Information used for an explicit request
After an event for a comment mentioning u/redpullerbot, the bot reads the triggering comment’s ID, text, author name, and author ID. The name is checked to avoid responding to the app’s own comment; the ID is used for rate limiting. To find supported links, the bot may also read up to three direct parent comments and the root post’s ID, URL, and text. Each piece of text is bounded before link extraction, and no more than three matching links are returned.
The text and URLs are used while resolving that request. The reviewed bot code does not write comment or post bodies, URLs, RedGifs media metadata, thumbnails, or media files to its Redis records.
Purpose and data minimization
The bot uses this limited context to find supported public RedGifs links and, when appropriate, reply with no more than three clean RedPuller URLs. It does not read private Reddit messages. The request text and URLs are processed for that link lookup and are not written into the bot’s Redis records described below.
Devvit Redis records and configured expiry
The app uses installation-scoped Devvit Redis for duplicate-response protection and rate limiting. The mention key is rpbot:v1:mention:<triggerCommentId>; its record contains v, status, at, and an optional replyId. The rate-limit keys are rpbot:v1:rate:user:<sha256UserId>:<window>, rpbot:v1:rate:post:<sanitizedPostId>:<window>, and rpbot:v1:rate:global:<window>. Their values are expiring counters.
- Processing status: configured to expire after 10 minutes.
- Successful-reply status: configured to expire after 30 days.
- No-match status: configured to expire after 24 hours.
- Failed status: configured to expire after 60 seconds.
- Rate-limited status: configured to expire after 10 minutes.
- User rate counter: 10-minute window.
- Post rate counter: 1-hour window.
- Global rate counter: 1-minute window.
- Post mention index: comment IDs and timestamps in fixed UTC-day buckets, expiring no later than 31 days after the bucket starts.
These are the expirations configured by the bot for its Redis keys; they do not describe Reddit’s or Devvit’s separate records or logs. They are automatic TTLs, not deletion-on-request behavior.
Operational logs
The production handler writes mention.received, mention.completed, mention.state_unconfirmed, mention.failed, and mention.failure_state_unconfirmed events with console.info. Depending on the event, fields can include the triggering comment ID (triggerId), outcome (result), elapsed time in milliseconds (durationMs), and an error category (errorCategory, an error name or unknown). The event objects do not include comment or post bodies. The bot source does not specify platform-log access or retention, so this notice makes no retention or deletion promise for those logs.
Deletion events and account-deletion limitation
Reddit’s Devvit Rules require stored user IDs to be removed when an account is deleted and deleted post or comment content to be removed from app storage. The Rules also note that certain contextual metadata, such as IDs, may be retained for deleted posts or comments.
The bot handles onCommentDelete and onPostDelete events in addition to onMentionInCommentCreate. A comment deletion removes its matching mention record and the comment ID from the bounded index buckets for its post. A post deletion removes the mention records referenced by that post’s bounded index, the index buckets, and that post’s current and immediately previous rate-counter windows. Cleanup is limited to the IDs in the validated event and the app’s own installation-scoped Redis keys; the bot does not scan Redis globally.
The app has no onAccountDelete trigger or immediate account-wide deletion mechanism. Its per-user rate counter uses a stable, linkable SHA-256 pseudonym of Reddit’s user ID and expires within 10 minutes of its first increment; deletion triggers do not remove that counter. This pseudonym is not anonymous and is not an account-deletion workflow. Per-post rate counters expire within one hour. The installation-wide rate counter expires within 60 seconds and is preserved by post deletion. The post mention index stores post IDs in keys and comment IDs with timestamps in sorted-set members; its fixed UTC-day buckets expire no later than 31 days after the bucket starts. These operational IDs and status metadata are not comment or post body content.
The bot does not delete its Reddit reply when the triggering mention is deleted. The stored reply ID is operational metadata; Reddit’s comment deletion and moderation behavior remains with Reddit and authorized users or moderators. If a deletion event is not delivered or cleanup fails, the configured expirations above bound the relevant Redis records.
Security
The reviewed implementation uses bounded Reddit context, limits the number of returned links, validates supported RedGifs URLs, uses expiring Redis records for duplicate and rate controls, and handles post/comment deletion events for its bounded Redis records. These are implementation safeguards, not a guarantee that every risk or unauthorized access can be prevented. The bot has no account-deletion trigger or user-directed account deletion endpoint.
Reddit access, network requests, and advertising
The bot uses Devvit’s Reddit API to read the triggering comment and bounded related context and, when appropriate, submit a Reddit comment reply. It also uses Devvit Redis. Its Devvit configuration disables the HTTP permission, and the reviewed source contains no outbound HTTP client call to RedGifs, RedPuller, or an advertising provider. The bot has no ad placement and does not send Reddit content to an advertising provider.
RedPuller.com is a separate ad-supported website. This bot notice does not describe data handled during a visit to that website; see the website’s Privacy Notice and Terms.
Eligibility and younger users
The bot’s stated eligibility is 18 years old or the age of majority where the user lives, whichever is higher, consistent with the separate website’s terms. The reviewed bot code does not implement an age-verification gate. The bot is not intended for children or anyone below that stated age.
Changes to this policy
This policy may be updated when the bot’s implementation or data practices change. The current version will be published at this URL; check it again when using the bot. This notice describes the reviewed implementation and is not legal advice.
Contact, reports, and requests
For bot privacy questions, support, and issue reports, contact support@legal.redpuller.com. The bot source does not specify platform-log retention or implement an account-wide deletion-request mechanism. The website’s Copyright and rights page is only for copyright notices about RedPuller.com; it is not a Bot privacy, support, or data-deletion channel. Do not send Reddit data or deletion requests there.
Related bot policies
See the RedPuller Bot overview and its Terms.