Privacy

Muse is a personal curation app. You control what you collect; we store only what the product needs to work.

What we store

Account

Your email address (provided when you sign in) and a display name derived from it. A one-way HMAC hash of your email is kept for contact matching — the hash cannot be reversed back to your address. A unique @username handle — auto-assigned when you sign up and yours to change afterward — public and searchable so others can find and look up your profile by name on the platform (by id or by username, either resolves to the same profile). You may also set an optional bio and style preferences in onboarding — your bio is public, shown as the tagline on your Style Profile to any signed-in viewer.

You can also choose a featured board— one of your own public boards, shown as the anchor of your Style Profile. Only a board you own and that is currently public can be featured; if you later make it secret it stops appearing there. It’s cleared automatically if you delete the board, and removed with your account.

An internal is_seed flag marks house/founding-member curation accounts used to seed community content. It is not personal data and is never returned in any API response; it is included in your account export if it applies to your account.

Social graph

Who you follow, which topics you follow, and which boards you collaborate on. The topics you follow are shown as vibe tags on your Style Profile, visible to any signed-in viewer.

Content you create

Boards and pins, notes, pin comments, reactions, item ratings, personal tags, and cart items. Comments you leave on a board item inherit that board’s visibility — comments on a secret board are only visible to its collaborators. Your ratings are visible to friends only — never public.

Home pins (personal tray)

A small personal tray on your home feed — up to 6 items you pin for quick reference. This is separate from saving an item to a board and from your cart, and it’s private to you — no one else can see or change it. Pinning and unpinning are both idempotent, so repeating either action is always safe.

If you use a Fitting Room (co-shopping session), that has its own separate, shared pin set that starts empty each session — your personal tray is unaffected either way. Unlike your personal tray, a room’s pins are not private: they persist after the session ends so the room’s recap can show them, and they’re visible to (and included in the data export of) anyone who was ever an active participant in that room, attributed to whoever pinned each item.

Your personal pins are included in your data export and are permanently deleted when you delete your account.

Board invite links

A board owner can generate a shareable, unguessable link to invite someone to collaborate — no email required, and it works for people who don’t have a Muse account yet. Anyone holding the link sees a minimal preview (the board’s name, cover image, and the inviter’s display name) — never the board’s pins or member list. Signing in and accepting reaches the same board-collaborator relationship as an email invite. Links default to a 14-day expiry and unlimited uses; the owner can set a shorter expiry or a use limit, and can revoke a link at any time. Links you create are included in your data export and keep working after you delete your account — a link grants access to the board, not to you personally.

Decision engine — takes, “should I get this?” polls, and connections

On any pin you can view, you can leave a quick love it / it’s okay / pass “take” — one per pin, changeable any time. Anyone who can already view that board (a collaborator, or anyone on a public board) can see the aggregate counts, your own take, and up to 4 recent takers’ avatars. No notification is sent for a take — it’s a quiet, inline signal only.

You can start a “should I get this?” poll on a pin you can view. Board members see the full poll — tallies, comments, and voter names for voters who can also independently view the board. Each poll also gets a unique, unguessable link so you can invite someone who isn’t a board member to vote — that link view shows only the item, the question, and tallies, and never reveals the board itself; a vote cast via the link renders to board members as “via link” unless that voter can also independently see the board. Starting a poll is visible under the same rule as a save to that board — never leaked from a secret board. The poll’s creator gets a notification the first time each friend votes (re-votes don’t re-notify).

On a product page or pin you may see “Saved by N people” and a “styled with” strip of frequently co-pinned items. This is computed live from public boards only — a pin on a secret board is never counted or shown here.

Your takes, polls, and poll votes are included in your data export and are permanently deleted when you delete your account.

Living boards — price tracking & bought/tried marks

Each pin snapshots the item’s price at the moment you save it. At read time we compare that snapshot to the item’s current price to show a price-drop badge on the pin, a board-level digest (price drops / out of stock / dead links), and a soft “if you bought this board” running total on the board page. This is a passive, read-time comparison — it does not track anything about your browsing outside Muse.

You can mark a pin Bought or Tried, with an optional short note. This mark is visible to anyone who can already view the board — a mark on a secret board is never leaked to non-collaborators, the same as a save to that board. Marking a pin Bought (only when you’re the person who originally saved it) creates a mock order for that item in your account, so it can appear in your own “rate from your orders” queue — see Order history below. Your price snapshots and outcome marks are included in your data export and are permanently deleted when you delete your account.

Order history (demo data)

Muse has no real checkout. The order history that powers “rate from your orders” is either seeded demo data or created automatically when you mark a board pin Bought (see Living boards above). Every order row is explicitly labeled as mock — it never represents a real purchase, payment, or retailer transaction. Your order rows are included in your data export and are permanently deleted when you delete your account.

Messages

Direct conversation threads, message text, and per-conversation read state. “Help me pick” polls you create or vote in are a structured message — visible only to that conversation’s participants, like any other message.

Contacts (opt-in only)

If you choose to match contacts, we store salted HMAC hashes of the emails you upload — never the raw addresses. You can skip this entirely; it has no effect on the rest of Muse.

Derived taste profile

From your existing engagement signals (saves, shelf adds, ratings, personal tags, and topic follows) we derive a taste profile: your top categories and brands with normalized weights, plus the aesthetic tags you engage with. It is computed on the fly from those signals — nothing extra is collected or stored. The profile is used to rank your feed and vibe-search results, and responses say so whenever it was applied. It is strictly self-only: only you can see your own taste profile, never other users. Room exception:while you’re in a Fitting Room, ranking for that room’s shared feed blends your taste signals with your co-shoppers’ (see Fitting Room below) — a computed ranking input only, never a readable value, and it stops applying the moment you leave or the session ends. The same summary is included in your data export, and deleting your account removes everything it is computed from.

Personalization style vector

From the visual style of items you have loved, saved, shelved, or rejected, we compute a numeric style vector that captures your aesthetic preferences. This is used to personalize your feed ranking and vibe-search results — feed responses say so whenever personalization was applied. It is strictly self-only, with the same Fitting Room exception as the derived taste profile above: the vector and its metadata are scoped to your account and are never visible to other users, only ever consumed as one input to a blended room-ranking formula.

Your data export includes a human-readable summary — whether a vector exists, how many signals shaped it, its version, and its explainable categorical complement — but never the raw numeric array itself, which is meaningless outside the model. This data is permanently deleted when you delete your account.

Browsing as a guest

You can browse the full Muse feed, search, and product pages without an account. When you tap something that needs an account — Save, Follow, New board — or view a product page while signed out, we remember the item locally in your browser only (a small, capped list; nothing is sent to us). If you then sign up or sign in, that local list is claimed into your new account: items you tried to save are recorded as loved, just like the taste-calibration picks above, so your feed is personalized from your very first session. Nothing is stored on our servers about your guest browsing until you create an account.

Product photos you upload (when you use this feature)

Photos you tag to a specific product on Muse (up to 5 per product, ≤8 MB each, JPEG/PNG/WebP). These photos are publicly visible— they appear on the product page, on boards containing that product, and on your profile's “Photos” tab. Photos can be reported by other users; after 3 distinct reports a photo is automatically hidden. Photos are automatically reviewed for relevance (not content moderation). If a photo is flagged it will be hidden; you can contact us to appeal. You can delete any photo at any time from the product page. All product photos — including the stored image files — are permanently deleted when you delete your account.

Watchlist and price history (when you use this feature)

If you watch an item, we store that you’re watching it (and when you started). Your watchlist is private — never visible to other users. You can unwatch an item at any time from the product page or your Watchlist page.

When a watched item’s price drops or it comes back in stock, we surface an alert in your activity inbox. Every fact shown (current vs. lowest/highest/median price over the last 90 days, whether it’s an all-time low, how often the merchant runs sales) is plain arithmetic computed from prices we’ve actually observed — never a prediction or forecast.

Item price history itself is catalog data, not tied to your account — it is not part of your data export and is not affected by account deletion. Your watchlist is included in your data export and is permanently deleted when you delete your account.

Fit Biodata (when you use this feature)

Self-reported fit context you enter (usually during onboarding, or any time from Fit & sizing settings): height, your usual sizes by category, body/fit descriptors, and optional body measurements (chest, waist, hips, inseam). Each record has a visibility control — private (default; only you), friends (you and mutual followers), or public— enforced at the query layer, so a record that isn’t visible to a viewer simply looks like it doesn’t exist. Your Fit Biodata is included in your data export and is permanently deleted when you delete your account. You can update or delete it at any time.

Size guidance (when you view a product)

On a product page, we can recommend a size using only data described elsewhere on this page — your Fit Biodata’s usual size for that item’s category, that item’s public fit-review consensus, and (only if you’ve opted in) your Fit Twins consensus. Height and measurements are used only to raise or lower our confidence in the recommendation, never to calculate it. This introduces no new stored data — it is a read-only computation, requires you to be signed in, and if you haven’t set up a fit profile yet we say so and link you to Fit & sizing settings instead of guessing.

Fit Twins (size-match network) — when you opt in

A separate opt-in flag on your Fit Biodata (off by default). Opting in matches you with other opted-in shoppers using a deterministic, categorical score — height band, shared category sizes, shared fit descriptors, and agreement on (brand, size) fit-verdicts. No photos, no measurement inference, no AI or embeddings — everything is computed fresh on every read; there is no stored match-score table.

This is a separate consent layered on top of visibility, not a replacement for it. If your Fit Biodata visibility is private, opting in still makes you a matchable candidate — your aggregate match score and reasons become computable by shoppers you match with — but your raw Fit Biodata record stays hidden to them unless visibility separately allows it.

Your ranked Fit Twins list (Settings → Fit & sizing → Fit Twins) is the one place that names your twins — both parties have opted in. Everywhere else (the product page’s “fit twins on this item” section, the home feed tile) is aggregate-only— counts and verdict breakdowns, never a twin’s name. You can turn this off at any time from Fit & sizing settings; it is included in your data export and permanently deleted when you delete your account.

Fit reviews (size-confidence) — when you use this feature

Structured fit feedback you attach to a specific item and size: the size you bought, your usual size, a fit verdict (runs small / true to size / runs large), feel/material notes, whether it worked for your body/fit context, and an optional fit photo. The written parts are publicly visibleon the product page — both as individual reviews and aggregated into a size-confidence summary (such as “% true to size”) so other shoppers can judge fit. Any fit photo you attach is stored in secure, private storage and is only ever served via secure, time-limited access links, never a public link. Your fit reviews are included in your data export and are permanently deleted when you delete your account. Only you can edit or delete your own reviews.

Friend fit signal (when you’re signed in):the product page can show a mutual-friends-only line like “3 friends have this — runs small”. “Friends” means mutual follows only — the same definition used for friends-only ratings. It never names which friend, only a count and an aggregated verdict, computed fresh from your friends’ closet items, mock orders, and fit reviews. Nobody sees this about you unless they are your mutual friend, and even then only the aggregate — never that it was specifically you. Nothing new is stored for this.

Your own size hint (self-only):if you’ve submitted fit reviews before, the product page may show a one-line hint like “Based on your history: consider M” for items in a category you’ve reviewed before — computed from your own fit reviews only.

Wardrobe / Closet (when you use this feature)

Garment photos you upload, product names, sizes, purchase prices, and purchase dates you add to your personal wardrobe. Items can be sourced from photos you upload, receipt emails you forward or paste, or manual entry — the three working ways to add an item today. Connecting your email inbox directly (Gmail OAuth) and scanning a care/size label are not yet built and are not offered in the app. All closet data is private to your account — it is never publicly visible. Closet items are included in your data export and are permanently deleted when you delete your account. You can delete any individual item at any time from your wardrobe.

From your wardrobe’s contents we derive a style profile— vibe descriptors matched from your items’ visual style, tag and garment-type breakdowns, and a taste embedding. It is visible only to you and is used only to personalize your own feed, search, and discovery results. It is recomputed from your current wardrobe — removing items updates it — and is removed along with your account.

When you tap “Log wear” on a wardrobe item, we record the date. This wear history powers a cost-per-wear figure (purchase price divided by times worn), a closet dashboard(spend by category, cost-per-wear leaders, unworn “dead stock” purchased 30+ days ago), and a wardrobe-gap nudge (garment types you own none of, with a few catalog suggestions) — all visible only to you. We also compare your own wardrobe items’ style against a product you’re viewing to show “you already own something similar”; this search never leaves your own closet and never reads another user’s items. Your wear logs are included in your data export and are permanently deleted when you delete your account.

Closet-aware recommendations (self-only):a product page can show up to 4 of your own closet items that visually match that product (“Works with your closet”). This only ever shows you your own items — nobody else’s closet is compared against a product on your behalf, and your closet is never shown to anyone else this way either.

Shoppable content (when you save or upload content)

When you upload closet or outfit images, we compute a style embedding from the image and match it against our shoppable catalog to show where to buy the exact item or similar ones. The image, its embedding, and the matched destinations are stored. Closet content is private to your account; creator and lifestyle content is public. Your content is included in your data export and is permanently deleted when you delete your account.

When you click a “Buy this exact item” or “Shop the vibe” link, we log the click (destination, provider, and — while signed in — your user ID) so we can measure which content drives shopping. On account deletion your user ID is stripped from these logs; the anonymous click event is retained for analytics.

Ask Your Friends — buy/skip votes (when you use this feature)

“Should I buy this?” lets you ask a subset of your mutual friends (up to 20) to vote buy it / skip it on an item, with an optional short prompt and optional per-vote comments (up to 500 characters). An ask and its votes are visible only to the asker and that ask’s recipients — no one else can see them, and there is no public tally anywhere on Muse.

Sending an ask also drops a chat message (with the vote card) into your DM with each recipient; casting a vote notifies the asker via their activity inbox. Your asks, who you sent them to, and every vote you cast are included in your data export and are permanently deleted when you delete your account.

The Second Opinion panel on a product page (whether the item matches your derived taste, aggregate fit consensus, whether your friends have saved or rated it, sale-price context, and overlap with items already in your closet) reads only data described elsewhere on this page — it stores nothing new.

Aggregated product reviews (across retailers)

To help you judge fit and quality, Muse aggregates publicly availablereviews for a product from across retailer sites into computed insights on the product page — a fit consensus (e.g. “68% say runs small”), aspect sentiment, and brand or brand-category patterns. In this preview the corpus is a synthetic, clearly labelled demo set.

Reviewer identities are never stored — any author reference is reduced to an irreversible hash at ingest. We do not republish full review text; the page shows only aggregates and links back to the original sources. This is third-party catalog data, not tied to your account, and is not part of your personal data export.

Push notifications (opt-in only)

If you turn on notifications in Settings, your browser generates a push subscription (a delivery endpoint plus encryption keys) which we store so we can send you a notification when the app is closed — a new message, a fitting-room or board invite, or a new follower. No message/board/poll content is ever includedin a push — only a sender’s display name and a generic action (e.g. “sent you a message”). You can turn notifications off at any time, which deletes the stored subscription. Push sends are always best-effort: a failed send never affects your account or data.

Per-category preferences:once notifications are on, you can separately turn off pushes for chat, boards, social (new followers), or Fitting Room from four sub-toggles in the same settings section. We store only which categories you’ve turned off (one boolean per category, on by default) — no other content.

Activity & analytics

A log of your actions (saves, follows, ratings, etc.) used to build your home feed and activity inbox. Recent searches, including a Fitting Room’s shared, committed search (see below). Fitting-room session data if you use co-shopping rooms — for rooms with more than two people and different room modes (co-shop, outfit check, drop watch party), this includes your buy-it / skip-it votes on candidate items, any items staged in the room’s shared group cart, items pinned to the room’s shared reference rail (attributed to whoever pinned them — see Home pins above), your love it / it’s okay / pass takes while in the room, and the room’s currently-committed shared search. All of this is visible only to that session’s participants — never public. Anonymous behavioral events that may carry no user identity when you are not signed in.

Taste-blend ranking— while you’re in a Fitting Room, the shared feed’s ranking blends every active participant’s derived taste profile and style vector into one formula. Your co-shoppers never see your raw profile, only its effect on what the room’s feed shows everyone.

Exporting the group cart to a boardis a single shared action for the whole session: the first participant to export it creates one board (containing every item ever staged in the cart) and every participant who was ever active in the session is added to it as an accepted collaborator, so all of them can find it afterward. Exporting again — by anyone, at any time — returns that same board rather than creating another one. From that point on the board follows normal board visibility rules (secret — its owner and accepted collaborators, i.e. the room’s participants, can view and add to it).

Topic Pulse— a “what's new” digest for topics you follow (new catalog arrivals, newly attached public boards, and matching activity from people you follow). It's computed at read time from data already covered above — no new data is collected or stored. Strictly self-only, and friend-activity entries follow the exact same visibility rules as your activity feed.

Provenance reasons on the feed and vibe search

When you’re signed in, the feed and vibe search may show a short reason under an item — “Saved by 2 friends”, “Matches your board Coastal”, or “Matches your taste in dresses” — explaining why you’re seeing it (at most one reason per item). These are computed fresh on every request from data already described above (mutual follows, your own boards, your derived taste profile) — nothing new is stored. A friend-save reason never names which friend, only an aggregate count from public boards.

Ask your people

From a product page you can ask up to 4 people “should I get this?” — this sends the item into chat with a fixed “Get it / Skip it” poll, using the same “Help me pick” poll infrastructure described under Messages above. No new data model: it’s an ordinary poll and message, with the same participant-only visibility, export, and deletion rules as any other chat poll.

Taste-twin discovery (opt-in)

A setting (default off) that lets people whose derived taste profile is similar to yours discover you in their “People you may know” suggestions.

Strictly opt-in and symmetric: turning it on only ever surfaces you to (and only ever shows you) other people who have alsoturned it on. If you never opt in, you neither appear in nor see this section — including when you have no derived taste profile yet. Suggestions never disclose your email, only your display name and avatar.

Recommendations & advertising

Ranking is never sponsored.No item, board, or person is ever promoted in your feed, vibe search, or people-you-may-know because someone paid for placement — there is no concept of a paid rank boost anywhere in this product. What you see is driven only by catalog freshness/quality, your own derived taste profile, and the trust-graph signals above (friend saves, board matches, mutual follows) — explained to you via the provenance reasons feature, not left as an opaque black box.

Outbound retailer links (“Buy this exact item”, “Shop the vibe”, product hand-off) may route through an affiliate network so Muse can earn a commission if you purchase — see Affiliate shopping links below. By default no affiliate network is contacted. Whenever a link genuinely is commission-wrapped, the product page labels it plainly (“Retailer link — we may earn a commission”); the label is driven by a live check, so it never appears when it isn’t true, and it never influences which items you see or how they’re ranked.

Third parties

We work with a small set of trusted service providers to operate Muse:

  • Authentication and account services — we use a third-party authentication service to manage sign-in securely. Your password is never stored by Muse directly.
  • Hosting and infrastructure — our app and databases are hosted by cloud infrastructure providers. Your data is stored in their secure, access-controlled data centers.
  • Error monitoring — when an unhandled error occurs, an error report is sent to our monitoring service. This report includes the error details and a non-reversible internal identifier — never your email address or personal information.
  • Email receipt import (optional, coming soon) — automatic import by connecting your email account is planned but not yet built (no third party is contacted today). What works right now is forwarding or pasting an order-confirmation email yourself from the wardrobe page: we parse only the text you provide and store only the extracted line items (product name, size, price) — never the raw email body.
  • Affiliate shopping links— “Buy this exact item” and “Shop the vibe” links may route through an affiliate network so we can earn a commission if you purchase. The network receives only the destination URL. We do not send your name or email. By default no affiliate network is contacted — links go directly to the retailer.

We do not sell your data, share your personal information with advertising networks, or send your personal data to any other third party.

Controls you have

ControlWhere
Delete your product photosProduct page — delete button on each photo
Board visibility (public / secret)Board settings
Rating visibility (friends / private)Ratings page — toggle per item
Contact matchingCommunity page — opt-in only
Push notificationsSettings → Account
Taste-twin discovery (opt-in)Settings → Account
Download all your dataSettings → Privacy
Delete your accountSettings → Privacy
Edit or delete your fit reviewsProduct page → your review
Fit Twins opt-inSettings → Fit & sizing
Edit or delete height, sizes, measurements, fit visibilitySettings → Fit & sizing
Watch or unwatch an itemProduct page / Watchlist page

Account deletion

When you delete your account all of your data is permanently removed from our database. Content you contributed to shared boards (pins, notes) may remain on those boards but will no longer be linked to any identity.

Your authentication record is currently retained after you delete your account; signing back in with the same email will create a fresh, empty account. Full authentication-record deletion is planned for a future update.

Last updated July 2026