Muza Privacy Policy

Last updated: 8 September 2026

Muza stores your library on your device, with optional sync through your own iCloud account. There is no Muza account or developer-operated server that stores your library. This policy covers the Mac and iPhone apps, the browser extension, and getmuza.app.

Who is responsible

Muza is provided by František Mastil, IČO 09515551, an independent developer based in the Czech Republic. For questions about your data, write to privacy@getmuza.app.

Your library

Images, videos, PDFs, SVGs, links and notes are stored in Muza’s own storage on your Mac or iPhone. The same applies to titles, summaries, tags, colour palettes, recognized text and search indexes that Muza creates from your content.

On macOS, Muza also registers your items with Spotlight when indexing is enabled. That search index stays on your device and is managed by the system. You can turn indexing off in Muza Settings.

If you enable iCloud sync, library content also travels through Apple’s CloudKit service into your own private iCloud database. This uses your Apple account and is subject to Apple’s terms. Muza does not send that library to a server operated by me.

You can manage and delete saved items in Muza. Copies you export, share or retain in device backups are separate copies, managed wherever you keep them.

On-device AI

Muza’s built-in tagging, summarizing, text recognition and semantic search run on your device, using Apple frameworks and models bundled with or downloaded into the app.

Muza does not send your saved content to an AI service for these features or use it to train models. Connecting another AI app is a separate, optional feature described below.

Network requests from the app

Muza’s app code contains no analytics, advertising or crash-reporting SDK. The app does not send me usage reports. Apple’s own system and App Store services operate under Apple’s policies and your settings.

Browser extension

The extension sends captures to the Muza app over a local connection on your Mac. That connection requires pairing with the app.

The extension also makes network requests to download media and import saved items from supported websites. It can use your existing browser session, including cookies and authentication headers, to retrieve content available to you on those sites.

The extension stores its Muza pairing token and integration data in browser extension storage. Integration data includes saved request information and authentication headers used by supported imports, and records of items already imported.

X and Instagram integrations can check for newly saved items in the background while Muza is running, using request information captured during browsing. These requests go to the source services; they are not sent to a server operated by me.

Resetting pairing in Muza revokes the extension’s access to the app. It does not sign you out of the source websites or erase their browser sessions. Your browser provides controls for disabling or removing the extension and managing its stored data.

Connecting other AI apps

MCP access is off by default. If you enable it and configure an AI client, that client can search your library, read saved content, and make supported changes such as saving items or updating tags.

Content available to a client can include images, notes and recognized text. The connection from Muza to the client runs locally on your Mac, but the client may send content to its own service or model provider under its own settings and privacy policy.

You can turn MCP access off or reset its access token in Muza Settings. This prevents further authorized access through that connection; it does not retrieve content a client has already received.

This website and launch notifications

If you submit your email address on getmuza.app, the website sends it to Resend to add it to the launch notification list. The signup flow also requests an immediate confirmation email. I use that list for the launch announcement only.

The form also carries an optional newsletter box, off by default. Ticking it adds your address to a second, separate list, and only that list receives anything beyond the confirmation and the launch announcement. Leaving it alone keeps you off it entirely.

Submitting the form again can request another confirmation. You can ask to be removed from the list by writing to privacy@getmuza.app.

Resend processes the contact and email delivery requests. The signup service records technical failures to help diagnose delivery or registration problems.

Cloudflare hosts the website and handles network requests, including the information needed to deliver a response to your browser. The website’s operational logging is enabled to help diagnose failures.

Some current website illustrations load from Picsum Photos. Your browser contacts that service and its image delivery infrastructure when those images are displayed.

The website source does not include advertising or behavioral analytics scripts. It does not set its own tracking cookies. Hosting, image delivery and email services still process the requests needed to provide their services.

Contacting me and your choices

If you email me, I receive your email address and the information you choose to include. That correspondence is separate from your Muza library.

You can contact privacy@getmuza.app to request access, correction or deletion of personal data I hold, or to leave the launch notification list. I cannot retrieve your device library or your private iCloud library for you.

Your rights depend on the data and circumstances. Under the GDPR, you may also complain to a supervisory authority. In the Czech Republic, this is the Office for Personal Data Protection; you can also contact the authority in your country.

Changes

The current shared policy for the apps and website is available at getmuza.app/privacy. If it changes, I will update the date above.

Contact

privacy@getmuza.app