Legal
Privacy policy
What muse.space keeps about you, why, who else sees it, how long it stays, and what you can do about all of it.
Last changed .
In short
- We keep what it takes to sign you in and to do what your agent asks: your address, your passkeys, the passwords, keys and sign-ins you give us (encrypted, and never readable by your agent), your rules, and a log of your agent’s calls.
- Your mail, events and contacts pass through in memory. The only parts we keep are notices of new mail and webhook deliveries waiting for your agent, for 7 days at most.
- What your agent asks for goes to your agent, and to the company that runs it, under their terms.
- We don’t sell data, show ads, run analytics or trackers, or train AI on anything of yours.
- You can export your audit log and delete everything, whenever you like, in settings.
Who we are
muse.space runs this service and is responsible for the personal data this policy describes. Questions and requests about it go to privacy@muse.space.
muse.space is for people 18 and older. It is an independent project, not affiliated with Apple, Meta or any other company whose products it works with.
What we keep
Everything we hold about you, and the things people assume we hold and don’t. This is the same table the security page shows.
| What | Kept? | How, and for how long |
|---|---|---|
| Your app-specific password | Stored, encrypted | Until you delete it here. Cancel it at Apple and our copy stops working at once. |
| Your name, email address and passkeys | Stored | To sign you in. A passkey is a public key, and there is no account password to steal. |
| The audit log | Stored | Tool, time, which token, where it went, result and how long it took. 30 days on Free, 1 year on Personal. |
| Your switches, limits and recipient list | Stored | So your rules hold on every call. Deleted with your account. |
| New-mail notices waiting for your agent | Stored | Who a new message is from, its first three recipients and its subject, with codes and sign-in links hidden while hiding is on, and never its text. Kept until your agent picks it up, for 7 days and 200 notices per mailbox at most, and deleted when you switch new-mail events off or disconnect the mailbox. Cloudflare encrypts it where it is stored; the vault, which guards your password, does not. |
| Webhook deliveries waiting for your agent | Stored | What a service posted to your inbox: its body, its query, and the few headers that say what it is, never a credential or a signature. Kept until your agent picks it up, for 7 days and 200 deliveries per inbox at most, and deleted with the inbox. The address holds a secret we keep only a hash of. Cloudflare encrypts it where it is stored; the vault does not. |
| Your inboxes’ signing secrets | Stored, encrypted | In the vault, as a password is, and used there only to check a sender’s signature. Never sent anywhere or shown again. Deleted when you stop checking signatures or delete the inbox. |
| Messages, attachments, events and contacts | Never stored | Passed to your agent in memory and gone when the call ends. |
| What your agent asked for | Never stored | Search words, recipients and other inputs are never written to the log. Each call keeps a fingerprint of them, which tells two identical calls from two different ones. Nothing can be read back out of it, though somebody holding the database could use it to check a guess. |
| Your agent token | Never stored | We keep a hash and the first few characters, enough to recognise it. |
- Your app-specific passwordStored, encrypted
Until you delete it here. Cancel it at Apple and our copy stops working at once.
- Your name, email address and passkeysStored
To sign you in. A passkey is a public key, and there is no account password to steal.
- The audit logStored
Tool, time, which token, where it went, result and how long it took. 30 days on Free, 1 year on Personal.
- Your switches, limits and recipient listStored
So your rules hold on every call. Deleted with your account.
- New-mail notices waiting for your agentStored
Who a new message is from, its first three recipients and its subject, with codes and sign-in links hidden while hiding is on, and never its text. Kept until your agent picks it up, for 7 days and 200 notices per mailbox at most, and deleted when you switch new-mail events off or disconnect the mailbox. Cloudflare encrypts it where it is stored; the vault, which guards your password, does not.
- Webhook deliveries waiting for your agentStored
What a service posted to your inbox: its body, its query, and the few headers that say what it is, never a credential or a signature. Kept until your agent picks it up, for 7 days and 200 deliveries per inbox at most, and deleted with the inbox. The address holds a secret we keep only a hash of. Cloudflare encrypts it where it is stored; the vault does not.
- Your inboxes’ signing secretsStored, encrypted
In the vault, as a password is, and used there only to check a sender’s signature. Never sent anywhere or shown again. Deleted when you stop checking signatures or delete the inbox.
- Messages, attachments, events and contactsNever stored
Passed to your agent in memory and gone when the call ends.
- What your agent asked forNever stored
Search words, recipients and other inputs are never written to the log. Each call keeps a fingerprint of them, which tells two identical calls from two different ones. Nothing can be read back out of it, though somebody holding the database could use it to check a guess.
- Your agent tokenNever stored
We keep a hash and the first few characters, enough to recognise it.
To run the service we also keep:
- Your plan. Which plan you’re on, until when, and the codes you redeemed. A code itself is kept only as a hash.
- Sign-in. An emailed sign-in link is kept only as a hash, and works once, for 15 minutes. Your browser keeps one cookie that keeps you signed in, for up to 30 days.
- Abuse limits. A hash of the network you connect from, and of your account, counted so that neither can ask for endless sign-in emails or try endless codes. Each count covers an hour at most, and is deleted within a day after that.
- Alerts. A note that an alert email went out, without what it said, kept for 32 days so the same alert isn’t sent twice.
- What you set up. The addresses a mailbox may send from, the addresses of the servers and apps you connect and the tools they list, and when each connector and token was last used.
- Operational logs. Our programs note what happened: an account’s id, which tool, how long it took, what went wrong. Never a password, a token or anything from your mail. Cloudflare keeps these logs for up to 7 days.
What we never do
- Sell or rent personal data, or share it for advertising.
- Show ads, or put analytics, tracking pixels or anyone else’s scripts on our pages.
- Use your data, or anything your agent reads, to train AI models.
- Read your mail, calendar or contacts for our own purposes. We reach them only when your agent asks, and only within the rules you set.
Why we use it
- To provide the service you signed up for. Signing you in, holding your passwords, keys and sign-ins, carrying out your agent’s calls, and keeping your rules and your log. This is what our agreement with you needs.
- To keep it safe. Abuse limits, logs, and looking into problems. We have a legitimate interest in a service nobody can misuse, and so do you.
- To email you. Sign-in links, the alerts you chose (you can turn them off in settings), and notices about the service or these documents.
- When the law requires it.
We don’t use your data for anything else, and we’ll ask you first if that changes.
Who else sees it
- Your agent, and the company that runs it. When your agent calls a tool, what the call returns goes to your agent: for Muse, that is Meta; for another agent, whoever provides it. We send it because you gave that agent your agent token, and in doing so we act on your instructions. What they do with it is governed by their terms and privacy policy, not ours.
- The services you connect. Apple, Google, Fastmail and the rest see our sign-ins and your agent’s requests, as they would from any mail app. The apps you sign in to, such as Notion or Linear, see the requests your agent makes there.
- Cloudflare, which runs our programs and databases and sends our email. Everything we store is stored with Cloudflare and encrypted there; your passwords and keys are encrypted again, under keys only our vault holds.
- The people who run muse.space. Our admin area shows an account’s address, plan, when it joined, and its connectors by kind and whether they work. Never their names, their addresses or anything they hold. Every change an admin makes is recorded.
- Authorities, only when the law requires it. We’ll tell you, unless the law forbids that.
- Nobody else. If muse.space is ever sold or merged, your data goes only under a policy at least as protective as this one, and we’ll tell you before it does.
Where it is processed
Cloudflare runs our programs in data centres around the world, close to whoever is making the request, so your data may be processed outside the country you live in. Transfers rely on Cloudflare’s data processing terms and the standard contractual clauses in them.
How long we keep it
As long as your account is open, and less for many things: the table above says how long for each.
When you delete your account, your passwords, keys, tokens, connectors and settings are deleted at once, and your audit log within 24 hours. Our database provider keeps a recovery history for up to 30 days, which we use only to recover from a failure of our own. Deleted data leaves it within 30 days.
Your choices and rights
- See it. Most of what we hold is in your dashboard, and you can export your audit log from settings. Ask us for a copy of the rest.
- Change it. Your name in settings; a password or key by replacing it.
- Delete it. A connector, a token or your whole account, in your dashboard, whenever you like.
- Keep less. Turn new-mail notices off for a mailbox, or keep your audit log for less time.
- Cut us off at the source. Cancel the app-specific password at Apple, or wherever you made it, and our copy stops working at once.
Depending on where you live, the law also gives you the right to see, correct and delete your data, to take it elsewhere, to restrict or object to how we use it, and to complain to your data protection authority. Write to privacy@muse.space; we answer within 30 days, and we won’t treat you differently for asking.
How we protect it
The security page says how we hold your passwords, what each kind of failure could reach, and how to report a problem. If a breach affects your data, we’ll tell you without undue delay.
Age
muse.space is for people 18 and older. We don’t knowingly hold data about anyone younger; if you think we do, write to privacy@muse.space and we’ll delete it.
Changes to this policy
When we change this policy, the date at the top changes. If a change affects what we keep or who sees it, we email you before it takes effect.
Contact
- About your data: privacy@muse.space
- Help with the product: support@muse.space
- Security reports: security@muse.space