Who is responsible
CJ Villanueva is the operator and data controller for Peasant. The operator is based in the United Kingdom.
Privacy questions and data requests can be sent to hello@itsmechristian.co.uk.
Information Peasant processes
Depending on the request, Peasant processes:
- Discord identifiers, including the authorised user ID and the channel or message IDs needed to receive and update replies;
- message content and instructions sent directly to the bot;
- selected Codex task IDs and names, recent task context, and assistant responses needed to answer or route a request;
- operational records such as job status, timestamps, final responses, and error details;
- limited technical logs used to operate, secure, and troubleshoot the bridge.
Information comes directly from the authorised user's Discord messages and from the existing Codex tasks connected by the operator.
Why the information is used
- to confirm that a Discord message is from the authorised user;
- to understand, route, and answer requests;
- to maintain task selection and conversational continuity;
- to show accurate progress, results, and errors;
- to protect the bridge and diagnose technical problems.
Where UK data-protection law applies, the primary lawful basis is the operator's legitimate interest in running and securing a private personal assistant. Processing may also be necessary to provide a service specifically requested by the authorised user.
Where information goes
Discord carries messages between the authorised user and Peasant. OpenAI/Codex processes the assistant request and accesses only the connected Codex task context needed for that request. Those providers process information under their own terms and privacy policies.
Operational records are stored in a local SQLite database on the operator's device. The bridge opens no public terminal or Codex network port. Information is not sold, rented, or used for advertising.
Discord, OpenAI, or their service providers may process information outside the United Kingdom under the transfer arrangements described in their respective privacy notices.
Retention
Local bridge records are currently retained until they are manually deleted or are no longer needed to maintain task history, operate the assistant, or investigate an error. A shorter fixed retention period is not presently applied.
The authorised user may request deletion of local bridge records. Information retained independently by Discord or OpenAI is governed by those providers' own retention policies.
Security
- Only one configured Discord user ID is accepted.
- Normal conversational use is limited to direct messages.
- Discord-started Codex work runs read-only without approvals.
- Credentials remain in local environment or account storage and are not intentionally returned to Discord.
- Likely credential values are redacted before task history or final output is sent back to Discord.
No security measure is perfect. If a privacy or security issue is suspected, contact the operator promptly.
Your rights
Where UK data-protection law applies, you may have rights to access, correct, erase, restrict, or receive certain personal data, and to object to some processing. These rights depend on the circumstances and lawful basis.
You may also raise a concern with the UK Information Commissioner's Office at ico.org.uk.
Automated decisions and children
Peasant uses AI to route requests and generate responses, but it does not make solely automated decisions that have legal or similarly significant effects on people.
Peasant is not intended for children and is not knowingly made available to anyone under 13 or below the minimum age required to use Discord in their country.
Changes to this policy
This policy may be updated when Peasant's features, providers, storage, or legal obligations change. The updated date at the top of this page will show when a revision takes effect.