Privacy Policy
How Muzings collects, uses, and protects personal data. Structured to meet GDPR Art. 13/14 and CCPA disclosure requirements.
Last updated: 2026-08-20
Who we are (the controller)
Muzings LLC (“Muzings,” “we,” “us”) is the data controller for the personal data described in this policy. We are a limited liability company registered in California, USA (entity no. B20260172274), with our registered office at 6615 Fathom Way, Goleta, CA 93117, USA.
For any privacy question, or to exercise the rights set out below, contact us at hello@muzings.ai.
We have not appointed a Data Protection Officer, and we have no establishment in the EU or UK requiring a representative. Privacy questions go to the address above and are handled by the operator directly.
What data we collect
We group the personal data we process into three categories.
- Account data. Your email address and name, an account identifier from our sign-in provider, and — if you choose to give them — your country and organisation. Also your own settings: language, theme and colour preference, whether the daily review is on, and a profile image if you upload one.
- Content you create. The notes you write, and anything the service derives from them so it can find them again — titles, categories, tags, the people and places named in them, due dates and reminders. Photographs and screenshots you capture, and the text read out of them. When you capture a photo we also read the date it was taken from the image and use it as the note's date, so a screenshot saved three weeks ago is dated three weeks ago and any relative date written in it ("next Tuesday") resolves against when the photo was taken. That single tag is the only camera metadata we keep — the image's GPS coordinates and device serial number are destroyed before the photo is stored or sent anywhere. Voice recordings you dictate, and their transcripts. Files you attach.
- Technical and usage data. Your IP address, device and browser information, your time zone, and activity logs of your sign-ins and requests. If you enable notifications on a phone, tablet or watch, the push token that identifies that device. Records of when a note was recalled or acted on, which is how the service decides what to resurface.
Why we process it (legal bases)
Under the GDPR we rely on one or more of the following legal bases, depending on the purpose.
- Performance of a contract. To provide the service you have signed up for and to operate your account.
- Legitimate interests. To secure the service and investigate unauthorised access, to prevent abuse and keep one account's usage from degrading the service for others, and to diagnose faults and improve how well the service finds your notes — each balanced against your rights. We keep an internal assessment of these interests and that balance, and review it whenever the processing changes.
- Consent. Where we ask for it, for example for non-essential cookies or optional communications. You can withdraw consent at any time.
- Legal obligation. To comply with laws that apply to us, for example tax, accounting, or lawful requests.
How long we keep it (retention)
We aim to keep personal data only for as long as necessary for the purpose it was collected, then delete or anonymise it.
- Account data — kept while your account is active, then deleted or anonymised after a short closure period, unless a longer period is required by law (for example tax or accounting records).
- Content you create — kept while your account is active, and deleted after you delete your account or make a valid erasure request. Backups cycle out on their own schedule, so a copy can persist in backups for a short time after that.
- Technical and usage data / logs — operational logs are kept only as long as we need them to run and debug the service. Security and audit logs are kept longer, because investigating a security incident depends on being able to look back beyond it.
- Voice samples for the “Hey Muzings” wake word — if you opt in to the separate collection described below, those recordings are kept for 180 days from the day you agree, then deleted, whether or not your account is still open. This is the one fixed retention window in this policy: it is a defined period rather than “while your account is active” because the recordings exist for a single, finite piece of work, not to run your account. You can delete them sooner from the app at any time.
Who we share it with
We use a small number of third-party processors to run the service, each under contract and only for the purposes we set. The current list — with purpose, data shared, and processing region — is published on our Subprocessors page. That page also names the third parties your own browser or phone reaches on your behalf (for example your device's built-in speech recognition), which we do not engage and cannot instruct, so you can see those flows too.
Push notifications. If you turn the daily review on and allow notifications, we send your reminder through your platform's push service — Firebase Cloud Messaging on Android. That means the notification we send, including the title of the note being resurfaced, passes through Google along with your device's push token. There is no way to deliver a notification to a phone without going through the platform's push service, so if you would rather your note text not travel this way, turn the daily review off in your profile and none is sent.
California residents (CCPA/CPRA). We do not sell your personal information, and we do not “share” it for cross-context behavioural advertising, as those terms are defined under California law — so no “Do Not Sell or Share My Personal Information” action is needed to stop such activity. In the preceding 12 months we have disclosed the categories of personal information described above (identifiers, customer content, and internet/usage activity) only to the service providers listed on our Subprocessors page, solely so they can operate the service on our behalf.
AI processing of your content
Muzings is an AI product: to file, recall, and answer questions about your notes, we send the content you submit to the AI providers listed on our Subprocessors page — Anthropic for text generation, chat answers, and ranking your notes for recall; Google’s Gemini API for capture-time enrichment of unfamiliar terms, including the web search that grounds it; and OpenAI for semantic-search embeddings and voice transcription. We share only what a given feature needs, attributed to your account. Where a feature draws on publicly available information (for example a web search to identify an unfamiliar name in a note), we may use that public information freely.
Photos and screenshots. When you capture an image, the image itself is sent to an AI provider to be read — that is what turns a photo into a note, so there is no version of the feature that keeps the picture on our servers. Every captured image goes to Google’s Gemini API first, together with any note you typed alongside it. If that first pass cannot read the image reliably, the image is sent to an Anthropic model at higher resolution to try again; most captures never reach that second step. Before either happens, the image is rebuilt from its raw pixels, which destroys the GPS coordinates and device serial number your camera embedded — those are never transmitted.
Voice. In a desktop browser, the audio is sent to OpenAI to be transcribed. On a phone we use your device’s own speech recognition first — Google’s on Android, Apple’s on iOS — and that audio goes to Google or Apple under your own relationship with them, not under our agreements. If your device’s speech recognition is unavailable or fails, the app falls back to sending the audio to OpenAI so your capture is not lost.
- In the mobile app, identifiers are replaced on your device before we receive the note at all. When you type or dictate a note in the Muzings app for Android or iOS, the app finds email addresses, phone numbers, payment-card and government ID numbers, IP addresses, and people’s names in that text and replaces each one with a placeholder before the note leaves your phone — so the identifier is not something we mask after receiving it, it is something we never receive. What we store is the placeholder; the list that maps a placeholder back to the real value stays on your device, encrypted under a key we cannot read, and is readable only there. This is the strongest protection described on this page and it is also the narrowest, so here is exactly what it does not cover: not photos or screenshots (as described above, the image and any note attached to it are sent as they are), not voice audio (which your device’s own speech recognition has already processed, as described above — it is the resulting text that is protected), not the web app at muzings.ai, where notes are protected by the masking described in the bullets below instead, and not anything the app does not recognise as an identifier, which is sent to us as you wrote it. The rest of this section describes what happens to everything the app did not replace.
- We mask personal identifiers before text-generation AI sees them. Before your text is sent for AI text generation and chat answers, we use machine-learning detection to replace high-risk identifiers — names of people, email addresses, phone numbers, government ID numbers, and payment-card numbers — with placeholders, and restore the real values only in the reply, on our own servers. Names use a stable per-account placeholder so the AI can still connect your notes about the same person without ever seeing who they are. This is masking (pseudonymisation), not encryption, and it is not end-to-end encryption. One narrow exception is described in the next bullet.
- One exception: the names of public things are looked up on the web as written. When a note mentions something we do not recognise — a film, a product, a company, a place, an event — we look that name up on Google Search, so the note can be found later by what it is about rather than by the exact words you used. A search only works if the real name is sent, so for those particular words the placeholder is removed. This is deliberately narrow, and here is the whole of it. Only the individual names are sent that way — the note itself is not sent with the search at all, not even masked. Earlier versions of Muzings did send the surrounding note text alongside the name; they no longer do. A name is sent only if a second, separate classifier independently identifies it as a public work, product, organisation, place or event. A person's name is never sent to a web search — nor is an email address, phone number, payment-card or government ID number, and those cannot be sent by this path whatever else goes wrong, because the system refuses to unmask them regardless of what asks it to. The honest limit is the one stated above: deciding that a name is a company rather than a person is a machine-learning judgement, and it can be wrong. If you would rather we did not do this, turn off “Recognise what you mention” in your profile: with it off, no name is ever unmasked for a search.
- If masking is unavailable, the AI request does not run either. Rather than quietly sending your text unmasked when the detection service is down or unreachable, we refuse the AI call and surface the failure — so a masking outage costs you a feature for a few minutes, never your privacy. One honest limit remains: detecting a name in free text is a machine-learning judgement, so it can occasionally miss one. Structured identifiers (email addresses, phone numbers, card and ID numbers) are additionally matched by fixed patterns that do not depend on that judgement.
- Name masking only works in English and Spanish. The detection service we use supports those two languages only. If you write a note in another language — including Telugu or Hindi, whether in their own script or typed in Latin letters — we cannot detect the names in it, so names in that note are sent to the AI as you wrote them. We do not block the request in this case, because this is a permanent limit of the detection service rather than a temporary outage, and refusing would mean those languages simply never work. Everything else still applies: email addresses, phone numbers, card and ID numbers are matched by fixed patterns that work in any language and are still masked, and the note is still covered by the no-train, retention and access-control protections below.
- Three paths are not masked at all: embeddings, voice, and images. To make recall work, the text of your notes is sent to the embeddings provider as written. Voice recordings are sent to the transcription provider as recorded. And captured images are sent as pixels, together with any note you typed alongside them — a photograph cannot be masked, and the note you attach to it travels with it. These three paths are covered by the no-train, retention, and access-control protections below rather than by masking.
- Remaining content is processed under the protections below. Places and the body of your notes are sent to the AI as written — the AI needs them to be useful — and are protected by the no-train, retention, and access-control measures in this section rather than by masking.
- Not used to train AI. The content we send to Anthropic, OpenAI and Google’s Gemini API is not used to train their models — those commercial APIs exclude API inputs and outputs from model training, and for Gemini we call it on a paid-tier project where that commitment applies. This covers the providers we engage. It does not cover your device’s own speech recognition: when Chrome, Android or Safari transcribes your voice, that audio goes to Google or Apple under your relationship with them, on their terms, and we are not in a position to make commitments about it.
- Retention at the provider. Each provider processes your content under a data-processing agreement with us, which governs how long they may keep it. We do not publish a per-provider retention period here, because we will not state a figure we have not verified against the signed agreement.
- Minimised in our own logs. Our internal AI-call ledger stores your prompts and the AI’s replies with personal-data shapes masked by default, and can be configured to store no content at all.
- No end-to-end encryption. Because the service reasons over your content on our servers and at the AI provider, your data is encrypted in transit and at rest and is logically separated per account, but it is not end-to-end encrypted — which would make these AI features impossible.
We do not use your content to build advertising profiles, and we do not sell it.
Voice samples for the “Hey Muzings” wake word
Separately from everything above, we may invite you to record yourself saying the phrase “Hey Muzings” a number of times, so that the app can learn to notice the phrase and be started hands-free. This is optional and nothing is recorded unless you read the disclosure and agree to it first. Declining changes nothing else about the app, and you can delete everything you have recorded at any time from Settings → Privacy. It is described here in its own section, rather than folded into the paragraphs above, because a new category of personal data should not be something anyone learns about after the fact.
If you do take part, this is the whole of it.
- What is recorded. Short clips of the phrase being spoken, a small number of deliberately similar-sounding phrases, and — if you choose to add one — a recording of the room with nobody speaking. Nothing is recorded unless you press the button for that clip, and the microphone is not opened until you do.
- What it is used for. Training the “Hey Muzings” wake word, so the app can tell when the phrase has been said out loud. That is the only purpose.
- What it is not used for. It is not speaker identification: the recordings are not used to identify you, to tell one person’s voice from another’s, or to decide anything about you. They are not used to train any other model, for us or for anyone else. They are not used for advertising or profiling, and they are not shared with any third party — the recordings stay in storage we run ourselves and the training runs on our own hardware, which is why this collection adds no new name to our Subprocessors page.
- How it is stored. Each recording is filed under a one-way pseudonym derived from your account identifier, and the stored recording carries no email address, name, account identifier or organisation. The pseudonym cannot be reversed and we keep no table mapping it back to an account; it is recomputed from your account only in order to find and delete your recordings when you ask us to, or when your account is erased.
- How long it is kept. 180 days from the day you agree, then deleted. The app shows you the exact date it will be deleted, calculated from the day you agreed rather than quoted from a page like this one.
- How to take it back. Two separate controls, because they do two different things. “Stop helping” withdraws your agreement, so nothing further is recorded — it does not, on its own, delete what you already gave us. “Delete my voice clips”, under Privacy in your settings, deletes the recordings themselves. Deleting your account deletes them too. In every case the audio is deleted, not flagged.
International transfers
Our infrastructure is hosted in the United States (Amazon Web Services, US-East-2 / Ohio), and the processors listed on our Subprocessors page are US-based. Where personal data is transferred from the EEA or the UK to the United States, we rely on the data-processing terms we have in place with each processor — which for our major providers incorporate the European Commission’s Standard Contractual Clauses — together with supplementary measures including encryption in transit and at rest. We are completing this paperwork provider by provider and will name the specific transfer mechanism per provider here once each is on file, rather than assert one in the abstract.
Our primary infrastructure provider, Amazon Web Services, also participates in the EU–U.S., UK Extension, and Swiss–U.S. Data Privacy Framework.
Your rights
Subject to applicable law, you may have the right to access, rectify, or erase your personal data, to data portability, to object to or restrict certain processing, and to withdraw consent. CCPA gives California residents comparable rights, including the right to know and to delete.
To exercise any of these, email hello@muzings.ai. If you are in the EEA or the UK, you also have the right to lodge a complaint with your local data-protection supervisory authority. Because we are established in the United States rather than the EEA/UK, the GDPR “one-stop-shop” lead-authority mechanism does not apply, so you may contact the authority in your country of residence.
How we protect it
We apply technical and organisational measures intended to protect personal data — including encryption in transit, access controls, and monitoring. A fuller, honestly-staged inventory of our controls is on the Trust Center.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above. If we make a material change we will email the address on your account and post a notice on this page, and the “Last updated” date above will change. Minor clarifications may be made with only the date changing.