Privacy
What Scout records, and what it cannot
Scout listens to tabletop sessions. That is an unusual thing to let into a room, so this page says exactly what it takes, what it keeps, how long, and how to make it stop.
Scout is not released. Nothing is running against anybody's table but our own, and no public bot exists yet. This page describes what the software does, so that it can be read before it matters rather than after. It will become the operative policy when Scout is first offered to a table outside the project.
Nobody is recorded without agreeing first
A session does not begin until every person present has answered. There are three answers, not two:
- Accept. You are recorded like everyone else.
- Decline. The session runs without Scout at all.
- Exclude me. The session runs, and your audio is discarded as it arrives.
One answer covers everything. You are asked once, when you first meet Scout, and that answer applies to voice and to any channel it reads. We ask once rather than repeatedly because a table asked at every turn stops reading the question, and an answer given carefully once is worth more than five clicked through.
Exclude me is not a filter applied afterwards. An excluded person's audio is dropped in the receiving code before anything is written down, which means there is no moment at which it existed somewhere and was later removed. It covers your messages too, without asking you a second question.
The same rule covers a gap the platform creates. Audio can arrive fractionally before Discord says who is speaking, and Scout discards anything it cannot attribute rather than holding it in case an answer arrives.
What Scout takes
- Voice audio from the channel it is invited to, per speaker.
- Who was speaking, as a Discord user identity.
- Consent answers, with the time and the version of the terms in force.
- Session and table identifiers, so a recording belongs to a table.
- Audio quality measurements (loudness, clipping, dropped frames). Numbers about the sound, not the content of it.
- Messages in channels your DM has specifically added, and no others. See below, because this one has conditions attached.
Text: only where you put Scout, and never anywhere else
Scout can read messages, and it starts able to read none. A channel becomes readable only when the person running your game adds it, one at a time. There is no setting that opens a server.
Where that rule lives is worth saying plainly. Discord will hand Scout the contents of any channel it can see. What stops Scout using anything outside your DM's list is our own software, not Discord withholding it. Those two things look identical from the outside, and Discord shows you neither — so we would rather tell you which one it is than let the stronger reading stand.
One thing Discord may have told you is worth correcting, because it points the wrong way. When you add an app, the screen lists Read Message History, and it also says the application cannot read your messages. Both are true of different things: the second is about your own account, not about a bot reading a channel. Scout can read the channels your DM adds, and nothing outside them.
- Only channels somebody added. Not the rest of the server, not channels created later, not a channel somebody forgot about.
- Never your direct messages. Not between you and another player, not between you and the DM, not ever. This is not a setting we chose and could change; DMs are a different thing that Scout is not part of.
- Nothing written before the channel was added. Adding a channel is not an import. Everything already in it stays unread unless somebody deliberately asks for it, which is a separate thing described below.
A channel Scout can read says so, in the channel. A pinned notice, the topic, or both. You agreed once, possibly months ago, and a room that reads your messages should tell you that where you are typing rather than leaving you to remember.
What Scout cannot take at all
- Server member lists.
- Presence: who is online, what they are playing.
- Any channel Discord has not given Scout access to. Your DM cannot add a channel Scout could not already see, so a private channel stays private whatever anybody clicks.
Importing what came before
A table two years in has its history in a channel already, and that history is often where the correct spelling of an invented name lives. A DM can ask Scout to read back over a stated period as preparation work.
That material is treated as the least consented thing in the system, because it is. Old history contains people who never met Scout, guests who turned up once, players who have left, and possibly people who were children at the time.
So imported history lands somewhere it cannot be used. It is not part of your campaign record and cannot be searched or retrieved while it sits there. It becomes usable only for people whose consent is established. Everything else is deleted rather than kept aside, and where somebody cannot be reached to ask, deletion is what happens rather than holding it in case they turn up.
How long it is kept
Twelve months by default. The period is fixed at the moment consent is given and travels with that session, so changing the default later does not reach back and extend anything already recorded.
The intention is to shorten this, and to let a table choose its own period, once Scout is past prototyping. A short default is the safer one and it is where this is heading.
Deleting it
You can ask for your audio to be removed and it will be, from every table you have played at rather than only the one you are thinking of. Scout knows which sessions you were part of, so this is a matter of finding records rather than searching recordings.
Two consequences of how it is built are worth stating plainly, because they are in your favour:
- Nothing is shared between tables. Two tables that record identical audio hold separate copies. This costs us storage and means erasing your data for one table can never damage another table's recording.
- A recording is stored under the table it belongs to, so the boundary between one group and another exists in the storage itself rather than in a query somebody has to remember to write correctly.
Who else sees it
Transcription requires speech recognition, which may run on a third party's service. When Scout is offered publicly this page will name that provider, what reaches it, and what it is permitted to do with it. It is not named here because it has not been chosen.
Beyond that: nobody. Recordings are not sold, not used to advertise to you, and not used to train a general model.
The signup form on the front page
If you asked to hear about the alpha, we hold the email address you gave and whether you ticked the alpha box. That is all it is used for. The form is protected by Cloudflare Turnstile, which is there to keep automated signups out; it sets no cookies and does not follow you elsewhere.
Asking us something
Questions, corrections and deletion requests go to the address on the front page. This section will carry a named contact and a response time when Scout is offered publicly.