ExoCort

Privacy Policy

Last updated 2026-09-21

ExoCort is built to hold your thinking, so it holds personal data by design. This page says exactly what it keeps, who else sees it, and how to make it go away.

1.Who is responsible

The controller of your personal data is [to be completed before launch], [to be completed before launch]. Contact: [email protected].

This policy covers the ExoCort application in Discord and the exocort.net website. It does not cover Discord itself, which is a separate controller with its own policy.

2.What we hold

Because ExoCort is an assistant with a memory, most of what it holds is what you gave it:

  • Conversations. The messages you send to ExoCort and the answers it gives, including files, images and voice messages you attach.
  • Notes and tasks you create, with their text, titles, dates and structure.
  • Memory. Facts and connections the assistant draws from your conversations, notes and files, so that it can recall them later. This may include details about you and about people you mention.
  • Identifiers from Discord. Your Discord user id, the server and channel ids, and the display names Discord shows. We do not receive your Discord password or your email address from Discord.
  • Settings and billing state: your plan, your allowance, language and time zone.
  • Technical logs kept for a short time so that faults can be diagnosed.

We also keep product metrics, and these are deliberately built so that they cannot be traced back to you: identifiers are replaced by keyed hashes, and no message text, note title or name is ever recorded in them.

3.Why we hold it, and on what basis

  • To provide the service you asked for, which is the performance of our contract with you. Without holding your conversations and notes, an assistant with a memory cannot exist.
  • To take payment and meet accounting obligations, which is a legal obligation and the performance of the contract.
  • To keep the service working and safe, and to understand how the product is used in aggregate, which are our legitimate interests. The metrics described above are designed so that this interest does not come at your expense.

4.Who else sees it

To answer you, ExoCort must send your message and the relevant material to a language model. We use the following processors and no others:

  • OpenRouter, which routes requests to model providers, and through it the providers that actually run the models, currently including Google, DeepSeek, Anthropic, xAI, Moonshot and z.ai. Every request is sent with settings that forbid the provider from retaining the content or using it for training.
  • Tavily, a search provider, and the public web pages it returns. This happens only when a search is actually performed for your request, and only the search query is sent.
  • Discord, which delivers every message in both directions and stores it under its own policy.
  • Oracle Cloud, where our servers and our database run, in the Stockholm, Sweden (European Union) region.
  • Paddle, which processes payments as merchant of record. Your card details are given to Paddle and never reach us; we receive only the fact of a payment and the plan it relates to.
  • Cloudflare and Resend, if you write to our support address. Cloudflare receives the message and Resend sends our reply. Support correspondence is handled by our team inside Discord, which means the content of your letter is stored there as well.

We do not sell personal data, we do not share it with advertisers, and we use no third party analytics or advertising trackers anywhere in the product or on this website.

5.Training

Your content is not used to train models, by us or by the providers we send it to. Requests are sent with retention and training switched off, and a provider that does not offer those terms is not used, even when it is cheaper.

6.Where the data goes

Your data is stored in the European Union. The database, your notes, your conversations and our backups live on servers in Stockholm, Sweden (European Union).

It does not stay there when an answer is produced. The model providers listed above are located outside the European Economic Area, mainly in the United States, and your message and the relevant material are sent to them so that a reply can be generated. Those transfers rely on the standard contractual clauses used by those providers, together with the retention and training restrictions described in section 5.

If you would rather nothing left the EEA at all, ExoCort is not the right product for you today, and we would rather say so here than let you discover it later.

7.How long we keep it

  • Conversations, notes, tasks and memory are kept for as long as ExoCort is present on your Discord server. They are not deleted by age.
  • When ExoCort is removed from a server, its data is deleted, including the vector memory built from it. This happens automatically and cannot be undone.
  • Technical logs are rotated and overwritten continuously, and older entries are gone within days.
  • Raw product metrics are deleted after 90 days. The aggregated daily figures derived from them contain no identifiers and are kept.
  • Backups. We keep encrypted backups so that a failure does not lose your work. A backup is a snapshot in time, so for a short period after a deletion your data may still exist inside one. Backups are kept on a rolling basis and older ones are destroyed as newer ones replace them; within that window, deleted data disappears from backups as well.
  • Payment records are kept by Paddle and by us for as long as tax and accounting law requires.

8.Your rights

You may ask us to give you a copy of your data, to correct it, to delete it, to restrict or object to its processing, and to provide it in a portable form. Write to [email protected] and we will answer within one month.

You can also delete most things yourself, without asking anyone: individual facts the assistant has remembered, notes, tasks and whole conversations can be removed from inside the product, and the settings panel has an option that deletes everything belonging to a server at once.

Letters you send to our support address are kept separately from your space, because a person who writes to us may not use the product at all. Ask us and we will delete that correspondence too.

If you think we have handled your data badly, please tell us first, and know that you also have the right to complain to the data protection authority in the country where you live.

9.Security

The database is reachable only from the machine it runs on, administrative access is by key and not by password, traffic to the website is encrypted, and backups are stored in private storage. Access to production is limited to the people who operate the service.

No system is perfect. If a breach occurs that puts your rights at risk, we will tell you and the relevant authority without undue delay.

10.Other people in your server

ExoCort reads the channels it is placed in, so it processes the messages of everyone who writes there, not only yours. If you add it to a shared server, you are the one who decides that, and you should tell the people in it. Each person may ask us to delete what relates to them.

11.Children

ExoCort is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has used it, write to [email protected] and we will delete the data.

12.Cookies

This website uses a cookie to remember the language you chose, and nothing else. There are no advertising cookies and no analytics cookies. When you buy a subscription, Paddle sets its own cookies on its checkout, under its own policy.

13.Changes

When the product changes in a way that affects this policy, we update this page and change the date at the top. If a change is material, we will tell you through the product or by email before it takes effect.