Privacy policy
dwik turns deliberately connected Discord communities into public, AI-assisted wiki pages. This policy describes what the service stores, publishes, and deletes.
Data we process
For connected servers, dwik stores guild and bot-visible channel metadata, normalized message content needed for generation, hashed author references, source scores, derived chunks, internal citation edges, generated revisions, synchronization records, and owner-operation records. Dashboard authentication temporarily processes a Discord user ID, display name, guild membership, and short-lived OAuth access token in an encrypted cookie.
dwik does not intentionally ingest direct messages, group DMs, private threads, voice or stage content, inaccessible channels, or channels excluded by the server owner.
Public output and AI processing
Approved wiki pages are public and may be indexed by search engines. Public pages contain generated summaries, not raw Discord transcripts or Discord user IDs. Selected source text is sent to the configured AI provider to plan, draft, audit, moderate, or embed content. Model output remains subject to deterministic citation, audit, moderation, and personal-data checks.
Retention and deletion
Discord-deleted sources are removed from retrieval immediately and uncited source data is removed according to the configured retention schedule. A verified server deletion stops publication and removes tenant content from the primary database and object storage. A minimal non-content tombstone is retained to prevent the bot from silently recreating a deleted tenant. An authorized server manager can deliberately reconnect it later, which creates a new empty tenant and starts a fresh consented sync.
To protect the service from repeated abuse, dwik may retain a minimal account restriction keyed by Discord user ID after the corresponding dashboard profile is deleted. The restriction contains no Discord message content or OAuth credential and is used only to enforce suspension or a ban.
Encrypted managed backups may retain deleted data for up to 30 days. Each deployment must configure and verify its hosting-provider lifecycle against that disclosed maximum. Restoring a backup requires reapplying deletion tombstones before restored services can publish or ingest.
Service providers and security
dwik relies on Discord, OpenAI, managed PostgreSQL and Redis hosting, and private S3-compatible object storage where configured. Secrets are stored outside the repository; public rendering excludes raw source dumps, attachment URLs, OAuth tokens, and prompts.
Your choices
Server administrators can control eligible channels, pause publication, hide pages, and request complete tenant deletion. Anyone can report sensitive, incorrect, or unauthorized material through the public removal workflow. Requests are reviewed against a 72-hour acknowledgement target.