Privacy Policy
Lestapenna ("the Bot", "we") is a Discord application that records tabletop role-playing sessions in voice channels, transcribes them, and generates AI-powered narrative summaries. This policy explains what data we process and why.
1. Data we collect
- Voice recordings — captured per user, only while a recording session is explicitly active (started by a server member with the dedicated command). The Bot never records outside an active session.
- Transcriptions and derived content — text transcripts of the recordings and AI-generated summaries, character sheets, and campaign notes.
- Discord identifiers — server (guild) IDs, channel IDs, user IDs, and display names, used to organize campaigns and attribute speech.
- Email addresses — only if voluntarily provided to receive session recaps.
- AI provider keys — if you choose to use the public instance, the keys you enter are encrypted at rest with a key held by the operator and are never returned by any endpoint. You can replace or delete them at any time. If you self-host, they never reach us.
- Pictures you upload — portraits attached to a sheet and reference images attached to a campaign or a faction, plus any screenshot you choose to attach to a bug report. They are converted to WebP on arrival, and that conversion strips the embedded metadata: the camera details and, more to the point, the GPS coordinates a phone writes into a photograph do not survive it and are never stored.
- Usage metrics — session duration, tokens consumed per phase and the resulting estimated cost, so your table can see what its own AI usage costs it. There is no billing relationship with us, and these figures are not used to charge anyone.
What we do not collect. There is no payment or billing data of any kind, because there is nothing to pay for. There is also no analytics and no tracking: this project contains no Google Analytics, no Plausible, no Sentry, no advertising pixel and no behavioural profiling — a claim you can verify yourself, since the source is public.
2. Recording: how you know, and how you opt out
Recording never starts silently. A member of the server has to start it with a command, and while it runs the Bot makes it visible in three ways at once:
- Its nickname becomes
[REC] …in the voice channel's user list, for the whole duration. If it cannot display that marker, it does not record at all — an indicator that can be silenced is not an indicator, so the missing permission stops the session rather than hiding it. - A notice is posted in the channel saying what is recorded, what happens to it, and how to opt out. In full the first time on a server, in short form afterwards.
- The Bot's status says that it is recording.
To opt out, leave the voice channel. That is enough, and nobody has to justify it.
Server administrators remain responsible for telling the people at their table that sessions are recorded — the Bot makes it as visible as it can, but it cannot obtain consent on anyone's behalf.
2a. Your data, and how to act on it
You do not need to write to anyone or wait for a reply. From Discord, on the server in question:
$mydata($imieidati) sends you, in a private message, a machine-readable copy of everything we hold about you: your transcripts, your notes, your character sheet, your conversations with the Bard.$forgetme($dimenticami) erases it: your audio files, the transcripts of what you said, your notes, your questions and your character sheet. The session recaps and the campaign's world stay — they are the whole table's work, and they no longer contain anyone's words verbatim.- A server administrator can erase the entire server's archive with
$eraseserver($cancellaserver).
Removing the Bot from a server erases that server's data. Recordings, transcripts, recaps, campaigns and every stored file go, automatically and without anyone having to ask.
To have data corrected rather than deleted, ask the server administrator — they decide what is recorded and are the data controller — or write to the address in section 8. Campaign entries you edit by hand are marked as manual and are never overwritten by the AI afterwards.
3. How data is processed
Lestapenna works on a bring-your-own-key basis: the AI runs on accounts you hold, and the relationship for those calls is directly between you and that provider, under your contract with them. We pass your content to the provider you configured, and nothing more.
Each table chooses, for itself:
- Transcription — either a computer you own, running our transcription server, in which case the audio never reaches a third party; or a cloud model on your key, which receives the audio.
- Summaries, extraction and chat — a model on your key, which receives the transcript text.
- Campaign memory (embeddings) — your own hardware, or a model on your key, which receives the text being indexed.
- Pictures — when you have a portrait drawn, the image model on your key receives the prompt, and it receives an uploaded picture only for the references you tick for that specific request. Nothing is sent because it happens to be in the gallery: an unticked picture never leaves our storage.
The operator's own hardware is not used to process other tables' content.
4. Storage and retention
- Recordings and pictures are stored on object storage your own server provides. Each table connects a bucket on an account it holds — with the provider and region of its choosing — and from that moment its recordings and its generated pictures live there and nowhere else. The operator holds no copy. Nothing can be recorded until a server has connected one, because there is no shared storage to fall back to.
- How long the raw per-speaker audio is kept is your server's decision. By default it is deleted after 30 days, or as soon as the mixed session archive exists and the bucket is filling up — whichever comes first — and that runs automatically every night without anyone having to ask. A server administrator may change that period, or switch the automatic cleanup off entirely, in which case nothing is removed for you and the recordings stay on your bucket until you delete them yourself. That choice is recorded with who made it and when. Two things happen regardless, because neither is retention: temporary upload files left behind by an interrupted job are always swept, and a deletion you ask for is always carried out.
- Transcripts, summaries, and campaign data are retained for as long as the
server uses the Bot, so the campaign archive keeps working — and go when the
Bot is removed, when someone uses
$forgetme, or when an administrator erases the server. - Pictures are kept while the campaign they belong to exists. A sheet
holds at most 12 and a reference set at most 6, so uploading beyond that drops the
oldest. A picture drawn by the AI and never accepted is deleted after 7 days.
Deleting a picture, an entity, a campaign or a server deletes the stored
file itself, not merely the record pointing at it, and so does
$forgetmefor the pictures you uploaded. - Database backups are kept for 7 days, on the operator's own storage. The
database is the one place a table's words — the transcripts and the summaries —
still live on the operator's infrastructure rather than on the table's own
bucket: it is a single database, and it is what makes the web app work. It goes
the way everything else does, with
$forgetme, an administrator's erasure, or the Bot being removed.
5. Sharing and sub-processors
We do not sell personal data, and we do not share it for anyone's marketing or profiling. There is no advertising business here to sell it to.
The parties involved in running the public instance are, in full:
- Discord (Discord Inc.) — the platform the Bot lives on. Voice, identifiers and messages pass through it under Discord's own privacy policy. We send nothing back to Discord beyond what the Bot posts in your own channels: the recaps, the notices and the replies to commands. Discord holds those the way it holds any other message in your server.
- The storage provider you choose — Backblaze, Cloudflare, Scaleway, Oracle, Amazon, or anything else that speaks the S3 protocol, including a computer in your own home. It holds your recordings and your generated pictures under your account and your agreement with them, in the region you picked. We are not a party to it. Your credentials are encrypted at rest here and are never returned by any interface.
- Oracle Cloud Infrastructure — the server, in the EU (Milan region). It holds the database and its backups, and the bug reports with any screenshot attached to them. It holds no recordings and no generated pictures: those are on each table's own storage, and the ones made before that change were moved there and removed from here on 2 September 2026.
- The AI provider you choose — OpenAI, Google, Anthropic or Ollama Cloud, depending on what your table configures. It receives what that phase needs (audio, text, or the reference pictures you ticked) under your account and your agreement with them. We are not a party to it, and if you run everything on your own hardware there is no AI provider at all.
- Porkbun — outbound email, if you ask for session recaps by mail.
There is no other recipient. Self-hosting removes Oracle and Porkbun from this list as well: only Discord, your chosen AI provider and your own storage remain.
5a. A warning about free AI tiers
We never use your content to train any model, and we never let anyone else do so on our behalf. But because the AI runs on your key, one thing is outside our control and you should know about it: several providers train on the content submitted through their free tiers. Google's free AI Studio tier is the clearest example — content sent with a free key may be used to improve Google's products, including its models.
If that matters to your table, use a paid API key (where the major providers do not train on API content by default) or run the models on your own hardware. The Bot warns you about this where the key is entered.
6. Your rights (GDPR)
You have the right to access your data, to receive a copy of it, to have it corrected, and to have it erased. Section 2a says how to exercise each of them — mostly without asking anyone. For anything not covered there, or to complain, write to the address below; you also have the right to lodge a complaint with your national data protection authority.
7. Age
Lestapenna is not directed at children. In line with Discord's own Terms of Service, you must be at least 13 years old, or older where the law of your country requires it, to use the Bot or to appear in a recorded session. We do not knowingly process the data of anyone below that age; if you believe we have, write to us and it will be deleted.
8. Contact
Data controller: the operator of Lestapenna — info@lestapenna.quest