Privacy
Muse is a personal curation app. You control what you collect; we store only what the product needs to work.
What we store
Account
Your email address (provided when you sign in) and a display name derived from it. A one-way HMAC hash of your email is kept for contact matching — the hash cannot be reversed back to your address. A unique @username handle — auto-assigned when you sign up and yours to change afterward — public and searchable so others can find and look up your profile by name on the platform (by id or by username, either resolves to the same profile). You may also set an optional bio and style preferences in onboarding — your bio is public, shown as the tagline on your Style Profile to any signed-in viewer.
You can also choose a featured board— one of your own public boards, shown as the anchor of your Style Profile. Only a board you own and that is currently public can be featured; if you later make it secret it stops appearing there. It’s cleared automatically if you delete the board, and removed with your account.
An internal is_seed flag marks house/founding-member curation accounts used to seed community content. It is not personal data and is never returned in any API response; it is included in your account export if it applies to your account.
Newsletter
If you subscribe to the newsletter on the About page, we store the email address you enter. Subscribing does not require an account. You can unsubscribe at any time with the same address; if you have an account under that email, deleting the account also removes the subscription, and your data export reports whether you are subscribed.
Social graph
Who you follow, which topics you follow, and which boards you collaborate on. The topics you follow are shown as vibe tags on your Style Profile, visible to any signed-in viewer.
Content you create
Boards and pins, notes, pin comments, reactions, item ratings, personal tags, and cart items. Comments you leave on a board item inherit that board’s visibility — comments on a secret board are only visible to its collaborators. Your ratings are visible to friends only — never public.
Home pins (personal tray)
A small personal tray on your home feed — up to 6 items you pin for quick reference. This is separate from saving an item to a board and from your cart, and it’s private to you — no one else can see or change it. Pinning and unpinning are both idempotent, so repeating either action is always safe.
If you use a Fitting Room (co-shopping session), that has its own separate, shared pin set that starts empty each session — your personal tray is unaffected either way. Unlike your personal tray, a room’s pins are not private: they persist after the session ends so the room’s recap can show them, and they’re visible to (and included in the data export of) anyone who was ever an active participant in that room, attributed to whoever pinned each item.
Your personal pins are included in your data export and are permanently deleted when you delete your account.
Board invite links
A board owner can generate a shareable, unguessable link to invite someone to collaborate — no email required, and it works for people who don’t have a Muse account yet. Anyone holding the link sees a minimal preview (the board’s name, cover image, and the inviter’s display name) — never the board’s pins or member list. Signing in and accepting reaches the same board-collaborator relationship as an email invite. Links default to a 14-day expiry and unlimited uses; the owner can set a shorter expiry or a use limit, and can revoke a link at any time. Links you create are included in your data export and keep working after you delete your account — a link grants access to the board, not to you personally.
Decision engine — takes, “should I get this?” polls, and connections
On any pin you can view, you can leave a quick love it / it’s okay / pass “take” — one per pin, changeable any time. Anyone who can already view that board (a collaborator, or anyone on a public board) can see the aggregate counts, your own take, and up to 4 recent takers’ avatars. No notification is sent for a take — it’s a quiet, inline signal only.
You can start a “should I get this?” poll on a pin you can view. Board members see the full poll — tallies, comments, and voter names for voters who can also independently view the board. Each poll also gets a unique, unguessable link so you can invite someone who isn’t a board member to vote — that link view shows only the item, the question, and tallies, and never reveals the board itself; a vote cast via the link renders to board members as “via link” unless that voter can also independently see the board. Starting a poll is visible under the same rule as a save to that board — never leaked from a secret board. The poll’s creator gets a notification the first time each friend votes (re-votes don’t re-notify).
On a product page or pin you may see “Saved by N people” and a “styled with” strip of frequently co-pinned items. This is computed live from public boards only — a pin on a secret board is never counted or shown here.
Your takes, polls, and poll votes are included in your data export and are permanently deleted when you delete your account.
Living boards — price tracking & bought/tried marks
Each pin snapshots the item’s price at the moment you save it. At read time we compare that snapshot to the item’s current price to show a price-drop badge on the pin, a board-level digest (price drops / out of stock / dead links), and a soft “if you bought this board” running total on the board page. This is a passive, read-time comparison — it does not track anything about your browsing outside Muse.
You can mark a pin Bought or Tried, with an optional short note. This mark is visible to anyone who can already view the board — a mark on a secret board is never leaked to non-collaborators, the same as a save to that board. Marking a pin Bought (only when you’re the person who originally saved it) creates a mock order for that item in your account, so it can appear in your own “rate from your orders” queue — see Order history below. Your price snapshots and outcome marks are included in your data export and are permanently deleted when you delete your account.
Order history (demo data)
Muse has no real checkout. The order history that powers “rate from your orders” is either seeded demo data or created automatically when you mark a board pin Bought (see Living boards above). Every order row is explicitly labeled as mock — it never represents a real purchase, payment, or retailer transaction. Your order rows are included in your data export and are permanently deleted when you delete your account.
“Rate this” reminder (nudge banner)
If you own an item (a real order, or a pin you marked Bought) and haven’t rated it yet, the app may surface a small banner nudging you to rate exactly onesuch item at a time — never a pile of them. If you dismiss the nudge for an item, we store that you dismissed it and when, so the same item isn’t immediately suggested again — the dismissal expires after 7 days. This is private, self-serving bookkeeping — it is never visible to anyone but you, and it does not affect your ratings, your rankings, or anyone else’s feed. Your dismissals are included in your data export and are permanently deleted when you delete your account.
Messages
Direct conversation threads, message text, and per-conversation read state. “Help me pick” polls you create or vote in are a structured message — visible only to that conversation’s participants, like any other message.
Contacts (opt-in only)
If you choose to match contacts, we store salted HMAC hashes of the emails you upload — never the raw addresses. You can skip this entirely; it has no effect on the rest of Muse.
Derived taste profile
From your existing engagement signals (saves, shelf adds, ratings, personal tags, and topic follows) we derive a taste profile: your top categories and brands with normalized weights, plus the aesthetic tags you engage with. It is computed on the fly from those signals — nothing extra is collected or stored. The profile is used to rank your feed and vibe-search results, and responses say so whenever it was applied. It is strictly self-only: only you can see your own taste profile, never other users. Room exception:while you’re in a Fitting Room, ranking for that room’s shared feed blends your taste signals with your co-shoppers’ (see Fitting Room below) — a computed ranking input only, never a readable value, and it stops applying the moment you leave or the session ends. The same summary is included in your data export, and deleting your account removes everything it is computed from.
Personalization style vector
From the visual style of items you have loved, saved, shelved, or rejected, we compute a numeric style vector that captures your aesthetic preferences. This is used to personalize your feed ranking and vibe-search results — feed responses say so whenever personalization was applied. It is strictly self-only, with the same Fitting Room exception as the derived taste profile above: the vector and its metadata are scoped to your account and are never visible to other users, only ever consumed as one input to a blended room-ranking formula.
Your data export includes a human-readable summary — whether a vector exists, how many signals shaped it, its version, and its explainable categorical complement — but never the raw numeric array itself, which is meaningless outside the model. This data is permanently deleted when you delete your account.
Browsing as a guest
You can browse the full Muse feed, search, and product pages without an account. When you tap something that needs an account — Save, Follow, New board — or view a product page while signed out, we remember the item locally in your browser only (a small, capped list; nothing is sent to us). If you then sign up or sign in, that local list is claimed into your new account: items you tried to save are recorded as loved, just like the taste-calibration picks above, so your feed is personalized from your very first session. Nothing is stored on our servers about your guest browsing until you create an account.
Product photos you upload (when you use this feature)
Photos you tag to a specific product on Muse (up to 5 per product, ≤8 MB each, JPEG/PNG/WebP). These photos are publicly visible— they appear on the product page, on boards containing that product, and on your profile's “Photos” tab. Photos can be reported by other users; after 3 distinct reports a photo is automatically hidden. Photos are automatically reviewed for relevance (not content moderation). If a photo is flagged it will be hidden; you can contact us to appeal. You can delete any photo at any time from the product page. All product photos — including the stored image files — are permanently deleted when you delete your account.
Watchlist and price history (when you use this feature)
If you watch an item, we store that you’re watching it (and when you started). Your watchlist is private — never visible to other users. You can unwatch an item at any time from the product page or your Watchlist page.
When a watched item’s price drops or it comes back in stock, we surface an alert in your activity inbox. Every fact shown (current vs. lowest/highest/median price over the last 90 days, whether it’s an all-time low, how often the merchant runs sales) is plain arithmetic computed from prices we’ve actually observed — never a prediction or forecast.
Item price history itself is catalog data, not tied to your account — it is not part of your data export and is not affected by account deletion. Your watchlist is included in your data export and is permanently deleted when you delete your account.
Fit Biodata (when you use this feature)
Self-reported fit context you enter (usually during onboarding, or any time from Fit & sizing settings): height, your usual sizes by category, your usual size in specific brands you know (e.g. “M at Zara”), body/fit descriptors, and optional body measurements (chest, waist, hips, inseam). Each record has a visibility control — private (default; only you), friends (you and mutual followers), or public— enforced at the query layer, so a record that isn’t visible to a viewer simply looks like it doesn’t exist. Your Fit Biodata is included in your data export and is permanently deleted when you delete your account. You can update or delete it at any time.
Size guidance (when you view a product)
On a product page, we can recommend a size using only data described elsewhere on this page — your Fit Biodata’s reference size for that item’s brand when you’ve entered one (takes precedence over the category default), otherwise your usual size for that item’s category, that item’s public fit-review consensus, and (only if you’ve opted in) your Fit Twins consensus. Height and measurements are used only to raise or lower our confidence in the recommendation, never to calculate it. This introduces no new stored data — it is a read-only computation, requires you to be signed in, and if you haven’t set up a fit profile yet we say so and link you to Fit & sizing settings instead of guessing.
Fit Twins (size-match network) — when you opt in
A separate opt-in flag on your Fit Biodata (off by default). Opting in matches you with other opted-in shoppers using a deterministic, categorical score — height band, shared category sizes, shared fit descriptors, and agreement on (brand, size) fit-verdicts. No photos, no measurement inference, no AI or embeddings — everything is computed fresh on every read; there is no stored match-score table.
This is a separate consent layered on top of visibility, not a replacement for it. If your Fit Biodata visibility is private, opting in still makes you a matchable candidate — your aggregate match score and reasons become computable by shoppers you match with — but your raw Fit Biodata record stays hidden to them unless visibility separately allows it.
Your ranked Fit Twins list (Settings → Fit & sizing → Fit Twins) is the one place that names your twins — both parties have opted in. Everywhere else (the product page’s “fit twins on this item” section, the home feed tile) is aggregate-only— counts and verdict breakdowns, never a twin’s name. You can turn this off at any time from Fit & sizing settings; it is included in your data export and permanently deleted when you delete your account.
Fit reviews (size-confidence) — when you use this feature
Structured fit feedback you attach to a specific item and size: the size you bought, your usual size, a fit verdict (runs small / true to size / runs large), feel/material notes, whether it worked for your body/fit context, and an optional fit photo. The written parts are publicly visibleon the product page — both as individual reviews and aggregated into a size-confidence summary (such as “% true to size”) so other shoppers can judge fit. Any fit photo you attach is stored in secure, private storage and is only ever served via secure, time-limited access links, never a public link. Your fit reviews are included in your data export and are permanently deleted when you delete your account. Only you can edit or delete your own reviews.
Friend fit signal (when you’re signed in):the product page can show a mutual-friends-only line like “3 friends have this — runs small”. “Friends” means mutual follows only — the same definition used for friends-only ratings. It never names which friend, only a count and an aggregated verdict, computed fresh from your friends’ closet items, mock orders, and fit reviews. Nobody sees this about you unless they are your mutual friend, and even then only the aggregate — never that it was specifically you. Nothing new is stored for this.
Your own size hint (self-only):if you’ve submitted fit reviews before, the product page may show a one-line hint like “Based on your history: consider M” for items in a category you’ve reviewed before — computed from your own fit reviews only.
Wardrobe / Closet (when you use this feature)
Product names, sizes, purchase prices, and purchase dates you add to your personal wardrobe. Items can be sourced from photos you upload or manual entry — the two working ways to add an item today. Connecting your email inbox directly (Gmail OAuth) and scanning a care/size label are not yet built and are not offered in the app.
Wardrobe photos (photo upload feature):when you upload a photo to identify a garment, the photo is sent to OpenAI (model gpt-5-nano) to identify the item and match it to our catalog. Its handling once it reaches OpenAI is governed by OpenAI’s own API data policies, not by Muse. What Muse itself does: the photo is not stored— it is discarded after identification and never written to our database. The wardrobe displays the matched catalog product’s image instead, so no user-uploaded photo is ever persisted or shown on Muse.
All closet data is private to your account — it is never publicly visible. Your wardrobe data (items, sizes, prices, dates, wear logs, outfits, outfit layouts, and outfit wear logs) is included in your data export and is permanently deleted when you delete your account. You can delete any individual item at any time from your wardrobe.
From your wardrobe’s contents we derive a style profile— vibe descriptors matched from your items’ visual style, tag and garment-type breakdowns, and a taste embedding. It is visible only to you and is used only to personalize your own feed, search, and discovery results. It is recomputed from your current wardrobe — removing items updates it — and is removed along with your account.
When you tap “Log wear” on a wardrobe item, we record the date. This wear history powers a cost-per-wear figure (purchase price divided by times worn), a closet dashboard(spend by category, cost-per-wear leaders, unworn “dead stock” purchased 30+ days ago), and a wardrobe-gap nudge (garment types you own none of, with a few catalog suggestions) — all visible only to you. We also compare your own wardrobe items’ style against a product you’re viewing to show “you already own something similar”; this search never leaves your own closet and never reads another user’s items. Your wear logs are included in your data export and are permanently deleted when you delete your account.
Closet-aware recommendations (self-only):a product page can show up to 4 of your own closet items that visually match that product (“Works with your closet”). This only ever shows you your own items — nobody else’s closet is compared against a product on your behalf, and your closet is never shown to anyone else this way either.
Outfits (the collage builder):you can arrange your own closet items into named outfit boards — each item’s position, size, and stacking order on the canvas is stored so your layout is exactly what you see next time. Outfits are private to your account and never shown to anyone else. Logging a wear on an outfit also logs a wear on every item in it, so cost-per-wear stays accurate. Your outfits, their collage layout, and their wear history are included in your data export and are permanently deleted when you delete your account.
Shopping agents (when you use this feature)
A shopping agent works a brief — a vibe you asked it to hunt for, or a gap it noticed in your wardrobe. To notice things it reads only your own closet: garment types you own none of, categories where a couple of items absorb almost every wear, seasons your closet barely covers, and items bought 30+ days ago you have never worn. Each of those observations is stored with the evidence behind it, a confidence value, and an expiry, and is visible only to you.
What a brief finds is stored as a finding: the catalog item, its score, the breakdown behind that score (how well it matched, whether it duplicates something you already own, whether it fills a gap, how many mutual friends loved it), and any loved / fine / no feedback you give it. Findings are pinned to a secret board the agent creates for that brief — only you, and anyone you later invite to that board, can see it. The agent never creates a public board, never posts anywhere else on your behalf, and never buys anything.
An item can be nudged up because people you are in a mutual follow with rated it “loved” — and only when that rating is friends-visible, the same rule that applies everywhere else ratings appear. You are shown a count, never who rated it, and a private rating is never used at all.
You control how much the agent may do unasked with an autonomy dial, set separately for hunting, watching, and retiring. Even at its most permissive it is inward-only: it can file a brief for you or create a secret board, nothing outward-facing. Watchingsends you price alerts on items you have watched — an all-time low, a restock, or a “sale” measured against a price the item rarely holds — and at its most permissive it also starts watching items you save. Retiring suggests mutual friends whose taste matches a piece you never wear; they are told nothing, and see nothing, unless you message them yourself. Every autonomous act is written to an append-only log — what it did, which brief and signal it concerned, and the autonomy level that allowed it — so you can audit it after changing the dial. Both your signals and this action log are visible to you in the app, not just in your data export. By default the agent searches our own catalog only. When external search is enabled, a brief that comes up short internally may also query a small set of commerce APIs (Shopify, eBay, Etsy) — and only the text of that brief (the search phrase and garment type) is sent. Your identity, closet, taste data, and everything else about you never leaves Muse. Once a week, if the agent did anything, you get a wardrobe report summarizing your own agent activity (also readable in-app at any time); an agent push notification names no items or prices; and your home feed may show a tile of your agent’s recent finds. All of it is included in your data export and is permanently deleted when you delete your account.
Shoppable content (when you save or upload content)
When you upload closet or outfit images, we compute a style embedding from the image and match it against our shoppable catalog to show where to buy the exact item or similar ones. The image, its embedding, and the matched destinations are stored. Closet content is private to your account; creator and lifestyle content is public. Your content is included in your data export and is permanently deleted when you delete your account.
When you click a “Buy this exact item” or “Shop the vibe” link, we log the click (destination, provider, and — while signed in — your user ID) so we can measure which content drives shopping. On account deletion your user ID is stripped from these logs; the anonymous click event is retained for analytics.
Outfit Composer (when you use this feature)
Body measurements you enter or have estimated from a photo — chest, waist, hips, inseam, shoulder, and height — are stored as whole centimetres, one record per account. All fields are optional; you may supply only the dimensions you know. You can update your measurements at any time, or delete them entirely, from Outfit Composer settings.
Photo for sizing: if you upload a photo to have your measurements estimated, the photo is sent to OpenAI for analysis and then immediately discarded — it is never stored in our database, on disk, or in any storage bucket. Only the extracted numbers are offered back to you; whether you save them is your choice.
Try-on rendering: outfit previews are generated by sending a generic, neutral base figure image and catalog product images to OpenAI. Your photo or likeness is never sent for rendering. Generated previews are cached and shared across all users — they carry no personal information and are not part of your account data or export.
Daily render limit:to control the cost of the rendering call, each account is limited to a number of real renders per day (cached renders don’t count against it). We store a single counter per account — today’s count, a lifetime total, and the date it resets — with no render content, garments, or images. It resets automatically every day and is included in your data export.
Your measurements are included in your data export and are permanently deleted when you delete your account. You can delete them at any time from Outfit Composer settings.
Ask Your Friends — buy/skip votes (when you use this feature)
“Should I buy this?” lets you ask a subset of your mutual friends (up to 20) to vote buy it / skip it on an item, with an optional short prompt and optional per-vote comments (up to 500 characters). An ask and its votes are visible only to the asker and that ask’s recipients — no one else can see them, and there is no public tally anywhere on Muse.
Sending an ask also drops a chat message (with the vote card) into your DM with each recipient; casting a vote notifies the asker via their activity inbox. Your asks, who you sent them to, and every vote you cast are included in your data export and are permanently deleted when you delete your account.
The Second Opinion panel on a product page (whether the item matches your derived taste, aggregate fit consensus, whether your friends have saved or rated it, sale-price context, and overlap with items already in your closet) reads only data described elsewhere on this page — it stores nothing new.
Aggregated product reviews (across retailers)
To help you judge fit and quality, Muse aggregates publicly availablereviews for a product from across retailer sites into computed insights on the product page — a fit consensus (e.g. “68% say runs small”), aspect sentiment, and brand or brand-category patterns. In this preview the corpus is a synthetic, clearly labelled demo set.
Reviewer identities are never stored — any author reference is reduced to an irreversible hash at ingest. We do not republish full review text; the page shows only aggregates and links back to the original sources. This is third-party catalog data, not tied to your account, and is not part of your personal data export.
Push notifications (opt-in only)
If you turn on notifications in Settings, your browser generates a push subscription (a delivery endpoint plus encryption keys) which we store so we can send you a notification when the app is closed — a new message, a fitting-room or board invite, or a new follower. No message/board/poll content is ever includedin a push — only a sender’s display name and a generic action (e.g. “sent you a message”). You can turn notifications off at any time, which deletes the stored subscription. Push sends are always best-effort: a failed send never affects your account or data.
Per-category preferences:once notifications are on, you can separately turn off pushes for chat, boards, social (new followers), Fitting Room, or agents from five sub-toggles in the same settings section. We store only which categories you’ve turned off (one boolean per category, on by default) — no other content.
Activity & analytics
A log of your actions (saves, follows, ratings, etc.) used to build your home feed and activity inbox. Recent searches, including a Fitting Room’s shared, committed search (see below). Fitting-room session data if you use co-shopping rooms — for rooms with more than two people and different room modes (co-shop, outfit check, drop watch party), this includes your buy-it / skip-it votes on candidate items, any items staged in the room’s shared group cart, items pinned to the room’s shared reference rail (attributed to whoever pinned them — see Home pins above), your love it / it’s okay / pass takes while in the room, and the room’s currently-committed shared search. All of this is visible only to that session’s participants — never public. Anonymous behavioral events that may carry no user identity when you are not signed in.
Taste-blend ranking— while you’re in a Fitting Room, the shared feed’s ranking blends every active participant’s derived taste profile and style vector into one formula. Your co-shoppers never see your raw profile, only its effect on what the room’s feed shows everyone.
Exporting the group cart to a boardis a single shared action for the whole session: the first participant to export it creates one board (containing every item ever staged in the cart) and every participant who was ever active in the session is added to it as an accepted collaborator, so all of them can find it afterward. Exporting again — by anyone, at any time — returns that same board rather than creating another one. From that point on the board follows normal board visibility rules (secret — its owner and accepted collaborators, i.e. the room’s participants, can view and add to it).
Topic Pulse— a “what's new” digest for topics you follow (new catalog arrivals, newly attached public boards, and matching activity from people you follow). It's computed at read time from data already covered above — no new data is collected or stored. Strictly self-only, and friend-activity entries follow the exact same visibility rules as your activity feed.
Provenance reasons on the feed and vibe search
When you’re signed in, the feed and vibe search may show a short reason under an item — “Saved by 2 friends”, “Matches your board Coastal”, or “Matches your taste in dresses” — explaining why you’re seeing it (at most one reason per item). These are computed fresh on every request from data already described above (mutual follows, your own boards, your derived taste profile) — nothing new is stored. A friend-save reason never names which friend, only an aggregate count from public boards.
Ask your people
From a product page you can ask up to 4 people “should I get this?” — this sends the item into chat with a fixed “Get it / Skip it” poll, using the same “Help me pick” poll infrastructure described under Messages above. No new data model: it’s an ordinary poll and message, with the same participant-only visibility, export, and deletion rules as any other chat poll.
Taste-twin discovery (opt-in)
A setting (default off) that lets people whose derived taste profile is similar to yours discover you in their “People you may know” suggestions.
Strictly opt-in and symmetric: turning it on only ever surfaces you to (and only ever shows you) other people who have alsoturned it on. If you never opt in, you neither appear in nor see this section — including when you have no derived taste profile yet. Suggestions never disclose your email, only your display name and avatar.
Connected apps (ChatGPT, Claude, and other AI assistants)
You can connect a third-party AI assistant to your Muse account so it can work with your Muse data on your behalf. Nothing is ever connected for you: a connection exists only if you went through the approval screen yourself and granted it.
Data you share with a connected app leaves Muse.When you approve a connection, everything covered by the permissions you granted is sent to the company that runs that app — OpenAI for ChatGPT, Anthropic for Claude — and from that point on it is governed by their privacy policy and terms, not this one. We cannot control what they do with it, and we cannot take it back. Only connect an app you trust.
You choose what it can reach.The approval screen lists each permission separately and you grant them one by one: search the catalog and read product details; see your boards and their pins; add and remove items on your existing boards (never create, rename, or delete a board); see your cart; add and remove items in your cart (never check out); see your wardrobe style profile — vibes, tags, and garment mix, no photos; add, correct, and remove wardrobe items; and see a summary of your style preferences. An app can never be granted more than you approve.
What a connected app can never reach, at any permission:your password, your messages, your product photos, fit-review photos or fit-check images, your body measurements, your Fitting Room sessions, anyone else’s data, and the raw numbers behind your taste profile.
Disconnecting is immediate.We re-check your approval on every single request an app makes, so disconnecting takes effect on that app’s very next request — you never have to wait for anything to expire. Disconnecting also invalidates the keys that app was issued. We keep the app’s name, the permissions you granted, and when you granted and last used it; that is included in your data export and is permanently deleted when you delete your account. The app’s keys and tokens are never part of your export — we store them only as irreversible hashes, never in readable form. To see and disconnect your connected apps, go to Settings → Privacy.
We log what a connected app does.Every action an app takes on your behalf is recorded: which app, which action, which item it touched, whether it succeeded, and when. We record the item’s id and never what you searched for, wrote, or looked at — that column can only hold an id, so content cannot end up there even by mistake. This log is in your data export and is deleted with your account.
Recommendations & advertising
Ranking is never sponsored.No item, board, or person is ever promoted in your feed, vibe search, or people-you-may-know because someone paid for placement — there is no concept of a paid rank boost anywhere in this product. What you see is driven only by catalog freshness/quality, your own derived taste profile, and the trust-graph signals above (friend saves, board matches, mutual follows) — explained to you via the provenance reasons feature, not left as an opaque black box.
Outbound retailer links (“Buy this exact item”, “Shop the vibe”, product hand-off) may route through an affiliate network so Muse can earn a commission if you purchase — see Affiliate shopping links below. By default no affiliate network is contacted. Whenever a link genuinely is commission-wrapped, the product page labels it plainly (“Retailer link — we may earn a commission”); the label is driven by a live check, so it never appears when it isn’t true, and it never influences which items you see or how they’re ranked.
Third parties
We work with a small set of trusted service providers to operate Muse:
- Authentication and account services — we use a third-party authentication service to manage sign-in securely. Your password is never stored by Muse directly.
- Hosting and infrastructure — our app and databases are hosted by cloud infrastructure providers. Your data is stored in their secure, access-controlled data centers.
- Error monitoring — when an unhandled error occurs, an error report is sent to our monitoring service. This report includes the error details and a non-reversible internal identifier — never your email address or personal information.
- OpenAI (wardrobe photos and Outfit Composer) — OpenAI receives data in three narrow contexts: (1) Wardrobe photo identification — when you upload a photo to identify a garment, it is sent to OpenAI (gpt-5-nano) to match it to our catalog; the photo is discarded immediately and never stored by Muse. (2) Outfit Composer sizing — if you upload a sizing photo, it is sent to OpenAI for measurement estimation and discarded immediately; only the numeric results are returned and only if you choose to save them. (3) Outfit Composer rendering — a generic neutral base figure and catalog product images are sent to OpenAI to generate an outfit preview; your photo or likeness is never sent for rendering.OpenAI API inputs are not used to train OpenAI’s models under its standard API data-usage policy; standard API data retention applies. How OpenAI handles received data beyond that is governed by OpenAI’s own API terms.
- Connected apps (ChatGPT, Claude, and other AI assistants) — if you connect a third-party AI assistant, the data covered by the permissions you granted is sent to the company that runs it (OpenAI for ChatGPT, Anthropic for Claude) and is governed from then on by their privacy policy and terms, not ours. Nothing is sent unless you approve the connection yourself, you pick which permissions to grant, and you can disconnect at any time — see Connected apps above.
- Affiliate shopping links— “Buy this exact item” and “Shop the vibe” links may route through an affiliate network so we can earn a commission if you purchase. The network receives only the destination URL. We do not send your name or email. By default no affiliate network is contacted — links go directly to the retailer.
We do not sell your data, share your personal information with advertising networks, or send your personal data to any other third party.
Controls you have
| Control | Where |
|---|---|
| Delete your product photos | Product page — delete button on each photo |
| Board visibility (public / secret) | Board settings |
| Rating visibility (friends / private) | Ratings page — toggle per item |
| Contact matching | Community page — opt-in only |
| Push notifications | Settings → Account |
| Taste-twin discovery (opt-in) | Settings → Account |
| Download all your data | Settings → Privacy |
| Delete your account | Settings → Privacy |
| Edit or delete your fit reviews | Product page → your review |
| Fit Twins opt-in | Settings → Fit & sizing |
| Edit or delete height, sizes, measurements, fit visibility | Settings → Fit & sizing |
| Watch or unwatch an item | Product page / Watchlist page |
| Dismiss the “rate this” reminder (snoozes 7 days) | Reminder banner — dismiss button |
| Delete your body measurements (Outfit Composer) | Outfit Composer settings |
| See which apps you've connected | Settings → Privacy → Connected apps |
| Disconnect a connected app | Settings → Privacy → Connected apps — effective on that app's next request |
Account deletion
When you delete your account all of your data is permanently removed from our database. Content you contributed to shared boards (pins, notes) may remain on those boards but will no longer be linked to any identity.
Your authentication record is currently retained after you delete your account; signing back in with the same email will create a fresh, empty account. Full authentication-record deletion is planned for a future update.