Skip to content

Privacy policy

Last updated 3 October 2026

Who is responsible

Orpheus is run by Glex, a private individual in Ireland who wishes to remain anonymous, and who is responsible for the data on this page. Questions go to privacy@orpheusbot.app.

What we store

  • Server settings you choose, such as 24/7, autoplay, volume, the DJ role and the player channel.
  • What’s playing: the queue, the current song and who added each one, so the player can show it and pick up after a restart.
  • Your playlists and liked songs, tied to your Discord account so they follow you between servers.
  • Listening history: each song played, where and when, and who asked for it. Songs chosen by radio or autoplay aren’t tied to anyone. Statistics, charts and Rewind come from this.
  • Listening sessions: when Orpheus joined and left a voice channel and how many people were there, as a number.
  • Radio, likes and blocks recorded in a server.
  • When Orpheus was added to or removed from a server.
  • Your privacy choices from /me privacy, including whether other members can dedicate a song to you.
  • Diagnostics: which commands ran and whether they worked, songs that failed to play, and searches that found nothing. These don’t record who ran them.

We treat Discord user and server IDs as personal data, because they can be linked to a person.

What we don’t store

  • Your messages. Orpheus can’t read your conversations.
  • Voice. Orpheus never records anything said in a voice channel.
  • Email addresses, real names, IP addresses or card details. Discord handles payment and doesn’t share card details with us.

Why

To run the features you use and keep them working. Our legal basis is legitimate interests (GDPR Article 6(1)(f)). We don’t sell your data, use it for advertising or build profiles from it.

Who else sees it

Only the providers that run the service for us: our hosting providers, who store it on servers in the United States, so data about people in the European Economic Area is transferred there. When Orpheus fetches a song, it never sends your Discord identity with the request.

This website

We count page views and a few button presses, such as Add to Discord and Sign in, with Vercel Web Analytics. It sets no cookies and stores nothing on your device. It records the page, the button and a rough country, never your name, your Discord account or anything that follows you between visits. There’s no advertising.

Signing in to the dashboard sets cookies that only keep you signed in. They last at most 24 hours and signing out removes them. “Find my Spotify playlists” asks Discord for one extra permission, used only to see which Spotify account you’ve linked there.

When you follow a link in an Orpheus announcement, the link carries a campaign number so we can count how many people used it. Nothing about you is attached to that number. The first time, the site sets one cookie, orpheus_campaign, holding only that number, so a reload isn’t counted twice. It lasts 24 hours and does nothing else.

How long we keep it

  • What’s playing: until playback ends, or 24 hours after Orpheus leaves.
  • Listening history: 90 days.
  • Diagnostics: 30 days for commands run, failed songs and empty searches, and for warnings and errors in the service log. Routine log lines are kept for 3 days.
  • When Orpheus was added or removed: one year.
  • Listening sessions, server settings and radio: until you ask us to delete them. They stay if Orpheus is removed from your server, and we don’t delete them automatically for inactivity.
  • Playlists, likes, your choices: until you delete them.

Your rights

You can ask for a copy of your data, or ask us to correct, delete, restrict or hand it over, and you can object to us keeping it. Email privacy@orpheusbot.app with your Discord user ID or server ID. It’s free and we answer within a month.

You can also do most of it yourself: /playlist delete, /liked remove, or remove Orpheus from your server.

If you’re unhappy with how we handled your data, tell us first. You can also complain to the Data Protection Commission in Ireland, or to the authority where you live.

Security

Only the service can reach the database. Backups are a nightly database dump kept on the server for 14 days, and an encrypted copy of the whole server, made with restic and stored on a second server, kept for up to six months. Data you delete can therefore remain in those backups until they expire. If a breach puts your data at risk, we’ll report it as the law requires and tell you directly when the risk is high.

Children

You need to be old enough to use Discord, which is at least 13. If we learn we hold data about someone younger, we delete it.

Changes

If we change what we store or why, we update this page and the date at the top.