Privacy Policy — MultiMuse

Last updated: July 15, 2026

Scope

This Privacy Policy applies to MultiMuse and multimuse.app (the "Service"), operated by BackStagePass Group ("we," "us," or "our"). It covers:

  • The MultiMuse Discord bot (muse profiles, proxy posting, thread tracking, connections, and related features).
  • This website (documentation, dashboard, account linking, and support pages).
  • The MultiMuse Discord Activity (embedded connection-cloud viewer launched from Discord).

Other BackStagePass Group products have separate policies: StageHand, BackDrop. Groupie is covered at groupie.lol/privacy.

This Policy is part of our Terms of Service. By using the Service, you agree to both documents where consent is required by law.

Information We Collect

We do not sell personal information. We collect only what is needed to operate MultiMuse.

Muse and profile content

Content you create or configure, including muse names, triggers, nicknames, tags, descriptions, quotes, notes, avatars, banner images, connection graphs, share settings, and group metadata.

Proxy and message data

When you post through a muse trigger, we store the text of proxied messages (and related metadata such as message IDs, channel IDs, webhook references, and muse association) so we can sync edits and deletions with Discord. We do not index unrelated messages that do not match a configured trigger.

Discord identifiers

  • Discord user IDs for users who interact with the bot or website.
  • Guild (server) and channel IDs where MultiMuse is used or configured.
  • Message IDs tied to proxy posts and tracking features.
  • Member display names and usernames when needed for member lists, sharing, or API integrations (requires Server Members intent).

Website and dashboard

  • Discord OAuth data when you sign in (scopes such as identify, guilds, and guilds.members.read as shown at login).
  • Session cookies to keep you signed in.
  • Technical logs (IP address, browser, request metadata) for security and reliability.

Anonymous web analytics

We use a self-hosted Umami instance to understand aggregate website traffic and feature use. It records page paths, referrers, browser and device categories, approximate location, Core Web Vitals, and fixed events such as bot-invite, documentation, login, and dashboard-navigation clicks.

Umami does not set analytics cookies or identify you across websites. It briefly uses your IP address, browser information, and this website's ID to derive an anonymous session and approximate location, but does not store the source IP address. We exclude URL query strings and hashes, do not send Discord or muse identifiers as analytics properties, and respect your browser's Do Not Track setting.

Billing (if applicable)

If you purchase premium features, payment processors (such as Stripe or Patreon) may receive billing details; we store subscription status and processor identifiers, not full card numbers.

Support and feedback

Information you send us by email, Discord, or support forms.

Discord Activities (Connections)

MultiMuse offers a Discord Activity that opens an embedded viewer for muse connection clouds inside Discord (launched via bot commands, buttons, or the Discord app launcher).

  • Authentication. Inside the Activity iframe we request the Discord identify scope only (via the Embedded App SDK). We use your Discord user ID and username to load your muses and, when you choose, published public connection clouds.
  • Launch context. When the bot starts an Activity, it registers a short-lived launch intent (Activity instance ID, muse ID, optional viewer slug, guild ID) so the iframe opens the correct cloud. These records expire and are not used for marketing.
  • What you see. The Activity is a viewer for connection data you or others have published. Editing connection graphs requires the full website dashboard, not the Activity alone.
  • Public browse. If you use the generic Activity entry (without a pre-selected muse), you may browse connection clouds that owners have marked public and non-private.
  • Media. Muse avatars and images may be loaded through our Activity media proxy from allowlisted hosts (for example Discord CDN and our image CDN) to comply with Discord's iframe security rules.
  • Discord's terms. Activities run inside Discord's client; Discord's Terms of Service and Developer Policy also apply.

How We Use Information

We use collected data to provide and improve MultiMuse (proxy posting, muse management, tracking, connections, dashboard features, and the Activity viewer), authenticate users, enforce API and consent rules, maintain security, and comply with law. We do not use your data for advertising or sell it. We do not train machine learning or AI models on your message or muse content.

Sharing and Processors

We share data only as needed to operate the Service:

  • Discord — to post proxy messages, run commands, and operate the Activity.
  • Hosting and database providers — to store muse and message records.
  • Payment processors — if you subscribe to paid features.
  • Cloudflare — image and file hosting and delivery (R2 object storage and/or Cloudflare Images, including shared CDN domains such as cdn.backstagepass.quest and product-specific media hostnames); CDN, WAF, and security services when traffic is proxied through Cloudflare. Where enabled on our media zones, Cloudflare's CSAM Scanning Tool compares cached image hashes against known abusive-material lists and may block matching URLs; we receive notifications as described in Cloudflare's documentation.

Depending on your settings, muse profiles or published connection clouds may be visible to other Discord users in your servers or through public browse in the Activity.

Retention and Deletion

We retain data while you use MultiMuse and as needed for legitimate operations or legal obligations. When you delete muses or content, disconnect the bot, or delete your Discord account, we remove or anonymize associated data within a reasonable time. Anonymous web analytics are normally retained for no more than 13 months. Contact us (below) for deletion requests we cannot handle in-product.

Security

We use reasonable technical and organizational measures (including access controls and encryption where appropriate) to protect data. No system is perfectly secure. Secure your Discord account with a strong password and two-factor authentication.

Children

MultiMuse is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe we have, contact us and we will delete it.

International Transfers

Data may be processed in the United States or other countries where our providers operate. Where required, we use appropriate safeguards for cross-border transfers.

Your Rights

Depending on where you live, you may have rights to access, correct, delete, or restrict processing of your personal data, or to object or port data. Use in-bot and dashboard tools where available, or email support@backstagepass.quest. We will not discriminate against you for exercising these rights.

Changes

We may update this Policy. The "Last updated" date will change when we do. Continued use after material changes means you accept the updated Policy.

Contact

Privacy questions: support@backstagepass.quest. See also our Terms of Service.