SprintBot

Privacy policy.

Last updated: 8 August 2026

Overview

SprintBot is a private Discord learning coach and staff operations tool for the IT@JCU Design Sprint community. It is designed to minimise collection of student conversation data and to keep operational access restricted to authorised staff.

Discord conversations

SprintBot retrieves recent Discord conversation messages only when needed to answer a request. SprintBot does not store student question text, answer text, thread transcripts, embeddings of student messages, or OAuth access tokens.

Messages remain subject to Discord server settings and Discord's own data practices. Discord's retention and processing are separate from SprintBot.

Operational and diagnostic data

SprintBot stores limited pseudonymous diagnostic information so the service can be operated, evaluated and troubleshot. This may include a secret-keyed user hash, request identifiers, internal sprint, team and learning-role identifiers, route and policy outcomes, model and backend identity, citation status, character counts, component timings, completion state and timestamps.

These diagnostic records do not contain question text, answer text, prompts, source text or conversation history. Event-level analytics and pseudonymous diagnostic traces expire after 90 days. Non-identifying daily usage aggregates may be retained for up to 12 months.

Sprint membership and role data

SprintBot stores the student-to-Discord mappings and temporal team and Design Sprint learning-role assignments required for its authorised sprint functions. Access to this information is limited to authenticated staff, with mutation restricted to authorised Sprint Manager roles.

The institutional owner must approve the retention period for identifiable student sprint-state data before operational use. At the authorised deletion date, those mappings and dependent temporal assignments are to be deleted from the operational database and applicable backup expiry verified.

Moderation records

When authorised staff use moderation functions, SprintBot may record the acting staff identifier, target member identifier, action, reason, result and necessary operational details. Moderation audit records are retained for up to 12 months. Secret-, token-, password-, authorisation- and cookie-shaped fields are redacted before audit persistence.

Staff authentication

The staff dashboard uses Discord OAuth2 for authentication. Dashboard sessions last up to eight hours. OAuth state and PKCE verifier data are removed after successful sign-in, and OAuth access tokens are not stored. Staff Discord membership is rechecked through Discord when protected functions are used.

Knowledge files

Approved SprintBot knowledge files, extracted text and associated embeddings are stored on infrastructure controlled for the service. Student submissions, private messages, special-consideration information and other material not approved for SprintBot must not be uploaded as knowledge sources.

Purpose and access

Data handled by SprintBot is used to provide the learning-coach, sprint-state, staff administration, safety, moderation, diagnostic and service-evaluation functions described above. SprintBot is not intended to create a hidden archive of student conversations or retain operational student data for unrelated research use.

Changes

This policy may be updated when SprintBot's features, deployment, retention rules or data practices change. Material changes should be reflected here before the affected functionality is used.

Contact and questions

For questions about SprintBot privacy, data handling or access, contact the SprintBot operator or teaching staff through the communication channels provided for the Design Sprint. Technical security concerns should not include sensitive details in a public issue.