Legal
This Privacy Policy explains what information Muse collects, how it is used, and the security principles that Muse is built on. It is written to be honest and readable — not buried in legal language.
Muse is operated by Faiz Khan, based in Georgia, United States. If you have any questions, you can reach me directly at faiz@usemuse.dev.
Muse is built to hold as little of your data as possible, and to protect what it must hold. Two rules define how it works.
Your code and data are never stored. When a task runs — reading a file, listing database rows, checking a deployment — the result passes through Muse to your phone and is not kept afterward. Muse records that a task ran, never the contents it touched.
Your connection credentials are encrypted at rest. When you connect GitHub, Supabase, or Vercel, those tokens are encrypted with AES-256-GCM before they are stored, and decrypted only in memory, for the moment it takes to run a task you started or a scheduled health check. They are never returned to your browser, and every connection can be revoked instantly from Settings — which cuts off access right away.
There is nothing to install. Muse acts on your projects by calling the official APIs of the services you connect — GitHub, Supabase, Vercel — with the scoped permissions you granted, and relays the result back to you.
During the current waitlist phase, Muse collects only:
That is everything collected during the waitlist phase. Nothing else.
When Muse launches, additional data will be collected to operate the service. This section is an honest outline of what that looks like so there are no surprises.
Connection credentials (API keys and tokens) are the one sensitive thing Muse does store, because the backend needs them to act on your projects when you ask it to. They are encrypted at rest and never returned to your browser, as described above.
In transit: All communication — between your browser and the Muse backend, and between Muse and the services you connect — uses encrypted HTTPS connections.
At rest: Waitlist emails and account data are stored in Supabase, which encrypts data at rest. Task records are scoped by workspace with row-level security enforced at the database level — meaning your data is only accessible to you.
Credentials: Your integration credentials are encrypted with AES-256-GCM before being stored, using a key held only by the Muse backend. They are decrypted in memory only to execute a task you initiated or a scheduled health check, and are never returned to your browser. Disconnecting an integration in Settings deletes its stored credentials, and you can additionally revoke Muse's access from the provider's side (GitHub, Supabase, or Vercel) at any time.
Muse uses the following third-party infrastructure:
| Service | Purpose |
|---|---|
| Supabase | Database, authentication, and user data storage |
| Vercel | Hosting the Muse web application and backend |
| Groq | Interpreting natural-language commands into skill actions |
| Google Search Console | Domain verification and search analytics |
Each of these services has its own privacy policy. Muse does not control their data practices and encourages you to review them independently.
Regardless of where you are located, you have the right to:
To exercise any of these rights, email faiz@usemuse.dev. I will respond within 14 days.
Muse is not directed at children under the age of 13. I do not knowingly collect personal information from children under 13. If you believe a child has submitted their information, please contact me and I will remove it promptly.
If this Privacy Policy changes materially, waitlist members and active users will be notified by email before the changes take effect. The "Last Updated" date at the top of this page will always reflect the most recent revision.
Privacy questions, data requests, or concerns:
Faiz Khan
faiz@usemuse.dev
usemuse.dev
I read every email and will respond personally.