1. Who this covers
This policy applies when you use the hosted Maxwell Discord bot, the website at maxwell.z3ki.dev, or sites Maxwell generates on that origin. If you run your own Maxwell, you are the operator of that copy — this page does not bind you and does not describe your server.
2. What we collect
Depending on how you use the hosted bot, the operator may process:
- Discord user IDs, usernames, display names, and server/channel IDs
- messages, attachments, stickers, and reply context when Maxwell is in the room or you talk to it
- slash-command / user-install payloads if you use those surfaces
- audio and other supported media attachments you explicitly send; Maxwell does not join voice channels or record calls
- memory the bot stores about you and the channel (RAG/vector store, long-term facts, knowledge-graph entities)
- generated sites, images, and files you ask it to publish
- operational logs: request IDs, timestamps, tool traces, error reports — usually not a second full copy of private message text, but IDs and state are still personal data
- usage-meter records: Discord user ID, server ID, and timestamps for counted AI use, used to calculate current usage and enforce limits; this ledger does not duplicate message text
- Legal notice delivery records (Discord user ID and when the DM was sent)
Personal preferences, including language, reply style, context size, and reply visibility, are stored by Discord user ID. If you use bring your own key, your provider, model choice, and encrypted API key are stored so Maxwell can send your authorized requests to that provider. You can remove the saved key in /config. Operator login credentials and bot tokens are separate from ordinary user preferences.
3. Why we process it
To run the bot you asked to talk to: generate replies, remember context, run tools, moderate abuse, debug outages, enforce these Terms, calculate usage-meter percentages, manage current limits, and (later) apply a paid plan. Legal basis where GDPR-style rules apply: you asked for the service (contract / steps at your request) and the operator's legitimate interest in operating, securing, and maintaining the service.
4. Model providers and other processors
Prompts, relevant memory, and attachments Maxwell needs for a turn are sent to whatever AI, embedding, image, search, or media-processing provider the operator has configured (for example an OpenAI-compatible API). Those companies see what the bot sends them. Discord already has the messages. Generated-site visitors hit the public origin, not Discord.
Providers have their own retention, review, and training policies, which may differ by provider and account settings. A private Discord reply does not prevent provider processing. Do not paste passwords, private keys, or other people’s private data into a request. Operators may review relevant content or logs to investigate errors, security issues, or abuse.
5. Where it lives
Application data lives in the operator's data/ directory and related databases on the host that runs Maxwell. Public Alpha means backups may be incomplete and wipes may happen.
6. Retention
Memory and logs are kept while they are useful to operate the bot, then deleted or overwritten as the operator rotates storage. Rolling-window usage records are deleted after they fall outside the current window when that account is next checked or uses the bot; an inactive account's expired rows may remain until then. Generated sites may expire on a timer or be deleted by you or the operator. Legal notice records are kept so we do not send duplicate DMs. There is no multi-year archive promise.
7. Sharing
We do not sell your data. We share it with processors needed to run the service (Discord, AI, image, search, and media-processing APIs, the host/network). We may share information if required by law, to stop abuse, or if the hosted project is handed to a successor who keeps this policy in spirit.
8. Your choices
Stop using the bot. Leave servers that have it. Contact the operator to request deletion of stored memory tied to your Discord user ID. Include that ID and enough context to identify the data. Deletion from active storage may not remove provider-held logs or copies in backups. Do not post private messages, credentials, or other sensitive information in a public GitHub issue. See the contact page.
Visibility controls. Choose Private in /maxwell or save it under /config → Default visibility. This controls who can see the reply in Discord. Public is the default. You can also reduce or disable recent channel context in /config or for a single command. Changing reply visibility does not remove earlier public replies or delete stored data.
9. Children
The hosted service is not directed at children under 13 (or the Discord minimum in your country). Do not use it if you are under that age.
10. Cookies
The public site has no legal agreement storage or advertising cookies. There is no browser admin dashboard or dashboard login storage.
11. International
The host and model providers may be in other countries. If you use the hosted bot, you understand your data may leave your country.
12. Changes
This policy can change. The version on this page is current. Changes are posted here.
13. Contact
See Contact for support and privacy requests, or the source repository for public project issues. Also see the Terms of Service.