Controlled technical preview
Sandbox rules, privacy, and project limits
The official sandbox is Bunnyland’s gated shared starting world for eligible supporters and trusted Discord members. It is operated on a best-effort basis and may be paused, updated, restored, reset, or closed as the experiment evolves.
Sandbox rules
- Treat other players and operators respectfully. Do not harass, threaten, impersonate, dox, or evade moderation.
- Do not probe another character’s claim, private memory, direct messages, credentials, or hidden world state. Privately report accidental disclosure without redistributing it.
- Do not submit secrets, sensitive personal information, or material you do not have the right to share. Ordinary play may remain in persistent world history and snapshots.
- Do not automate high-rate commands, reconnect loops, scraping, or model calls outside a coordinated test. Respect rate limits and cooldowns.
- Autonomous characters are automated and can be wrong, repetitive, or inappropriate. Do not treat their output as professional advice or a statement from a real person.
Operators can pause the world, suspend automated characters, revoke claims or accounts, disable model-backed features, and restore a verified save when safety, privacy, world integrity, or operating cost requires it.
Privacy and retained data
The hosted sandbox can retain account and claim identifiers, character actions, command results, speech and direct-message events, character-scoped memories, relationships, world history, media, moderation records, and operational or security logs. World snapshots, memories, and media persist so the world can continue and be restored. Recovery backups may temporarily retain data after it is removed from the live world.
Hosted autonomous-character and world-generation features use Ollama Cloud. A model call receives the bounded context needed for that feature, which can include a character’s current perspective, persona, needs, relevant memory excerpts, recent visible events, conversation text, and available actions. The normal controller path does not intentionally send credentials, claim secrets, full administrative snapshots, or another character’s private memories.
For a private access, export, deletion, abuse, security, or privacy request, use the private Bunnyland security advisory form. Do not place credentials, private memory, or vulnerability details in a public issue. Non-sensitive reproducible defects belong in the public issue tracker.
Requirements and control
| Path | What you need | Who controls it |
|---|---|---|
| Official sandbox | Eligibility, an individual account, and a modern browser or approved Discord access | Sandbox operators control service access, data, providers, backups, and policy |
| Private offline world | A local Python environment; external models, image generation, and tracing are optional | The local player controls the world and can keep it offline |
| Self-hosted group world | A Linux host or container environment, TLS for remote clients, and operator-managed accounts and backups | The server operator sets access, data, provider, moderation, and retention policy |
Limitations and support
- Bunnyland is experimental, developed with extensive agent assistance, and supported on a best-effort basis.
- APIs, schemas, plugins, and saves can change during the
0.xseries; only documented migrations carry compatibility promises. - Autonomous behavior and emergent stories are experimental objectives, not guaranteed outcomes.
- Optional models and image generation have their own availability, cost, privacy, and quality limits.
- The official sandbox is gated and is not a production MMO, hosted-agent platform, or service with an uptime guarantee.
- Self-hosted operators are responsible for their users, providers, data retention, backups, moderation, and public exposure.
Issues and reproducible bug reports are welcome through the public issue tracker. Individual installation consulting, guaranteed response times, long-term hosted data retention, and recovery of arbitrary local worlds are outside the support boundary.