Privacy policy
Effective date: August 1, 2026
Juno is a workflow platform for Discord communities, operated by Veld Labs LLC, a Delaware limited liability company (“Veld”, “we”). This page explains what data Juno touches, why, who is responsible for it, and how long it is kept — in plain language, because that is how the rest of the product talks too. If anything here is unclear, write to us at hello@veld.gg.
This policy covers the Juno website and editor, the Juno API, and the Juno Discord bot. Juno is not affiliated with Discord.
The short version
- You sign in with Discord. We receive your Discord identity — never your email address or password.
- Servers install Juno and build workflows. Those workflows decide what data Juno processes on that server, and the server's operators are responsible for what they build and for telling their members.
- When a workflow on a server listens to messages, Juno receives and stores those Discord event records — including message content — for a limited time, so the workflow can run and its runs can be audited.
- We do not sell personal data, we do not run ads, and we do not use personal data for targeted advertising.
Who is responsible for what
Two different kinds of processing happen on Juno, with different roles:
- Your account, billing, the Store, security, and abuse prevention. Here Veld decides what is processed and why. In privacy-law terms, Veld acts as the business (controller) for this data.
- Workflow data on a server. A server's operators decide which workflows to install, which events they listen to, and what they keep. Veld supplies and operates the infrastructure that carries out those instructions — in privacy-law terms, Veld acts as a service provider (processor) for this data, and the server's operators are responsible for it.
If you operate a server, that responsibility is real: only deploy workflows you have the authority to deploy, and inform your members about what runs on your server where the law or basic decency requires it. Organizations that need a data processing addendum (DPA) can request one at hello@veld.gg.
If you are a member of a server that uses Juno, you may never visit this website — so this paragraph is for the administrators who do: your members' first point of contact is you. Members can also always contact us directly (see Your rights and choices).
What we collect and why
Your Discord identity
When you sign in, Discord shares your user ID, username, display name, and avatar with us. We store these so you can be recognized as the owner of your sessions, workflows, and purchases. We do not ask Discord for your email address, and you never enter a password on Juno.
Your server list
To show which servers you can manage, we ask Discord for the list of servers on your account. This list is held in a short-lived cache (minutes, not days) and is not kept permanently.
Servers that install Juno
For each server where the bot is installed we keep the server's ID, name, and icon, when it was installed, and whether it is still active.
What you build
Workflows, their settings, names, descriptions, and version history are stored so your server can run them and you can keep editing them. A workflow document can contain whatever its creator puts into it — for example message templates or channel and role choices.
What workflows process when they run
This is the most important part. Juno's bot connects to Discord's gateway and receives events for servers where it is installed. When a published workflow on a server subscribes to an event, Juno stores a record of that event so the workflow can run reliably and so its runs can be traced afterwards:
- Event records. The Discord event as Discord sent it. For message-based triggers this includes the message content, its author, and attachments' metadata. Juno's workflow runtime does not store direct messages.
- Actions. The messages and other actions a workflow sends back to Discord, and Discord's response to them.
- Workflow state. Values a workflow keeps between runs — for example an XP counter per member. The workflow's creator decides what is stored and whether it is per-server, per-member, or per-channel.
- Run receipts. Timing, outcome, and error codes for each run, together with the Discord user ID and channel ID involved — but no message content.
Each of these categories has a retention limit — see How long we keep things.
The activity screen creators see in the editor is built only from run receipts: it shows IDs, timings, and outcomes, never message content or event payloads.
Juno is not meant for sensitive data. Discord messages can incidentally contain anything, but workflows must not be built to collect health details, credentials, payment card numbers, government identifiers, or other highly sensitive information — our terms of service prohibit it, and server operators are responsible for avoiding such configurations.
Billing
Paid plans are handled by Stripe. Your card details go directly to Stripe and never touch Juno's servers. We store the Stripe customer and subscription identifiers, which plan a server is on, and who purchased it. Billing records are kept as long as tax and accounting law requires.
The Store
If you publish a workflow to the Store, the listing, its releases, and its release notes are public by design. If you report a listing, we store your report, including the description you write, so moderators can act on it.
Connected AI tools
If you connect an AI tool or agent to Juno, it acts with your account through scoped, revocable grants. We record which tool was granted access, which scopes it holds, and an audit trail of the actions it takes. You can revoke a grant at any time from the connections page.
What a connected tool can reach is bounded by its scopes. Today's scopes cover reading and editing your workflows, publishing, and the same payload-free activity view you see in the editor — they do not expose stored message content. What a connected tool does with data it receives — including whether it retains it or uses it for training — is governed by that tool's own policies, and connecting it is your decision and your responsibility. Veld does not send your data to AI providers and does not use your data or your server's messages to train models.
Cookies and sessions
Juno uses one cookie during Discord sign-in — a short-lived (10 minute), essential cookie that protects the sign-in from forgery. After sign-in, your browser holds a session token that is valid for up to 30 days. We keep at most ten active sessions per account; older ones are removed automatically. The Discord tokens that back your session are encrypted at rest. There are no advertising or tracking cookies.
What we do not do
- We do not sell or rent personal data, and we do not share it for targeted advertising. Ever.
- We do not run ads.
- The product does not include third-party analytics or advertising trackers.
- We do not send marketing email — we do not even have your email address.
- We use your IP address to rate-limit abuse and to keep the service secure. Like on virtually every online service, IP addresses and request metadata can appear briefly in infrastructure and security logs, which rotate automatically; we do not store IP addresses in our application database or link them to your profile.
Who we share data with
We share personal data only with the service providers below, only for the purposes described, and never for their own advertising:
- Discord — Juno is built on Discord; running a workflow means exchanging data with Discord's API on your server's behalf. Avatars and server icons are loaded from Discord's CDN.
- Payment processing — Stripe, for paid plans.
- Website delivery and security — Cloudflare serves and shields the Juno website and editor.
- Cloud infrastructure — the servers and databases Juno runs on, operated under our configuration and access controls.
We keep a current list of these providers and will share it on request at hello@veld.gg. Beyond them, we only disclose data if the law requires it, or to protect the rights and safety of our users and service.
How long we keep things
Our rule is simple: nothing is kept longer than it is needed for the purpose it was collected for. The default schedule:
| Data | Kept for |
|---|---|
| Server-list and permission lookups | Minutes (cache) |
| Sign-in cookie | 10 minutes |
| Sessions | Up to 30 days |
| Event records and action payloads (may include message content) | 30 days |
| Run receipts, capability and grant audit records (IDs and outcomes, no content) | 12 months |
| Workflow state | Until the workflow or its server removes it; deleting a workflow deletes its stored state |
| Workflows and your account | Until you delete them or ask us to |
| Your account and workflows after your account ends | Deleted within 30 days (published Store releases excepted — see the terms) |
| Archived Store install records | 90 days |
| Store reports and moderation records | 12 months after the matter is closed |
| Billing records | As long as tax and accounting law requires |
| Infrastructure and security logs | Short-lived, rotated automatically |
When the bot is removed from a server, that server's runtime records and workflow state follow the same schedule. Deleted data also leaves our backups as they expire in rotation. Where we are legally required to keep something longer — or need it for an active security investigation or legal claim — that specific record is kept for that purpose only.
Your rights and choices
- See and edit — your workflows, settings, and activity are visible in the editor.
- Revoke — remove Juno's authorization in your Discord settings, revoke a connected tool's grant on the connections page, or remove the bot from your server to stop all processing for it.
- Access, export, correct, delete — subject to identity verification and applicable legal exceptions, you can request access to, a copy of, correction of, or deletion of personal information associated with your account or server by emailing hello@veld.gg. The legal exceptions are the usual ones: records we must keep for billing and tax, fraud and abuse prevention, security investigations, or legal claims, and backups awaiting rotation.
- Server members — you can make these requests too, even without a Juno account: tell us your Discord user ID and the server, and we will verify and handle it. Where the data belongs to a server's workflows rather than to us, we may need to involve that server's operators.
- Appeal — if we decline a request, we will say why, and you can appeal by replying to our answer. Depending on where you live, you may also complain to your state attorney general or data protection authority.
We answer requests within the timelines applicable law sets, and we do not treat anyone worse for exercising their rights.
International users
Juno is operated from the United States and data is processed there. If you use Juno from the European Economic Area, the United Kingdom, or another region with its own data-protection rules, the following applies to the data Veld is responsible for:
- Legal bases. We process account and billing data to perform our contract with you; billing records to meet legal obligations; security, abuse-prevention, and service-improvement data on the basis of our legitimate interest in running a safe, working service. Workflow data on a server is processed on that server operator's instructions — the operator is responsible for having a lawful basis for it.
- Transfers. Where the law requires safeguards for transfers to the United States, we put recognized safeguards such as standard contractual clauses in place with our providers and customers.
- Your rights under those laws — access, rectification, erasure, restriction, portability, objection — are honored through the process in Your rights and choices.
Security
Discord tokens are encrypted at rest, sessions are validated on every request, workflow execution runs in an isolated runtime designed to keep workflows inside their own server's data and permissions, and connected tools act only through scoped, revocable grants with an audit trail. No online service can promise perfect security, and we do not — but security is a design constraint in everything we ship. If a security incident affects personal information, we will investigate it and notify affected individuals, customers, and regulators where applicable law requires.
Children
Juno is not directed at children, and we do not knowingly collect personal information from children under 13. You must meet Discord's minimum age requirements (Discord Terms of Service) to use Juno, and our terms of service prohibit workflows built to collect information from or about children. If you believe a child's data has ended up in Juno, contact us and we will delete it.
Changes to this policy
When this policy changes in a way that matters, we will update this page and its effective date, and for significant changes we will say so in the product.
Contact
Veld Labs LLC, a Delaware limited liability company 1111B South Governors Avenue, Dover, DE 19904, United States hello@veld.gg