Effective July 19, 2026. Last updated July 19, 2026.
1. What data we process
Account data: email, password hash, role, plan, sign-in log
(IP, browser, time), to operate and secure your workspace.
Platform connection data: Fanvue OAuth tokens (issued by the platform;
we never see your account password), model profile settings.
Chat and CRM data: chat messages, fan profiles, sales, processed on
your behalf and on your instructions (you are the controller, we are the
processor).
Metacleaner files: processed in memory to perform the operation and
not retained, except reference files you explicitly save as phone profiles.
Cookies: technical only: session (fv_session), trusted device
(fv_device), language (fv_lang). No advertising trackers.
2. Why
Providing the service: chat and sales automation, CRM, workspace analytics.
Response generation: chat text is shared with third-party AI model providers
strictly to the extent required to generate a reply.
We process data to perform our contract, for legitimate interests in service
security and improvement, to comply with law, and with consent where required.
Service providers may include Fanvue (connected platform), xAI (generation
and analysis), Google (OAuth, reCAPTCHA, and Maps), Telegram (optional operator
notifications), email delivery, hosting, and backup providers.
Where data is transferred outside the EEA, we rely on the contractual and
organizational safeguards available for the relevant provider.
4. Storage and protection
Workspaces are isolated; API keys are encrypted in the database; passwords
are stored only as strong hashes (scrypt).
Staff access to client data is restricted to those who need it to operate
and support the service.
Account, CRM, and chat data is kept until account deletion; sessions until
expiry or sign-out; temporary codes until expiry; security logs up to 12 months;
encrypted backups up to 30 days.
5. Your rights
You can export or delete data through the workspace settings/API, or email
support@muza.chat from your workspace email. Active
data is deleted immediately and backups age out within 30 days.
Subject to applicable law, you may request access, correction, deletion,
restriction, portability, object to processing, withdraw consent, and complain
to a competent data-protection authority.
We comply with GDPR; a DPA is available on request.