← Back to Muse

GDPR Privacy Policy

Last updated: 28 May 2026 · Effective for users of Muse (lovemuse.app) located in the European Union, the European Economic Area or the United Kingdom.

This Policy explains how Muse ("we", "us", "our") processes personal data of users in the European Union ("EU"), the European Economic Area ("EEA") and the United Kingdom ("UK"), in compliance with Regulation (EU) 2016/679 ("GDPR") and, where applicable, the UK GDPR and the UK Data Protection Act 2018. Where you reside outside these jurisdictions, our PDPO Privacy Policy applies instead.

1. Who we are (Controller, art. 4(7) GDPR)

Muse operates as an online service available at lovemuse.app and via mobile applications. For the purposes of the GDPR we act as the data controller in respect of personal data we collect from you. We have not appointed a Data Protection Officer because our core activities do not require one under art. 37 GDPR, but you can reach our privacy contact at info@lovemuse.app.

2. Personal data we collect

We collect only the data we need to run the service:

We do not process special categories of personal data within the meaning of art. 9 GDPR (e.g. data revealing health, religion, political opinions). Note that dietary preferences are not, on their own, "special category" data, but we collect them only if you choose to provide them. We do not knowingly collect data from individuals under the age of 16 (art. 8 GDPR); some member states permit consent from age 13 — where this applies in your country, the lower age is observed.

3. Purposes and legal basis (art. 6 GDPR)

We process your personal data for the following purposes, on the following legal bases:

4. How we share data

We do not sell your personal data and we do not engage in advertising-driven profiling. We share data only as follows:

5. International transfers (Chapter V, art. 44–49 GDPR)

Some of our processors are located outside the EEA/UK, in particular in the United States, which is not subject to a current adequacy decision covering all sectors. Where this is the case, we rely on the European Commission's Standard Contractual Clauses ("SCCs", Commission Implementing Decision 2021/914) or the UK Addendum, together with supplementary measures (TLS encryption in transit, access controls, data minimisation). A copy of the relevant SCCs is available on request.

6. Retention (art. 5(1)(e))

We keep personal data only for as long as is necessary for the purposes set out above. When you delete your account, we delete or anonymise your personal data within 30 days, except where retention is required to comply with a legal obligation, to resolve disputes or to enforce our agreements. Backups containing residual copies are purged on a rolling 90-day cycle.

7. Security (art. 32)

We apply technical and organisational measures appropriate to the risk, including TLS 1.2+ for all traffic, hashed password storage (Django's PBKDF2 default), access controls on our infrastructure, rate-limiting on sensitive endpoints, and logging. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where feasible (art. 33) and inform affected users without undue delay where the breach is likely to result in a high risk (art. 34).

8. Accuracy (art. 5(1)(d))

You can edit most of your personal data directly from your profile screen. If any data we hold is inaccurate, please correct it in-app or write to us.

9. Your rights (art. 15–22 GDPR)

Subject to the conditions set out in the GDPR, you have the right to:

To exercise any of these rights, email info@lovemuse.app from the address linked to your account. We will respond within one month of receipt (extendable by two further months for complex requests, art. 12(3)). Exercising your rights is free of charge unless the request is manifestly unfounded or excessive (art. 12(5)).

10. Right to lodge a complaint (art. 77)

If you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the supervisory authority of your habitual residence, place of work or where the alleged infringement took place. A directory of EU authorities is available at edpb.europa.eu. For users in the UK, the supervisory authority is the Information Commissioner's Office (ICO) — ico.org.uk.

11. Changes to this Policy

We may update this Policy. Material changes will be notified in-app or by email at least 14 days before they take effect. Continued use after the effective date constitutes acceptance.

12. Contact

For any privacy-related question or to exercise your rights, contact us at info@lovemuse.app.