Privacy Policy
Last updated: September 20, 2026
1. Introduction
SummaryBot (“we,” “us,” or “our”) operates the SummaryBot Discord bot, the web dashboard at discordsummarybot.com, and related services (collectively, the “Service”). This Privacy Policy explains how we collect, use, store, and protect your information when you use our Service.
By using the Service, you consent to the data practices described in this policy. If you do not agree with this Privacy Policy, please do not use the Service. We encourage you to read this policy in its entirety and to also review our Terms of Service.
2. Information We Collect
We collect the following categories of information to provide and improve the Service:
2.1 Discord Data
- User IDs: Discord user identifiers for users who interact with the bot or sign in to the dashboard.
- Server (Guild) IDs: Identifiers for Discord servers where the bot is installed.
- Channel Names and IDs: Names and identifiers of channels configured for summarization.
- Message Content: The text content of messages in channels where summarization is enabled. Message content is read for the purpose of generating summaries and is sent to our AI provider for processing. To do this the bot uses only Discord's Server Members and Message Content privileged intents; it does not request the Presence intent and does not collect your online status or activity.
- Message Content in Exports: Separately from summarization, a server administrator can ask the Service to produce a CSV archive of that server's own message history — a single CSV file for one channel, or, for a whole server, a ZIP holding either one CSV per channel or one combined CSV. Message content read for an export is written directly into the export file: it is not sent to our AI provider and is not used to train any model. An export covers only the date range the administrator chooses, never includes channels opted out of processing, and never includes a channel that administrator cannot already read in Discord. The finished file goes only to the administrator who requested it: attached to their own private reply in Discord when it is small enough, and otherwise in the dashboard and by Discord DM, through a private download link that expires within 7 days and is re-issued only to that same administrator. The export file, and any copy of it held on the export record, are deleted 30 days after the export completes.
- User Display Names and Avatars: Used to display user information in the dashboard.
2.2 Integration Data
- OAuth Access Tokens: When you connect third-party services (Trello, Notion), we store OAuth tokens to maintain those connections.
- Webhook URLs: URLs you configure for receiving summary notifications.
- Board and Task Data: Information about Trello boards, Notion databases, and task data retrieved from those services in the course of syncing tasks.
2.3 Bot Feature Data
- Alert Keywords: If you set up smart alerts, we store your keyword patterns and associated Discord user ID to deliver notifications when matching messages appear.
- Board and Task Data: Task titles, descriptions, assignees, and board configurations created through SummaryBot's built-in kanban boards.
- Email Addresses: If you subscribe to daily email digests, we store your email address to deliver scheduled summary emails.
2.4 Dashboard and Account Data
- Authentication Data: Session tokens and authentication cookies used to maintain your dashboard login (via NextAuth).
- Billing Data: Payment-related information processed through Stripe. We do not store your full credit card number on our servers. Stripe handles payment processing in accordance with PCI-DSS standards.
2.5 Automatically Collected Data
- Usage Data: Basic analytics such as feature usage, command invocations, and error logs to help us improve the Service.
3. How We Use Your Data
We use the information we collect for the following purposes:
- AI-Powered Summarization: Message content from configured channels is sent to Google Gemini to generate summaries. Only message text and associated metadata (such as author display names and timestamps) necessary for generating useful summaries are transmitted.
- Task Synchronization: Extracted tasks and action items are synced to Trello and/or Notion when you have authorized those integrations.
- Webhook Delivery: Summary content is sent to webhook URLs you have configured.
- Email Digests: If you subscribe to daily email digests, summary content is compiled and sent to your email address via Amazon SES.
- Smart Alerts: If you configure keyword alerts, the bot monitors messages in your server to deliver relevant notifications via Discord DM.
- Dashboard Display and Document Export: Summary history, server configurations, and integration status are displayed in the web dashboard. Where Google Docs export is enabled for the Service, the content of an Intelligence Report is also uploaded to Google Drive as a document that anyone with the link can view and comment on.
- Service Improvement: Aggregated, anonymized usage data helps us identify and fix issues, improve performance, and develop new features.
- Billing: Processing subscription payments and managing your account through Stripe.
4. Data Storage and Security
We take the security of your data seriously and implement appropriate technical and organizational measures to protect it:
- Database: Data is stored in PostgreSQL hosted on Supabase, a managed database platform with access controls, authentication, and encryption at rest enabled. Message export files too large to attach in Discord, and every export that runs in the background, are stored separately in a private S3-compatible object storage bucket, reachable only through a signed link that expires within 7 days and is re-issued only to the administrator who requested the export.
- Token Encryption: Third-party OAuth tokens (Trello, Notion) are encrypted at rest using AES-256-GCM encryption before being stored in our database.
- Transport Security: All data in transit between your browser, the Discord bot, and our servers is encrypted using TLS/HTTPS.
- Access Controls: Access to production systems and data is restricted to authorized personnel and follows the principle of least privilege.
While we implement robust security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
5. Data Retention
How long we keep each kind of data, and what a server administrator can change:
- Default Retention: By default, summary content and associated data are retained indefinitely to provide continuous access to your summary history in the dashboard.
- Configurable Retention: Server administrators can ask us to set a retention period for a server, after which summary data older than that period is automatically purged. To set or change a retention period, contact us at [email protected].
- Raw Message Content: Raw Discord message content is processed in real time for summarization and is not retained afterwards; only the generated summary content is kept. The one exception is an administrator-requested message export: that file, and any copy of it held on the export record, are deleted 30 days after the export completes; what then remains of the export record — its status, counts and any error text, never message content — is deleted 90 days after the export completes.
- Account Data: Server configuration data and integration credentials are retained for as long as the bot remains installed in the server. Upon removal, the server's subscription record is deleted immediately; remaining configuration data and stored integration credentials are retained until you ask us to delete them at [email protected].
6. Third-Party Services
The Service relies on and integrates with the following third-party services. Each has its own privacy policy governing how they handle your data:
Google Gemini
Message content from configured channels is sent to Google Gemini's API for AI-powered summarization. Google processes this data in accordance with their API Terms of Service.
Trello (Atlassian)
When you connect a Trello integration, task data is synced between SummaryBot and Trello. Trello processes this data under Atlassian's Privacy Policy.
Notion
When you connect a Notion integration, task data is synced between SummaryBot and Notion. Notion processes this data under Notion's Privacy Policy.
Stripe
Payment processing is handled by Stripe. When you subscribe to a paid plan, your billing information is collected and processed by Stripe in accordance with Stripe's Privacy Policy.
Amazon SES (AWS)
If you subscribe to daily email digests, your email address and digest content are transmitted to Amazon Simple Email Service (SES) for email delivery. AWS processes this data under the AWS Privacy Notice.
Supabase
Our application data (summaries, configurations, user records) is stored in PostgreSQL databases hosted on Supabase. Supabase processes this data under Supabase's Privacy Policy.
Railway (object storage)
Message exports that are too large to attach in Discord, and every export that runs in the background, are stored as files in an S3-compatible object storage bucket hosted by Railway, our infrastructure provider, and are deleted 30 days after the export completes. Railway processes this data under Railway's Privacy Policy.
Sentry
We use Sentry for error monitoring and crash reporting. When errors occur, diagnostic data (stack traces, request metadata) may be sent to Sentry. No message content or personal data is intentionally included. Sentry processes this data under Sentry's Privacy Policy.
7. Data Sharing
We do not sell, trade, or rent your personal information to third parties. We share your data only in the following circumstances:
- AI Summarization Provider: Message content is sent to Google Gemini solely for the purpose of generating summaries.
- Authorized Integrations: Task data is shared with Trello and/or Notion, and newsletter content is delivered as a draft to GoHighLevel, only when you have explicitly authorized those integrations.
- Email Delivery: If you subscribe to email digests, your email address and digest content are shared with Amazon SES for delivery.
- Payment Processing: Billing information is shared with Stripe for processing subscription payments.
- Error Monitoring: Diagnostic error data (stack traces, request metadata) is shared with Sentry for crash reporting and service reliability.
- Legal Requirements: We may disclose your information if required to do so by law, regulation, legal process, or governmental request.
- Protection of Rights: We may disclose information when necessary to protect our rights, your safety, or the safety of others; to investigate fraud; or to respond to a government request.
8. Your Rights and Controls
Server administrators have the following controls over their data:
- Channel Opt-Out: Administrators can exclude channels, forums, or whole categories at any time through the dashboard or bot commands. An excluded channel is left out of every kind of processing: summaries, search, scheduled summaries, reports, newsletters, task detection, voice-call transcripts and message exports; excluding a category covers everything inside it.
- Retention Settings: Administrators can ask us to set a retention period for a server, after which older summary data is automatically purged. Contact us at [email protected] to set or change one.
- Data Purge: To have a server's stored summary data deleted, contact us at [email protected] and we will delete it. Deletion is permanent and irreversible.
- Disconnect Integrations: Third-party integrations (Trello, Notion) can be disconnected at any time through the dashboard, which revokes stored tokens.
- Email Unsubscribe: You can unsubscribe from daily email digests at any time using the
/digest unsubscribecommand, which stops all digest email to your address; to have the stored address itself deleted, contact us at [email protected]. - Bot Removal: Removing the bot from a Discord server stops all data collection for that server. Configuration data stays in our database until you ask us to delete it at [email protected].
9. GDPR and Data Protection Rights
If you are located in the European Economic Area (EEA), the United Kingdom, or another jurisdiction with applicable data protection laws, you have certain rights regarding your personal data:
- Right of Access: You have the right to request a copy of the personal data we hold about you.
- Right to Rectification: You have the right to request correction of inaccurate personal data.
- Right to Erasure: You have the right to request deletion of your personal data. Server administrators can exercise this right by contacting us at [email protected].
- Right to Restrict Processing: You have the right to request restriction of processing of your personal data under certain conditions.
- Right to Data Portability: You have the right to receive your personal data in a structured, machine-readable format.
- Right to Object: You have the right to object to processing of your personal data for certain purposes.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.
10. Cookies and Session Data
The SummaryBot web dashboard uses cookies for the following purposes:
- Session Cookies: We use session cookies (via NextAuth) to authenticate your dashboard sessions. These cookies are essential for the dashboard to function and cannot be disabled while using the dashboard.
- CSRF Protection Cookies: We use cookies to protect against cross-site request forgery attacks.
We do not use advertising cookies or third-party tracking cookies. The dashboard does not include third-party analytics scripts that set cookies.
11. Children's Privacy
The Service is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe that your child has provided personal information to us, please contact us at [email protected] so that we can take appropriate action, including deleting the information.
In accordance with Discord's own Terms of Service, users must meet the minimum age requirement to use Discord, which in turn is a prerequisite for using SummaryBot.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will update the “Last updated” date at the top of this page and, where practicable, provide additional notice through the Service.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data. Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the updated policy.
13. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Email: [email protected]
Website: discordsummarybot.com