Legal
Privacy Policy
How AvalynnAI collects, uses, and stores Discord account data, chats, diaries, memories, server lists, and voice or phone audio.
1. Overview
This Privacy Policy explains how AvalynnAI, LLC ("we," "us," or "our") collects, uses, discloses, and protects information when you use https://avalynn.ai, sign in with Discord, talk with the companion, read diaries or memories, invite the bot to a server, or use voice or phone features.
AvalynnAI, LLC is an independent company. AvalynnAI is built and maintained by members of the Grok user community. We are not affiliated with, endorsed by, or operated by SpaceX, SpaceXAI, the former xAI company, X Corp., or Discord Inc., except that we call their APIs as a customer/developer. Trademarks belong to their owners. Corporate history of xAI folding into SpaceXAI is summarized in our Terms of Service.
This policy covers avalynn.ai and the AvalynnAI Discord bot. It does not cover Discord itself or xAI/SpaceXAI.
By using the Service, you agree to this policy. If you do not agree, do not use it.
2. Who we are
The data controller for AvalynnAI is AvalynnAI, LLC, operator of avalynn.ai. For privacy requests, email privacy@avalynn.ai.
AvalynnAI chat, Discord replies, diaries, and memories are processed on infrastructure we operate so the website and the bot stay in character together. We do not use your companion chats, diaries, or memories for unrelated public catalogs.
3. Information we collect
3.1 Discord account (OAuth)
When you choose Login with Discord, we receive information Discord releases for the scopes you approve. Today that is identify and guilds:
- Discord user id, username, global display name, and avatar hash;
- A list of guilds you belong to, with your permission bits and owner flag, so we can show servers you own, administer, or hold a matching tool permission in;
- A short-lived OAuth access token, stored with your session so the Dashboard can refresh that list until the session ends or the token expires.
We do not store your Discord password. We currently do not request the email scope. If we add it later, we will update this policy and Discord's consent screen will show the new permission.
3.2 Website chat
- Messages you send and Avalynn's replies, kept as separate chat sessions you can reopen;
- Generated or attached media (images, video, audio) stored as files we can show again in the thread;
- Optional standing notes you write, including which ones are toggled on to send with every message;
- Timestamps and the internal chat id tied to your AvalynnAI user row.
3.3 Diaries
Avalynn may write diary notes about you (memory kind self). These are companion-authored, read-only in the product except for Reset bot, and can include inferences from website or Discord conversations. They are shown only to the signed-in Discord user they are about, and to people at AvalynnAI, LLC who need them to run or moderate the Service. Reset bot deletes diary entries about you.
3.4 Memories
Avalynn may store memories: short facts about your Discord account (memory kind user), plus tags and timestamps. You can read them. You cannot edit or delete a single memory in the UI. Reset bot wipes account memories and diary entries about you. Website chat history stays. New chats can write new memories and diary entries afterward.
People who never visit avalynn.ai but talk to the bot in Discord can still receive diary and memory records keyed by Discord user id. Logging in with that Discord account is how they review or reset those records.
Avalynn may also store channel memories (memory kind channel): notes about a Discord channel, such as a running joke, a decision, or what that room is for. On avalynn.ai those notes are shown only when Discord says you are a member of that server and AvalynnAI is in it. Anyone in the server who signs in can read them. They are not private to one account, and Reset bot does not delete them.
3.5 Servers you can manage
The Dashboard is built from Discord's /users/@me/guilds for your token. We keep only guilds where you are owner, Administrator, or Manage Server. We do not show you other users' servers. We may also note whether AvalynnAI is already a member of a guild you manage, using the bot's own membership list, so the invite button can say she is already in.
If you open Manage on a guild, we store the feature switches you set (moderation, channels, spam words, studio tools, and similar) keyed by that guild id, the Discord id of the last editor, and which account's wallet pays for credit features in that guild. We keep an audit of those setting changes. Tagged Discord messages from guilds you manage may be shown in Dashboard search, with search, tag, timeframe, and sort filters.
3.5b Wallet and codes
We store a usage wallet on your Discord id: starting credit, remaining credit, whether unlimited use is on, and a status of active, suspended, or banned. We keep a ledger of credit grants and spends (for example image or video). Redeem codes and which Discord ids used them are stored so a code cannot be reused past its limit.
If you save a phone number under Settings, we store it as +1 and the 10-digit number (for example +14075550100) on your account so a call from that number can be matched to you. Clearing the field removes it.
If you save a custom connector under Settings, on the MCP tab, we store its name and https address on your Discord id. The bot may call that connector only while it is talking to you. Another person's request does not use it. Removing the connector deletes that address.
3.6 Discord bot activity in guilds
If AvalynnAI is in a server, we may process:
- Message content and attachment metadata in channels the bot can read, when needed to reply or to run tools;
- Slash commands, reactions, and join/leave events we subscribe to;
- Voice channel audio when a voice feature is enabled and the bot is connected;
- Guild id, channel id, and Discord user ids involved in those events;
- Moderation and error logs for operators.
We do not sell guild message databases. Channel history the bot never needed for a reply may not be kept as a full archive. When a reply, diary, or memory is produced, the relevant text is stored.
3.7 Voice, phone, and audio (including features we add later)
When you use Discord voice, website voice, or a telephone number we publish (including numbers from console.x.ai / xAI voice):
- Audio of the session, which may be streamed live and may be recorded;
- Transcripts produced so the companion can reply;
- Call metadata: time, duration, direction, our number, your number or caller id, Discord voice channel id, disconnect reason;
- Synthetic speech we generate (Avalynn's voice, not a clone of your voice unless a future feature clearly asks you to enroll a voice sample).
Some laws (including Illinois BIPA and similar biometric rules) may treat voice recordings or voiceprints as biometric identifiers. We collect that audio only to provide the voice or phone feature, to debug it, to enforce the Terms, and to respond to lawful requests. We do not sell biometric identifiers and we do not use them for independent identification of strangers. Using a voice or phone feature is consent to this processing. If you do not consent, do not call, do not join voice with the bot, and do not enable website mic capture.
3.8 Automatically collected technical data
- Session cookie
ava_sid(HttpOnly, Secure, SameSite=Lax, about 30 days) to keep you signed in; - Server logs: IP address, user agent, URL, status code, timestamps, error traces;
- Security headers and CSRF-style OAuth state during Discord login.
We do not run third-party advertising pixels on avalynn.ai. We may load fonts from Google Fonts, which can see your IP address under Google's policies.
3.9 AI provider processing
Prompts, recent chat, relevant memories or diaries, and sometimes media or audio transcripts are sent to xAI / SpaceXAI (Grok, including grok-4.6 and voice models) so Avalynn can reply. That processing is under the provider's terms and privacy policy. We do not use your AvalynnAI data to train our own models. We cannot promise the provider will never train on API traffic; assume a third-party model provider can see what you send.
4. How we use information
We use information to:
- Sign you in and keep a session;
- Run website and Discord chat with the same companion settings;
- Write and show diaries and memories, and reset them for your account when you use Reset bot;
- List only the Discord servers you can manage, and produce invite links for those servers;
- Generate media and spoken replies you request;
- Operate voice and phone features, including transcription;
- Prevent abuse, debug outages, and secure the Service;
- Comply with law and enforce the Terms;
- Contact you about the Service when you email us, and, if you later pay, to process that purchase.
We do not use this information to build a third-party advertising profile, to train our own foundation models, or for cryptocurrency or token schemes.
5. Legal bases (EEA, UK, Switzerland)
Where GDPR or similar law applies, we rely on:
- Contract: providing the companion, diaries, memories, server list, and voice features you request;
- Legitimate interests: security, fraud and abuse prevention, keeping website and Discord personality aligned, limited operator debugging;
- Consent: Discord OAuth, microphone access, phone calls, and any biometric/voice processing that requires consent in your jurisdiction. You can withdraw consent by logging out, revoking Discord access, leaving voice, hanging up, and asking us to delete data. Withdrawal does not undo processing already done;
- Legal obligation: when we must keep or disclose records.
7. Grok, xAI, SpaceX, and SpaceXAI
AvalynnAI is not part of SpaceX or SpaceXAI. When chat, tools, media, or voice run:
- We send prompts, context (which can include memories or diary snippets), and sometimes files or audio-derived text to Grok APIs that may still be branded xAI (x.ai, console.x.ai) even though operations sit under SpaceX / SpaceXAI after the 2026 acquisition and restructuring;
- Those companies process that data under their own policies;
- We do not sell your data to them for training, and we do not train our own models on it;
- Phone numbers issued through their console, and voice models hosted by them, are third-party services we configure.
Read their published policies at x.ai and any SpaceXAI notices they post.
8. Discord-specific disclosures
Discord data is used to authenticate you, list servers you can manage, operate the bot, and key diaries and memories to a Discord user id. Message and voice content may be analyzed automatically to reply or to write memories.
Guild admins who add the bot should tell their members the bot is an AI companion that can store memories. Members can revoke the bot's access to a server by kicking it. You can revoke avalynn.ai's OAuth access in Discord Settings → Authorized Apps.
We never present one user's guild list to another user. We may see bot guild membership as needed to run the bot, which is different from the website Dashboard.
9. Voice and phone-specific disclosures
Voice and phone are optional. Website mic access is requested by your browser only if we ship in-page voice. Discord voice uses Discord's capture. PSTN calls use the public telephone network plus xAI/SpaceXAI.
Assume a voice or phone session is recorded and transcribed. Do not discuss information you would not type into chat. If another person might be recorded, get their consent first.
We are not a telephone carrier, 911 relay, or HIPAA provider. Call quality, number portability, and lawful intercept on the PSTN are outside our control.
If we retain recordings, we keep them only as long as needed to provide the feature, debug a report, or meet a legal hold, then delete or overwrite them in the ordinary course. Transcripts may live longer if they were written into chat, a diary, or a memory.
11. Retention and deletion
We keep data while your account is active and as needed to operate the companion, then delete or anonymize it when it is no longer needed, unless a legal hold applies.
- Account profile: until you ask us to delete the account or we close it;
- Sessions and Discord access tokens: until logout, expiry (about 30 days of inactivity for the session; Discord token expiry is shorter), or deletion;
- Website chat and media files: while the thread exists, and for a reasonable period after last activity unless you request deletion;
- Diaries: until you use Reset bot, we delete the account, or a verified diary-deletion request;
- Memories: until you use Reset bot, we delete the account, or a verified request asks us to wipe them;
- Guild lists: fetched live; we do not keep a historical map of every server you ever joined beyond logs and invite actions;
- Guild feature switches and custom spam words: until you change them, kick the bot, or we delete the guild row;
- Wallet, ledger, and redeem-code uses: while the account exists, and for a limited period after a ban if we need to stop reuse;
- Voice/phone recordings: as short as practical for the feature; transcripts that became chat/diary/memory follow those stores;
- Server logs: rotated on a limited window unless needed for a security investigation.
Deletion on our systems is intended to be permanent for everyday use. Residual copies can exist briefly in backups or caches and are not kept so we can rebuild your companion profile.
12. Your rights and choices
You are responsible for what you type, say, and upload. Keep your own copies of anything important.
Depending on where you live, you may have rights to access, correct, delete, or export personal information, to object to or restrict some processing, and to withdraw consent.
- Logout: ends the website session;
- Revoke Discord OAuth: Discord Settings → Authorized Apps;
- Reset bot: in-product button; wipes account memories and diary entries about you. Website chat stays;
- Diaries: read only in the product; Reset bot clears them, or email us to request deletion;
- Kick the bot: any guild you administer;
- Account deletion: email privacy@avalynn.ai from a context that lets us verify the Discord id. We will delete profile, session, chat, diaries, and memories we control, subject to legal exceptions;
- Voice: hang up, leave the voice channel, or refuse mic permission.
We will respond to verified requests within the time applicable law requires. We may decline where an exception applies (for example, we cannot un-send a bot message already delivered in Discord, and we may keep limited records of a ban).
13. California (CCPA / CPRA)
California residents may request to know categories and specific pieces of personal information, request deletion or correction, and opt out of "sale" or "sharing" as those words are defined in California law.
AvalynnAI does not sell personal information for money and does not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes Cal. Civ. Code § 1798.121 treats as requiring a limit-use right beyond providing the Service you asked for. Voice audio is used only for the voice or phone feature.
To exercise rights, email privacy@avalynn.ai. We will not discriminate against you for exercising privacy rights. If we designate an authorized-agent process, we will say so here.
We do not have actual knowledge that we sell or share personal information of consumers under 16.
14. EEA, UK, and Switzerland
You may lodge a complaint with your local supervisory authority. Legal bases are in Section 5. International transfers are in Section 16. Where we rely on consent, you may withdraw it without affecting earlier processing.
We do not use solely automated decision-making that produces legal or similarly significant effects about you. Companion replies, diaries, and memories are automated, but they do not grant or deny credit, employment, housing, or a legal right.
15. Children
AvalynnAI is for people 18 and older. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. We also do not knowingly create companion accounts, diaries, memories, or voice sessions for anyone under 18.
If you believe a minor has used the Service, email privacy@avalynn.ai. We will take steps to delete the data.
16. International transfers
The Service is operated from the United States. If you use it from another country, your information is transferred to and processed in the U.S. and in other countries where Discord, xAI/SpaceXAI, and our hosts run, which may have different data-protection laws than your home.
Where a transfer mechanism is required, we rely on the provider's published clauses or on the necessity of the transfer to perform the contract you requested (a companion chat or a phone call).
17. Security
We use HTTPS, session cookies with Secure and HttpOnly flags, restricted storage directories, and access control for operator tools. Discord bot tokens and xAI keys are kept as secrets. No method of transmission or storage is perfectly secure. You send personal and sometimes intimate text to an AI companion at your own risk.
18. Changes
We may update this Privacy Policy. The effective date at the top will change when we do. Material changes may also be noted on avalynn.ai. Continued use after an update is acceptance of the revised policy.
19. Contact
The data controller is AvalynnAI, LLC.
Privacy: privacy@avalynn.ai
Legal: legal@avalynn.ai
Support, webmaster, and feedback: avalynn@avalynn.ai
Terms of Service: https://avalynn.ai/terms
Website: https://avalynn.ai