Privacy Policy
Last updated September 18, 2026
This Privacy Policy (the "Policy") describes how People Make Things, Inc. ("People Make Things," "Company," "we," "us," or "our"), the operator of the Discap Discord application (the "Bot") and the website at discap.bot and its subdomains (the "Website," and together with the Bot, the "Service"), collects, uses, stores, discloses, and otherwise processes information that relates to an identified or identifiable person ("Personal Data"). It is written to meet the transparency obligations of the EU General Data Protection Regulation ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended ("CCPA"), and other applicable privacy laws, to the extent they apply to the processing described here.
Discap records, transcribes, and summarizes voice conversations in Discord servers. Voice conversations are personal, and this Policy is deliberately specific about what happens to them, including our use of recordings and transcripts to train AI models (Section 6.1). Please read it.
1. Introduction and Scope
This Policy applies to everyone whose Personal Data is processed through the Service: server owners and administrators who add or configure the Bot ("Server Administrators"), people who speak or are present in a voice channel while Discap is connected ("Participants"), people who use Discap's commands or receive its messages, visitors to the Website, and anyone who is mentioned or discussed in a recorded conversation. It should be read together with the notices Discap shows inside Discord, such as the recording card posted when it joins a call, which form part of this Policy.
2. Definitions
"Meeting Content" means, collectively, the audio Discap captures in a Discord voice channel, the transcripts derived from that audio, and the outputs generated from those transcripts, including summaries, decisions, action items, open questions, answers to questions about past calls, statistics, and related metadata. "Controller" means the entity that decides the purposes and means of processing; for the Service, the Controller is the Company. "Processor" means a provider that processes Personal Data on our behalf. "Training Program" means the AI-model development described in Section 6.1.
3. Personal Data We Collect
What we collect depends on how you interact with the Service. The categories below are not exhaustive, but they describe the Service as it works today.
3.1 Discord account and server data
Discord user IDs, usernames, display names, avatars, and the roles and permissions that are visible to the Bot. Server (guild) IDs, names, member counts, preferred locale, channel IDs and names, voice-channel membership and join/leave times, and the configuration choices made for the Bot. When the Bot is added to or removed from a server, we may read the server's audit log to identify the administrator who added or removed it, so that we can send setup messages and understand why servers leave.
3.2 Meeting Content
When Discap is connected to a voice channel it captures each Participant's audio separately, in short segments, including non-speech sounds such as laughter and background noise picked up by a microphone. After a call, we assemble a combined recording and per-speaker audio tracks from those segments. We generate speaker-labeled transcripts that record the words spoken, which Discord user spoke them, and when. From transcripts we generate summaries, decisions, action items, open questions, answers to /ask questions, and statistics such as talk time and /wrapped recaps. We do not record video or screen sharing. Discord does not deliver video streams to bots.
3.3 Commands, messages, and feedback
The commands you run and their inputs, including questions you ask with /ask; text you submit through /feedback or ratings, which is delivered to our operations team inside Discord; and the first 300 characters of text-channel messages that @mention Discap, so that the Bot can respond. Discap does not otherwise read your server's text messages.
3.4 Usage and diagnostic data
Event logs, error reports, latency and reliability measurements, feature usage, and similar operational data generated when the Bot runs.
3.5 Website, analytics, advertising, and attribution data
On the Website: page views, referrers, browser and device information, approximate location derived from your IP address, campaign parameters, advertising click identifiers (for example Meta's fbc/fbp and Reddit's rdt_cid), analytics identifiers, and messages you send through the website chat. When you click "Add to Discord," your IP address and user agent are forwarded to Reddit's conversion measurement service and used for attribution; we do not store your IP address ourselves. If you add the Bot after clicking a link or advertisement, we associate the installation and later product milestones (such as the first completed call) with the identifiers from that click, so we can measure which channels bring servers that get value from Discap.
3.6 Support and communications data
The contents of your messages to us through the website chat, our Discord support server, or email, and any Personal Data you include in them. If your server votes for or rates Discap on Top.gg, Top.gg sends us the Discord user ID of the voter.
3.7 Personal Data about other people
Recorded conversations naturally include Personal Data about every Participant, and may include information about people who are discussed but not present. Server Administrators and Participants are responsible for having an appropriate basis for the Personal Data about others that they introduce into a recorded call (see the Terms of Service).
3.8 Records of notices, choices, and exclusions
We keep records of the notices Discap posted, the choices you made (such as /optout, Stop, Discard, and recap-DM mutes), deletion requests, and the dataset lineage needed to keep excluded audio and transcripts out of the Training Program. These records are kept separate from training inputs.
4. Sources
We collect Personal Data directly from you (commands, settings, feedback, website chat); automatically through the operation of the Bot and the Website (audio capture, logs, analytics); from Discord, which delivers voice audio, account, and server information to the Bot through its API; from other Participants and Server Administrators, whose calls and settings include data about you; and from advertising platforms and Top.gg, which report clicks, conversions, and votes.
5. Recording, Notice, and Your Choices
5.1 When Discap records
By default, once a Server Administrator adds Discap, the Bot automatically joins active voice channels in that server and records them. Server Administrators can limit this with /automode, /norecord, /channel, and /settings (for example, restricting Discap to specific channels or requiring a manual /join). Recording can also be started manually with /join.
5.2 How recording is announced
While recording, Discap is visible in the voice channel with the status "Recording a call," and it posts a recording card in the voice channel's text chat with Stop, Discard, and Keep my voice out controls. It re-posts a notice when new Participants join. Capture begins as soon as the Bot is connected, and the card is delivered on a best-effort basis: if Discord delays or blocks the message, the recording still runs. Bot visibility and the notice are information, not proof that every Participant agreed. Server Administrators remain responsible for any notice or consent that recording laws require in their community (see the Terms of Service). Where applicable law requires us to obtain additional notice or consent before recording or transmitting audio, we obtain it before the affected processing occurs.
5.3 Keep your voice out: /optout
Any Participant can run /optout (or press Keep my voice out on the recording card) to exclude their own voice. New opt-outs apply to the server where they are set; opt-outs created before September 2026 apply across all servers. While an opt-out is active, your voice is never transcribed, never shown in transcripts, summaries, statistics, or answers, and never used in the Training Program. Raw audio of opted-out speakers is still received from Discord and stored in a separate, segregated archive, retained solely so that an accidental opt-out can be reversed on request; it is never transcribed, displayed, used in any product surface, or used to develop or train AI models. You can ask us to delete your archived audio at any time (Section 19). Audio in transit may be buffered briefly in service memory during processing.
5.4 Stop and Discard
Anyone in the call, or an administrator, can stop a live recording. "Discard" removes a call from your server's transcripts, recaps, and meeting memory and is reversible for a period. Discarding a call does not by itself delete the stored audio and transcript; to have them deleted, contact us (Section 19).
5.5 Recap messages
After a published call, Discap may send each speaker a direct message with a link to the recap. Each person can mute these messages using the button in the message; the mute applies everywhere. Server Administrators can also disable them for a server.
5.6 Where Meeting Content appears
Summaries and transcripts are posted to the channel configured for the Bot. Who can see them inside Discord is controlled by your server's own permissions, which Server Administrators manage. Audio downloads are off by default; when an administrator enables them, downloads are served through access-controlled links that expire after seven days. Very short calls may not produce a published recap, but their audio segments and transcript rows are still stored.
6. Purposes and Legal Bases
We process Personal Data to provide the Service (joining channels, recording, transcribing, attributing speech to speakers, generating summaries and answers, posting them to your server, serving downloads), relying on the performance of our contract with the Server Administrator and our legitimate interest in providing the Service that Participants' communities have chosen to use; to secure, maintain, debug, and improve the Service, relying on our legitimate interests; to measure the Website and our marketing, relying on your consent where required and otherwise on our legitimate interests; to communicate with you about the Service and support requests; and to comply with legal obligations. Where we rely on consent, you can withdraw it at any time without affecting earlier processing. We also process eligible Meeting Content for the Training Program described in Section 6.1, subject to all of its limits. The GDPR and UK GDPR legal bases above do not by themselves authorize use of EEA or UK Meeting Content in the Training Program; that use requires consent as described in Section 6.1.
All model development, training, testing, and evaluation using Meeting Content or data derived from it is governed exclusively by Section 6.1. These limits cannot be avoided by transforming data or removing identifiers.
6.1 Using recordings and transcripts to improve our AI models
Purpose and limits. We may use eligible call audio and the transcripts derived from it to develop, train, test, evaluate, and improve artificial-intelligence and machine-learning models, including speech recognition, speaker attribution, summarization, meeting-memory, and related voice and language models. Models developed under this purpose are used to provide and improve Discap and other products built by People Make Things. Training is run by People Make Things. Service providers may assist only on our behalf under contractual confidentiality, security, and use restrictions, and may not train their own models on the data. This purpose does not authorize selling or licensing recordings or transcripts to AI labs or any other third party for their own training.
Eligible data. Audio and transcripts are eligible only if the Participant has not opted out (Section 5.3), no deletion request applies, and the data was collected after the Participant's community received the recording notice described in Section 5.2. We do not knowingly use the audio or transcript of anyone under 18 in the Training Program; if we learn that a Participant was under 18, we exclude their data. Where the law of your jurisdiction requires your consent for this use (including in the European Economic Area, the United Kingdom, and Switzerland), we use your voice for training only with your consent; absent that consent, we exclude your data.
Previously collected calls. Recordings collected before the effective date of this Policy were collected under earlier versions that disclosed their use to develop, test, and improve the Service and the technologies behind it. We use those recordings only to improve Discap's own models under that previously disclosed purpose. We do not use them to develop models for other People Make Things products unless the affected Participants have given separate, specific consent covering those recordings and that use. Historical recordings must have been lawfully collected and remain lawfully retained; later consent does not cure unlawful original collection or revive data we were required to delete.
Safeguards. Before Meeting Content is used for training, testing, or evaluation, we keep the exclusion records and dataset lineage needed to honor opt-outs and deletion requests separately from the training inputs. Training inputs are organized by Discord user ID so that exclusions can be applied; we do not add profile information beyond what the Service already holds. A voice or a conversation can itself be identifying, and we do not treat training data as anonymous. We do not use the Training Program to identify people by voice or to create voiceprints for identity verification. Quality checks are primarily automated; we may also engage contracted annotators, bound by confidentiality and use restrictions, to correct and label transcripts used for training.
Your choices. Running /optout, pressing Keep my voice out, or asking us to delete your data excludes your audio and transcripts from all subsequent training, testing, and evaluation, including datasets already prepared. Opting out does not itself erase previously stored audio or transcripts; their retention and deletion are governed by Section 10, and you may request deletion at any time. Opting out or deletion does not automatically reverse training already completed; models lawfully trained before your opt-out may continue to be used as described above, subject to applicable law and your rights. This is not a waiver of any deletion or other privacy right.
7. Service Providers
We use the following providers to operate the Service. Each processes data on our behalf for the stated purpose, subject to contractual confidentiality, security, data-protection, and restricted-use obligations. Providers that receive audio, transcripts, or related request data are prohibited from using it to train their own models.
- Discord: the platform the Bot operates on; delivers voice audio, account, and server information and carries the Bot's messages.
- Inworld: speech-to-text; receives Participants' audio in real time during a recorded call and returns transcripts.
- OpenRouter: routes requests containing transcripts and Participants' display names to the model provider selected for the request and returns generated summaries and answers. OpenAI models served through Amazon Bedrock in the United States are currently used. Routing may change as described in Section 18.
- Amazon Web Services: object storage in the United States for audio segments, rendered recordings and per-speaker tracks, manifests, and operational snapshots.
- Fly.io: hosting for the Bot and its database (transcripts, summaries, settings, and records), currently in the United Kingdom.
- PostHog: product and website analytics; processes usage, device, and diagnostic data and attribution identifiers.
- Meta: advertising measurement through a website pixel and server-side conversion events for milestones such as installation and first use; receives click and cookie identifiers and hashed identifiers, never Meeting Content.
- Reddit: advertising measurement through a website pixel and server-side conversion events; receives click identifiers and, for the install click, your IP address and user agent, never Meeting Content.
- Google: advertising conversion measurement on the Website through the Google Ads tag.
- Crisp: the chat widget on the Website and the support conversations you start there.
- Top.gg: bot directory listing; we share server counts, and Top.gg sends us vote and review events with the voter's Discord user ID.
- Contracted annotators: where engaged, individuals or firms under confidentiality and use restrictions who correct and label transcripts for the Training Program.
We may add, remove, or replace providers as the Service evolves and will keep this list current in all material respects. Providers act on our behalf; their role is not permission to sell the data or to train independently on it.
8. Disclosures to Third Parties
We do not sell Personal Data, and we do not share Personal Data for cross-context behavioral advertising. We do not sell or license recordings or transcripts to third parties for their own model training. We disclose Personal Data to the providers in Section 7; within your Discord server, where transcripts, summaries, and recordings appear according to the server's permissions; to professional advisers, auditors, and insurers; to a successor entity in a merger, acquisition, financing, reorganization, or sale of assets, subject to the commitments in this Policy; and to authorities, courts, or others where we believe in good faith that disclosure is necessary to comply with law, respond to lawful requests, or protect the rights, property, or safety of the Company, our users, or others.
9. International Transfers
The Bot is hosted in the United Kingdom, and audio storage, transcription, AI generation, and analytics take place in the United States. Where we transfer Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum.
10. Retention and Deletion
Meeting Content. We retain audio segments, rendered recordings, per-speaker tracks, transcripts, summaries, and derived outputs for as long as reasonably necessary and proportionate to provide the Service to your server (recaps, meeting memory, downloads), to secure and improve the Service, and, where Section 6.1 authorizes it, for the Training Program, or until you ask us to delete them. The Service does not currently apply an automatic expiry to Meeting Content: it is kept until a deletion request, our retention review, or a legal requirement removes it. We review retention periodically and delete data no longer needed for a permitted purpose. Copies, excerpts, and derivatives are subject to the same limits; transforming or copying data does not create a new retention entitlement, and "it might be useful someday" is not a permitted purpose.
Discard and removal. Discarding a call hides it from your server; it does not delete the underlying audio and transcript. Removing Discap from a server stops new recording but does not delete Meeting Content already collected, and server configuration records are kept so that settings and opt-outs are honored if the Bot is re-added. To delete data, use the deletion request path below.
Opted-out audio archive. Audio in the segregated opt-out archive (Section 5.3) is retained only to reverse accidental opt-outs and is deleted on request.
Other data. Attribution click records are kept for seven days; audio download links expire after seven days; support conversations, analytics, and advertising data are retained according to the settings of the relevant provider and our operational needs.
Deletion requests. Any Participant may ask us to delete their audio, transcript lines, and derived data, and any Server Administrator may ask us to delete a server's Meeting Content, by contacting us (Section 19) with the Discord server, channel, approximate dates, and the Discord user ID concerned. We may need to verify that a request relates to your own data, and some requests require coordination with the administrators of the server where the data was created. Deletion also excludes the data from all subsequent training, testing, and evaluation, including prepared datasets. We apply deletions to our providers' copies and to backups through scheduled rotation; residual backup copies awaiting erasure are isolated from ordinary use and training, and exclusions are re-applied if a backup is restored.
Records and trained models. We may keep minimal, restricted records of notices, choices, exclusions, deletions, and dataset lineage to honor your choices and demonstrate compliance; these are kept separate from training inputs and never justify retaining raw Meeting Content beyond its limit. Deleting source data does not automatically reverse completed training; models lawfully trained before a deletion may continue to be used as described in Section 6.1, subject to applicable law and your rights.
11. Security
We use technical and organizational measures designed to protect Personal Data, including encryption in transit, scoped credentials for internal systems, segregated storage for opted-out audio, and time-limited access links for downloads. Access to stored Meeting Content is limited to what is needed to operate, support, develop, and improve the Service. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Your Privacy Rights
12.1 Everyone
Subject to applicable law, you may request access to the Personal Data we hold about you, correction of inaccurate data, deletion, and a copy of certain data. You can exclude your voice from transcription and the Training Program at any time with /optout, and you can mute recap messages from the message itself.
12.2 European Economic Area, United Kingdom, and Switzerland
You may additionally have the right to restrict processing, to object to processing based on our legitimate interests, to data portability, to withdraw consent, and to lodge a complaint with a supervisory authority, in particular in the country where you live, work, or where the alleged infringement occurred.
12.3 California
California residents may have the right to know the categories and specific pieces of Personal Data we collect, the sources, purposes, and categories of recipients; to request deletion and correction; and not to be discriminated against for exercising these rights. We do not sell or share Personal Data within the meaning of the CCPA.
12.4 How to exercise your rights
Contact us using Section 19. Because Discap does not have accounts of its own, we verify requests through your Discord identity (for example, a message from your Discord account in our support server). You may use an authorized agent, subject to our verification of the agent's authority.
13. Sensitive Personal Information
Voice conversations can reveal sensitive information, such as health, beliefs, sexual orientation, or other intimate matters, and a voice recording may be treated as sensitive data under some laws. We process this information only to provide the Service's features and, for eligible data, for the Training Program under Section 6.1. Where applicable law requires additional consent or restrictions for sensitive information, we obtain that consent or exclude the information. We do not use the Training Program to infer sensitive characteristics for advertising or for purposes unrelated to our products, and we do not treat your presence in a recorded call, by itself, as consent to processing for which the law requires a separate consent.
14. Automated Processing
Summaries, action items, answers, talk-time statistics, leaderboards, and /wrapped recaps are generated automatically from transcripts. They are provided for convenience and information, may be inaccurate, do not produce legal effects concerning you, and should not be treated as a record of what was actually said without checking the transcript or recording.
15. Children
The Service is not directed to children under 13, or under the higher minimum age that applies to Discord in your country, and we do not knowingly collect Personal Data from them. Server Administrators must not use Discap in communities intended for children. If we learn that we have collected Personal Data from a child below the applicable minimum age, we will delete it. As described in Section 6.1, we do not knowingly use the audio or transcripts of anyone under 18 in the Training Program.
16. Cookies, Analytics, and the Website
The Website uses PostHog for analytics, the Meta and Reddit pixels and the Google Ads tag for advertising measurement, and Crisp for chat. These load on all pages of the Website, including this one, and may set cookies or read identifiers in your browser. You can limit them through your browser settings and the ad-platform preferences of Meta, Reddit, and Google; the website chat is optional. Where the law requires consent for non-essential cookies, we ask for it.
17. Third-Party Links and Services
The Service links to Discord, Top.gg, our support server, and other third-party sites and services that we do not control. This Policy does not cover them; please review their own privacy policies.
18. Changes to This Policy
We may update this Policy. We will update the "Last updated" date and, for material changes, give notice through the Website, the Bot's messages, or our support server before the changes take effect, explaining the change and how to exercise your choices. We will obtain consent where applicable law requires it. Continued use of the Service after an update does not waive your privacy rights or authorize new uses of previously collected recordings beyond what Section 6.1 permits.
19. How to Contact Us
People Make Things, Inc. is the operator of Discap and the Controller responsible for the processing described in this Policy.
People Make Things, Inc.
2261 Market Street, STE 35679
San Francisco, CA 94114, United States of America
Email: support@discap.bot
Discord: Discap Support server, or the website chat.
This Policy, and any non-contractual obligations arising out of or in connection with it, are governed by the laws of the State of California, United States of America, without regard to its conflict-of-laws principles, save to the extent that the mandatory data protection laws of your jurisdiction of residence apply.