Privacy Policy
Effective: 2026-09-27
Mimiq is a Discord bot and dashboard that generates text-to-speech audio and lets server members create cloned voices from audio samples. This page explains what data we collect, why we collect it, and how long we keep it.
The data controller is Nadia Danu Maxine Christiana Alton, a UK sole trader trading as Mimiq. Contact: support@mimiq.gg.
What we collect
- Discord identifiers. Your Discord user ID, username, and avatar; the IDs and names of servers you administer; the IDs of channels and roles in those servers. We receive these from Discord's OAuth flow and gateway events.
- Voice samples (cloning only). When you run
/cloneor upload samples on the dashboard, we send the audio to our TTS provider to train a custom voice model. Raw audio is not retained after the clone is created. - Generated audio. Text you submit is sent to our TTS provider, which returns audio that we play back. Generated audio is not retained server-side beyond what's needed to deliver it.
- Audit log. Timestamp, channel, user ID, voice used, message text, and status for each TTS message; plus a record of dashboard configuration changes. Retention is currently 60 days. When Mimiq Pro subscriptions open, it will be 7 days for new Free servers and 60 days for Pro and early access servers, then deleted automatically.
- Monthly allowance totals. Server ID, calendar month and aggregate caption seconds and recap count. These counters contain no transcript, message content or member IDs. They are used to enforce and display each server's allowance and for service monitoring and cost review, including on plans without a usage limit.
- Billing records. For Mimiq Pro, we store the server ID, payment provider, subscription or entitlement ID, subscription status and billing period dates. Discord or Stripe handles payment card details; Mimiq does not store them.
- Custom server profile. If a Pro admin gives Mimiq a custom server profile, Discord stores the uploaded avatar and banner. Mimiq stores the custom bio so it can be shown again in the dashboard. Admins can replace or remove these details.
- Session data. When you sign in, we store your Discord OAuth tokens server-side and place an opaque session identifier in a cookie. The cookie is HTTP-only and, in production, marked Secure.
Voice cloning & consent
Voice samples may be biometric data under some jurisdictions. Before any clone is saved we require an explicit consent click. By submitting samples you confirm the voice is yours, or that you have permission from the person whose voice it is. Cloning a public figure or another person without consent may violate publicity, defamation, or privacy laws in your jurisdiction. We will remove any clone on request from the voice's owner.
How we use the data
- Operate the bot and the dashboard.
- Enforce rate limits and per-server moderation rules.
- Generate the audit log so server admins can review activity.
- Diagnose errors and protect against abuse.
We do not sell personal data, run ads, or use your data to train generic AI models.
Who we share data with
- Discord: bot activity and OAuth.
- Our TTS provider: text and voice samples submitted through the bot or dashboard.
- Our moderation provider: message text, when AI moderation is enabled on your server.
- Hosting + database: the persisted data described above.
- Discord, Stripe and Onelink: subscription checkout, entitlement, billing and transaction support for the payment method you choose. Onelink is Stripe's current UK name for Link.
- Analytics providers: on our public marketing pages only (not the dashboard or admin), Simple Analytics (cookie-free, aggregate page views) and Microsoft Clarity (anonymised usage heatmaps and session replays). Neither runs on signed-in settings pages.
Retention
- Audit log (including message text): currently 60 days; 7 days on Free and 60 days on Pro or an early access server once subscriptions open.
- Cloned voice records: kept until removed by an admin or at the voice owner's request, and deleted automatically 30 days after the bot leaves the server (the grace period lets a quick re-install keep its voices).
- Raw audio used for cloning: not retained after the clone is built.
- Server settings, permissions, moderation rules: kept while the bot is installed.
- Session data: 14 days from last sign-in, or until you sign out.
- Billing records: while a subscription is active and afterwards where needed for accounting, disputes, abuse prevention or legal obligations.
Your rights
You may have the right to access, correct, delete, or export the personal data we hold about you, and to withdraw consent for processing voice biometrics. To exercise any of these rights, or if a clone of your voice has been created without your consent, email support@mimiq.gg or contact us in our support server.
Children
Mimiq is not directed at children under 13 (or under 16 in the EEA/UK). We rely on Discord's own age policies for that gate.
Changes to this policy
We'll update the "Effective" date at the top whenever the policy changes materially. Continued use of the bot after changes take effect means you accept the updated policy.