Bot & Automation Policy
Pre-launch draft · not effective. Before any bot feature launches, counsel must set the conduct-bot member threshold, the exact contents of a serious-category escalation, and the bot-operator terms. This policy is incorporated into the Terms of Service.
1. What a bot is
A bot is an automated member account. Every bot must be visibly labelled as a bot, attached to a responsible operator, and given an explicit role like any other member. A bot acts only through the permissions its project grants it, and every action it takes is attributed to the bot in the project’s history. Undisclosed or deceptive automation is prohibited by the Acceptable Use Policy.
There are two kinds:
- Mahanu bots are operated by Mahanu as part of the hosted service, under these policies and the Privacy Notice. The required conduct bot in Section 3 is a Mahanu bot.
- Third-party bots are operated by someone else — a member’s reminder bot, a bridge to a community on another service, a tool a project trusts. Their operators are not Mahanu.
2. Adding a bot to a project
A project owner decides which bots a project uses; in a project with a supervised member, the Guardian Addendum requires the guardian’s approval. Before a bot is enabled, Mahanu must show who operates it, which permissions it requests, and what material those permissions let it receive.
A third-party bot’s operator is a separate recipient the project deliberately chooses, like a custom endpoint or personal API-key provider: it acts under its own terms and privacy practices, it is not Mahanu’s subprocessor, and Mahanu does not make a data-use promise on its behalf. Removing a bot revokes its future access; it cannot unshare material the operator already received.
A bot operator must keep the bot labelled, stay within its granted permissions, collect only the material its function needs, secure its credentials, and never harvest member data, profile members, resell or trade material it receives, or contact members outside the project’s surfaces. Mahanu may suspend or remove a bot or its operator under the Acceptable Use Policy.
3. The required conduct bot
A hosted project must run the Mahanu conduct bot when it has more than [member threshold] members or includes a supervised member. While either condition applies, the conduct bot appears as a visible, labelled member and cannot be removed, muted, or filtered by the project.
The conduct bot checks project conduct surfaces against the Acceptable Use Policy, warns in place, and raises flags to the project’s owners — and to the guardian, for anything involving a supervised member. It does not make Mahanu a reader of the project: an ordinary conduct flag stays inside the project and is not transmitted to Mahanu or used as a moderation feed.
Only the serious categories defined in the effective policy — child sexual exploitation or grooming, and imminent violence — generate an escalation to Mahanu. In a managed-cloud project, an escalation carries the flagged material and the minimum context needed to assess it. In an encrypted project, team-private payloads remain ciphertext to Mahanu; an escalation is content-free (category and project identifiers only) and the guardian is notified directly. The effective policy must state exactly what an escalation contains before the conduct bot is required.
The conduct bot handles data narrowly. It evaluates conduct surfaces in place and keeps no copy of unflagged content; it builds no behavioural profile of any member; and its material is never used for advertising, profiling, paid placement, or AI training. It does not grade quality, viewpoint, or artistic merit. A flag lives inside the project and expires under the Retention & Deletion Policy; an escalation is access-controlled and logged at Mahanu, and no account-level enforcement decision is made by automation alone — a person reviews first, and the decision is appealable under Reporting & Appeals.
Where law requires it — for example, apparent child sexual-abuse material — Mahanu must report an escalation to the designated authority and preserve the reported material for the legally required period. Counsel must confirm each supported jurisdiction’s reporting and preservation duties before the conduct bot launches.
4. Reports and review
Report a bot that misbehaves — including the conduct bot — through Reporting & Appeals. A conduct-bot flag or escalation that leads to an enforcement action is reviewable there like any other hosted-service decision.
Mahanu