Legal
This Privacy Policy explains how Muse collects, uses, and protects information when you visit usemuse.dev, create an account, or connect a service. Muse is operated by Faiz Khan in Georgia, United States. Questions can be sent to faiz@usemuse.dev.
Muse collects your email address, account identifier, and account-creation data. Password authentication is managed by Supabase Auth. To verify a new account, Muse temporarily stores a hashed email-verification code and related expiry and rate-limit information.
Muse stores workspace settings; connected-service metadata; sites created through Muse; Guardian findings; notification preferences; push-subscription details; and records needed to run, display, secure, and troubleshoot tasks. Task records can include the skill and action used, parameters, status, errors, and results. For example, those records may include repository, table, deployment, or calendar references you provide or select.
Muse also collects limited technical and abuse-prevention data, such as rate-limit records, and product-usage events associated with onboarding and service use.
When you connect GitHub, Supabase, Vercel, or Google Calendar, Muse receives the access credentials and data necessary to provide the feature you requested. This can include repository and file information, database schema or rows, deployment and project information, and Google Calendar event and calendar information. Google Calendar access is read-only.
Connection credentials are encrypted at rest before storage and decrypted in memory only when needed to perform an authorized task or monitoring check. They are not returned to your browser. Disconnecting an integration deletes the stored credentials for that connection.
Muse does not sell personal information or use connected-service data for advertising.
When you use Muse's natural-language interface, your request and limited recent context may be sent to an AI provider to identify the Muse skill and action that can handle it. Do not submit secrets or other sensitive information you do not want processed for this purpose.
Muse uses Google Calendar data only to provide the calendar features you ask for, such as summarizing your schedule or finding an event. Muse does not use Google Calendar data for advertising, does not sell it, and does not allow humans to read it except where necessary for security, legal compliance, or to investigate abuse. Muse's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Muse uses trusted providers to operate the Service and to connect services you choose. Depending on your use, these include:
| Provider | Purpose |
|---|---|
| Supabase | Authentication, database, and secure data storage |
| Vercel | Application hosting, web analytics, and connected deployment features |
| Cloudflare | Turnstile bot protection for account and verification forms |
| GitHub | Connected repository and codebase features |
| Connected Google Calendar features and aggregate Search Console data | |
| Groq | Natural-language request routing |
| Resend | Transactional email, including verification and alert emails |
Muse uses strictly necessary authentication cookies after you sign in to keep your session secure. We use Cloudflare Turnstile to protect account forms from automated abuse. Vercel Web Analytics uses anonymized, cookie-free measurement. We do not use advertising or cross-site tracking cookies.
We may also disclose information when required by law, to protect the rights and safety of Muse or others, or as part of a business transfer. We do not share your information with third parties for their own marketing.
Account and workspace information is generally retained while your account is active. Integration credentials are retained until you disconnect the integration. Operational, security, and task records are retained for as long as reasonably necessary to provide the Service, resolve disputes, protect against abuse, and meet legal obligations. You may request deletion of your account and associated personal data by emailing faiz@usemuse.dev.
Muse uses encrypted HTTPS connections in transit, encryption at rest for stored integration credentials, access controls, and workspace-scoped database policies. No security method is perfect, so please use strong account credentials and revoke a provider connection promptly if you believe it has been compromised.
You can disconnect integrations in Settings, control browser notifications, and request access to, correction of, or deletion of your personal information. You can opt out of non-essential email communications using the instructions in those messages or by contacting us. We will respond to privacy requests within a reasonable period and as required by applicable law.
Muse is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided personal information, contact us and we will take appropriate steps to remove it.
We may update this Privacy Policy as Muse changes. The Last Updated date above identifies the current version. For material changes, we will provide notice when required by applicable law.
Privacy questions or data requests:
Faiz Khan
faiz@usemuse.dev
usemuse.dev