Privacy policy
What data Kelu processes, what for, with whom and for how long.
1. Controller
The data controller is Kelu, an independent project operated by an individual in Colombia, based in Medellin, Colombia. Write to [email protected] for anything about your data or to exercise your rights.
2. Which law reaches you
The service is provided from Colombia and used from every country, so there is no single applicable statute but several at once. This policy is written to meet all three:
- Because we are in Colombia, all processing is governed by Ley 1581 de 2012 and its implementing decrees. That is the base layer and it reaches everyone, wherever they are.
- If you are in the European Economic Area or the United Kingdom, the GDPR applies on top, because we offer you the service from here. With it come its legal bases, some additional rights and its own deadlines.
- If you are anywhere else, we apply that same standard. If your local law grants you a right that does not appear in this document, write to [email protected] and we will honour it all the same.
Where two of those rules disagree on the same point —a response deadline, say— we apply whichever is better for you.
3. Two different roles, worth not confusing
We are the controller for the data of whoever creates a dashboard account and whoever buys a plan: data we process on our own behalf to run and bill the service.
We are the processor for the data of members of a Discord server. There, whoever administers the server decides what gets processed: turning levels on decides that activity is counted, turning tickets on decides that conversations are kept. We only process that data following their instructions and what these documents say.
4. What data we process
From whoever uses the dashboard:
- Discord ID, username, display name and avatar.
- The email address associated with the Discord account.
- Discord access tokens, so we can list your servers. Stored in our database, never shared with anyone, and scoped to what we ask for on sign-in: your profile, your email and the list of your servers. They go when the account is deleted, and you can withdraw them at any time by revoking the application from your Discord settings.
- Session data: date, IP address and browser, so sessions can be closed and improper access detected.
From members of a server, and only if the relevant module is on:
| Module | What is processed |
|---|---|
| Levels | ID, accumulated experience and level. Message text is not stored. |
| Moderation | Sanctions: who, against whom, reason, duration and date. Message content only if a filter held it. |
| Tickets | Who opened, who handled it, when each side spoke, form answers and, if the server enables it, the channel transcript. |
| Logging | Server events: deleted or edited messages, joins and leaves, channel changes. |
| Birthdays | The date each person writes about themselves. The year only if the server allows it. |
| Economy | Balance and movements: who earned or spent, how much and why. |
| Polls and suggestions | What each person voted, so the vote can be changed and not counted twice. |
| Reminders | The text you write and when you want to be reminded. |
| AI | A ticket conversation is sent to the model provider to summarise it or draft a reply. |
5. Purposes, and on what basis
Ley 1581 requires prior, express and informed authorisation. You give it by adding the bot to your server or by signing in to the dashboard, and this document is the information that goes with it. The GDPR, for whoever is in the EEA or the UK, allows other bases as well — hence the two columns.
| Purpose | Basis in Colombia (Ley 1581) | Basis in the EEA and the UK (GDPR) |
|---|---|---|
| Running the service and keeping your account | Your authorisation | Performance of a contract |
| Charging paid plans and keeping the accounts | Your authorisation and a legal obligation | Performance of a contract and legal obligation |
| Telling you about incidents, failed payments or relevant changes | Your authorisation | Performance of a contract |
| Keeping the service secure, detecting abuse and debugging | Your authorisation, with security among the stated purposes | Legitimate interest |
| Processing data of server members | Instructions of the server administrator, who is the controller | Instructions of the server administrator, who is the controller |
You can withdraw that authorisation whenever you like: by removing the bot from the server, deleting your dashboard account or writing to us. The only limit is what we are legally required to keep, which is spelled out in the Data Retention Policy.
We do not use your data for advertising, we do not sell it, and we do not profile you or make automated decisions with legal effects on you.
6. Who else can see the data
Only whoever is needed for the service to work. Each sees the minimum and is contractually barred from using it for anything else:
| Who | What for | When |
|---|---|---|
| Discord | The platform everything runs on | Always |
| Our hosting provider | Servers and database | Always |
| Lemon Squeezy | Charging subscriptions as merchant of record | Paid plans only |
| Anthropic | Generating a ticket summary or a reply draft | Only with AI enabled |
| Email provider | Billing notices | Only when there is something to notify |
| Translation provider | Translating a message | Only with translation enabled |
| Audio node | Playing music in a voice channel | Only with music enabled |
If a server configures its own Anthropic key, its calls go with that key and the relationship with that provider is theirs, not ours.
Nothing that leaves for the model provider is used to train models. It is sent to produce that summary or that draft, the answer comes back, and there it ends: no conversation on Discord feeds any model, ours or anybody else’s. Discord forbids it of its developers and the provider’s commercial terms say the same from the other side.
7. International transfers
Our providers are outside Colombia: Discord and Anthropic in the United States, and hosting, billing and email in the United States or the European Union depending on which one.
For data covered by Colombian law, the Superintendencia de Industria y Comercio lists the United States and the European Union countries among those offering an adequate level of protection (Circular Externa 005 de 2017). On top of that, the transfer is necessary to perform the contract you have with us and is covered by your authorisation: two of the grounds in article 26 of Ley 1581.
For data of people in the European Economic Area or the United Kingdom, transfers rely on the Standard Contractual Clauses approved by the European Commission and, where applicable, on the relevant adequacy framework. You can ask us for a copy of the safeguards at [email protected].
8. How long it is kept
The exact periods, item by item, are in the Data Retention Policy. In short: while the service is active and, afterwards, as long as legal obligations require.
9. Your rights
By writing to [email protected] from the address linked to your account —or otherwise proving your identity— you can:
- Know, update and rectify your data, and access it free of charge.
- Ask us for proof of the authorisation you gave, and to be told what use we have made of your data.
- Withdraw that authorisation and ask for your data to be deleted, limited only by what the law requires us to keep.
- Complain to the supervisory authority, under the conditions explained below.
If you are in the European Economic Area or the United Kingdom, the GDPR adds three more: objecting to the processing, asking for it to be restricted, and taking the data you gave us in a reusable format.
Deadlines. A query is answered within 10 business days and a claim within 15, which are the periods in articles 14 and 15 of Ley 1581; if we cannot make it, we tell you why and by when, within the extension the statute itself allows. The GDPR grants one month. We apply whichever expires first.
If your data is processed by a specific server — your experience, your birthday, a ticket you opened — the one deciding about it is whoever administers that server: go to them first. If you get no answer, write to us and we will help you find them.
If you believe we have not handled your request properly: in Colombia the complaint goes to the Superintendencia de Industria y Comercio (sic.gov.co), and the law requires having filed the query or claim with us first. If you are in the European Economic Area or the United Kingdom, you can go straight to the supervisory authority of your country.
10. Minors
The service is not aimed at anyone below the minimum age Discord requires in each country, never under 13. If we find data belonging to someone below that age, we delete it.
11. Security
- All traffic is encrypted in transit.
- The secrets a server configures — its AI key, its third-party tokens — are stored with envelope encryption, and no function in the system returns them once saved.
- Only a hash of our own API keys is stored: not even we can recover them.
- Technical logs redact email addresses and contain no secrets.
- Access to production data is limited to the people who need it and is audited.
12. Changes
If we change this policy we will announce it in the dashboard. The date of the last revision appears at the top of the document.