This Privacy Policy explains what information PaLLi collects, how it is used, and the choices you have. PaLLi is a personal AI companion that can run on Discord and includes a web dashboard for account management.
1. Who we are
"PaLLi", "we", "us", and "our" refer to the PaLLi project/team. You can contact us at support@trypalli.com.
2. What we collect
The information we collect depends on how you use PaLLi (Discord, web dashboard, and optional features like web search or voice).
2.1 Account and security information (website)
- Email address (for your account and billing communications).
- Authentication data (for example, a password hash if you set a password, and security signals such as session data and CSRF tokens).
- Security and audit data (for example, login events, password reset events, and associated IP address and user agent where available).
- Connected identifiers you choose to link (for example, your Discord user ID and/or Google account ID used for sign-in).
2.2 Billing information
- Subscription status and payment metadata (for example, Stripe customer IDs and checkout/session IDs).
- Payment card information is handled by Stripe; we do not receive your full card number.
2.3 Content you provide to PaLLi
- Messages and conversation content sent to PaLLi (including in DMs and in servers/channels where PaLLi is present).
- Attachments and files you send to PaLLi (for example, text files whose contents you upload, and images).
- Images you upload, along with AI-generated descriptions/analysis associated with those images (if vision is used).
- If you use voice features, we process audio to generate a transcript; we store the transcript and related session metadata. We do not intentionally store raw audio long-term (temporary files may exist briefly for processing).
2.4 Data PaLLi generates from your use
PaLLi is designed to build "memory" so it can stay consistent over time. To do this, PaLLi may create and store derived data such as:
- Preferences you set (for example, preferred name, response length, and feature toggles like voice/proactive messages).
- AI-generated summaries, user profile notes, and long-term "facts" extracted from your conversation history (for example, interests, recurring projects, or communication preferences).
- Reminders you create and related scheduling metadata.
- Operational analytics (for example, metrics about usage/response behavior that help us tune the system).
- Web search events (for example, a search query PaLLi ran when you asked for up-to-date information).
2.5 Technical information
- Basic request metadata from the website (for example, IP address, device/browser user agent, and cookie identifiers used for authentication).
- System logs related to service operation, debugging, reliability, and abuse prevention. Depending on settings and the type of issue, logs may include message snippets, request identifiers, and error context. For example, when diagnostic logging is enabled, logs may include copies of AI request payloads used to debug response generation.
3. How we use information
- Provide and operate PaLLi (generate responses, maintain conversation context, and run your settings).
- Store conversations and memory so PaLLi can personalize and remain consistent over time.
- Run optional features you enable (for example, web search, image understanding, and voice features).
- Process payments, manage subscriptions, and provide account access.
- Maintain security, prevent abuse, and troubleshoot bugs.
- Improve the service (for example, performance tuning and reliability work).
- We do not use your content to train our own foundation AI models. Third-party providers that process data to generate responses may have their own data handling policies.
4. How we share information
We do not sell your personal information. We share information only as needed to run PaLLi and provide the service you request.
4.1 Service providers and infrastructure
- Discord. If you use PaLLi on Discord, Discord will process your messages and account data according to Discord's terms and privacy policy.
- AI/LLM providers. PaLLi sends relevant content (such as your message and recent context) to third-party AI model providers to generate responses. Depending on configuration, this may include providers such as OpenAI and/or DeepSeek.
- Web search provider (Exa). If PaLLi runs live web research, it sends a search query to the search provider and receives results for summarization.
- Voice provider (Deepgram). If voice features are enabled, audio may be sent to a speech provider for transcription (STT) and text may be sent for voice synthesis (TTS).
- Payments (Stripe). Stripe processes payments and manages billing details.
- Email delivery (Resend). If email features are enabled (for example, password reset emails), we send the email address and email content needed to deliver the message.
4.2 Legal and safety
We may disclose information if we believe it is reasonably necessary to comply with law, enforce our Terms, protect the safety of users or others, or prevent fraud and abuse.
5. Human access to conversations
PaLLi processes your messages automatically to provide responses and memory. We do not routinely read your private conversations. However, we may access stored content in limited cases when necessary to provide support, debug issues, investigate abuse, or improve and maintain the service.
6. Your choices and controls
- Export. You can export stored conversation history via the web dashboard (where available).
- Deletion/purge. You can request deletion and/or use dashboard controls to purge selected categories of PaLLi data (for example, conversations, memories, images, and analytics).
- Feature toggles. You can disable optional features such as proactive outreach and voice (where available).
- Discord context. If you use PaLLi in a server/channel, other members can see what you post there. Use DMs for private conversations.
7. Data retention
We keep your information as long as needed to provide the service, maintain system integrity, and comply with legal obligations. In practice:
- Conversation history, memories, and profiles are generally retained until you delete them (for example, via purge tools) or you request account deletion.
- We retain certain records related to billing, fraud prevention, and security auditing as required or appropriate (for example, subscription status and audit logs).
- Server logs are retained for a limited period and rotated as part of normal operations.
- Backups may retain residual copies for a limited time after deletion (typical of most hosted services).
8. Security
We take reasonable measures to protect your information (for example, password hashing for website accounts and access controls). No system is perfectly secure, and we cannot guarantee absolute security.
9. Children's privacy
PaLLi is not intended for children under 13. If you believe a child has provided us personal information, contact us and we will take appropriate steps.
10. International users
PaLLi may process and store information in the United States and other locations where we or our service providers operate. By using PaLLi, you understand that your information may be transferred to and processed in these locations.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date and, where appropriate, provide additional notice.
12. Contact
Questions, deletion requests, or privacy concerns: support@trypalli.com.
