Controlled technical preview

Sandbox rules, privacy, and project limits

The official sandbox is Bunnyland’s gated shared starting world for eligible supporters and trusted Discord members. It is operated on a best-effort basis and may be paused, updated, restored, reset, or closed as the experiment evolves.

Sandbox rules

Operators can pause the world, suspend automated characters, revoke claims or accounts, disable model-backed features, and restore a verified save when safety, privacy, world integrity, or operating cost requires it.

Privacy and retained data

The hosted sandbox can retain account and claim identifiers, character actions, command results, speech and direct-message events, character-scoped memories, relationships, world history, media, moderation records, and operational or security logs. World snapshots, memories, and media persist so the world can continue and be restored. Recovery backups may temporarily retain data after it is removed from the live world.

Hosted autonomous-character and world-generation features use Ollama Cloud. A model call receives the bounded context needed for that feature, which can include a character’s current perspective, persona, needs, relevant memory excerpts, recent visible events, conversation text, and available actions. The normal controller path does not intentionally send credentials, claim secrets, full administrative snapshots, or another character’s private memories.

For a private access, export, deletion, abuse, security, or privacy request, use the private Bunnyland security advisory form. Do not place credentials, private memory, or vulnerability details in a public issue. Non-sensitive reproducible defects belong in the public issue tracker.

Requirements and control

PathWhat you needWho controls it
Official sandboxEligibility, an individual account, and a modern browser or approved Discord accessSandbox operators control service access, data, providers, backups, and policy
Private offline worldA local Python environment; external models, image generation, and tracing are optionalThe local player controls the world and can keep it offline
Self-hosted group worldA Linux host or container environment, TLS for remote clients, and operator-managed accounts and backupsThe server operator sets access, data, provider, moderation, and retention policy

Limitations and support

Issues and reproducible bug reports are welcome through the public issue tracker. Individual installation consulting, guaranteed response times, long-term hosted data retention, and recovery of arbitrary local worlds are outside the support boundary.