Privacy Policy
Last updated: July 14, 2026
SnapMuse ("SnapMuse", "we", "us", or "our") is a bookmark and note assistant that helps video creators organize public inspiration and generate AI-assisted analysis. This Privacy Policy explains what data we collect, how we use it, where it is processed, and the choices and rights you have. We designed SnapMuse to be privacy-first: we collect the minimum data required to run the service, and we never sell your personal data.
1. Information We Collect
We only collect data that is necessary to provide the service. Specifically:
- Account information: when you sign in with Google, we receive your email address, display name, profile picture URL, and your Google account identifier (the "sub" claim). We do not receive your Google password.
- Public video metadata you choose to save: objective, factual metadata of publicly available videos, such as video title, text tags/hashtags, view/like/comment/favorite/share counts, background music (BGM) name, publish date, platform, and the video URL.
- Transcripts: when you request transcription, the speech-to-text conversion runs entirely inside your browser extension using Whisper WASM — your browser never sends any audio or video bytes to our servers. Only the resulting text transcript (with timestamps) is uploaded to our servers for storage and AI analysis. We never store, cache, or redistribute any audio or video files.
- Usage and billing data: subscription plan, quota usage counters, and payment records processed by our payment provider (we do not store full card numbers).
- Technical data: coarse region derived from your IP (for AI routing and PPP pricing), language preference, and session tokens.
2. Information We Do NOT Collect
To respect the privacy of third parties and comply with platform terms, SnapMuse strictly limits collection to objective, public metadata. We do not collect:
- Any audio or video file bytes — neither our browser extension nor our servers download, cache, or forward video/audio files for redistribution.
- Personal data of third parties appearing in videos, including usernames intended as private identifiers, private messages, or comment content.
- Portrait thumbnails are not persisted. Cover images are loaded on demand directly from the platform CDN and are never stored in our database.
- We never sell, rent, or trade your personal data to advertisers or data brokers.
3. How We Use Your Information
- To authenticate you and maintain your account and boards.
- To provide core features: saving inspiration cards, generating AI analysis reports, transcribing audio, and exporting content.
- To enforce usage quotas and process subscriptions and payments.
- To send service and account-related communications, including optional re-engagement emails (you can opt out).
- To maintain security, prevent abuse, and comply with legal obligations.
4. AI Processing and Cross-Border Data Transfers
In line with GDPR Article 44, we disclose our AI data-processing chain transparently. When you request an AI analysis, the text you provide (video metadata, transcript, and any optional product context) is sent to an AI model through the OpenRouter gateway, which returns structured text.
We route data by region to keep it compliant: data from users in the US, EU, and other Western markets is processed by models on US/EU-based infrastructure (e.g., GPT-4o-mini); data from Asia-Pacific users may be processed by DeepSeek V3. EU/EEA user data is never transferred directly to servers in mainland China. For EU/EEA users, we prioritize processing options with EU data residency where available.
Our operator’s administrative access to EU/EEA data is limited, encrypted, and used only for support and maintenance, consistent with the data-isolation approach above.
5. Third-Party Services
We rely on the following processors, each governed by its own privacy policy:
- Google (Sign-In / OAuth) — authentication.
- OpenRouter and the underlying model providers (e.g., OpenAI, DeepSeek) — AI text analysis.
- Creem — subscription billing and payment processing (Merchant of Record).
- Resend — transactional and re-engagement email delivery.
- Google Cloud Platform — application hosting (storage, API, and AI analysis). Speech-to-text transcription is performed locally in your browser extension and is not processed on our servers.
6. Cookies and Local Storage
We use strictly necessary cookies and browser local storage to keep you signed in (session tokens), remember your language preference, and store UI settings. These are essential for the service to function and do not require your consent under ePrivacy rules.
We use a privacy-friendly, cookieless analytics service (Cloudflare Web Analytics) to understand aggregate usage. It does not set cookies, does not identify you across sites, and is loaded without a consent banner. We do not use third-party advertising or cross-site tracking cookies.
7. Data Retention
We retain your account data and saved content for as long as your account is active. Transcripts and AI reports are retained to power your boards. When you delete a card, board, or your account, the associated data is deleted from our active systems within a reasonable period, subject to legal or accounting retention requirements for payment records.
8. Data Security
We protect data in transit with HTTPS/TLS and restrict access to production systems. Passwords are not stored for social login. No method of transmission or storage is 100% secure, but we take reasonable, industry-standard measures to safeguard your information.
9. Your Rights
Depending on your jurisdiction (including the EU/EEA under GDPR and California under CCPA), you have the right to:
- Access, correct, or delete your personal data.
- Export your data in a portable format.
- Object to or restrict certain processing, and withdraw consent at any time.
- Lodge a complaint with your local data protection authority.
10. Children's Privacy
SnapMuse is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us data, please contact us and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the "Last updated" date. Material changes will be communicated through the service or by email.
12. Data Controller and Contact
SnapMuse is operated by an individual, who acts as the "Data Controller" for the purposes of GDPR. [Operator legal name / trading name placeholder — to be completed before launch.] For questions about this Privacy Policy or to exercise your rights, contact us at privacy@snapmuse.app.
EU/EEA users: we currently rely on the GDPR Article 27(2) exemption (occasional, limited-scale, low-risk processing) and have not appointed a separate EU representative. You may exercise your rights and direct inquiries directly to the contact above. If this changes, we will update this section.