← Back to Muse

Privacy Policy

Last updated: 18 May 2026 · Effective for users of Muse (lovemuse.app).

Muse ("we", "us", "our") respects your privacy. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the rights you have. It is written to comply with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong ("PDPO") and the six Data Protection Principles ("DPPs") issued by the Office of the Privacy Commissioner for Personal Data, Hong Kong ("PCPD").

1. Who we are (Data User)

Muse is operated as an online service available at lovemuse.app and via mobile applications. For the purposes of the PDPO, we act as the Data User in respect of the personal data we collect from you. Contact details for privacy enquiries are set out at the end of this Policy.

2. Personal data we collect

We collect only the data we need to run the service:

We do not knowingly collect data from individuals under the age of 13. If you believe a minor has provided us with personal data, contact us and we will delete it.

3. Purposes of collection (DPP 1 & 3)

We collect and use your personal data for the following purposes:

We will not use your personal data for a new purpose that is materially different from those listed above without first obtaining your express and voluntary consent, as required by DPP 3.

4. How we share data (DPP 3)

We do not sell your personal data. We share it only in the following circumstances:

5. Cross-border transfer

Although Section 33 of the PDPO (regulating transfers of personal data outside Hong Kong) is not yet in force, we apply its spirit voluntarily. Where we transfer data to processors outside Hong Kong (for example, to AWS data centres in the United States or to Resend in the European Union / United States), we ensure that:

6. Retention (DPP 2)

We keep personal data only for as long as is necessary for the purposes set out above. When you delete your account, we delete or anonymise your personal data within 30 days, except where retention is required to comply with a legal obligation, to resolve disputes or to enforce our agreements. Backups containing residual copies are purged on a rolling 90-day cycle.

7. Security (DPP 4)

We apply reasonable and practicable security measures, including TLS 1.2+ for all traffic, hashed password storage (Django's PBKDF2 default), access controls on our infrastructure, rate-limiting on sensitive endpoints, and logging. No system is perfectly secure; if we become aware of a personal data breach that is likely to result in real risk of significant harm, we will notify affected users and, where appropriate, the PCPD without undue delay.

8. Accuracy (DPP 2)

You can edit most of your personal data directly from your profile screen. If any data we hold is inaccurate, please correct it in-app or write to us.

9. Your rights (DPP 5 & 6)

Under the PDPO, you have the right to:

To exercise any of these rights, email info@lovemuse.app from the address linked to your account. We will respond within 40 days, as required by the PDPO. We may charge a reasonable fee for compliance with a Data Access Request, in line with PCPD guidance.

10. Complaints

If you believe we have failed to comply with the PDPO, you may lodge a complaint with the Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD), 12/F, Sunlight Tower, 248 Queen's Road East, Wanchai, Hong Kong — www.pcpd.org.hk.

11. Changes to this Policy

We may update this Policy. Material changes will be notified in-app or by email at least 14 days before they take effect. Continued use after the effective date constitutes acceptance.

12. Contact

For any privacy-related question or request, contact us at info@lovemuse.app.