This policy describes what DLetter (Avendavi) collects, who else receives it, and how long it is kept. It matches how the service works today. Questions: hello@dletter.com.
1. What DLetter is
DLetter is a Discord bot and a website. A server owner adds the bot, picks the channels it may read, and optionally marks some members as VIPs. Once a day, DLetter reads the last 24 hours of messages in those channels, sends them to an AI model, and saves the result as a daily letter that the owner and paying readers view on dletter.app.
2. What we collect
From you
- Sign-in: via Discord OAuth (scopes identify, email, guilds). We store your Discord user ID, username, email address, avatar URL, the OAuth access and refresh tokens (used to list your servers, never to read messages), and a session record.
- Billing: your Stripe customer ID, subscription ID, status, plan, and which servers it unlocks. Card details stay with Stripe; we never see them.
- Email: whether you switched on email delivery.
From your Discord server
- Settings: server ID, name, icon, configured channel IDs, VIP member IDs and usernames, and the daily generation time.
- Messages: once a day the bot reads the configured channels only (text channels, announcement channels and threads), never direct messages, voice channels or channels the owner has not added. Messages from other bots are skipped. Per message it reads the text, author username and ID, channel name and timestamp, up to 1,000 messages per channel. Raw messages are not stored; they are held in memory while the letter is generated, then discarded.
3. How we use it
To sign you in and show you the servers and letters you have access to; to generate letters; to bill subscriptions through Stripe; and to record errors and rate limit a few API routes. We do not sell personal data or use it for advertising.
A letter is stored as the AI-written HTML summary, which may name members and quote or paraphrase what they wrote, plus a structured block: a short intro excerpt, up to three VIP messages quoted word for word (up to 280 characters each) with the author's username and channel, the day's most frequent keywords with counts, and the number of messages processed.
Letters are shown to the server owner and to readers with an active subscription. Each server also has a public page on dletter.app; visitors without access do not see the letter body.
If a message is edited or deleted on Discord after it was included in a letter, the letter is not updated. Discord deletions are not propagated to DLetter. To have something removed from a letter, contact us.
4. Who else receives it
- Discord: handles sign-in and serves channel messages to our bot under Discord's terms.
- A third-party AI provider: for each letter we send the message text (within a budget of roughly 24,000 characters, VIP messages kept first), usernames, channel names, timestamps, the server name, a VIP marker, per-user and per-channel message counts, and the top keywords. The provider processes the text only to produce the summary; its own privacy terms apply to that processing.
- Stripe: processes payments. Stripe receives your email address, your DLetter user id, and the name of the server you are paying for (and the channel and MVP counts for a Server Plan).
- Sentry: error monitoring. On an error Sentry receives the error report, the request path and method, and on the website a replay of the failing page with all text masked and media blocked. Sentry also receives timing data for a 10% sample of requests and page loads, including request URLs, with no message content. We leave Sentry's default personal data collection off. Message content is not sent unless it happens to appear inside an error message.
- Hetzner: hosting. The website, the bot and our PostgreSQL database run in Docker on a Hetzner server in Germany.
- An email delivery provider: if you switch on email, it receives your email address and the letters sent to you.
- Upstash: when enabled, rate limiting stores short-lived request counters in Upstash Redis keyed by user ID or IP address. No content.
5. Cookies
dletter.app sets only the cookies needed to sign you in: a session cookie, plus a CSRF token, a callback URL and a short-lived OAuth state cookie during the Discord sign-in. We set no advertising or analytics cookies. The session cookie expires 30 days after your last visit, renewed at most once a day, so you stay signed in until you log out. We also keep a few display preferences in your browser's local storage, such as theme, server order and letter reactions; they never leave your browser. Stripe's checkout pages set their own cookies on Stripe's domain.
6. Retention
- Daily letters, including the quotes and usernames inside them, are kept until deleted on request. Nothing deletes them automatically today: not a lapsed subscription and not removing the bot from the server.
- Server settings are kept after the bot is removed, so the setup survives if it is re-added, until you ask us to delete them.
- Account data (Discord profile, tokens, subscription records) is kept until you ask us to delete your account. There is no self-serve delete button yet; email us.
- Sessions expire 30 days after your last visit or when you log out.
- Stripe and Sentry keep their own copies under their own retention rules.
7. Your rights
We are based in the EU and the GDPR applies. You can ask what personal data we hold about you, have it corrected or deleted, restrict or object to its use, or get a copy. This applies whether you have a DLetter account or you are a member of a server that uses DLetter and were named or quoted in a letter. You can also complain to your local data protection authority.
Email hello@dletter.com from the address on your account or tell us your Discord username. We may ask you to confirm your identity through Discord before deleting anything. You can cancel a subscription from the dashboard; a server owner can stop collection by removing channels from DLetter or removing the bot.
8. Server owners' responsibility
If you enable DLetter on a server, you choose which channels it reads. Tell your members that messages in those channels are sent to a third-party AI provider every day, that letters may name them and quote what they wrote, and that letters are shown to subscribers on dletter.app. Only add channels whose members would expect this.
9. Changes to this policy
When the way DLetter handles data changes, we update this page and the date at the top.
10. Contact
DLetter (Avendavi), hello@dletter.com.