Pepper
Legal

Privacy Policy

What Pepper stores when you play music on Discord, why it stores it, who else sees it, and how to have it removed.

Last updated
September 30, 2026
Effective
September 30, 2026
Applies to
Pepper bot & pepper.muralianand.in

We never sell your data

No advertising networks, no data brokers, no selling or renting of anything we hold.

Music data, not messages

Pepper stores the tracks and radio stations you play, never your chat messages. Autoplay’s AI sees song details only — never who you are.

Spotify stays optional

Linking Spotify is opt-in via /login, limited to reading playlists, and revoked with /logout.

Deletion on request

Ask in our support server and we will erase your stored history and connections.

Section 01

Overview & scope

This Privacy Policy explains what information the Pepper music bot (the "Bot") and the website at pepper.muralianand.in collect, why we collect it, how long we keep it, and the choices you have. It applies to everyone who uses Pepper in a Discord server, links an account to it, or browses the website.

Pepper is an independent project. It is not affiliated with, endorsed by, or operated by Discord, Spotify, Apple, SoundCloud, Deezer or any other platform it can play from. Your use of those platforms remains governed by their own policies.

In short

Pepper stores what it needs to play music, keep your queue and preferences working, power recommendations and your /chart statistics, and keep the service running. Nothing more.
Section 02

Information we collect

Pepper has no sign-up form. Everything below is collected as a by-product of using the Bot's commands inside Discord.

Discord identifiers

Your user ID, username, discriminator and avatar URL, stored alongside tracks you request.

To attribute queued tracks to the right person, apply per-user settings and cooldowns, and show who requested what.

Server identifiers

Guild ID, the DJ role ID you configure, and the server language preference.

To keep per-server settings, permissions and localisation working across restarts.

Listening history

Track title, artist, duration, ISRC, source platform, artwork URL, track link, play count and the time it was played — recorded per user and per server.

To power the /chart command, smart autoplay, queue features and aggregate statistics.

Autoplay session

While /autoplay is on: who turned it on, the songs people requested this session, the songs autoplay has already added, songs skipped within the first 30 seconds, and a short mood label such as "mellow 90s Tamil melodies".

To keep autoplay on the mood of the session, avoid repeats and steer away from songs you skip. It is held with the player and discarded when autoplay is turned off or the player ends.

Radio listening

If you use /radio: each station’s ID, name, genre, country, stream link, logo, audio format and whether it is a verified or directory station, with how many times it was started, how long it stayed on, how often its stream dropped or failed, when it was first and last played, and who last started it — recorded per user and per server.

To rank stations on our statistics page and spot stations whose streams keep failing. Radio is kept apart from your listening history, so it never affects /chart.

Custom playlists

If you use /playlist: each playlist’s name, share code, owner, visibility, songs (track details plus who added each one and when), play count and when it was last played. A transfer offer records who it was sent to and expires after 24 hours; songs offered to pick from while adding are held for 10 minutes.

To save, play, share and transfer the playlists you build, and to rank public playlists on our statistics page.

Connected Spotify account

If you run /login: an OAuth access token, a refresh token and your Spotify display name.

To read your own Spotify playlists so you can queue them with Pepper.

Server metadata

When Pepper is added to or removed from a server: server ID, name, icon, owner, approximate member count and creation date.

Operational logging, abuse handling and capacity planning.

Feedback submissions

The text you submit through /feedback, along with your Discord tag, user ID and the server you sent it from.

To reply to you, reproduce bugs and act on suggestions.

Technical logs

Command names, errors, playback failures and timing data, kept in short-lived operational logs.

To detect outages, fix bugs and protect the service from abuse.

Website analytics

Google Analytics collects standard usage data (pages viewed, approximate region, device and browser) when you visit our website.

To understand which pages are useful. The website has no login and stores no personal account data.

What Pepper does not collect

Pepper does not read, store or analyse the content of your messages, does not record voice channels, does not collect email addresses, phone numbers or payment details, and does not track your activity outside Discord and this website.
Section 03

How we use your information

We use the information described above only to:

  • Run the Bot — resolve searches, queue and play tracks, apply filters, loops and volume, and restore state after a restart or node failover.
  • Smart autoplay — when you turn on /autoplay, Pepper looks at the songs requested this session, plus the top songs of the people in the voice channel and of the server from the last 90 days, gathers similar songs and queues the ones that best fit the mood. See AI in smart autoplay below.
  • Show your statistics — the /chart command reports your own top tracks, artists and listening time, plus the same for the server you run it in.
  • Localise responses — your saved language preference selects one of Pepper's supported translations.
  • Enforce permissions — the DJ role and command cooldowns depend on stored identifiers.
  • Maintain and improve the service — diagnosing bugs, investigating abuse and planning capacity.
  • Publish aggregate statistics — see the section on public statistics below.

We do not use your data to build advertising profiles, and we do not make automated decisions that have legal or similarly significant effects on you.

Section 04

AI in smart autoplay

Smart autoplay is the only part of Pepper that uses AI, and it only runs while someone in your server has turned on /autoplay. Pepper first builds a shortlist of similar songs with its own scoring, then sends that shortlist to an AI model from OpenAI, which chooses the songs that best continue the session and returns a short mood label.

  • What the AI receives: song titles and artist names — the songs requested this session, a few favourites of the listeners and the server, recently skipped songs and the shortlist — along with genre tags for those artists from Last.fm.
  • What it never receives: Discord usernames, user or server IDs, avatars, messages, voice audio, or who requested or skipped which song.
  • No training on your data by us: we do not use your data to train AI models. OpenAI handles API requests under its own API data policies, which state that API data is not used to train its models by default.
  • No decisions about you: the AI only chooses which songs play next. If it is slow, unavailable or over its daily limit, Pepper uses its own scoring instead.
  • Opting out: turn autoplay off with /autoplay enabled:false. Nothing is sent to the AI while it is off.
Section 05

Linking a Spotify account

Linking Spotify is entirely optional. Pepper works fully without it. When you run /login spotify, you are sent to Spotify's own authorisation page — Pepper never sees your Spotify password.

  • Scope requested: playlist-read-private and playlist-read-collaborative — permission to read your playlists, and nothing else.
  • What Pepper cannot do: it cannot modify or delete your playlists, cannot follow or unfollow anything, cannot post to your account, and cannot see your Spotify listening activity or account details beyond your display name.
  • What is stored: the access and refresh tokens Spotify issues, and your Spotify display name, held so the link survives restarts without asking you to sign in again.
  • How to revoke: run /logout and the stored tokens are deleted immediately. You can also revoke access at any time from your Spotify account's Apps settings page.
Section 06

Public statistics page

Our website publishes aggregate statistics about Pepper — total tracks played, popular songs and artists, the most played radio stations, active servers and a live view of what is currently playing across the network.

Worth knowing

The "top requesters" leaderboard shows Discord usernames and avatars of the people who have played the most tracks. Bot accounts are excluded. If you would rather not appear there, ask us in the support server and we will exclude you.

Public playlists

A playlist you make public with /playlist visibility can appear on the statistics page once it has been played — its name, share code, play count and the songs in it, and your Discord username and avatar as its owner. Private playlists are only counted; nothing else about them is published. Make a playlist private again and it drops off the page within a few minutes.

Radio stations

The radio leaderboard shows stations only — name, genre, country, logo, how many times each was started and how long it has played, added up across every server. It never shows who listened or in which server.

Server-level statistics are keyed by server ID and reflect what was played by that community. Private message content, member lists and voice activity are never part of these statistics.

Section 07

Third-party services

Pepper relies on a small number of external services to work. Each one receives only what it needs:

  • Discord — the platform Pepper runs on. All interactions pass through Discord and are subject to their privacy policy.
  • Music platforms and radio stations — our audio servers fetch the track or live stream itself from its source. Those sources see a request from our infrastructure, not from you.
  • Spotify — contacted only when you have linked an account, and only to read your playlists.
  • Radio Browser — the public station directory behind /radio. It receives the text you type into /radio (as you type, to suggest stations), your server's region to put local stations first, and a play count when one of its stations is started. These requests come from our servers and carry no Discord identifier.
  • Last.fm and Deezer — used by smart autoplay to find similar songs and genre tags. They receive song titles and artist names only, sent from our servers with no Discord identifier.
  • OpenAI — the AI model behind smart autoplay's picks. It receives song titles, artist names and genre tags, as described in AI in smart autoplay, and no Discord identifier.
  • Database and hosting providers — store the data described in this policy on our behalf under their own security commitments.
  • Google Analytics — website usage measurement only. It is not used inside the Bot.

Run by us, not by third parties

The audio (Lavalink) servers Pepper streams through and the lyrics service behind /lyrics are hosted by us. Those parts of the service pass nothing to an outside company: /lyrics sends only a track link to our own service, with no user identifier attached.

We do not sell, rent or trade your information. We disclose it only to these service providers, or where required to comply with a valid legal obligation, or to investigate abuse and protect the safety and integrity of the service.

Section 08

Retention & deletion

  • Listening history and preferences are kept while you continue to use Pepper, because they power /chart and the statistics on this site.
  • Spotify tokens are deleted immediately when you run /logout.
  • Radio listening is kept on the same terms as listening history, because it powers the radio statistics on this site.
  • Custom playlists are kept until you delete them with /playlist delete, which erases the playlist and its songs immediately.
  • Autoplay session data is discarded when autoplay is turned off or the player ends. Neither Pepper nor the AI keeps a record of it afterwards.
  • Technical logs are short-lived and rotate out automatically.
  • Server data may be removed once Pepper is no longer in that server.

To request deletion of your personal data, contact us in our official Discord server. We will verify that the request comes from the account in question and action it, keeping only what we are legally required to retain.

Section 09

Your choices and rights

Depending on where you live, you may have the right to:

  • Access a copy of the personal data we hold about you.
  • Ask us to correct information that is inaccurate.
  • Ask us to delete your data.
  • Withdraw a connection you previously authorised, such as Spotify.
  • Object to, or ask us to restrict, certain processing.

You can exercise all of these by contacting us in the support server. You can also limit what Pepper records simply by not using it — no data is collected about a member who never issues a command and whose tracks are never queued.

Section 10

How we protect your data

Access to Pepper's database is restricted to the maintainers who operate it. Traffic between Pepper, Discord and our providers uses encrypted connections, and the statistics API that powers our website is protected by a server-side key that is never exposed to browsers.

No system is perfectly secure. We cannot guarantee absolute security, and you share information with Pepper at your own discretion. If we ever become aware of a breach affecting your data, we will inform affected users through our support server and, where required, the relevant authorities.

Section 11

Where your data is processed

Pepper is operated from India and uses hosting and audio infrastructure in several countries. By using the Bot, you understand that your information may be transferred to and processed in countries other than your own, which may have different data protection rules. We take reasonable steps to ensure it remains protected as described here.

Section 12

Children's privacy

Pepper is not directed at children. Discord requires users to be at least 13 years old, or older where local law sets a higher minimum, and the same applies to Pepper. We do not knowingly collect information from anyone below that age. If you believe a child has provided us with personal information, contact us and we will delete it promptly.

Section 13

Changes to this policy

We may update this Policy as Pepper evolves. The "last updated" date at the top of this page always reflects the current version, and material changes will be announced in our support server. Continuing to use Pepper after an update means you accept the revised Policy.

Section 14

Contact us

Questions about this Policy, a data request, or something that looks wrong? Reach us in our official Discord server. We aim to respond to privacy requests within 30 days.

By using Pepper, you acknowledge that you have read and understood this Privacy Policy and consent to the handling of information described in it.