Privacy Policy

Muse · Last updated August 4, 2026

Muse is built to collect nothing about you. This policy explains the few points at which it touches a network, and what the optional collection-sharing feature does.

What the app collects

Nothing. Muse stores everything locally on your Mac. There are no accounts, no analytics, no telemetry, no advertising, and no tracking of any kind. The developer receives no data about you or your files.

When Muse connects to a network

There are four cases, and three of them only ever happen because you started them:

  • App updates. Muse checks for updates and downloads them over HTTPS. No personal data is sent beyond what any HTTPS request inherently reveals to the host serving the file, such as your IP address. Updates are cryptographically verified before installing.
  • Sharing a collection (optional, you initiate). When you sign in to Google and press Publish, the images you selected and the text you typed are uploaded to your own Google Drive, under your own Google account. The developer never receives these files or any information about them. Your use of Google Drive is governed by Google’s own Privacy Policy.
  • Announcements (optional, on by default). Once per launch, Muse fetches a single small static file containing any current notices. The request sends no information about you or your library, and the session is discarded afterwards. Turning announcements off in Settings disables the fetch itself — it does not merely hide the result.
  • The on-device search model (optional, you initiate). Muse can offer to download a model that lets you search photographs by what they look like. It downloads only if you accept the offer, its contents are verified against a known checksum before being unpacked, and it then runs entirely on your Mac. Nothing you search is ever transmitted.

That is the complete list. Nothing else in Muse opens a network connection.

How sharing a collection works

The link can feel like magic, so here is exactly what happens, step by step. The short version: the images go to your Google Drive, the captions ride inside the link, and the people who make Muse never see any of it.

  • You sign in to your own Google account. Muse uses Google’s standard sign-in (OAuth, with PKCE and no shared secret stored in the app). It asks for the narrowest possible permission — drive.file — which lets Muse see and manage only the files it creates in your Drive. It cannot read, list, or touch anything else you keep there. The resulting access token is stored in your Mac’s Keychain, on this device only; it is never written to logs, never synced, and signing out revokes it.
  • Muse uploads the images to your Drive. The pictures you selected are copied into a tidy folder in your own Drive, named for the collection and date. They live under your account and count against your storage — the developer has no copy and no access. Every image is stripped of its embedded metadata first, and the strip is verified before the upload proceeds; a file that cannot be verified clean stops the whole publish.
  • Muse builds the link. The title, the per-image captions, the layout, and the IDs of the uploaded images are bundled into a small manifest. That manifest is encoded and compressed into the part of the URL after the # — the “fragment”. By web standards a fragment is never sent to the server that hosts the page, so the host never learns your captions or which images you shared.
  • You send the link. However you send it — Messages, email, anywhere — is your choice and outside Muse.
  • The recipient opens a plain static page. The page is a fixed file on Cloudflare Pages with no database, no API key, and no secret. Their browser reads the manifest from the link, then loads each picture directly from your Google Drive via Drive’s own image links. The page runs under a strict content-security policy and treats everything in the link as untrusted text, so a tampered link cannot do more than show garbled text.
  • The recipient can print it to a PDF. “Save as PDF” uses their browser’s own print, at whatever paper size they pick. Muse does not generate or upload a PDF.
  • You stay in control. Take a share down anytime from Muse’s Manage Drive Shares, which deletes the Drive folder it made, or delete the folder yourself in Drive. Muse also sweeps expired shares for you.

The share web page

A share link opens a static page hosted on Cloudflare Pages. A few things are worth being clear about:

  • Hosting logs. As the host, Cloudflare may process standard technical request data — such as IP address, browser type, and timestamps — to operate and secure the service. We do not add cookies, analytics, or trackers, and we do not use this data to identify or profile anyone.
  • The collection details stay out of the server’s reach. The link carries the collection’s contents in the URL fragment, which by web standards is not sent to the server. The page host therefore does not receive your images or text.
  • Images load from Google. The pictures are loaded directly from Google Drive into the viewer’s browser; that loading is subject to Google’s Privacy Policy.
  • Two local preferences. The page remembers a chosen background shade and grid density in your browser’s local storage. They never leave your device.

What recipients of a link can see

A share link reveals the images and captions you chose to include — that is its purpose. One point is worth being explicit about: because the images live in your own Google Drive under your own account, a recipient who opens a shared image in Google Drive, or looks it up through Google’s Drive tools, can see the name and profile photo of the Google account you published from. This is how link sharing works for any file in Google Drive, and it is outside Muse’s control — Google offers no way to share a file anonymously. The Muse share page itself never shows your account; this only surfaces if a recipient deliberately looks the file up in Google Drive. If you would rather not reveal your identity, publish from a separate Google account created for sharing.

Your control over shared content

Anything you share lives in your own Google Drive. You can delete it there at any time, and Muse’s Manage Drive Shares lets you unpublish a share.

Children

Muse is not directed to children and does not knowingly collect personal information from anyone.

Changes

We may update this policy. The date above reflects the current version.

Contact

Questions about privacy: carlostarrats00[at]gmail.com (replace [at] with @).

Terms of Use →