Privacy policy

This policy explains what Kōtuitui processes when it helps coordinate Discord scheduled events and, if you choose, synchronize them with Google Calendar.

Effective 27 August 2026

Overview

Kōtuitui is a Discord bot for scheduled-event coordination. It can show which members have marked a scheduled event as Interested. Google Calendar synchronization is optional and begins only after you connect Google Calendar and enable synchronization.

The public Kōtuitui website is a static site hosted by Cloudflare Pages. The site itself does not intentionally set cookies, use analytics or advertising, include embedded trackers or externally hosted fonts, or load client-side scripts.

Information from Discord

To provide its commands and synchronization, Kōtuitui may process:

  • Your Discord user ID, the Discord guild ID, and scheduled-event IDs.
  • Your interest status for a scheduled event.
  • Scheduled-event details: title, description, start and end times, location, and the Discord event URL.
  • Operational account information such as your last recorded interaction and whether the operator has blocked the account.

Kōtuitui is configured with Discord's guilds, members, and scheduled-events intents. It is not configured with Discord's message-content intent and does not read ordinary channel messages.

Google Calendar information

If you connect Google Calendar, Kōtuitui uses Google's OAuth flow to request only the calendar.events permission needed to create, update, and delete synchronized calendar events. It does not request access to Gmail, Drive, Contacts, or unrelated Google services.

Kōtuitui stores a reference to your credential and your primary calendar ID. Google refresh tokens are stored separately on protected persistent storage with restricted filesystem permissions. Short-lived access tokens remain in process memory while needed.

For an event you have requested to synchronize, Kōtuitui sends the event title, description, start and end times, location, and Discord URL to Google Calendar. Calendar notifications are disabled for these operations. Kōtuitui uses deterministic event IDs so it can find and update the event it created.

Google API Services User Data Policy. Kōtuitui's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

How information is used

Kōtuitui uses the information above to:

  • Answer the /interested command with the members interested in a scheduled event. These responses are sent ephemerally.
  • Backfill and maintain Google Calendar copies of Discord events when you have enabled synchronization.
  • Process updates and removals for the synchronized events you requested.
  • Operate, secure, troubleshoot, and improve the bot. Console logs may include timestamps, exceptions, HTTP status codes, and event IDs. There is no separate analytics database.

Kōtuitui does not sell personal information and does not use calendar information for advertising.

Who receives information

Information is shared with the services needed to provide the feature you choose:

  • Discord: Kōtuitui operates within Discord and uses Discord's scheduled-event and member information to answer commands and determine event interest.
  • Google: If you enable synchronization, the event details described above are sent to Google Calendar to create, update, or remove the requested event.
  • Cloudflare Pages: The public website is hosted by Cloudflare Pages. Cloudflare may process ordinary web-request information, such as an IP address, timestamp, user agent, and security metadata, to deliver and protect the site. See Cloudflare's privacy policy.

The bot's database, outbox, refresh-token files, and backups are kept on protected persistent storage controlled by the operator.

Retention

Database user rows older than one year since their last recorded interaction are deleted. Related database records are deleted through the database's cascading relationships.

Disabling synchronization queues removal of the Google Calendar events created by Kōtuitui, but it does not itself delete the stored Google connection or refresh token. Refresh-token files are not automatically pruned by the database cleanup. Runtime logs do not have a fixed retention period described here and may be retained for operational and security purposes.

Your choices

  • You can use Kōtuitui without connecting Google Calendar.
  • You can enable or disable calendar synchronization through the bot's calendar commands.
  • You can revoke Kōtuitui's Google access through your Google Account. Revocation prevents the revoked credentials from being used for further access.
  • You can ask the operator to delete stored personal information, including the stored Google connection and refresh-token file. Contact details are below.

If you disable synchronization, event removal is queued for processing. If you need the stored connection or token deleted as well, make that explicit in your request.

Security

The operator uses protected persistent storage for the database, outbox, refresh tokens, and backups. Refresh-token files have restricted filesystem permissions, and access tokens are held in process memory. No online service can guarantee absolute security, so do not share credentials or sensitive information in Discord commands.

Contact and changes

To ask a privacy question or request deletion, contact the operator through the relevant Discord community or via the operator's public GitHub profile. Please include enough information to identify the Discord account or Google connection involved, but do not send a Google password or refresh token.

This policy may change as Kōtuitui changes. The effective date at the top of this page identifies the current version. Material changes will be reflected here with an updated date.