Privacy Policy

Last updated: August 27, 2026

Muster (“we,” “us”) runs Bounty, Assemble, Gear, and Recap at muster.quest and its subdomains. This policy describes what information we collect, how we use it, who we share it with, and how we protect it.

What we collect

  • Account information: when you sign in, we collect what your chosen method provides — an email address (Magic Link/Email OTP), or your name, email, and avatar image (Google or Discord sign-in). We request identity information only; we never request access to your Discord server, messages, or guilds.
  • Party and quest content you create: party names, quest titles and descriptions, photo-proof images you upload, notes attached to a quest, RSVP details, and similar content you or your party members enter.
  • Two functional cookies: a session cookie that keeps you signed in across muster.quest and its subdomains, and a cookie that remembers which party you're currently viewing. Neither is used for advertising or cross-site tracking, and neither is set until you sign in.
  • Child profile information, if you add one: a party owner or admin can add a child to their party as a lightweight profile. We collect only the display name, an optional avatar image, and a PIN — all chosen and entered by you, the parent or guardian, never by the child directly. See “Children's data” below.
  • Nothing else. We don't run ad networks, third-party analytics, or tracking scripts of any kind — see “Respectful Software” on our landing page. We don't collect location data, device fingerprints, or browsing history outside Muster itself.

How we use it

Solely to operate the product: authenticate you, show you your parties' quests/events/gear, deliver photo proof to the right people, and — only if a party admin sets one up — post an update to a Discord channel that party chose. We do not use your data for advertising, and we do not sell or rent it to anyone.

Who we disclose it to

  • Supabase — our database, authentication, and file-storage provider. They process data on our behalf to run the product and don't use it for their own purposes.
  • Vercel — our hosting provider, who serves the application and processes requests in transit.
  • Google or Discord — only if you choose to sign in with one of them, and only to verify your identity (name/email/avatar). We don't share any other Muster data with them.
  • Discord (webhooks) — only if a party admin configures a webhook for their own Discord server. That message goes directly from Muster to the Discord channel that admin chose; we don't share it with Discord as a company beyond that one delivery.
  • Ko-fi and Stripe — only if you choose to click our “Support Muster” link. That takes you to Ko-fi's own site, where Ko-fi (and its payment processor, Stripe) handle everything from that point on under their own privacy policies. Muster itself never receives, transmits, or stores any payment or card information — we don't know if or how much you donated.
  • We disclose data to no one else, and never for marketing purposes.

How it's disclosed

Data is sent to the processors above via encrypted (TLS) API calls as part of normal product operation — never as a bulk export, a data sale, or a shared marketing list.

Security practices

  • Every party's data is protected by database-level Row-Level Security — a party member can only ever read or write data for parties they actually belong to.
  • Photo-proof images are stored in a private file bucket and served only via short-lived signed links, never a public URL.
  • We don't run third-party ad or tracking scripts, so there's no cross-site identifier leaking your activity to anyone else.
  • Sign-in is handled by Supabase Auth (industry-standard OAuth / magic-link flows) — we never see or store your Google or Discord password.

Your data, your control

You can ask us to export or permanently delete your account data at any time — email hrp.workspaces@gmail.com and we'll action it.

Children's data

Muster offers parentally-managed child profiles: a party owner or admin can add a child to their party as a lightweight profile, so a family can share quests together without giving the child their own account.

  • A parent or guardian provides everything. A child profile's display name, avatar, and PIN are all set by the adult who creates and manages it — never collected from the child directly, and never anything the child enters or edits unsupervised.
  • No account, no email, no login of its own. A child profile has no email address, no password, and no Google/Discord identity. It cannot sign in independently, on any device — every action taken under a child profile happens through the managing adult's own signed-in session.
  • PIN-protected switching on shared devices. Setting a child profile as the active profile on a shared family device requires a PIN, checked on our servers against a securely hashed value we store — we never store or transmit it as plain text. Only the managing parent or guardian can set or reset it; there's no email-based recovery flow, because none is needed.
  • No way to contact anyone outside the family's own party. A child profile can only add quest titles, descriptions, and proof notes inside the one party it belongs to. Nothing in Muster lets a child profile message, or be contacted by, anyone outside that party.
  • Our approach to children's privacy. Because a child profile's information is always entered and controlled by a parent or guardian, and a child profile can never independently submit personal information, sign in on its own, or be contacted by anyone outside its own party, we don't collect personal information directly from children. We intend this to be consistent with the U.S. Children's Online Privacy Protection Act (COPPA) and it also informs our UK Online Safety Act self-assessment.
  • Removing a child's profile. Email us at hrp.workspaces@gmail.com to have a child's profile and its data deleted, the same as the account deletion described above.

Changes to this policy

If we change what we collect or how we use it, we'll update this page and change the “Last updated” date above.

Contact

Questions about this policy: hrp.workspaces@gmail.com.