YORRLEGAL & PRIVACY

YORR / Privacy Policy

Privacy Policy

How YORR processes data, separates servers, and handles retention and owner-reported deletion.

Privacy requests go to the operator.Contact @shyn13_ or fuu.gamersindo@gmail.com. Original data deletion target: 7 days from report receipt. Related backups: 30 days after original deletion.

01. Operator and scope

YORR is operated by T A K A _. This policy applies from 9 October 2026 to the bot and dashboard when used. Report requests through Discord @shyn13_ or fuu.gamersindo@gmail.com.

The bot and dashboard currently run on the operator’s local computer. Public policy pages use GitHub Pages. Material changes to hosting or processing require a policy update.

The static documentation site has no login, forms, application analytics, external fonts, or application cookies. GitHub may process visitor information, such as IP addresses and browser information, under its Privacy Statement. Discord sign-in occurs in the separate dashboard.

02. Data processed and purposes

Processing depends on enabled features, bot access, and member usage. Data supports requested features, access checks, responses/notifications, security, and user reports.

DataPurpose
Discord User, Guild and Channel IDs, roles, display names, and membership eventsAccess checks, server configuration, automatic roles, and operation in the correct server.
AI messages/responses, names in context, and memory factsResponses and conversation context. History/facts are stored locally; relevant context is sent to AI providers. Image prompts are processed to generate images.
New member names and avatarsWelcome messages/cards sent to the administrator-selected channel, visible to members with channel access.
YouTube/TikTok source IDs/names, notification state, source avatar caches, and monitoring settingsFetching selected source information and sending configured notifications.
PUBG player nicknames/identities; tournament team names, player/registrant Discord identities, team status, and message/voice channel IDsPUBG and UC96 tournaments. Lists/announcements in Discord are visible according to channel permissions.
Scanned messages/attachments; message/channel IDs, action actor, time, and moderation resultsLocal reference-image matching and moderation. Results and action metadata may be held in scan jobs or audit records.
Server settings, AI usage/tokens/credits, estimated costs, plan status, drafts, and auditsFeature operation, usage limits, diagnosis, and management records. Plan status does not mean payments are active.
OAuth2 data and session cookies when the dashboard is usedDiscord identity, server lists/permissions, and access tokens enable authentication/authorization. Access tokens and sessions remain server-side; bot/API tokens are not browser configuration.
Privacy reports, User/Guild IDs, receipt time, verification/deletion status, and operational metadataVerifying requests, scheduling deletion, and preventing deleted data from returning through backups.

Some settings and metadata are stored in SQLite/local files. Operational logs can contain status, IDs, or feature errors. This policy does not claim all server messages are stored as AI memory or that no data is stored.

03. Server separation and access

AI history and memory facts use Guild ID and User ID scopes. Direct messages use a separate scope. Legacy unscoped data is quarantined and is not automatically used as active server context.

The dashboard checks management permissions and bot membership before serving server data. Owner and UC96 features have restricted access. Other features keep their own storage formats; AI isolation does not imply every file/integration uses the same structure.

The operator has administrative access to local storage. Application scoping limits cross-server use; it does not guarantee encryption against the operator.

04. Recipients and external services

Discord supplies account/server data and receives bot messages/actions. Server members see feature outputs according to channel permissions. See Discord Privacy.

OpenAI API processes AI requests, which may include messages, contextual names, relevant history/facts, and image prompts. Processing follows OpenAI API data controls and operator account settings. API content is not used for training by default unless the customer opts to share it. This policy does not assert account-specific opt-in settings or guarantee Zero Data Retention.

Tavily receives web-search queries, which may contain words from user requests. See Tavily Privacy.

YouTube/Google, TikTok, and PUBG may receive source/player identities and required request parameters when relevant features are enabled. Gmail email reports and Discord DMs also use their respective communication platforms. See Google Privacy and the policies of the platforms used.

GitHub hosts public policy pages. Bot data, credentials, memory, and databases are not included in the prepared static site.

Providers may process data in different countries according to their services, agreements, and settings. YORR does not promise a particular provider processing location, zero retention, or removal of provider copies through local deletion. Contact the operator about data sent to providers.

05. Retention and backups

StorageRule
Active AI history30 days from first storage, with a maximum of six active history entries. New messages do not extend older messages’ lifetime.
AI memory facts30 days from creation or a value change. Reading or using a fact does not extend its lifetime.
Legacy AI data without timestamps30 days from first recognition by the new retention system; original dates are not assumed.
AI history/fact backupsRelated records are removed 30 days after original deletion, including expiry, pruning, and fact changes. Shared backups are redacted per record so unrelated users/servers are not prematurely erased.
Internal deletion queueCompleted request metadata is removed after the related backup period and successful maintenance. Pending, review, or failed requests remain for review/retry.
Deletion journalIdentity/record hashes and deletion dates prevent restoration from old snapshots. It contains no conversation text and currently has no automatic expiry.
Settings, audits, usage, participants, caches, logs, and email/DM reportsOutside the automatic 30-day AI cleanup. Persistent data can remain until edited/deleted by the operator or relevant feature/platform. Owner-reported deletion is handled according to verified scope.
Dashboard sessions/access tokensActive sessions last at most about one hour, also limited by token expiry. Sessions/tokens are held in process memory. Persistent drafts/audits follow the settings/audits rule above.
Provider data or external backupsSubject to the relevant party’s storage/policies, outside YORR’s local backup worker.

The worker checks jobs approximately every 60 seconds while the bot is online. Offline periods or storage errors can delay cleanup; failures are recorded/retried and require operator attention. Removing the bot or ending a session does not automatically erase all persistent data.

06. Reports and deletion

Access, correction, and deletion requests are submitted only to the operator through Discord @shyn13_ or fuu.gamersindo@gmail.com. There is no Discord command to request or check privacy deletion.

The operator verifies the requester’s identity, authority, and affected data/server. Server management rights do not automatically authorize access to another user’s or server’s data. Verification never requires passwords, bot tokens, OAuth secrets, or API keys.

The target for deleting original data within verified request scope is within 7 days of report receipt, including verification time. Recording the request later does not reset the deadline. Verified requests are recorded internally; the worker deletes active AI memory on the next online cycle.

Related backup data is removed 30 days after original deletion and may remain during that waiting period. New AI data generated after deletion has its own retention lifetime.

Automation covers local AI history/facts and bot-managed backups. Settings/audits, tournaments, logs, external backups, email/DM communications, and provider data need separate operator/platform handling. The operator explains request scope, status, and limitations. Local deletion does not automatically delete Discord messages or others’ copies; applicable user rights remain protected.

YORR operator: T A K A _

Discord: @shyn13_
Email: fuu.gamersindo@gmail.com

For privacy reports, include your Discord User ID, Guild ID where relevant, the data scope, and request type. Do not send passwords, bot tokens, OAuth secrets, or API keys. The operator verifies identity and authority before disclosing or deleting data.

07. Security and user choices

The dashboard uses OAuth2 state, server-side permission checks, CSRF protection for changes, and HttpOnly/SameSite session cookies. Secure cookies are used with HTTPS. Bot tokens, OAuth secrets, and API keys are server-side environment settings, not public browser configuration.

The operator manages local storage and recovery. Absolute security and encryption of every stored file/backup are not guaranteed. Report suspected unauthorized access to the operator.

You may stop using AI or report a deletion request. Administrators may disable features or remove the bot. Avoid unnecessary sensitive information. These choices alone do not erase existing data; use the report process above.

08. Updates and user rights

Version 1.0 takes effect on 9 October 2026. Material hosting, provider, retention, or processing changes will be described here with a new version/date before implementation.

Request explanations, access, correction, or deletion through the operator according to applicable law. Complaints use the same contact. This policy does not limit legally protected rights.

Read the Terms of Service. The official Privacy Policy is published at fuu-cmd.github.io/privacy/.