Privacy Policy

How MediaMuse collects, uses, stores, and protects personal information.

Last updated: 2026-08-27

Introduction

We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share information when you use MediaMuse (https://mediamuseai.com) (the "Service").

Please read this Policy before using the Service. By using the Service, you acknowledge that you have read and understood this Policy. We may update this Policy from time to time. Material changes will be announced as described in Section 13.

1. Data Controller

The data controller for the Service is:

  • Operator: the individual operating MediaMuse
  • Contact email: support@mediamuseai.com
  • Data Protection Officer (DPO): not appointed at this time

For privacy-related requests, email support@mediamuseai.com with the subject line Privacy.

2. Personal Information We Collect

We collect only what we need to operate the Service.

2.1 Information you provide

  • Account information: name, email address, password (stored using industry-standard hashing), and profile details you choose to provide.
  • Payment-related information: order amount, currency, payment status, subscription status, and transaction identifiers. We do not store full payment card numbers. Card data is processed by Waffo Pancake (see Section 5).
  • Support communications: emails, support tickets, feedback, and other messages you send us.
  • Generation inputs: prompts, uploaded images, generation settings, and related metadata needed to run your requested tasks.
  • OAuth profile data: if you sign in with Google, GitHub, or another supported provider, we receive the profile fields authorized by that provider (such as email and display name).

2.2 Information collected automatically

  • Device and network data: IP address, browser type, operating system, device type, time zone, and language preferences.
  • Usage data: pages visited, features used, generation history, credit consumption, session activity, and error events.
  • Log data: request timestamps, diagnostic logs, security events, and performance metrics.
  • Cookies and similar technologies: see Section 4.

We do not intentionally collect precise geolocation unless you explicitly grant it through your browser or device and we disclose a specific use at that time.

3. How We Use Personal Information

We use personal information for the purposes below.

Provide and maintain the Service — contract performance

Billing, subscriptions, and credit grants — contract performance

Customer support and account administration — contract performance / legitimate interests

Service notices (billing receipts, security alerts, policy updates) — legitimate interests

Security, fraud prevention, and abuse detection — legitimate interests

Product analytics and reliability improvements — legitimate interests

Legal compliance — legal obligation

Marketing communications (only if you opt in) — consent

We may aggregate or de-identify data for statistics and service improvement. Aggregated data cannot reasonably identify you.

4. Cookies and Tracking Technologies

We use cookies and similar technologies as follows:

  • Strictly necessary: maintain login sessions, security, and core functionality — cannot be disabled while using the Service
  • Functional: remember language and interface preferences — can be disabled in browser settings, may reduce convenience
  • Analytics: understand usage patterns and improve the Service — can be disabled where your browser or our configuration allows
  • Marketing (if enabled): measure campaign performance — only with consent where required

Analytics and support tools we may use include:

You can control cookies through your browser settings. Blocking strictly necessary cookies may prevent the Service from working correctly.

5. Sharing and Disclosure

We do not sell your personal information, including as "sale" is defined under applicable laws such as the CCPA.

We share information only in these limited cases:

  • Service providers who help us operate the Service under confidentiality obligations, including:
    • Waffo Pancake — payment processing and merchant-of-record services; payment card data is processed exclusively by Waffo Pancake and is not stored on our servers
    • Kie and related AI infrastructure providers — to run generation tasks you request
    • Cloudflare — hosting, CDN, storage (including R2), and security services
    • Resend — transactional email delivery
    • analytics, chat, and support tools listed in Section 4 when enabled
  • Legal and regulatory requirements — when required by law, court order, or lawful request from public authorities
  • Business transfers — in connection with a merger, acquisition, or asset sale, with notice where required and continued protection obligations
  • With your consent — for any other purpose you explicitly authorize

6. Data Security

We implement reasonable technical and organizational measures, including:

  • encryption in transit (TLS / HTTPS);
  • hashed storage for passwords and protection for sensitive configuration values where applicable;
  • access controls based on least privilege;
  • monitoring, logging, and periodic security review.

No method of transmission or storage is completely secure. Please protect your account credentials and notify us promptly of suspected unauthorized access.

If a security incident is likely to affect your rights, we aim to notify you and relevant regulators within 72 hours of becoming aware of it, where required by law.

7. Retention Periods

We retain personal information only as long as necessary for the purposes described in this Policy:

  • Account information: for the life of the account; deleted or anonymized within 90 days after account closure, unless a longer period is required
  • Transaction and billing records: typically 7 years, for accounting, tax, and dispute purposes
  • Support records: 3 years after the last interaction
  • Security and audit logs: 12 months, unless needed for an active investigation
  • Generation inputs and outputs: retained while your account remains active and according to your saved assets settings; deleted or made inaccessible after account closure subject to backup cycles and legal holds
  • Promotional credit records: according to the offer terms (for example, 30 days for current signup promotional credits)

When retention ends, we delete or anonymize data where practicable.

8. Your Data Rights

Depending on your location, you may have rights to:

  • know what personal information we collect and how we use it;
  • access a copy of your personal information;
  • correct inaccurate or incomplete information;
  • delete information in certain circumstances;
  • restrict processing in certain circumstances;
  • receive portable copies of information you provided;
  • object to processing based on legitimate interests or direct marketing;
  • withdraw consent where processing is based on consent.

To exercise these rights, email support@mediamuseai.com with the subject line Privacy. We aim to respond within 30 calendar days.

You may also manage some information directly in your account settings. If you believe we have not handled your request properly, you may contact your local data protection authority.

9. Marketing and Unsubscribe

We may send product updates or promotional messages only if you have opted in, where required by law. You can unsubscribe at any time by using the unsubscribe link in an email, adjusting notification settings in your account, or emailing support@mediamuseai.com.

Unsubscribing from marketing does not affect essential service messages such as billing receipts, security alerts, or legal notices.

10. International Data Transfers

Our Service uses infrastructure and providers that may process data in countries other than your own, including the United States and other regions where Cloudflare, Kie, Waffo Pancake, Resend, and analytics providers operate.

Where required, we rely on appropriate safeguards such as contractual protections with service providers and, where applicable, standard contractual clauses or equivalent mechanisms.

11. Children

The Service is intended for users aged 18 or older. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact support@mediamuseai.com and we will take steps to delete it.

12. Third-Party Links and Services

The Service may contain links to third-party websites or integrate third-party services. This Policy applies only to information we collect directly. We are not responsible for third-party privacy practices. Review their policies before using those services.

13. Changes to This Policy

If we make material changes, we will provide at least 15 days' notice where practicable by updating this page and, when appropriate, by email or in-product notice. The "Last updated" date at the top reflects the latest revision. Continued use after the effective date constitutes acceptance where permitted by law.

14. Contact Us

  • Privacy requests: support@mediamuseai.com (subject: Privacy)
  • General support: support@mediamuseai.com
  • Operator: the individual operating MediaMuse

This Policy is provided for transparency and does not constitute legal advice.

MediaMuse · https://mediamuseai.com