Privacy Policy

Last Updated: August 5, 2026

Muse AI (“Muse,” “we,” “our,” or “us”), operating the website and application at https://justmuse.app (the “Service”), is committed to protecting the privacy and personal data of our global user base.

This Privacy Policy explains how we collect, use, process, and disclose personal data across international jurisdictions, including compliance with the General Data Protection Regulation (GDPR - EU/UK), the California Consumer Privacy Act (CCPA/CPRA), and India's Digital Personal Data Protection Act (DPDP Act).


1. Data Controller and Contact Information

For the purposes of applicable data protection laws, Muse AI is the Data Controller responsible for your personal data.


2. Information We Collect

We collect data directly from you, automatically through your interaction with our platform, and via third-party social media APIs.

A. Account & Identity Data

  • Authentication Data: Email address, user ID, avatar image, and sign-in telemetry collected via our authentication provider (Clerk).
  • Billing Data: Billing name, email, tax identification numbers (e.g., GST/VAT where applicable), payment history, and subscription tier information processed via our payment partners. We do not store raw credit card or UPI credentials on our servers; these are processed and secured by our Merchant of Record partners.

B. Creator & Video Input Data

  • Public Social Media Data: Public Instagram/YouTube/Threads handles, public video URLs, captions, engagement metrics (likes, comments, views), thumbnail images, and public profile information fetched via authorized social media APIs.
  • User-Provided Content: Video files, script inputs, persona prompts, audio tracks, and creative briefs explicitly uploaded or pasted into the Muse engine for analysis or generation.
  • Analysis Outputs: Generated scripts, hooks, captions, carousel text, and video improvement recommendations you create within Muse.

C. Technical & Usage Telemetry

  • Device Telemetry: IP address, browser type, operating system, language settings, referring URLs, and session duration tracked via PostHog analytics.
  • Usage Data: Feature interactions, number of analyses run, credits consumed, subscription changes, and error logs to improve the Service.

3. Legal Basis for Processing (GDPR / DPDP Act)

We process personal data under the following legal bases:

  • Contractual Necessity: To execute video frame-by-frame analysis, generate creative optimizations, deliver personalized recommendations, and fulfill paid subscription services.
  • Legitimate Interests: To improve Service performance, prevent fraudulent multi-account abuse, ensure platform security, and understand user behavior for product development.
  • Consent: Where required by applicable law (e.g., marketing communications, optional analytics features).

4. How We Use Artificial Intelligence

  • Multimodal AI Processing: User-submitted videos are processed using AI vision models (Google Gemini API) to extract visual pacing metrics, hook timing, text overlay positioning, and content structure analysis.
  • Chat & Script Generation: Text inputs are processed via Gemini AI to generate scripts, hooks, captions, and creative recommendations based on your creator profile and preferences.
  • Model Training Guarantee: Your private uploaded video drafts, custom brand personas, non-public scripts, and personal subscriber data are not used to train public foundational AI models. Your content remains private.

5. Data Sharing & International Transfers

Because we operate globally, your data may be transferred to and processed on secure cloud servers located in the United States, European Union, and India.

We maintain strict Data Processing Agreements (DPAs) with Standard Contractual Clauses (SCCs) with all third-party processors:

  • Authentication & Identity: Clerk (US)
  • Database & Backend Hosting: Supabase (PostgreSQL with Row-Level Security, EU/US regions)
  • Frontend Hosting & Edge CDN: Vercel (Global Edge Network, US primary)
  • AI Models & Vision Processing: Google Cloud / Gemini AI (US, EU regions)
  • Video Analysis Server: Render (US)
  • Video Upload & Storage: UploadThing (US)
  • Analytics: PostHog (EU/US)
  • DNS & Infrastructure: Cloudflare (Global)
  • Transactional Email: Resend (US)
  • Payment Processing: Dodo Payments (India), Stripe (US)

All data transfers are encrypted end-to-end via TLS 1.3.


6. Your Rights Under International Laws

A. European Union & United Kingdom (GDPR)

  • Right to Access: Request a copy of all personal data we hold about you.
  • Right to Rectify: Correct inaccurate personal data.
  • Right to Erase (“Right to be Forgotten”): Request deletion of your personal data, subject to legal retention obligations.
  • Right to Data Portability: Export your account data, generated scripts, and analysis history in machine-readable format.
  • Right to Restrict Processing: Limit how we use your data in certain circumstances.
  • Right to Object: Object to automated decision-making and profiling.

B. California Residents (CCPA / CPRA)

  • Right to Know: Request disclosure of categories and specific pieces of personal information collected.
  • Right to Delete: Request erasure of personal data, subject to exceptions.
  • Right to Correct: Correct inaccurate information.
  • Right to Opt-Out of Sales/Sharing: We do not sell or share your personal data for cross-context behavioral advertising.
  • Right to Non-Discrimination: We do not discriminate against consumers who exercise CCPA/CPRA rights.

C. Indian Residents (DPDP Act 2023)

  • Right to Access: Access personal data processed by Muse.
  • Right to Correct, Erase, or Complete: Modify or delete inaccurate data under consent-based processing.
  • Right to Nominate: Designate a nominee to exercise your rights in case of death or incapacity.
  • Right to Grievance Redressal: Submit complaints to our Data Protection Officer.

To exercise any of these rights, email support@justmuse.app with “Data Request” in the subject line. We will respond within 30 days free of charge.


7. Data Retention & Security

A. Retention Periods

  • Account Data: Retained for as long as your account is active. Upon account deletion or written request, personal data is permanently purged within 14 business days.
  • Public Social Media Cache: Public profile metrics and engagement data are cached for a maximum of 24 hours to ensure fresh analytics and reduce API load.
  • User-Uploaded Video Files: Video files remain on our servers only while they are being analyzed. After analysis is complete, videos are automatically deleted within 24 hours unless you explicitly request storage (coming in future updates). Metadata and analysis results are retained until account deletion.
  • Transactional Logs: Payment records, account activity logs, and audit trails are retained for 7 years to comply with financial regulations and tax requirements.
  • Analytics Data: Usage telemetry (PostHog) is retained for 90 days, then anonymized and archived for 12 months.

B. Security Controls

  • Encryption in Transit: All data is encrypted via TLS 1.3 (HTTPS).
  • Encryption at Rest: Database records encrypted with AES-256.
  • Access Control: Row-Level Security (RLS) enforced at the database level; users can only access their own data.
  • Infrastructure Security: Regular penetration testing, vulnerability scanning, and security audits conducted by third-party vendors.
  • Employee Access: Strict need-to-know access policies; all employee access is logged and monitored.

8. Cookies & Tracking

  • Essential Cookies: Required for authentication (Clerk), session management, and basic platform functionality.
  • Analytics Cookies: Used via PostHog to understand user behavior and improve the Service (optional; can be disabled).
  • Third-Party Cookies: Social media platforms (Instagram, YouTube, Threads) may set cookies when you connect your accounts.

You can control cookie preferences through your browser settings. Disabling essential cookies may impact platform functionality.


9. Third-Party Integrations

Social Media Connections

When you connect your Instagram, YouTube, or Threads accounts to Muse:

  • We request permission to read your public profile and public video data only.
  • We do not request permission to post, delete, or modify your content without your explicit action.
  • You can revoke Muse's access at any time through your social media account settings.

Payment Partners

  • Dodo Payments (India): Processes Indian subscription payments; subject to Indian financial privacy laws.
  • Stripe (US): Processes US/international payments; subject to PCI-DSS compliance.

10. Data Breach Notification

In the event of a confirmed data breach affecting your personal data, we will:

  1. Notify affected users within 72 hours (GDPR requirement) or as soon as practicable.
  2. Provide details of the breach, affected data categories, and recommended protective actions.
  3. Notify relevant supervisory authorities where legally required.

Contact us immediately at support@justmuse.app if you suspect a security incident.


11. Children's Privacy

Muse is not intended for users under 13 years of age (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that a child has provided personal data, we will delete it promptly and notify the parent/guardian.


12. Policy Updates

We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. Updates will be posted on this page with a revised “Last Updated” date. Continued use of the Service after updates constitutes acceptance of the revised policy.

Significant changes (e.g., new data sharing practices) will be communicated via email to active users.


13. Data Protection Impact & Governance

  • DPIA (Data Protection Impact Assessment): Conducted annually for high-risk processing activities (video analysis, AI model usage).
  • Privacy by Design: New features are assessed for privacy implications before launch.
  • Regulatory Compliance: We maintain compliance frameworks for GDPR, CCPA/CPRA, and DPDP Act 2023.

14. Contact & Dispute Resolution

For Privacy Questions or Data Requests:

For Unresolved Privacy Complaints:

  • EU/UK Users: File a complaint with your local Data Protection Authority (e.g., ICO for UK, CNIL for France).
  • California Residents: Contact the California Attorney General's Office.
  • Indian Residents: File a complaint with the Data Protection Board of India (DPBI) under the DPDP Act.

This policy is effective as of August 5, 2026, and applies to all users of justmuse.app.