Voice audio & AI processing
  5. Third-party processors
  6. Data retention
  7. Your recording responsibilities
  8. Your rights & data deletion
  9. Security
  10. Children
  11. Changes to this policy
  12. Contact

1. Who we are

Decibot ("Decibot", "we", "us", or "our") is a Discord bot and service operated by Actium LLC, a Massachusetts limited liability company, that records voice channels, transcribes them using AI, and delivers Markdown transcripts. This Privacy Policy explains what information we collect when you add Decibot to a Discord server and use it, how we use that information, and the choices you have.

By adding Decibot to a server or using its commands, you and the members of your server agree to the practices described here.

2. Data we collect

We collect only what we need to provide transcription and manage subscriptions:

  • Discord identifiers — Discord user IDs, usernames/display names, server (guild) IDs, and voice/text channel IDs of participants in an active recording session.
  • Voice audio — the audio of participants captured only while a recording is active (after /start or the Start control). Each speaker's audio is captured separately so the transcript can attribute speech. Users who have opted out with the /ignore command are never captured: Decibot does not open an audio stream for them at all, in any server.
  • Transcripts — the text generated from the audio, formatted as a Markdown document and delivered to your chosen Discord channel or DM.
  • Usage data — the duration of each recording and timestamps, used to enforce your plan's monthly minute limits.
  • Account & subscription data — your subscription plan, status, billing period, and a Stripe customer/subscription identifier. Payment card details are handled by Stripe and are never stored on our servers.
  • Preferences — settings you choose, such as transcript delivery (channel vs. direct message).
  • API keys — if you create keys for the agent (MCP) integration, we store only a cryptographic hash of each key, its name, and when it was last used; the key itself is shown once and never stored.
  • Website analytics — our website uses Cloudflare Web Analytics, a cookieless, aggregate measurement tool. It sets no cookies and uses no persistent identifiers, and we see only aggregate statistics — which is why our site has no cookie banner.

3. How we use your data

  • To join voice channels and record audio when a host starts a session.
  • To transcribe recorded audio into a Markdown transcript and deliver it.
  • To measure recording minutes and enforce subscription limits.
  • To process subscriptions, billing, and account status through Stripe.
  • To operate, maintain, secure, and improve the service.
  • To respond to support requests and comply with legal obligations.

We do not sell or share your personal data (including for cross-context behavioral advertising), and we do not use your audio or transcripts to train our own models.

3.1 Legal basis & our role (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (to provide the service to subscribers and to bill them), legitimate interests (to operate, secure, and improve Decibot and to prevent abuse), and compliance with legal obligations (tax, accounting, and responding to lawful requests). For the recording of participants in a voice channel, the host who starts a session is responsible for establishing an appropriate basis (typically the consent of participants) — see Section 7. For account and subscription data we act as a data controller; for the audio and transcripts generated at a host's direction we act as a processor on that host's behalf.

4. Voice audio & AI processing

Recorded audio is converted to a standard format and sent to OpenAI for transcription by their speech-to-text models. Under OpenAI's API data privacy terms, audio submitted via the API is not used to train OpenAI models, and OpenAI may retain API inputs for a limited period (typically up to 30 days) for abuse and misuse monitoring before deletion. We have a signed Data Processing Addendum with OpenAI. Your audio is processed by OpenAI subject to their policies. See OpenAI's policies for details on how they handle API data.

Decibot posts a clear, public status message in the text channel when it joins and while it is recording, so participants can see that a session is active. In addition, any user can opt out of being recorded entirely by running the /ignore command — the opt-out is global across servers, takes effect from their next utterance, and is enforced before capture, so an opted-out user's audio is never recorded rather than recorded and discarded.

5. Third-party processors

We rely on the following service providers to operate Decibot. Each processes data only as needed to provide their part of the service:

  • Discord — the platform the bot runs on (voice, messaging, identifiers). Subject to Discord's Privacy Policy.
  • OpenAI — transcription of recorded audio (speech-to-text models). See OpenAI policies.
  • Stripe — subscription billing and payment processing. See Stripe's Privacy Policy.
  • Supabase / PostgreSQL — database hosting for account, subscription, and usage records (DPA in place).
  • Railway — hosts the always-on bot and API process.
  • Cloudflare — serves our website and provides cookieless, aggregate site analytics.
  • Sentry — error monitoring. When something breaks, the error report can include technical context such as Discord IDs; request bodies are stripped before sending, and reports are retained by Sentry for a limited period (typically 90 days).

6. Data retention

  • Voice audio is transient. Raw and intermediate audio files are created only to produce a transcript and are deleted from our servers immediately after processing completes.
  • Transcripts are generated to be delivered to your Discord channel or DM. Once delivered, the copy that persists lives in your Discord under your control, and our working copy is removed. There are two exceptions, both time-limited to 7 days, after which deletion is automatic:
    • If we could not deliver it. When the bot is removed mid-session, your DMs are closed, or transcription fails, we hold the transcript for 7 days so you can download it from your account page. This is not optional and not a setting: it is your recording surviving our error. Nothing is kept when delivery succeeds.
    • If the server turned retention on. Someone with Manage Server permission can enable retention for a Discord server, which keeps a downloadable copy of that server's transcripts for 7 days. It is off unless enabled, it applies to everyone who speaks in that server's voice channels, and switching it off deletes the stored copies immediately.
    Stored transcripts are held in Cloudflare R2 (see §5) and are additionally expired by the storage provider after 8 days as a backstop. We never retain the audio itself in either case.
  • Usage logs (duration, timestamps) are retained to enforce plan limits and for billing accuracy, and are deleted when you delete your account.
  • Account & subscription records are retained while your account exists and are deleted when you delete your account; billing records that we are legally required to keep (tax and accounting) are retained by Stripe per their policies.

7. Your recording responsibilities

Recording other people may be regulated by law in your jurisdiction. You are responsible for ensuring that everyone in a voice channel is aware of and consents to being recorded before you start a Decibot session, and for complying with all applicable laws and with Discord's Terms. Decibot displays a visible recording notice, but that does not replace your obligation to obtain consent.

8. Your rights & data deletion

Self-serve, instantly: if you have signed in, your account page lets you export all data we hold about you (a JSON download) and permanently delete your account (which cancels any active subscription and erases your account, usage, and key records) — no email required.

You may also request access to, correction of, or deletion of your personal data by emailing [email protected] from an address you control, or with enough information for us to identify the relevant Discord account. We will process deletion upon verified request; audio is already deleted automatically after processing. If you spoke in a recorded session but do not have a Decibot account, any transcript containing your words is either already deleted or held for at most 7 days; email us with the server and approximate date and we will delete it sooner, and you may also ask the person who ran the recording, since the delivered copy in their Discord is outside our control. We do not discriminate against you for exercising any of these rights.

8.1 EEA/UK residents (GDPR)

If you are in the European Economic Area or the United Kingdom, you have the right to access your data, to request rectification or erasure, to restrict or object to processing, and to data portability. Where we rely on consent, you may withdraw it at any time. You also have the right to lodge a complaint with your local data protection authority. We transfer data to processors outside the EEA/UK (see Section 5) under appropriate safeguards such as the Standard Contractual Clauses.

8.2 California residents (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect and how we use it (see Sections 2 and 3), the right to access and delete that information, the right to correct inaccurate information, and the right to opt out of the sale or sharing of personal information. We do not sell or share personal information, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights. To exercise a right, contact us using the details above; you may use an authorized agent to submit a request on your behalf.

9. Security

We use reasonable technical and organizational measures to protect data, including encrypted connections to our processors and restricted API keys. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Children

Decibot is not directed to children. Discord requires users to be at least 13 years old (or older where required by local law). Do not use Decibot if you do not meet the minimum age.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will revise the "Last updated" date above and, where appropriate, provide additional notice. Continued use of Decibot after changes take effect constitutes acceptance of the updated policy.

12. Contact

Questions about this policy or your data? Email us at [email protected].

← Back to home
Decibot

© 2026 Actium LLC · decibot.tech · Transcription by OpenAI · Not affiliated with Discord Inc.

Home Privacy Terms Support Status [email protected]