Privacy Policy
This Privacy Policy describes how the operator of MysticMommy (“MysticMommy”, “we”, “us”, or “our”) collects, uses, stores, and shares information when you interact with the MysticMommy Discord application (the “Bot”), its associated web dashboard, and any related services (together, the “Service”). By adding the Bot to a Discord server or interacting with it, you acknowledge this Policy. While the Bot is connected to a voice channel, the operator dashboard records member presence intervals and mute/deaf state changes for voice analytics and shows a live roster (see Section 1). If you do not agree with this Policy, do not use the Service and remove the Bot from your server. You can view this Policy at any time by running the /about command.
1. Information we collect
We collect information automatically whenever the Bot is used. This includes, without limitation:
- Discord account data: your Discord user ID, username, display name, avatar URL, and interface locale (language setting), as provided by the Discord API.
- Server (guild) data: server IDs, server names, server icons, approximate member counts, server locale, voice channel IDs where the Bot is active, and when the Bot is added to or removed from a server.
- Usage and telemetry data: every command and interaction you direct at the Bot (slash commands with their option values, button presses, menu selections, and form submissions - including timestamps, success/failure status, error details, and response latency), every track you request or search for, and detailed playback events - including what was played, who requested it, when playback started and ended, how long it played, who skipped or stopped it, loop iterations, queue activity (tracks added, cleared, or dropped), the Bot’s voice-channel session times, and the voice channel in which it occurred. We also record the number of people in the voice channel when a track starts and ends.
- Coin economy and roulette data: every coin credit, charge, and refund, including its source, amount, resulting balance, timestamp, and related command, playback, or roulette reference. For roulette we record each wager, bet type, multiplier, winning number, win/loss result, payout, net profit or loss, balance after settlement, interaction source, and placement/settlement timestamps. Bets that have been placed but not settled remain visible for reconciliation.
- Voice analytics: while the Bot is connected, we record who joins, leaves, reconnects, or moves into or out of its voice channel, with timestamps, display metadata, bot status, and self/server mute, deaf, streaming, and video state intervals. The live roster is deleted when the Bot disconnects; interval history is retained under Section 4. The current playback architecture does not provide inbound audio to the Bot. If audio measurement becomes available, decoded audio is processed only in memory and immediately discarded; only speech timing and numerical audio-level summaries are stored. We do not store recordings, audio samples, or transcripts.
- Content data: playlists you create (names, emoji, ordering), tracks you add to playlists, tracks you “like”, the URLs and identifiers you submit for playback, and associated metadata (titles, artists, sources, ISRCs, artwork URLs, durations).
- Derived and aggregated data: statistics, trends, rankings, and other insights we compute from the data above (for example, listening histories, most-played tracks, and per-user or per-server activity metrics).
- Dashboard data: for authorized dashboard administrators, the GitHub account identifier used to sign in and session cookies required for authentication and theme preference.
Telemetry collection is an integral, always-on part of how the Service operates and cannot be disabled while the Bot is present in a server. The Bot does not read or store the content of text messages other than commands and inputs directed at it, and it does not record or store voice recordings or transcripts.
2. How we use information
We use the information we collect for purposes including:
- operating, maintaining, and providing the features of the Service;
- producing telemetry, analytics, dashboards, statistics, and reports about how the Service is used, at any level of granularity (per-user, per-server, per-track, or aggregate);
- improving, developing, testing, and training new and existing features, systems, and services;
- monitoring performance, debugging, and diagnosing errors;
- preventing abuse, enforcing our Terms of Service, and securing the Service;
- complying with legal obligations; and
- any other purpose disclosed to you at the time of collection or to which you consent.
Where the EU/UK General Data Protection Regulation applies, we rely on the following legal bases: performance of a contract (providing the Service you request), our legitimate interests (operating, analyzing, securing, and improving the Service), consent where required, and compliance with legal obligations. Our legitimate-interest processing of usage telemetry is necessary to run, understand, and improve the Service and is limited to data generated by your interaction with it.
3. How we share information
We may share information:
- With service providers that host and support the Service (including hosting infrastructure and database providers), who process data on our behalf;
- With audio sources: when you request a track, the relevant identifier or URL is transmitted to the applicable third-party source (such as YouTube, SoundCloud, Spotify, Bandcamp, Vimeo, or Twitch) to resolve and stream it. Those services have their own privacy policies;
- Within Discord: information such as now-playing details, queue contents, playlists, and requester names is visible to other members of the server where the Bot operates;
- For legal reasons, if we believe disclosure is required by law or necessary to protect our rights, users, or the public;
- In a business transfer, such as a merger, acquisition, or sale of assets, in which case data may be transferred to the successor; and
- In aggregated or de-identified form that does not reasonably identify you, which we may use and share without restriction.
We do not sell your personal information for money.
4. Data retention
We retain personal data only as long as it is needed for the purposes described above. Individual telemetry and playback-history records (play events, command and interaction events, queue and session events, coin ledger entries, and roulette events) are retained for up to 24 months from collection, after which they are deleted or irreversibly aggregated and de-identified so that long-range statistics remain accurate without identifying you. Raw voice state events are retained for up to90 days; voice presence/state intervals and numerical audio aggregates are retained for up to 365 days. Account and content records you create (playlists, likes, coin balances) are kept while you continue to use the Service. You may request earlier deletion at any time as described below. Aggregated or de-identified data may be retained indefinitely.
5. Your rights and choices
Depending on where you live (for example, under the GDPR, UK GDPR, or the California Consumer Privacy Act), you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. You will not be discriminated against for exercising these rights.
All requests are handled by email: to exercise any right - including your right to object to our legitimate-interest processing of usage telemetry, or to request deletion of your records - contact us at lev@gymshackles.com from a means that lets us verify you control the Discord account concerned. We respond within the timeframe required by applicable law. You may also lodge a complaint with your local data protection authority. You can stop new collection at any time by ceasing to use the Bot or by removing it from your server (server administrators only). The /about command in Discord links to this Policy and the contact address above.
6. International transfers
The Service is hosted on infrastructure that may be located in countries other than your own, including the United States. Where required, we rely on appropriate safeguards (such as standard contractual clauses implemented by our hosting providers) for such transfers.
7. Security
We use reasonable technical and organizational measures to protect data, including encrypted transport, access controls on the dashboard, and private networking between internal components. No system is perfectly secure, and we cannot guarantee absolute security.
8. Children
The Service is not directed to children under 13 (or the higher minimum age required to use Discord in your country), and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
9. Changes to this Policy
We may update this Policy at any time. The “Last updated” date above reflects the latest revision, and material changes will be indicated by updating that date. Continued use of the Service after a revision takes effect constitutes acceptance of the revised Policy.
10. Contact
Questions about this Policy or our data practices: lev@gymshackles.com. See also our Terms of Service.