Privacy Policy
Effective August 2, 2026. The short version: we collect what the Service needs to work, we don't sell it, and you can ask us what we hold and ask us to delete it.
1. What we collect
- Early-access requests. If you submit the form on our home page, we store the email address you typed and the date you sent it — nothing else, no tracking pixels, no analytics on that page. We use it once, to tell you when access opens, and you can have it removed at any time by asking.
- Account basics. When you sign in with Discord: your Discord ID, username, and avatar. We don't receive your Discord password.
- Community configuration. The settings, automations, and permissions your server's operators configure in YourKey.
- Messages and commands sent to Key. When you talk to the agent or invoke it, that content is processed to produce a response, and relevant parts may be retained as the agent's memory for your community.
- Operational records. Logs, metrics, and traces about what the Service did — including records of agent actions and the authority they ran under. These records are the product's accountability spine, not advertising telemetry.
2. How we use it
To run, secure, and improve the Service: producing agent responses, executing the automations your community configured, preventing abuse, debugging, and keeping an auditable record of what automated systems did. We do not sell your data or use it for third-party advertising.
3. AI processing
Messages sent to Key are processed by third-party large-language-model providers through their commercial APIs to generate responses. We send what the request needs, under those providers' API data-handling terms. If you configure your own model API keys, requests using them are governed by your own agreement with that provider.
4. Where it lives and who sees it
Data is stored on infrastructure we operate (see key-gateway.io). We share data only with the service providers required to run YourKey — hosting, Cloudflare (network and DDoS protection), Discord (the platform the bot operates on), and the AI providers above — and where the law requires it. Within a community, what agents did is visible to that community's operators; one community's data is not visible to another's.
5. Retention and deletion
We keep data while it's needed to run the Service for your community. Server operators can remove the bot and ask us to delete their community's data; individuals can ask us what we hold about them and ask for its deletion. Write to [email protected] and we'll act on it within 30 days.
6. Changes
When this policy changes, we'll update this page and its effective date, and flag material changes in the product.
7. Contact
[email protected] — privacy questions, data requests, or anything else. Security reports: see /.well-known/security.txt.