# Nirupama Privacy Policy

Effective date: 2026-07-07

This Privacy Policy explains what data Nirupama collects, how it is used, and the choices available to users and server administrators. By inviting, configuring, or interacting with Nirupama, you acknowledge this policy.

## 1. Data Controller and Scope

Nirupama is operated by the bot owner and deployed as a Discord bot and related website. This policy applies to data collected through the bot, its command handlers, and the public website pages that reference these legal documents.

## 2. Data We Collect

Nirupama is designed to collect only the data needed to operate its features.

### 2.1 Discord identifiers and metadata

We may process Discord user IDs, guild/server IDs, channel IDs, message IDs, display names, usernames, timestamps, and command usage metadata. This is necessary to deliver commands, route responses, keep per-server settings, and generate statistics.

### 2.2 Message activity statistics

For activity tracking and graphing, Nirupama stores message counts aggregated by time period. The bot does not intentionally store full message content for this feature; it stores counts and related timestamps instead.

### 2.3 Conversation context for AI responses

When you mention or otherwise trigger the bot, Nirupama may keep a short rolling conversation context so it can respond coherently. In the current implementation, this context is limited to the last ten messages in the shared conversation history used for the AI feature.

### 2.4 User-provided content

If you send a command, mention the bot, attach an image, or otherwise submit content for processing, that content may be transmitted to the services used to generate the response.

### 2.5 Diagnostic and operational data

We may collect logs or operational data such as errors, uptime signals, command failures, and moderation-related events. This may include timestamps, server IDs, and limited technical metadata needed to keep the bot functioning.

## 3. How We Use Data

We use the data above to:

- respond to commands and mentions,
- generate AI responses,
- produce activity graphs and message counts,
- administer the bot and troubleshoot failures,
- maintain security and prevent abuse,
- show health and status information for the service.

## 4. AI Processing and Third-Party Services

Nirupama uses third-party services to provide some features.

### 4.1 Groq AI API

AI replies are generated using Groq's API. The text you send to the bot, and any context needed to answer it, may be transmitted to Groq for processing. If you attach an image to a supported AI interaction, that image URL may also be sent for model processing.

### 4.2 Supabase

Message activity data is stored in Supabase-backed tables to support graphs, totals, and related statistics.

### 4.3 GitHub Gist and monitoring providers

The public website may publish aggregate bot stats to a GitHub Gist and use monitoring providers such as Cronitor or Healthchecks for uptime reporting. These services are used for operational telemetry and generally rely on aggregate or non-personal data.

We do not intentionally sell personal data.

## 5. Legal Basis and Consent

Where applicable law requires consent or another lawful basis, the server owner, administrator, or person inviting the bot represents that they have the right to invite Nirupama into the server and that they will make members aware of this policy and the related terms. Users are responsible for reviewing these documents before interacting with the bot.

Nothing in this policy removes rights or obligations that cannot be waived under applicable law.

## 6. Retention

We keep data only as long as needed for the feature it supports or for legitimate operational purposes.

- Conversation context is kept on a rolling basis and older entries are overwritten.
- Activity totals and aggregate statistics may be retained longer-term so graphs and history remain useful.
- Logs and diagnostic records may be retained for a reasonable period to help with support, security, and debugging.

## 7. Sharing

We share data only with service providers that help run the bot, or when required by law, platform policy, or a valid request from an authorized party. Access is limited to what is reasonably necessary to operate the service.

## 8. Security

We use reasonable technical and organizational measures to protect data, but no online service is perfectly secure. You use the bot at your own risk.

## 9. Your Choices and Requests

If you are a server owner or user and want to ask about data associated with the bot, you may contact the bot owner through the support or contact information published on the website or bot profile. Requests may be limited by Discord's architecture, the data we are legally required to keep, and the data necessary for the bot to function.

## 10. Minors

Nirupama is not intended to knowingly collect data from children where that would violate applicable law. If you believe a minor's data has been processed inappropriately, contact the bot owner promptly.

## 11. Changes to This Policy

We may update this Privacy Policy from time to time. The website's terms gate may require renewed acceptance after material changes.

## 12. Contact

For privacy questions, contact the bot owner through the public project page or the contact method listed on the website.